Skip to content
Founderz: Responsible Use of AI home

in collaboration with Microsoft

Toolkit contents

Reference

Where the law fits

The standard describes good practice, and the law sets the floor. Here’s where the law most often meets everyday AI use at work.

Overview

The RUAI Standard describes what good practice looks like for anyone using AI at work. The law sets the floor, and it differs by country, sector and role. This page points to the rules people meet most often, so you know when to involve your legal, privacy or HR team. It’s a guide, not legal advice.

Personal data

Data protection law applies whenever AI processes information about identifiable people. In the EU, the GDPR defines personal data broadly, as any information relating to an identified or identifiable person, and it asks for a lawful basis, a clear purpose and no more data than needed. Replacing names with codes doesn’t take data outside the law. Other countries have their own rules, such as the UK GDPR, Brazil’s LGPD and Canada’s PIPEDA.

The GDPR also gives people rights around decisions based solely on automated processing that have legal or similarly significant effects on them. Where such decisions are allowed, people must be able to obtain human intervention, give their view and contest the decision. The European Commission has proposed changes to this rule, so check whether they have been adopted.

The EU AI Act

The EU’s AI Act applies in stages, and the AI Omnibus of July 2026 changed several dates. The parts people meet most at work:

  • Since February 2, 2025, some practices are banned, including AI that infers people’s emotions at work or in education, except for medical or safety reasons.
  • Organizations that provide or use AI systems must take measures to support their staff’s AI literacy. The July 2026 amendment kept this duty without setting a required level.
  • Since August 2, 2026, transparency rules apply: people must be told when they are interacting with an AI system, and deepfakes must be disclosed. Generative systems already on the market have until December 2, 2026, to mark synthetic content.
  • From December 2, 2026, the AI Omnibus adds bans on AI-generated non-consensual intimate images and child sexual abuse material.
  • From December 2, 2027, obligations apply to the high-risk uses listed in the Act, including AI used to recruit, promote, dismiss or evaluate workers.

The Act can also apply to organizations outside the EU, for example when the output of their AI systems is used in the EU. Your legal team can tell you which role your organization has for each system.

Decisions about people

Employment and anti-discrimination law apply to decisions about people whether or not AI is involved. Where AI touches recruitment, promotion, pay, performance or dismissal, involve HR and legal before you start: in the EU these uses are classified as high-risk, and data protection rules apply to every application and record. Principle 1 explains why these decisions stay with people.

Copyright and your content

Who owns AI-assisted work, and what you may feed into AI tools, depends on the country and on the licenses involved. In the United States, the Copyright Office’s 2025 report concluded that copyright protects human authorship, and that purely AI-generated material isn’t protected. Check your organization’s rules before you publish AI-generated images, text or code, and respect the licenses of what you upload.

Contracts and client terms

Your clients and suppliers may have contract terms about AI: whether it may be used on their work, how their data may be processed and when its use must be disclosed. Check before you use AI on client work. In 2025 a consulting firm repaid part of a government fee after a report with invented references was published, and the department also cited the firm’s failure to follow its own policy on disclosing AI use.

Voluntary frameworks

Many organizations use voluntary frameworks alongside the law. Widely used examples include the OECD AI Principles, the NIST AI Risk Management Framework and its generative AI profile, ISO/IEC 42001 for AI management systems and, for agents, Singapore’s Model AI Governance Framework for Agentic AI. None of them is law. They’re useful references for the organizational side of what this standard asks of individuals.

Practical steps

  1. 01Ask your legal, privacy or HR team before you use AI in a new way with personal data, for decisions about people or in a regulated activity.
  2. 02Check client contracts before you use AI on client work.
  3. 03When in doubt, keep the task at a level where AI drafts and you decide.

Sources

What each source establishes, and its limits. The practices and recommendations on this page are ours, and the facts come from the sources. See every source we use.

  1. Regulation (EU) 2016/679 (General Data Protection Regulation) European Union, Official Journal · April 27, 2016 · Law Defines personal data broadly (Article 4) and gives people rights around decisions based solely on automated processing that have legal or similarly significant effects on them (Article 22). Limits: Other countries have their own data protection laws. The European Commission has proposed changes to Article 22, so check whether they have been adopted.
  2. Regulation (EU) 2024/1689 (Artificial Intelligence Act) European Union, Official Journal · June 13, 2024 · Law The binding text of the EU AI Act, including the definitions of AI literacy and deep fake (Article 3), banned practices such as emotion recognition at work (Article 5), human oversight that guards against automation bias (Article 14) and transparency duties (Article 50). Limits: Applies in stages and was amended in July 2026 (see the AI Omnibus). Which duties apply depends on the organization’s role and the system. The summaries on this site aren’t legal advice.
  3. Regulation (EU) 2026/1744 (AI Omnibus) European Union, Official Journal · Adopted July 8, 2026; in force July 27, 2026 · Law Amends the AI Act: keeps the AI literacy duty of providers and deployers without a guaranteed level, moves high-risk dates to December 2, 2027 (Annex III), and August 2, 2028 (Annex I), gives generative systems already on the market until December 2, 2026, to mark synthetic content, and adds bans on non-consensual intimate deepfakes and child sexual abuse material from December 2, 2026. Limits: An amending act. Read it with the consolidated text of the AI Act.
  4. AI Act: regulatory framework for AI European Commission · Updated August 3, 2026 · Official summary The Commission’s summary of the AI Act. It lists AI tools for employment, management of workers and access to self-employment, such as résumé-sorting software, among high-risk uses, with obligations from December 2, 2027. Limits: A summary, not the legal text.
  5. Code of Practice on transparency of AI-generated content European Commission · Final version June 10, 2026; judged adequate July 8, 2026 · Voluntary code A voluntary code for marking AI-generated content (providers) and labeling deepfakes and some text (deployers), which the Commission judged adequate for Article 50 of the AI Act. Limits: Voluntary. Signing it isn’t conclusive evidence of compliance, and the legal duties apply either way.
  6. Deloitte’s AI mess just got worse, and HR should be paying close attention Human Resources Director Australia · November 14, 2025 · News report Reports correspondence released by the department showing it sought A$97,587.11, citing the report’s problems and Deloitte’s failure to follow its own policy on telling the client about AI use. Limits: A news report of released correspondence.
  7. Recommendation of the Council on Artificial Intelligence (OECD AI Principles) OECD · Adopted May 22, 2019; revised May 3, 2024 · Intergovernmental principles Calls for safeguards such as capacity for human agency and oversight (principle 1.2), accountability with traceability of datasets, processes and decisions (1.5), and systems that can be overridden, repaired or shut down safely (1.4). Limits: Not legally binding.
  8. AI Risk Management Framework US National Institute of Standards and Technology · AI RMF 1.0, January 2023 · Voluntary framework A widely used voluntary framework for managing AI risks in organizations. Limits: Voluntary. NIST says the framework is being revised.
  9. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) US National Institute of Standards and Technology · July 26, 2024 · Voluntary framework Lists twelve risks of generative AI, including confabulation (confidently stated false content, sometimes with invented citations) and human-AI configuration, which covers automation bias and over-reliance. Limits: Voluntary. It was issued under an executive order that has since been revoked, and the wider framework is under revision.
  10. ISO/IEC 42001: Artificial intelligence management system ISO and IEC · 2023 · International standard The international standard for AI management systems in organizations. Limits: An organizational management-system standard. It sets requirements for organizations, not guidance for individuals.
  11. Model AI Governance Framework for Agentic AI Infocomm Media Development Authority, Singapore · Version 1.5, May 20, 2026 (first published January 22, 2026) · Voluntary framework Keeps organizations and their human supervisors accountable for agents’ actions; asks for human approval at significant checkpoints such as deleting data, sending messages and payments; treats very low override rates and very fast reviews as possible signs of rubber-stamping; prefers approvals enforced by system controls over prompts. Limits: Voluntary guidance, not law. Its case studies were supplied by the companies themselves.