MCF horizons Podcast Series Ep.4: From Hype to Reality – AI in the Workplace

AI is transforming the workplace at pace. But what are the legal, regulatory and practical implications for employers?

In this episode of MCF horizons, Jack Larkin, Paula Fearon and Adam Finlay discuss the realities of AI adoption and the key considerations organisations need to address.

Audio Transcript

Transcript available to view here, or in full below.

[00:00 - 00:25]

Welcome to MCF horizons, McCann FitzGerald’s podcast series, where we explore the legal and market developments, trends and policy milestones that are shaping today's landscape.  Through conversations with our lawyers, we share practical, forward-looking insights to help organisations navigate change and make informed decisions. Now let's turn to today's episode.  Hello. Welcome to the fourth episode of the MCF horizons podcast series.

[00:25 - 00:45]

My name is Jack Larkin. I'm an associate in the Employment Law Group here in the firm, and today we are going to discuss AI in the workplace. Now, last week, we were kind of treated to the spectacle of a rogue AI agent from OpenAI going wild in another business. The only thing worse than a rogue AI agent is a rogue associate.

[00:45 - 01:06]

So I am joined here by the two pillars of the firm's AI strategy. That is Paula Fearon, who is the Head of our Project Services Group, and Adam Finlay, who is the Head of the Technology and Innovation Group here at the firm. So thank you for joining us, Paula and Adam. Delighted to be here. Very glad. And Jack you're doing yourself a disservice by describing yourself as a rogue associate.

[01:06 - 01:22]

But we are delighted to be talking to you. Footnoted in caveat. I'll bring that in my next performance review. Yeah. Thank you. Adam. So, Paula, just to kind of begin, I think what we're seeing at the moment is 2 or 3 years ago, when a lot of these AI platforms came out, there was a lot of hype.

[01:22 - 01:52]

It was a very exciting time. There was a lot of discussion about what the future might look like. And now I think, particularly in the workplace, we're seeing businesses becoming a bit more cautious and a bit more perhaps realistic about the use cases and even the downside of using AI. And I think one of the interesting things that's happened here is we've gone from businesses having AI mandates and token-maxxing into a kind of a new consideration of the use of AI in the workplace.

[01:52 - 02:14]

Can you talk about that a little bit? Yeah, for sure. So we've definitely seen a position and it's really interesting the arc that AI has gone on because originally it was kind of really cautious and then it was all in. And now we're back to a little bit more sort of circumspect about the whole thing. And I think we've learned from, as you say, the token-maxxing and the mandating.

[02:14 - 03:00]

So there have been examples across jurisdictions where companies have chosen to mandate the use of AI and where it hasn't really gone terrifically well. Certainly there was a Financial Times story in December 2025 about Amazon's use, mandated use of AI and how their engineers were required to use it. One of their engineers built an agent that ultimately decided, rather than to patch the problem that it encountered, to delete the AWS product that it was working on entirely and rebuild it from scratch, which resulted in 13 hours of downtime across China for that product.

[03:00 - 03:31]

So that is rolled-out as a kind of cautionary tale of that sort of downside of mandating AI use. And the other issue which has really come to the fore now is this idea of token-maxxing. And everybody was all excited about token-maxxing until people started realising that the bills were coming in, and that token-maxxing maybe wasn't the best way of getting your ROI for your AI investment, because it's really only starting to emerge the picture of how much AI actually -

[03:31 - 03:57]

- and when I talk about AI, I'm going to be talking about GenAI largely - and how much that costs. So we've definitely learned from those situations to a situation where businesses are actually facing the reality of they've paid a lot of money for tools, and how did they deploy them, and what do they do? And there are a number of challenges, and I think you and I sort of have discussed this.

[03:57 - 04:32]

There are challenges for businesses themselves, and there are challenges for businesses as employers with the use of AI. So an example of the businesses themselves is expecting AI to just replicate or produce work that was traditionally done by human employees without providing the proper framework. And then the other side with the issues with their employees is how employees are perhaps using those tools in ways that don't benefit the employer.

[04:32 - 04:50]

Yes, certainly I think there's an interesting tension, I think even sometimes between different departments in a business. So, you know, an employer might have a marketing department, and we were talking about this yesterday, that's kind of talking about all the exciting AI that's being rolled out in the business. And then it's also telling its employees, look, you have to use this technology.

[04:50 - 05:07]

It's really important that you use this. And then the employee has a bit of a think and it says, might even have a think aided by an AI tool. And it might say, well, hang on, this technology is really transformational. You're telling me to use it. You're saying it's fundamentally changing my role. Is that not a fundamental change to my contract of employment?

[05:07 - 05:33]

We haven't seen any cases in Ireland with that yet. But it's certainly an argument I think could be deployed for a very specific type of employee in a certain kind of role. And I think businesses just need to be aware that when you are rolling out this technology, it can't just be different departments all siloed from each other, and you're kind of sort of at the command-and-control station in the firm itself in terms of using these tools.

[05:33 - 05:50]

And so in your own kind of like internally, how have you had to interact with different parts of the business in rolling out AI? And is there any kind of tips you've learned along the way that can help other businesses in doing that? Sure. So the interesting thing about generative AI is that can be all things to all people.

[05:50 - 06:10]

So unlike all previous iterations of, particularly legal tech which is what our firm would use, but sort of technology generally for business where it was a specific-purpose tool, it did a particular thing in a particular way, and you could train your staff and they would use it that way and it would have that outcome.  Generative AI isn't like that.

[06:10 - 06:40]

And the models that have emerged over the last number of years have a multitude of applications. And so when a business acquires a tool, it needs to be really considered about what it intends the AI to be used for and to choose a platform. Obviously, there's huge information security and confidentiality issues. Choose the right platform for the thing that that the business needs the AI to do.

[06:40 - 06:58]

Write a clear policy about what AI can be used for and should not be used for, because those things aren't always focused on and that can cause problems for a business. And the important thing is to train people. So people need to understand how the tools work. They need to understand how they can be embedded into their workflows.

[06:58 - 07:30]

And this isn't, this isn't just taking a human out of a piece of work and inserting an AI. You have to actually reconstruct the entire workflow. It's a kind of change management piece, and that's really important. And the other side of it is being able to measure success by reference to real outcomes. So, you know, we've seen some businesses chosen to sort of measure success by the volume of AI use, and that isn't a good benchmark.

[07:30 - 08:03]

So what I would say is you have to be really thoughtful about what it is you want this tool to do within your business and really importantly, what it is that you don't want it to be used for. I mean, it might be useful to bring that to life with some examples, like we have seen clients come to us with data subject access requests or complaints that have absolutely been generated using the business’s, the employer's own AI tools, using the business's own information.

[08:03 - 08:37]

And obviously that's problematic. And you need to have thought that through as a business and to mandate what it can and can't be used for. We became aware of a situation in a third party organisation where an employee had actually gone off and, in the course of manufacturing a grievance, which was prior to their eventual resignation, they uploaded highly confidential employee salary information belonging to their colleagues to the AI platform, and asked it to compare it to their own salary, and then said, well, have I got a case here?

[08:37 - 09:16]

And then went off and uploaded much more confidential trade secrets as well. This triggered a number of processes, including a report to the Data Protection Commissioner. So yeah, we're just seeing, you know, from the beginning of just having the AI present, it kicks off a whole chain of events from a regulatory and employment perspective.  It’s not really just about necessarily a policy, but also, you know, if a lot of confidential information is being given via an employee to a third-party AI platform, you do need to have kind of clauses in your contract around intellectual property.

[09:16 - 09:41]

That all needs to be thought through, doesn't it? Hugely. And Adam it's much more your territory than mine. But you really have to be careful about what rights you are granted by the software provider and granting to the software provider in terms of your own data and how it's going to be dealt with. Because to get sort of the best use out of a tool, you want to be able to use it freely within your organisation and within the parameters of that organisation.

[09:42 - 10:10]

There are things like privilege is a big concern because if you are using so there's plenty of models that are paid for and therefore people think are confidential, but which actually don't guarantee confidentiality. And you could risk losing privilege, you could risk losing your intellectual property, trade secrets, information – as you said, the data breach example where information has leaked out and that's it's really important.

[10:10 - 10:48]

And actually the transfer of data even internally is really important. So we had an example of a business who rolled-out Microsoft Copilot and across their business, and they were a Microsoft house. Their data storage was SharePoint and OneDrive. And they had examples where employees were asking questions on Copilot, and the information that was coming back was from locked down repositories within the organisation, because Copilot hadn't been sort of linked to the user permissions on the tool.

[10:48 - 11:06]

So it really is very important to get granular with these tools to make sure that they are, as I keep saying, doing what you want them to do and not doing what you don't want them to do. So kind of touching then Adam on a lot of what Paula’s talking about, it only needs to kind of really go wrong once in a business.

[11:06 - 11:40]

And so kind of getting more into that granular compliance side of things. Your practice area touches on the EU AI Act, which also says a number of specific things about employment. Can you kind of discuss that more? Sure. Yeah, happy to get into that. And people often come and ask us very specific questions about the AI Act, and a point we always just tease out to people as they come to us, is it's always worth bearing in mind that the AI Act is one aspect of legal compliance when it comes to AI, but it's not a comprehensive governance of the use of AI.

[11:40 - 12:11]

So the EU AI Act is all about the safe use of AI, and what a lot of businesses come to us asking is: if we do this, are we fundamentally out of scope of the AI Act? Or how do I avoid using either a prohibited AI system or a high-risk AI system? And you will know in the context of employment, that's one of the areas where you might butt up against products categorised under the AI Act as a high-risk AI system, but a lot of the time where people are coming to us trying to find a way is, how do I get out of that?

[12:11 - 12:30]

How do I get out of using high-risk AI systems? And we'll get into that in a second. But if you get there. If I'm not using a high-risk AI system for the purpose of the AI Act, that doesn't mean that you don't have all the problems that Paula was talking about: about confidentiality, you know, inappropriate access to data, etc. IP.

[12:30 - 12:52]

So there's a much broader scope, but answering your question as asked by focusing specifically on the AI Act - when you're looking at it, generally employers, most employers aren't going to be using a prohibited AI system. If they were, that would be foolish.  What they might be coming up against and what most organisations are at risk of, is using what's called a high-risk AI system.  And a high-risk AI system, there’s

[12:52 - 13:21]

various definitions. But in the employment context, if you're using an AI system for recruitment or for effectively managing people. So making decisions about people hiring, firing, allocating work, performance assessment, that kind of thing, you're potentially using a high-risk AI system. But then because it's a law, there is very convoluted exceptions and double exceptions and double negatives. So in principle, maybe a high-risk AI system - there are exceptions to that.

[13:21 - 13:49]

If you're only using AI in a kind of a relatively simple way, doing what is more of an efficiency gain rather than decision-making, then it's potentially not use of a high-risk AI system. But then there's an exception to that exception. If you're engaging in profiling of people, you are using a high-risk AI system. So, you know, for example, if an employer was to say we are currently in a restructuring exercise, we are going to select a number of people for redundancy.

[13:49 - 14:14]

We've had the AI system profile a number of employees to select who might go into a certain redundancy pool. You know, you're kind of the alarm bell is then ringing, you know, for you. Absolutely. Yeah. And an additional point I’d make in the context of profiling. So profiling is the thing to remember. If you're engaging in profiling with people, you're probably using a high-risk AI system.  An ordinary person,

[14:14 - 14:39]

if you think about what profiling means, you think a relatively sophisticated kind of building a view of a person, making kind of key decisions about a person. The term profiling is as defined in the GDPR and, in the GDPR, profiling is defined broadly. So it's really assessing in an automated way anything to do with people. So it's not just hiring, firing, redundancies, you know promotions that kind of thing.

[14:39 - 15:03]

It's also does Jack turn up on time every day, is he a bit late on occasion, does Jack do his work on time, is Jack ploughing through the mandates that have been given, does Jack merit reward, bonus, etc. So it's a much broader kind of concept, and it is so tempting, Paula was saying earlier that, you know, the opportunities presented by AI are amazing.

[15:03 - 15:24]

All of us in our personal capacities - you start mucking around with something like Copilot, you will start doing all sorts of inventive things, but you are quickly straying down the path - if you're doing that with employees, and I use that term broadly, not just in your employment world, workers generally - you are entering into dangerous territory that you need to be thinking about.

[15:24 - 15:49]

If I was explaining myself to a regulator, to a court, the WRC, would I be able to stand over what I've done and whether that's through the prism of the AI Act or more generally, that's where you don't want to find yourself, that you're scrabbling at that stage. It's just interesting when you're talking about the GDPR there. You know, like in the sort of history of technology, there's this question of, well, is this change or is this kind of continuity?

[15:49 - 16:19]

So I'm not going to ask you that question, sorry. But in terms of the older like the older data protection regime now, it seems that that's actually being layered on in a big way to a lot of these questions surrounding AI. And one of the ones I was thinking of was there's this sense that if an employee is using AI, personal data is going into the platform, that actually the potential for further personal data to be generated through the platform itself, it's interacting with it and it's actually inferring new data.

[16:19 - 16:41]

Have you seen cases around that, or is that a live concern as to the data protection angle to AI? It is, and something that we would actually overlap with Paula and her team a lot, and Paula and team are very helpful in terms of dealing - I'm interacting with you and your team as well - on data subject access requests and kind of scoping what personal data is being processed by what system.

[16:41 - 17:03]

And yes, the main thing and I know we've talked about this before, is the trail of prompts that you generate as an employee. What you're looking up sometimes that's purely business, sometimes it's quite personal. Where shall I go on holiday with my family and much more invasive things than that. And all of that is being recorded on a system.

[17:03 - 17:22]

And it might just be personal data relating to you, but it might also be assess, compare Jack and Paula and tell me which of them is better at their job and which should be promoted. I am now doing that myself. I'm also generating personal data about Jack and Paula and the AI system might say Jack's a great fellow altogether.

[17:22 - 17:45]

Paula is limited in these ways. That's the AI system’s interpretation. That's not correct. You're both fantastic. It's not correct. But the problem is the AI system is collecting personal data about me. It's generating personal data. Often it's inferred personal data. It's not actually correct. It's what the AI system thinks. And when I say thinks you will know you will describe it better than I do Paula

[17:45 - 18:09]

about what it's actually generating. But sorry, you're probably better placed to do that. No, I was going to say that that exact problem also arises in, and it's important for companies to think about this, other records that are generated, for example, transcription tools of where people are recording meetings and they're recording every aspect of the meeting, including the banter at the start of the meeting where people might exchange personal information.

[18:09 - 18:47]

And so that's another record with personal information that's held on a company's system. And those issues arise. And that's why it's really important to be thoughtful about what information you are generating and storing in relation to your employees from a personal data perspective. And what's coming down the line is big. Data subject access requests, whether that's in the employment context or others, where people are going to suddenly have their dirty washing on show about what the senior executive was using the AI system for in terms of thinking about hiring, firing, redundancy programs, all of that.

[18:47 - 19:09]

And there is, I think, this temptation that in a personal capacity, we all think of email, I think as a formal business channel - shouldn't say something compromising by email. Most people are pretty relaxed on WhatsApp or the equivalent, and often will say deeply incriminating things on WhatsApp. And some senior businesspeople are better at that, but a lot of people are not.

[19:09 - 19:38]

AI, it remains to be seen. We've seen some pretty relaxed commentary going into AI, so at the moment, I think on average - I have no science to back this up whatsoever – but I think on average people are treating AI systems more like something like WhatsApp rather than more like an email, formal business communication. And I think that comes back to the importance of training your staff about the tools that you're using and how the information generated is stored.

[19:38 - 20:01]

So if you knew, like your email, that what you type into your AI model was going to be stored along with your emails, you might take a different view. And we've certainly in the discovery and investigation space, seen examples where it was very clear that the user did not appreciate that their prompts and their exchanges with the models were going to be disclosable.

[20:01 - 20:20]

So it just has me kind of thinking and not to sound sort of Victorian about this, but there is a kind of a return then to sort of personal responsibility. That does need to be inculcated in the culture of any business. But another question I was kind of or another issue I was sort of thinking about was, we're talking a lot here about employers, employees.

[20:20 - 20:43]

There's obviously much more ease of monitoring and oversight within that relationship. But when it comes to atypical employment, so you might have agency workers, you also might have contractors who they have access to a lot of an employer's information. They are using an AI platform. Adam, have you seen any clauses in business-to-business contracts that are dealing with the use of AI?

[20:43 - 21:05]

Yes. And you see a real range of approaches. So if you start off with the providers of AI systems, understandably they will try to limit their exposure as much as possible. And often it's standard terms, no ability to negotiate, take it or leave it. We're not responsible if anything goes wrong. You  give us access to whatever we need to do.

[21:05 - 21:29]

More or less full stop. When you get into the more complicated scenarios you're talking about, like letting a contractor onto an employer's system and enabling them to use the AI tools of the employer as subscribed for from a third party. Often people are working with standard T&Cs. Often people are using AI agents to update if necessary those standard T&Cs.

[21:29 - 21:55]

And we are seeing weird and wonderful contractual relationships where grammatically they're correct. Legally, I don't know what anybody was trying to achieve with them, and they don't make a huge amount of sense in terms of allocation of responsibility. And certainly when it comes to what you're talking about, the practicality of actually applying them, making sure that the organisation is properly covered, the people have the appropriate restrictions on what they're doing.

[21:55 - 22:12]

I think there's room for improvement on a lot of that. Yeah. Okay. Can I just ask either of you, do you have any kind of key takeaways in this space at the moment? I suppose I'm going to loop, if you don't mind me using the pun, back to the whole idea of the human in the loop.

[22:12 - 22:34]

And I would sort of caution anybody against looking at that purely through the lens of your obligations under the EU AI Act, and to see it as a more generally required means of deploying AI in your business. I think it's critically important that these are tools to assist the human, rather than tools to replace the human.

[22:34 - 23:04]

I think it's sort of generally accepted now that the jobs apocalypse that was, you know, was sort of expected hasn't quite arrived. But I think it's really important that we maintain proper human oversight in what the tools are doing and how they're being deployed. We used human oversight when we had humans doing the work. I'm not sure why we would not do that when we have AI assisting us.

[23:04 - 23:29]

So I just think if you start from that position, I think it will help you be a lot more considered and robust in your rollout of AI in the business. Thank you Paula. Adam? I would go back to when you're thinking about AI, think beyond the AI Act, it raises so many legal issues. We've been talking today in the employment context, but all the other laws, GDPR, employment law, etc. they all apply as well.

[23:29 - 23:50]

And often your main exposure as a business is not really compliance with the AI Act or not. It's all the other things that can go wrong.  Ultimately, classic lawyer thing, think about yourself explaining what you did as a business in front of a judge, the WRC, the Data Protection Commission, or whatever regulator is relevant to your business and thinking

[23:50 - 24:07]

could you stand over what you did? And if you're not comfortable with that, you need to go back to what I was talking about and get a bit more comfortable about the guardrails.  And give you two a call maybe. Yeah, happy to help is right. Okay. Well, thank you both very much. That was absolutely fascinating. And thank you everyone for listening.

[24:07 - 24:16]

Thank you for listening to MCF horizons.  For more insights and updates, visit mccannfitzgerald.com. And don't forget to subscribe to stay up-to-date with future episodes.

This content has been prepared by McCann FitzGerald LLP for general guidance only and should not be regarded as a substitute for professional advice. Such advice should always be taken before acting on any of the matters discussed.