Skip to main content
Open accessibility toolbar

AI tools have quietly become part of the HR toolkit. They help TA teams rewrite job ads at speed, summarise interview notes, sense-check policies, draft internal comms, and even brainstorm recruitment messaging. Used well, they save hours. Used carelessly, they can put your candidates, employees – and your employer brand – at serious risk.

And here’s the uncomfortable truth: HR teams handle some of the most sensitive data in the business. CVs, salary details, performance notes, medical adjustments, grievance records, workforce plans. Exactly the kind of information that should never end up inside a public AI model. So how do you get the benefits of AI without accidentally leaking people data? Let’s break it down.

Why AI risk looks different for HR and TA

Public AI tools are designed to learn. In many cases, that learning happens using the prompts people enter – unless you’re on a business-grade plan with the right safeguards in place.

That means:

  • Pasting a CV into an AI tool to ‘summarise key skills’
  • Asking AI to ‘rewrite interview feedback more professionally’
  • Dropping in headcount plans or restructuring scenarios for clarity

…could expose personally identifiable information (PII), confidential employee data, or sensitive business strategy.

This isn’t about bad actors. It’s about busy recruiters and HR partners trying to work faster – without clear guardrails. And when something goes wrong, it’s HR who deals with the fallout: loss of trust, regulatory risk, reputational damage, and very awkward conversations with the legal team.

The cost isn’t just financial – it’s trust

A people-data breach doesn’t just trigger compliance issues. It damages credibility. Candidates trust you with their career history. Employees trust you with deeply personal information. If that trust is broken – even accidentally – the impact on your employer brand can last far longer than any fine.

The widely reported Samsung incident in 2023 is a good reminder. Employees pasted confidential material into a public AI tool to ‘work faster’. No hacking. No malicious intent. Just a lack of policy, training, and technical controls – which ultimately forced the company to ban generative AI altogether.

For HR teams trying to modernise, that’s the worst-case scenario: AI becoming off-limits instead of well-governed.

Six practical ways HR & TA teams can use AI safely

1. Create an AI usage policy that actually reflects HR reality
Generic IT policies don’t cut it here. HR needs a clear, practical AI policy that spells out:

  • What counts as sensitive people data
  • What must never be entered into public AI tools (CVs, interview notes, salary data, DEI metrics, medical or performance information)
  • What is safe (anonymised data, templates, structure, tone, idea generation)

Make this part of onboarding for recruiters and HR partners – and revisit it regularly. AI usage evolves fast. Your guidance needs to keep up.

2. Use business-grade AI tools – not free public accounts
If your recruiters are using free AI tools, you’re relying on goodwill and settings most people don’t understand.

Business plans like ChatGPT Team or Enterprise, Microsoft Copilot, or Google Workspace AI come with contractual guarantees that your data won’t be used to train public models. That matters – a lot – when you’re dealing with candidate and employee data. This isn’t about ‘premium features’. It’s about creating a legal and technical barrier between your people data and the open internet.

3. Put guardrails in place with Data Loss Prevention (DLP)
Even with policies and training, mistakes will happen. That’s why HR teams benefit from Data Loss Prevention tools that can:

  • Detect when sensitive information is being pasted into AI prompts
  • Block or redact PII in real time
  • Flag risky behaviour before data leaves your environment

Tools like Microsoft Purview or Cloudflare DLP act as a safety net – especially helpful in high-volume recruiting teams where speed is everything.

4. Train HR teams on how to prompt safely – not just what not to do
‘Don’t do this’ training rarely sticks. Instead, run practical sessions where recruiters and HR partners learn:

  • How to anonymise CVs and interview notes
  • How to ask AI for structure, tone, or frameworks rather than content
  • How to sense-check AI outputs for bias or compliance risk

This turns AI safety into a skill – not a restriction – and helps teams work smarter without crossing lines.

5. Regularly review AI usage – without creating fear
If you’re using business-grade AI tools, you’ll have access to usage logs and admin dashboards. Use them. Not to catch people out – but to:

  • Spot patterns that suggest confusion or training gaps
  • Identify teams that might need extra support
  • Refine your policies as real-world usage evolves

Good governance feels collaborative, not punitive.

6. Build AI awareness into your HR culture
Policies and tools only go so far. The biggest shift happens when HR leaders:

  • Model good AI behaviour themselves
  • Encourage questions and uncertainty
  • Normalise saying “I’m not sure if this is safe – let’s check”

When AI safety becomes part of everyday HR decision-making, you reduce risk without slowing people down.

AI belongs in HR, but only if it’s used responsibly

AI isn’t going anywhere. And for HR and Talent teams under constant pressure to do more with less, it can be a genuine advantage. But when you’re handling people data, speed can’t come at the cost of trust.

With the right policies, tools, and training in place, HR teams can use AI confidently – protecting candidates, employees, and the employer brand they work so hard to build. If AI is shaping the future of work, HR needs to be leading the conversation – not cleaning up the mess afterwards.

Need a little help?

We hope you’ve found this article helpful. If you want help, support or even just a chat about this or any aspect of your employer brand or talent strategy, then drop us a line. Between you and I, much of our best work has started with a cup of tea, chocolate Hobnob and a video call.