legal247

AI policy for employees: what can an employer require and monitor?

In brief

Under Norwegian law, an employer can set an AI policy for employees under its managerial prerogative, including bans on certain tools and requirements to check the output. Monitoring how employees actually use AI is a control measure that requires objective grounds, discussion with employee representatives and prior information. Continuous monitoring of individual use is generally prohibited.

Most employees already use AI at work, with or without their employer’s blessing. The question is therefore not whether the business needs rules, but how far the employer can go in setting and enforcing them. Under Norwegian law, the answer is that the employer has wide latitude to decide how AI is to be used, but far narrower scope to monitor each individual’s use.

What is an AI policy for employees?

An AI policy consists of written instructions on which AI tools employees may use, what the tools may be used for, which information must not be entered, and how the output must be checked before it is used. A good policy is short, specific and tied to the business’s actual tools and risks.

The policy serves three functions. It protects the business’s information, it allocates responsibility, and it gives the employer a basis for responding when something goes wrong. Without written rules, it is difficult to blame an employee for using a tool nobody said was prohibited.

The basis is the managerial prerogative (styringsretten), meaning the employer’s right to direct, allocate, organise and control the work within the limits of statute, collective agreements and the employment contract. Deciding which work tools are to be used, and how, lies at the core of the managerial prerogative.

The employer can therefore, without agreement from the employees,

  • ban certain AI services, for example free versions where the vendor may use the content to train its own models,
  • require that only approved tools covered by a data processing agreement are used at work,
  • prohibit personal data, customer information or trade secrets from being entered into tools not approved for that purpose,
  • require AI-generated content to be checked by a human before it is sent out, and
  • require the use of AI to be disclosed internally or to customers where relevant.

The line is crossed where the policy intrudes on the employee’s private life or involves monitoring of the individual. Separate rules then apply, as discussed below.

The need for rules is closely linked to the protection of the business’s secrets. Read more about why a lack of internal rules can weaken protection under the Trade Secrets Act in the article on trade secrets and AI.

When does monitoring AI use become a control measure?

Monitoring how an individual employee uses AI is a control measure under Chapter 9 of the Working Environment Act (arbeidsmiljøloven). This includes logging prompts, reviewing chat history, tools that capture what is pasted into online services, and spot checks of an individual’s use.

Under Working Environment Act § 9-1, an employer may only implement control measures that have an objective basis in the business’s circumstances and do not impose a disproportionate burden on the employee. The Personal Data Act (personopplysningsloven) applies to the processing of the information, with requirements for a legal basis, purpose limitation and data minimisation under GDPR Art. 5 and GDPR Art. 6.

Working Environment Act § 9-2 adds procedural requirements. The employer must, as early as possible, discuss the need for the measure, its design, implementation and any material changes with the employee representatives. Before the measure is implemented, the employees concerned must be informed of its purpose, its practical consequences and its expected duration. The need for the measure must be evaluated regularly together with the employee representatives.

An employer can decide almost everything about how AI is to be used, but little about watching what each individual actually does.

Can an employer monitor employees’ use of AI tools?

Not on a continuous basis. Email Regulation § 2(2) of the email regulation (e-postforskriften) states that the employer has no right to monitor an employee’s use of electronic equipment, including use of the internet. The only exceptions are administering the business’s computer network and detecting or investigating security breaches in the network. The Norwegian Data Protection Authority (Datatilsynet) emphasised this prohibition in guidance published in 2023.

In practice this means the following.

Measure Assessment
Blocking certain AI services on the network Normally permitted, as it is network administration and not monitoring of the individual
Technically preventing upload of classified documents Normally permitted as a security measure, but should be discussed and communicated
Aggregated usage statistics without personal identification Normally permitted
Alerts on suspected security breaches, with follow-up of a specific incident Permitted within the exception for security breaches
Systematic review of every employee’s prompts As a rule, prohibited monitoring
Access to one employee’s chat history on reasonable suspicion Only under the conditions and procedures in Email Regulation §§ 2 and 3

In several enterprise versions of AI assistants, prompts and answers are stored against the employee’s account, and in some cases in the employee’s mailbox. Whether such chat history is a “personal area” under Email Regulation § 1 has not been settled in the practice of the Norwegian Data Protection Authority or the Privacy Appeals Board (Personvernnemnda). The safest course is to treat it in the same way. Access then requires that it is necessary for the day-to-day operation of the business or other legitimate interests, or that there is reasonable suspicion of a serious breach of duty. The procedure is described in the article on when an employer can read an employee’s email.

The employer must also inform employees of what information is recorded, under GDPR Art. 13. Introducing a new AI tool that processes personal data about employees or customers on a large scale may in addition require a DPIA for AI tools under GDPR Art. 35.

What happens when an employee breaches the AI policy?

A breach of a written AI policy is a breach of an instruction and is handled like other breaches of duty. The response must be proportionate to the breach. A first-time mistake in which an employee pasted an internal memo into the wrong tool will normally justify guidance or a written warning, not dismissal.

Repeated or serious breaches may constitute objective grounds for dismissal with notice under Working Environment Act § 15-7. If the employee deliberately entered trade secrets or sensitive personal data into a service that was expressly prohibited, with significant potential for harm, summary dismissal under Working Environment Act § 15-14 may be relevant in the case of gross breach of duty or other material breach. The threshold is high, and the assessment depends on the specific facts.

Three factors often decide the case. Was the policy in writing and known to the employee? Did the employee receive training? And has the employer itself followed the rules, or has management tolerated the same practice? An employer that has not enforced the rules before is in a weak position when a single employee faces a severe sanction.

Evidence is a separate problem. If the employer learned of the breach through unlawful monitoring, the business risks both enforcement action by the Data Protection Authority and a weakened position in an employment dispute. The control rules should therefore be in place before a conflict arises.

What role does the AI Act play?

AI Act Art. 4 requires providers and deployers of AI systems to ensure that their staff have a sufficient level of AI literacy. The obligation has applied in the EU since 2 February 2025. In Norway the regulation has not yet been implemented, but training is in any case what makes the policy enforceable. See the article on AI literacy under the AI Act.

The policy should also take into account that the tools produce wrong answers. Employees who pass AI-generated content on to customers without checking it expose the business to liability. This is discussed further in the article on liability for AI hallucinations.

What should an AI policy contain?

A practical template for an internal AI policy should cover the following points.

  1. Purpose and scope. Who the policy applies to, including temporary staff and consultants, and which tools it covers.
  2. Approved tools. A list of the tools that may be used, and for which purposes. Anything not on the list is not approved.
  3. Information that must not be entered. Personal data, customer information, trade secrets and confidential information, unless the tool is approved for it.
  4. Human oversight. A requirement that AI-generated content is checked before external use, and who is responsible.
  5. Transparency. When the use of AI must be disclosed internally or to customers.
  6. Monitoring and logging. What is recorded, why, who has access and how long the information is kept.
  7. Incidents. How mistakes are to be reported, and that reporting in good faith does not in itself give grounds for a sanction.
  8. Consequences of breach. That breaches may have employment law consequences.
  9. Training and review. When training is given and when the policy is reviewed.

What should the business do?

  1. Map actual use. Find out which tools employees already use before the rules are written.
  2. Write a short AI policy. Base it on the managerial prerogative and make it known to everyone, preferably with confirmation that it has been read.
  3. Separate rules of use from control measures. Rules of use can be set unilaterally. Control measures must be discussed with employee representatives and communicated before they are implemented.
  4. Choose technical blocks over monitoring. It is lawful to block services and prevent uploads. As a rule, it is not lawful to watch each individual’s use.
  5. Create an access procedure. Decide in advance how access to a specific employee’s chat history is to take place, modelled on the email regulation.
  6. Train staff and follow up breaches consistently. Rules that are not enforced equally are difficult to rely on when it really matters.

More articles on the subject are available on the topic page on artificial intelligence and the topic page on data protection.

Questions and answers

Can we ban employees from using free AI services at work?

Yes. A ban on particular tools, or on entering particular types of information, falls within the managerial prerogative as long as it has an objective justification, such as protecting trade secrets and personal data. The ban should be in writing and known to all employees.

Can we read what an individual employee has written to the AI assistant?

Only exceptionally. Systematic review of an individual's prompts is, as a rule, prohibited monitoring. Access to a specific employee's chat history should follow the same conditions and procedures as access to email, with reasonable suspicion, notice and documentation.

Must the AI policy be discussed with employee representatives?

The employer may set the rules of use on its own, but it is wise to involve the employee representatives. If the policy includes control measures, such as logging or spot checks, discussion with the employee representatives is a statutory duty under Working Environment Act § 9-2.

Next legal review: 1 April 2027