Categories
Communication Confidentiality Data Protection Act 2018 Disciplinary Employment Law Employment Rights Act 2025 GDPR Grievance Lousha Reynolds

AI in Disciplinary & Grievance Processes: A growing challenge for employers

Artificial intelligence (AI) has rapidly become part of everyday working life. Whether employees are using ChatGPT to draft emails, employers are introducing AI-powered workplace tools, or managers are relying on AI to improve productivity, its influence on the employment relationship is growing.

One area where this is becoming increasingly apparent is within disciplinary and grievance processes.

It is now common to receive grievances, disciplinary responses and appeal letters that have clearly been generated, or heavily assisted, by AI. Whilst AI can undoubtedly help employees articulate their concerns more clearly, it also presents several practical and legal challenges for employers.

The reality is that AI-generated submissions are here to stay. The key question for HR professionals and business owners is not whether employees should use AI, but how organisations should respond effectively when they do.


The challenges

Length over clarity

One of the most obvious features of AI-generated grievances is their length.

Rather than setting out the key issues succinctly, AI often produces documents that are repetitive, overly detailed and lacking a clear structure. What could have been a straightforward complaint quickly becomes several pages of information, making it much harder (and more time-consuming!) to identify the real issues that require investigation.

Legal language without accuracy

AI also tends to produce documents that sound highly legalistic.

Instead of simply explaining the facts, grievances often contain references to statutory provisions, legal terminology and Employment Tribunal case law. Unfortunately, public AI tools are well known for occasionally inventing cases or misapplying genuine legal authorities. This can make documents appear more persuasive than they actually are and distract attention from the factual issues that genuinely need to be addressed.

Escalated allegations

AI is designed to generate persuasive writing and, in doing so, can unintentionally exaggerate concerns.

A workplace disagreement can suddenly be described using terminology such as “harassment”, “victimisation”, or “systemic discrimination” where the employee may simply be trying to explain that relationships have broken down. Whilst every allegation must be considered, employers should concentrate on establishing the facts rather than becoming distracted by dramatic or emotive language.

Unrealistic expectations

Anyone who has used AI will probably have noticed that it tends to reinforce the user’s position.

If an employee asks whether their grievance is likely to succeed or whether they have a strong tribunal claim, AI frequently provides an optimistic assessment. This can create unrealistic expectations before the employer has even started investigating the issues, making it more difficult to manage the process and achieve an acceptable outcome.

Data protection risks

The biggest concern is one that often goes unnoticed.

Employees using public AI platforms may upload confidential company information or personal data relating to colleagues to obtain assistance with drafting their grievance or disciplinary response. That creates obvious confidentiality and data protection risks which employers should not overlook (see UK GDPR and the Data Protection Act 2018).


5 top tips for dealing with AI-generated grievances and disciplinary responses

  1. Focus on prevention

Formal grievances are expensive, time-consuming and often damage working relationships.

The best approach is to encourage informal resolution wherever appropriate. Grievance policies should actively signpost employees towards discussing concerns informally with their manager/an appropriate manager or HR before commencing formal procedures.

Managers should also be trained and empowered to deal with workplace concerns at an early stage rather than feeling that every issue automatically requires a formal process.

  1. Don’t respond line by line

When faced with a lengthy AI-generated grievance or disciplinary response, it is tempting to answer every single point in writing. In practice, this often creates more work than it solves.

Detailed written responses can legitimise irrelevant arguments and often result in another equally lengthy AI-generated reply. Instead, focus on identifying the central issues that require investigation and ensure those are addressed thoroughly.

  1. Prioritise conversations over correspondence

One of the most effective ways to deal with AI-generated documents is to talk to the employee.

Whether in person or remotely, asking employees to explain their concerns in their own words often cuts through pages of unnecessary text and helps identify what the dispute is really about.

If their explanation differs from the written grievance or disciplinary response, clarify the position during the meeting by referring back to the document. This ensures that important issues are not missed whilst avoiding arguments later that particular points were ignored.

The same principle applies throughout the process. Where clarification is needed, a short conversation is often far more productive than an email exchange that generates increasingly lengthy AI-assisted responses.

  1. Protect confidential information

Employers should now consider implementing a clear AI policy if they have not already done so.

The policy should explain when AI can be used, prohibit employees from uploading confidential company information or colleagues’ personal data into public AI platforms, and remind employees that they remain responsible for the accuracy of any information submitted on their behalf.

It is also sensible to include a paragraph within disciplinary and grievance procedures (and in fact any procedures related to a formal process) that cover the use of AI. This could then be drawn to their attention during the process if the use of AI is clear.

  1. Train your managers

Finally, managers should understand both the benefits and the limitations of AI. This should include guidance on recognising AI-generated documents, understanding that AI may misstate legal principles or cite inaccurate case law, and focusing investigations on establishing the underlying facts rather than becoming overwhelmed by lengthy legalistic submissions. This could be built into manager training, whether as a stand-alone or as part of training on disciplinaries and grievances.


Looking ahead 

Although AI and LLMs (Large Language Models) are currently having the biggest impact on disciplinary and grievance procedures, this is only the beginning.

We are already seeing AI-assisted correspondence in flexible working requests, redundancy consultations, capability processes, settlement negotiations and in ET claims. As AI becomes embedded within everyday working life, employers will need to adapt their processes accordingly.

The key is not to be intimidated by AI-generated correspondence. Focus on the facts, encourage conversations rather than lengthy written exchanges, ensure managers are appropriately trained and put clear boundaries in place around the safe use of AI.

Those organisations that adapt now will be best placed to deal with the opportunities, and the challenges, that AI continues to bring to the workplace.


CONTACT US

We’re here to help with any questions or concerns you may have. Whether you need expert advice or would like an initial conversation about our services, pricing, or the options available, please don’t hesitate to get in touch. At Refreshing Law, what sets us apart from other law firms is that you’ll get to speak to an experienced employment lawyer right from the very first call.

02920 599 993

07737 055 584

lreynolds@refreshinglawltd.co.uk

Lousha Reynolds
Refreshing Law

Categories
Anna Denton-Jones Data Protection Act 2018 Data Subject Access Requests Data Use and Access Act 2025 Employment Law GDPR

The Data Use and Access Act 2025 (DUAA) has passed – What does it mean for employers?

This new Act of Parliament updates existing data protection laws and paves the way for things like artificial intelligence. It is supposed to make things easier for organisations but still protect people and their rights.

The changes will be phased between June 2025 and June 2026 so there is nothing to do immediately.

I think it will change two things for employers:

The first is that it makes clear that when dealing with a Subject Access Request, you only have to make “reasonable and proportionate searches” when someone asks for access to their personal information.

The current guidance says “You should perform a reasonable search for the requested information”.

I hear you all saying ‘but what does a reasonable and proportionate search’ look like? Ultimately we don’t know until a court tells us, but the Information Commissioner’s office will be updating their guidance in due course, which will give us clues.

A reasonable search is likely to include using IT search tools to retrieve data. It probably isn’t reasonable to expect you to search archived data which would take you time and money to restore eg:- from tapes.

Is this likely to change much in real life? Probably not – we try our best to retrieve as much as we can when searching and if doing it properly are probably acting reasonably and proportionately already. If the request is ‘manifestly excessive’ we already have an existing pathway to charge a fee.

The second implication is that if you don’t already, you will need a data protection complaints process.

The DUAA requires you to take steps to help people who want to make complaints about how you use their personal data such as providing an electronic complaints form. You also have to acknowledge complaints within 30 days and respond to them ‘without undue delay’.   At the moment, we tend to bury information about how to complain in the small print of privacy notices and at the back of policies. We probably need to put this a bit more front and centre going forward.

Anna Denton-Jones
Refreshing Law

Categories
Anna Denton-Jones Data Protection Act 2018 Data Subject Access Requests Employment Law GDPR Privacy

Updating your GDPR Privacy Notice

It’s hard to believe that it’s 7 years ago since the GDPR came into force on 1st May 2018. I’d hazard a guess that many of us haven’t given our privacy notices any thought since then and have just been wheeling them out.

Given that the world is moving at pace, you may need to update your recruitment candidate privacy notice to inform the candidate about any automated shortlisting software that you are using, or indeed that your recruitment agents are using on your behalf. The privacy notices would need to describe the software that you are using and what it does, and highlights to the candidate their right to have a human review the output.

You will recall that your privacy notice lists out the ways in which personal data of an employee might be used. There is also likely to be a section where you describe what third parties might have access to data and the purposes for which they do so. This probably covers things like accountants but you may not have covered off litigation. Clearly if somebody is suing the organisation then an individual’s personal data may be used, for example, in the disclosure documents for that case. This need not necessarily be the data subject themselves bringing the legal action because they could be being used as a comparator, for example, in an equal pay claim, or when showing consistency of treatment, for example in a disciplinary scenario.

Another legal use might be where a TUPE transfer is occurring or the organisation is, for example, undergoing a round of investment or a sale or merger process. Personal data might well be shared at some point with investors, potential buyers etc. At initial stages of such processes, employee spreadsheets for example are normally anonymised so there is nothing to worry about but further down the due diligence process, questions might be asked which would reveal personal data when answered.

Anna Denton-Jones
Refreshing Law

Categories
Anna Denton-Jones Anonymity Data Protection Act 2018 Data Subject Access Requests Data Use and Access Act 2025 Duty of Care Employment Law Employment Rights Act 1996 GDPR

Loss of an employee’s records — A data breach claim

An employee who worked for Tesco settled her data breach claim for £3,000. She had requested copies of the information that Tesco held on her, using the subject access request mechanism that you are probably familiar with. She had, during a period of over 15 years working for her employer, given them a significant amount of ‘sensitive personal data’ in the old data protection jargon, now called ‘special category data’. This included details about counselling she had received in relation to her mental health, details of post-natal depression and the management of those health conditions. Most employers will have this sort of ‘special category data’ even if they don’t collect other data like criminal records.

It appears that Tesco could not lay their hands on this information, presumably in a physical format and there was a delay because the file had been lost at some point in the past, perhaps when there was a move of offices.

Tesco had written to her explaining that they had looked for her employment records but couldn’t find them. This then triggered her putting in her data breach claim, which would be to a Court and not an Employment Tribunal.

Tesco settled the case for £3,000 and it has been reported in the local press. The publicity surrounding these events is bound to give other employees ideas. It shows that the loss of data can be just as problematic as retaining historic data that you don’t really need to and can’t justify retaining.

Anna Denton-Jones
Refreshing Law