What I Look At First When Reviewing an HR Team's Use of AI


This week I joined a webinar run by Hireful on using ChatGPT in recruitment.
I use AI most days, so I went into it wondering how much I'd actually learn. Would I pick up
anything new, or would I already know most of it?
Turns out, I learnt quite a bit.
A few new tips, some features I hadn't really explored properly and, probably most usefully, a different way of thinking about how I interact with the tool.
It was a good reminder of how ridiculously quickly all of this is moving.
Something I learnt six months ago might already be out of date. Features appear. Settings change. And tools I've previously written off have quietly got a lot better.
It's one of the reasons I started my own Training Tuesday. If I don't deliberately make time to keep learning, I know I'll fall behind.
But the webinar also got me thinking about something else.
We keep telling HR teams to experiment with AI. Get curious. Have a play. See what it can do.
And I completely agree.
But HR has an added complication. We hold some of the most sensitive information in an organisation.
So when I'm looking at how an HR team is using AI, I don't start with all the exciting things they could be doing with it.
I start with what they're already doing.
And these are some of the first questions I'd ask.
What are people actually using?
This can be quite revealing.
You might have Microsoft Copilot approved across the business, but that doesn't necessarily mean everyone is using it.
Someone might prefer ChatGPT. Someone else might be using Claude. And somebody might be putting something into a personal AI account on their phone because it's quicker and they haven't really thought about the implications.
That last one would immediately get my attention.
Because if employee information is being entered into a personal or unapproved account, you've potentially lost control of where that data is going, how it's being processed and who has access to it.
And most of the time I don't think this happens because somebody is deliberately ignoring the rules.
They're busy.
They've found something that makes a task easier.
And nobody has explained where the boundaries are.
You can't manage what you don't know is happening.
What does IT already allow?
I've learnt to ask this one early.
Some AI tools might already be blocked. Others may be approved but with certain restrictions. There might even be functionality available within systems you're already paying for that HR doesn't know exists.
Before looking at anything new, I want to understand what the organisation already has.
I've become quite convinced that the AI projects that work best are the ones where HR and IT talk to each other early.
HR understands the people, processes and risks. IT understands the technology, security and infrastructure.
Neither should be trying to do this in isolation.
Is there a policy, and does anyone know it exists?
I'm actually more interested in the second half of that question.
You can have a beautifully written AI policy sitting on the intranet.
If nobody knows it's there, it isn't doing very much.
Equally, having no guidance at all means people are making their own decisions about what's acceptable.
And when technology is moving this quickly, "use your common sense" probably isn't enough.
People need practical boundaries they can understand and actually use.
What information is going in, and who can see it?
This is probably the area I'd worry about most.
HR deals with names, salaries, sickness information, grievances, performance issues, disciplinary matters and all sorts of information that shouldn't casually be dropped into an unapproved AI tool.
But again, context matters.
Someone might think, "I'm not doing anything risky, I'm asking it to tidy up my grievance notes."
Except those notes contain names, allegations and potentially health information.
That's why training needs to go further than teaching people how to write a good prompt.
We also need to teach people what not to put into one.
And then I'd want to understand what happens to the information afterwards.
Where is it stored? Who can access it? Is it retained? Could it be used to improve or train the service?
The answers aren't necessarily the same across every AI tool, account type or organisational set-up.
It's worth knowing what you've actually signed up to.
Where does GDPR come in?
Quite early, ideally.
Employee data is personal data, and HR regularly handles special category data such as health information.
If you're going to use AI with employee information, data protection can't be something you think about once everything else has been built.
Depending on what you're doing and the level of risk involved, you may need a Data Protection Impact Assessment.
This is also where I'd bring in whoever is responsible for data protection in the organisation.
HR doesn't need to become the DPO, the IT department and the AI expert all at once.
But we do need to know when to bring the right people into the room.
How confident are people, really?
This week's webinar was a useful reality check for me.
I use AI pretty much every day and I still learnt things.
So I wouldn't expect an HR team to all be at the same level.
You'll probably have a mixture.
People who use it every day.
People who opened Copilot once, asked it a question, got a rubbish answer and haven't touched it since.
And people who are very confident using it but perhaps a little too confident in what it gives them back.
Those groups don't need the same training.
That's why I'd want to understand confidence and behaviour before deciding what support people need.
And finally, where is the time actually going?
This is the bit I really enjoy.
Because once you've understood the risks, the tools and how people are currently working, you can start looking at where AI could genuinely help.
Every HR team has those tasks.
The ones that don't look huge individually but somehow eat hours every week.
Chasing information. Copying things between systems. Pulling reports together. Drafting variations of the same document. Answering the same questions. Checking spreadsheets.
Preparing meeting notes.
That's where I start looking for opportunities.
Not "where can we use AI?"
But:
Where are we spending time that we don't need to be spending?
That's a much more useful question.
Where I've landed
I'm firmly in the camp that HR should be experimenting with AI.
We won't learn what works by sitting on the sidelines waiting for everything to settle down.
At the rate things are moving, we could be waiting a very long time.
But experimenting doesn't mean throwing everything into ChatGPT and hoping for the best.
There needs to be some structure around it.
Know what people are using.
Know where your data is going.
Give people sensible boundaries.
Understand their confidence.
Then start looking at where AI could genuinely make work better.
These are some of the areas I look at as part of my HR AI Review, because before I recommend what an HR team should do next, I want to understand where they actually are now.
If you'd like a fresh pair of eyes on how your HR team is using AI, you can find out more about my HR AI Review here.
And I'm curious.
If you asked your HR team these questions tomorrow, which one would you struggle to answer?



Comments