Is AI at work dangerous? Six fears employers hear, and what UK law actually says
The office manager at a twelve-person roofing firm wants to paste the week's timesheet notes into ChatGPT to draft the overtime summary. The operations director says no, you'll get us fined. Out on the scaffold, one of the lads has heard that the new clock-in app "uses AI" and reckons it'll sack anyone who's late three times. Both of them are wrong. Not in the same direction, though.
Most of what people say about AI at work being dangerous mixes up three things: risks the law already deals with, rules the law has never made, and one or two duties that are real and get ignored because everyone was arguing about the rest. This guide takes the fears in the order people actually report them and puts each one next to the statute or the regulator's own words.
It isn't a case for switching AI on everywhere. Some of it is genuinely risky, and the riskiest parts are the boring ones.
What people are actually afraid of
In spring 2025 Acas had YouGov ask 1,023 employees in Britain what worried them most about AI at their workplace. Acas published the results in April 2025: 26% said job losses, 17% said AI making errors, 15% said it isn't regulated and 11% said data protection. Another 17% had no concerns at all. The employers' side of the same exercise found 35% expecting higher productivity, and 11% picking "more work done with fewer staff" as the main benefit, which rather explains the 26%.
The fears below follow that list, plus the two an employer hears from its own managers: "it'll discriminate and we'll get sued" and "it's illegal to put staff data into it".
| The fear | Verdict | Where the answer comes from |
|---|---|---|
| AI will take our jobs | Half true | Redundancy law, unchanged |
| AI will decide who gets sacked | Overstated | UK GDPR Articles 22A to 22C |
| It's illegal to put staff data into AI | Overstated, with a real catch | UK GDPR Articles 28, 30 and 35 |
| AI monitoring is unlawful | Overstated | ICO monitoring guidance |
| AI is biased and we'll be sued | Real, and it's yours | Equality Act 2010 |
| Nobody regulates it | Wrong | Existing law, a renamed regulator |
"AI will take our jobs"
This is the one the law says least about, because it was never designed to stop a business changing how it works. GOV.UK's guide to making staff redundant gives "doing things in a different way, for example using new machinery" as an ordinary reason for redundancy. Software counts. If an estimating tool does in an afternoon what a junior estimator did in a week, and you genuinely no longer need anyone doing that job, a redundancy is open to you.
What doesn't change is everything after that. GOV.UK says that for a redundancy to be genuine you must show the job will no longer exist, that employees have the right not to be unfairly selected, and that you must try to find them suitable alternative work. On consultation, its page on consultation is blunt: if you don't consult, any redundancies "will almost certainly be unfair". Propose 20 or more at one establishment within 90 days and the collective rules apply, with at least 30 days' consultation before the first dismissal (45 days for 100 or more) and form HR1 to the Redundancy Payments Service.
So the honest verdict is half true. AI can remove a job. It can't remove the procedure, and a firm that tells staff "the AI's doing it now" and stops there has handed them a tribunal claim. Acas's advice to employers is to consult before bringing AI in, and to remember that expecting a role to start using it could mean a change to terms and conditions.
"AI will decide who gets sacked"
The worry here is a machine taking a decision nobody can question. The law moved on 5 February 2026, and it's worth being precise about which way.
Section 80 of the Data (Use and Access) Act 2025 replaced the old Article 22 of the UK GDPR with Articles 22A to 22D. A solely automated significant decision, one with "no meaningful human involvement", is now allowed in general. But Article 22C says that where one is taken, the worker must be able to get information about it, make representations, get a person at the employer to intervene and contest it. Article 22B still restricts it outright where the decision rests on special category data, which includes a face match used to identify someone.
Put that next to the fear. Nothing in UK law lets software dismiss someone with no route back to a human. The employer is still the one who decided, and the one a tribunal asks about. Our guide to automated decisions about workers goes through what counts as meaningful involvement and which actions count as significant. The short version for this fear: a supervisor rubber-stamping forty flags on a Friday isn't a human decision, and having a name on the rubber stamp isn't a defence either.
Overstated, then. The real risk isn't that AI decides. It's that a manager lets it, and nobody notices until the claim arrives.
"It's illegal to put staff data into AI"
This is the operations director's objection from the opening, and as stated it's wrong. No provision of the UK GDPR mentions AI tools, and none bans putting personal data into one. What applies is what applies to any other software that handles staff information. There is a real catch, though.
When an outside company processes personal data for you, Article 28 of the UK GDPR requires you to use only processors giving "sufficient guarantees", under a contract that says what they may do with the data and binds them to act only on your documented instructions. A free consumer chatbot account, signed up with somebody's personal email, usually comes with the provider's standard terms and nothing more. That's the catch. The law isn't against the tool. It's against using one with no contract making the provider your processor.
Then there's the assessment. Article 35 requires a data protection impact assessment before processing that's likely to be high risk, and the ICO's guidance on AI accountability says that "in the vast majority of cases" the use of AI will trigger that requirement. The same page makes a point that cuts against the fear: whether a system using AI is more or less risky than one that doesn't "depends on the specific circumstances". AI isn't presumed dangerous. It's presumed to need thinking about first.
Acas's advice reads like a summary of all this: check with whoever runs your IT for approved platforms, and be careful entering anything personal or business-sensitive into public tools, because it could be made public or used by others. The roofing firm's office manager can draft the overtime summary with AI. Do it in a business account under a proper data processing agreement, keep names and pay figures out of the prompt, and most of the problem goes away.
"AI monitoring of staff is unlawful"
The ICO's monitoring guidance answers this one in its own words: "Data protection law does not prevent you from monitoring workers." You need a lawful basis. You have to tell people what you collect and why. And it has to be proportionate, which the guidance illustrates with a miner who'd reasonably expect a tracking device underground and an office worker who wouldn't.
Two parts of that guidance matter more than the word "AI". Consent is "not usually appropriate" at work because of the imbalance of power, so a signed form doesn't make monitoring lawful. And biometric data, such as a face match at clock-in, is special category data, which needs a separate condition before you start. Neither rule cares whether the system calls itself AI.
Overstated. Monitoring is lawful when it's proportionate and people were told, and unlawful when it isn't, exactly as before anyone sold it with the letters A and I on the box. Our GPS tracking guide works through the lawful basis, the impact assessment and the out-of-hours problem for location data.
"AI is biased, and we'll get sued"
This one is real. It's also the fear that usually gets pointed at the vendor, when the law points it at you.
Start with how bias gets in. The ICO's page on fairness, bias and discrimination explains that AI systems learn from data that may be unbalanced or reflect past discrimination, and that discrimination "can occur even if the training data does not contain any protected characteristics". A tool trained on years of a firm's own promotion decisions will learn whatever those decisions had in them. The ICO also keeps the two regimes apart: complying with data protection law "will not guarantee compliance" with the Equality Act, or the other way round.
Now the employer's position. Section 39 of the Equality Act 2010 bars an employer from discriminating in dismissal, promotion, training or by "any other detriment". Section 19 catches a "provision, criterion or practice" that puts people sharing a protected characteristic at a particular disadvantage, unless you can show it's a proportionate means of achieving a legitimate aim. A scoring rule built into software you chose to apply to your staff is very hard to describe as anything other than your practice. Section 109 makes you liable for what your employees do in the course of their work, whether or not you knew, and the only defence is having taken all reasonable steps to prevent it.
Two procedural points make this sharper than people expect. Under section 136, once a worker shows facts from which a tribunal could find discrimination, the burden moves to you to prove it didn't happen. A system you can't explain makes that very hard. And since 1 October 2026, under section 123 as amended, a claim can be brought up to six months after the act rather than three, for acts on or after that date (SI 2026/954). Section 124 ties compensation to what a county court could award, and the Act writes in no fixed ceiling.
The case people cite is real but often overstated. In March 2024 the Equality and Human Rights Commission announced that an Uber Eats courier, Pa Edrissa Manjang, had settled claims that the facial recognition checks on his work app were racially discriminatory. He'd been removed from the platform in 2021 after a failed recognition check and an automated process, and told only that there were "continued mismatches". It settled, so no tribunal ever ruled that the software discriminated. What the EHRC objected to was that he hadn't been told how the decision was made and had no effective route to challenge it. That's the lesson for a small firm: the claim got as far as it did because nobody could explain the system.
Real, then. It still isn't a reason to avoid AI. It's a reason to test a tool on your own staff data before trusting it, to keep a person between the tool and anything that touches someone's pay or job, and to be able to explain each decision in a sentence.
"Nobody regulates AI"
Search the titles of primary legislation on legislation.gov.uk for "artificial" (the search is public) and you get four Acts. The newest is the Food and Drugs (Milk, Dairies and Artificial Cream) Act 1950. The oldest exempted artificial mineral waters from stamp duty in 1833. There is no AI Act.
That's where the 15% are half right and still wrong. The UK hasn't written one law about the technology. It leaves it to the laws about what the technology does. A decision about a worker is covered by the UK GDPR and employment law. Discrimination is covered by the Equality Act, which applies however the outcome was produced. A redundancy is a redundancy.
The regulator changed this week, too. Section 118 of that Act abolished the office of Information Commissioner, and SI 2026/1015 brought that into force on 30 September 2026, passing its functions to the new Information Commission. Anything the ICO had started carries on. Its guidance on AI and on monitoring workers still sits on ico.org.uk, both pages with a banner saying they're under review because of the Data (Use and Access) Act, so expect them to change.
The dangers people don't mention
The 17% worried about AI making errors are closer to the real risk than anyone worried about killer robots. Acas puts it plainly: AI "is not perfect", so outputs should be checked for accuracy, tone and bias. At work the costly mistakes are small and dull. A summary that drops a worker's overtime. A letter drafted with the wrong notice period. A face check that fails one worker more often than the others because of the low sun at the site gate, and nobody spots the pattern because each failure got sorted on the day.
None of that makes the news. All of it turns up later as a pay claim or a grievance, and the defence is the same every time: somebody looked, and wrote down that they looked.
The paperwork that answers every fear
No statute sets a single "AI record", but the duties above add up to a short file:
- The data protection impact assessment, done before you start (Article 35(1)) and reviewed when the risk changes (Article 35(11)).
- A record of processing activities under Article 30. Firms with fewer than 250 staff are exempt only if the processing is occasional, unlikely to be risky and involves no special category data. Weekly AI use on staff records, or any face matching, takes most small firms out of the exemption.
- The processor contract with whoever provides the tool, meeting Article 28.
- A review log: each time a person checked or overturned what the system suggested about a worker, with the date and their name.
- Your AI policy, and a note of how you consulted staff before introducing it, which is what Acas recommends.
How long to keep it? Nothing fixes a period. Keep the impact assessment for as long as the system runs. For the review log the tribunal clock sets the floor: six months from the act for a discrimination claim, longer if a tribunal thinks that just and equitable, and section 123(3)(a) treats conduct extending over a period as done at the end of it. A scoring rule that runs every week is that kind of conduct. So keep the log for as long as the system is in use and for at least a year after you switch it off, and decide that once rather than case by case.
Common questions
Is it legal to use AI to make decisions about employees in the UK?
Yes. Since 5 February 2026, Articles 22A to 22D of the UK GDPR allow a significant decision about a worker to be taken with no meaningful human involvement, as long as safeguards are in place: the worker is told, can make representations, can get a person to intervene and can contest it. The restriction that survives covers decisions resting on special category data, such as a face match, and processing that relies on a recognised legitimate interest.
Can I put employee information into ChatGPT or another AI tool?
No law bans it, but the ordinary data protection rules apply. You need a lawful basis, the tool's provider has to be under a processor contract that meets Article 28 of the UK GDPR, and the ICO's guidance says most uses of AI on personal data will need a data protection impact assessment. A free consumer account usually gives you none of that, which is why Acas warns staff to be careful entering personal information into public tools.
Is AI monitoring of employees legal in the UK?
It can be. The ICO's monitoring guidance says data protection law does not prevent you from monitoring workers, but you need a lawful basis, you have to tell people, and the monitoring has to be proportionate. Consent is not usually the right basis at work because of the imbalance of power. Biometric checks such as face matching are special category data and need an extra condition.
Who is liable if an AI tool discriminates against a worker?
The employer. The Equality Act 2010 applies whether a person or a system produced the outcome. A scoring rule or an algorithm you apply to staff can be a provision, criterion or practice under section 19, and once the worker shows facts from which discrimination could be found, section 136 puts the burden on you to show it didn't happen.
How long does a worker have to bring a discrimination claim?
Six months from the act complained of, where that act happened on or after 1 October 2026. Before that it was three months. The tribunal can allow a longer period if it thinks that just and equitable, and conduct extending over a period is treated as done at the end of it.
Can I make staff redundant because AI now does their job?
Yes, if the job genuinely no longer exists. GOV.UK lists doing things in a different way, for example using new machinery, as a reason for redundancy. The normal rules still apply: fair selection, looking for suitable alternative work, consultation, and collective consultation if you propose 20 or more redundancies at one establishment within 90 days.
Is there a UK law that regulates AI?
There is no UK Act of Parliament about artificial intelligence as such. AI used on staff is governed by the laws that already apply to the decisions and the data: the UK GDPR and Data Protection Act 2018, the Equality Act 2010 and employment law. The data protection regulator has been the Information Commission since 30 September 2026, when the office of Information Commissioner was abolished.
What records should an employer keep about AI used on staff?
The data protection impact assessment, kept under review; a record of processing activities under Article 30 if the processing is not occasional or involves special category data, either of which removes the under-250 exemption; the processor contract with the AI provider; and a log of each time a person reviewed or overturned what the system suggested. No law sets a retention period for these.
Where hours fit in
Temporra records the hours people actually work: clock-in and clock-out against a job and a site, on a phone or a shared site tablet, with the location checked against the site's geofence at those two moments only. It sends alerts for things like late arrivals and overtime, and timesheets go to a manager to approve. It doesn't score or rank workers and it doesn't decide anything about them. Those calls stay with a person at your firm.
The face check is optional and needs each worker's explicit consent at setup. A face-matching model turns a live photo into a set of numbers and compares them with the template stored when the worker enrolled. It isn't a liveness test, so treat it as one control against buddy punching, not proof of identity, and there's a PIN route on the site kiosk for anyone who'd rather not use it. Temporra isn't payroll software (it exports hours to yours), and it doesn't build your rota.
Related guides
- AI and automated decisions about workers: what changed on 5 February 2026
- GPS Tracking of Employees: What UK Law Actually Allows
- How to Stop Buddy Punching on UK Construction Sites
- How to Track Employee Hours: A UK Small-Business Guide
No card needed for the trial. One flat monthly price by team size, from £39 for up to five workers, VAT included. See pricing.