Generative AI has arrived in everyday work. Employees use tools for drafting, research, translation and communication, often without formal approval and without clear rules. What starts as a private productivity aid quickly becomes a company standard nobody ever decided on.

From an employment-law perspective this creates a regulatory vacuum with real risks. The employer carries responsibility for protecting business secrets, client data and personal data, even where the leak happens through a freely accessible AI tool. The employee's duty of loyalty (Art. 321a CO) helps little after the fact if nobody said beforehand what is allowed.

Three questions therefore belong in every company: First, which tools are approved for which tasks, and who decides on new ones? Second, which data may be entered, and which under no circumstances? Third, how are AI outputs checked before they are used towards clients, authorities or internally?

The employer's right to issue directives (Art. 321d CO) is the right instrument. An AI usage policy defines approvals, prohibited inputs, review duties and responsibilities, and makes violations actionable under employment law, from a warning to dismissal in serious cases. Without a policy, all that remains is the argument about what should have been \u201cobvious\u201d.

A blanket ban falls short. Whoever prohibits AI tools outright loses productivity and drives usage into the shadows, where neither control nor training happens. Better practice: a few approved tools, clear data rules, documented training and a contact point for new use cases.

Since August 2026 there is a further layer for companies with EU exposure: the EU AI Act requires, among other things, sufficient AI literacy of the people working with the systems. A clean internal policy with training records serves both purposes at once, employment law and regulation.

Our free AI usage policy template covers the standard case. We are happy to help adapt it to your industry, data categories and existing regulations, and with the delicate question of what should happen to the shadow usage that already exists.