5 things you’re doing wrong when using AI in HR

9 June 2026
Monika Świderska
5 things you’re doing wrong when using AI in HR
5 min.

AI in HR is growing from the bottom up. Someone on the team starts using ChatGPT, another person turns to Gemini, and a third pastes candidates’ CVs into a free AI tool to create summaries faster. No one told them they weren’t allowed to. But no one told them how to use these tools safely, either.

In the AI in HR 2026 study, data security ranked as the top concern among HR professionals. HR holds a wealth of information about both people and the organization. That’s precisely why mistakes involving AI can have more serious consequences in HR than in almost any other department.

Below are five of the most common mistakes – along with practical tips for avoiding them.

Mistake 1: You paste candidates’ and employees’ personal data into AI

A recruiter copies a CV directly into ChatGPT to create a candidate summary faster. An HRBP uploads annual review results, including the employee’s full name, to get help wording feedback. These situations happen every day in companies of all sizes. Public AI tools may process data outside the EU, and depending on the service and settings, submitted information may potentially be used to improve or train models. Candidates’ and employees’ personal data is protected under the GDPR, so sending it to an unauthorized system can create a serious compliance risk.

Instead:

  • Anonymize data before entering it: replace the person’s name with initials or describe the role instead (e.g., “candidate with 5 years of B2B sales experience”).
  • Remove identifying information: phone numbers, addresses, national ID numbers, names of previous employers, and other details that could identify the person.
  • Focus on the content, not the individual: give AI the context it needs without exposing unnecessary personal information.

Mistake 2: You share the company’s internal documents with AI

Next year’s HR strategy, compensation plan, work regulations, organizational structure, or department financial results can all end up in an AI tool after just a few clicks – simply because someone needs a summary or wants to rephrase a section. Documents like these may contain confidential information and trade secrets. Even if the final output looks harmless, the original data has already been shared with an external system.

Instead:

  • Work from an outline rather than the original document: describe the context and objective without pasting the full document into AI.
  • If you need to work with the complete document, use a tool approved by IT that processes data within your company’s environment.
  • Agree with IT on which documents may be shared with external systems and which tools should be used when working with sensitive information.

Mistake 3: You use a free model without checking the training settings

Depending on the tool and account type, conversations in consumer versions of AI tools may be used to improve or train models. This means that prompts and pasted content can potentially become part of the data used for model improvement. Many users have never checked these settings simply because no one told them they needed to.

Instead:

  • In ChatGPT: go to Settings > Data Controls and turn off “Improve the model for everyone.”
  • Check the equivalent settings in every AI tool you use – including Gemini, Copilot, Claude, and others.
  • Don’t assume the default configuration is safe: always check how the service handles your data and what settings apply to your account.
  • Consider enterprise-grade solutions: for sensitive HR data, use a model hosted within your company’s environment or an Enterprise solution with appropriate contractual and data-protection safeguards.

Mistake 4: You make personnel decisions based on AI output alone

AI sorted the CVs and placed three candidates at the top. It assessed an employee as having “low growth potential.” It suggested that a candidate wasn’t a good fit for the organizational culture. And you accepted the output without further review.

This isn’t just a matter of accuracy. AI doesn’t have access to everything an HR professional or manager learns through conversations, experience, and context. More importantly, using AI in high-impact decisions about people can trigger specific legal and compliance requirements. Under the GDPR and the EU AI Act, certain decisions concerning recruitment, promotion, and employee evaluation require meaningful human involvement and cannot simply be delegated to an algorithm. AI can support the decision-making process, but responsibility for the final decision remains with people.

Instead:

  • Treat AI output as a starting point, not a final decision. AI can sort, suggest, and flag information, but a human should always review the result.
  • Follow the principle: AI recommends, the human decides. Establish a simple framework with your team: AI provides analysis and suggestions, while the responsible HR professional or manager evaluates them in context and makes the final decision.
  • Be transparent about AI use where required. Depending on the use case, the AI Act may require organizations to inform candidates or employees that AI is being used.

Mistake 5: You Don’t Know Which AI Tools Your Team Is Using

A common scenario looks like this: several people in the HR department use different AI tools independently, without IT’s knowledge, without checking how those tools process data, and without any shared rules. This isn’t necessarily an act of rebellion. More often, it’s simply a lack of structure.

Shadow AI – the unofficial use of AI outside approved company channels – is becoming increasingly common. The AI in HR 2026 study found that 59.6% of organizations have no systemic approach to AI use in HR. That leaves many HR professionals operating without clear guidelines to protect themselves and the organization.

Instead:

  • Run an AI usage audit: ask your team which AI tools they are already using and what they use them for.
  • Create a list of approved tools together with IT. Define which tools can be used with anonymized data and which should never receive confidential information.
  • Classify HR data: determine what is sensitive, what is internal, and what may be processed by external AI systems.
  • Share the rules with your team. People rarely use AI incorrectly on purpose. More often, they simply don’t know where the boundaries are.

How to Get Started?

In the long run, one question is worth putting to your team: Do we know which data can go into AI and which can’t? If the answer is “I don’t know,” that’s a clear starting point for a conversation with IT and for developing an AI policy for HR – and potentially for the entire organization.

A good question to raise at your next team meeting is: Which HR data can be entered into external AI tools, and which cannot? If no one in the room knows the answer, you already have a strong reason to involve IT and management. Start with three things: a clear data classification, a list of approved AI tools, and a simple set of rules that everyone in the department can understand in a few minutes.

The regulations already exist. GDPR and the EU AI Act impose obligations regardless of whether your company has an internal AI policy. A lack of rules doesn’t remove the responsibility that comes with using AI.

See how AI can support your HR processes!

Book a demo and discover what AI agents can do in HRM Productive24AI.