# AI HR assistants: what they can and can't answer for your staff

> What AI HR assistants do well and badly for a small UK company, the five rules to insist on, and what the ICO and ACAS say about privacy, monitoring and checking AI output.

Source: https://forematter.com/guides/ai-hr-assistant/
Updated: 2026-09-29
Author: Jack Stovell (https://jstov.uk/)

An AI HR assistant is a narrow tool, and the name promises more than the thing delivers. It searches your own documents, pulls out the relevant passage, explains it in plain language and, if it's set up properly, tells you where it found the answer. That's it.

It isn't a decision-maker. It isn't an adviser on anyone's personal situation. It explains what the policy says, and a person decides what happens. I'd keep that sentence somewhere visible, because almost every problem further down this guide comes from someone forgetting it.

So if you're a small company wondering whether to let staff ask a chatbot about holiday, sick pay or the expenses process, the honest answer is: maybe, for a very specific job. Here's what that job is, and what has to be true before you hand it over.

## What it's good at

Finding things. That's the headline, really. Somebody wants to know where the expenses form lives, or how much notice they need to give to book leave, and instead of pinging whoever handles people stuff, they ask the assistant and get the passage from your own handbook, explained in plain words, with a pointer to the document so they can read it themselves.

It works at 10pm. It works on a Sunday. It gives the same answer to everyone, which sounds trivial until you've watched two managers explain the same policy two different ways.

And it frees up whoever currently answers "where's the expenses form?" for the twentieth time. In a small company that's often one person doing three other jobs, and I think handing them back that time is the best argument for one of these things. Not cost cutting. Just letting a busy person stop being a human search bar.

Notice what all of that has in common: it's about your documents. Finding them, explaining them, pointing at them. The moment it steps outside that, things get shaky.

## Where it goes wrong

There are five ways this breaks, and they're worth going through one at a time, because none of them announce themselves.

**It answers from general knowledge instead of your policy.** This is the big one. If your handbook is silent on something, a badly set up assistant doesn't say so. It fills the gap with what's typical, or what "usually" happens in UK workplaces. The answer sounds right. It might even be right for some other company. But it isn't yours, and your staff will act on it as though it is.

**It reads out-of-date documents.** Somewhere on your shared drive there's an old version of the leave policy, a copy of the copy, and something called "final_v2_USE THIS ONE". If the assistant can see all of them, it may quote the wrong one. Confidently.

**It sounds equally sure when it's wrong.** That's the bit people underestimate. A person who isn't certain usually hesitates, or says "I think so, but check." These tools tend to deliver a shaky answer in exactly the same calm tone as a solid one. ACAS's tips for employers on AI put it plainly: ["Organisations should remember that AI is not perfect, so outputs should be checked for accuracy, tone and bias."](https://www.acas.org.uk/one-third-of-employers-think-ai-will-increase-productivity) I'd treat that as a design requirement, not a nice thought.

**It gets questions that need a person.** Grievances. Harassment. Health, pregnancy, disability. Pay disputes. Anything about one specific individual. Someone will type these in, because it's late and the box feels easier than knocking on a door. The assistant can't handle them, and shouldn't try.

**It keeps what people type.** Employees put sensitive things into a chat box that feels private. It often isn't. More on that below, because it's where the legal points live.

## The rules to insist on

Five rules, set before anyone switches it on. To be clear, these are my recommendations, good practice rather than anything the law spells out for HR chatbots. But I'd be nervous running one without them.

**Answers only from documents you've approved.** The assistant answers from the documents you've chosen and signed off, and nothing else. No general knowledge, no "typical practice", no filling in the blanks. If it isn't in the approved set, it doesn't get to talk about it.

**The source, date and owner under every answer.** This does two jobs. It lets an employee check the answer for themselves, and it makes stale material obvious, because a date from years ago is hard to miss.

**An honest "I don't know."** This is the one I care about most. A good assistant says it can't find the answer rather than producing something plausible. Test for this specifically, because it's the behaviour that separates a useful tool from a liability. There's more on why in [this note on assistants that won't guess](/notes/why-forematter-wont-guess/).

**Gaps go to a named person, but only with the employee's say-so.** When the assistant can't answer, it should offer to pass the question to someone real. Offer, not just do it. The question itself can be sensitive, and someone asking about a health condition may not want it landing in a colleague's inbox without being asked first.

**Clear rules on who can read conversations.** Decided before launch, and told to staff. Is it nobody, the person who runs the tool, or the employee's manager? Whatever you pick, pick it first and say it out loud.

Behind all five sits one habit: a review date on every document the assistant uses. ACAS says of workplace policies generally, ["You should regularly review your policy."](https://www.acas.org.uk/policies-for-home-and-hybrid-working/how-to-structure-a-policy) An assistant is only as current as the paperwork underneath it. Our guide to [keeping an internal knowledge base people actually use](/guides/internal-knowledge-base/) covers owners and review dates in more detail.

ACAS also suggests employers ["reassure staff that human involvement will still be needed."](https://www.acas.org.uk/one-third-of-employers-think-ai-will-increase-productivity) I'd go further and make it true. If staff think the assistant is replacing the people who look after them, they'll either distrust it or over-rely on it, and neither helps you.

## Privacy: what happens to what staff type

Right, the part people skip. Please don't.

First, a caveat. The ICO's [guidance on AI and data protection](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/) and its [guidance on monitoring workers](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/employment/monitoring-workers/) both carry the same notice: "Due to changes made by the Data (Use and Access) Act, this guidance is under review and may be subject to change." So check the current versions before you rely on anything here. I'm quoting what's there now, not promising it stays put.

On transparency, the ICO says ["You need to be transparent about how you process personal data in an AI system, to comply with the principle of transparency."](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/how-do-we-ensure-transparency-in-ai/) Your privacy information should cover "your purposes for processing their personal data; your retention periods for that personal data; and who you will share it with." Purposes, retention, sharing. If your privacy information can't answer those three for the assistant, it isn't ready.

Then there's reading the conversations. Whether a particular set-up counts as monitoring is a question for your own situation, but the ICO's definition is broad: ["We use the term ‘monitoring workers’ to mean any form of monitoring of people who carry out work on your behalf."](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/employment/monitoring-workers/data-protection-and-monitoring-workers/) If anyone at your company will be able to read what staff type, I'd treat that guidance as the place to start. It says "you must tell workers about monitoring in a way that is accessible and easy to understand", and warns that "Monitoring conducted without transparency is unfair and could negatively impact trust relationships." It also says you should "only monitor workers in ways they would reasonably expect and not in ways that cause unjustified adverse effects on them."

Would an employee reasonably expect their HR questions to be read by their manager? Probably not, unless you've told them. Hence the rule about deciding who reads conversations, and saying so before anyone types a word.

The sensitive stuff matters here too. The ICO notes that "Monitoring workers often includes capturing sensitive information", and its list of special category data, which needs extra protection, includes "health or disability;" and "trade union membership;". Its email example is pointed: "monitoring all email traffic could detect special category data, such as emails sent to union representatives or to occupational health personnel." People ask HR assistants about sick leave, health conditions and union matters, so I'd assume the same applies to the chat log.

And don't hang on to it forever. The same guidance says "You must not keep personal information obtained from monitoring workers for any longer than is necessary for your particular purpose or purposes."

Finally, the impact assessment. The ICO says ["In the vast majority of cases, the use of AI will involve a type of processing likely to result in a high risk to individuals’ rights and freedoms, and will therefore trigger the legal requirement for you to undertake a DPIA. You will need to make this assessment on a case by case basis."](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/what-are-the-accountability-and-governance-implications-of-ai/) If you decide one isn't needed, "you still need to document how you have made this assessment." So: most likely yes, decided case by case, with your reasoning written down either way.

## Before you switch one on

Practical steps, roughly in order.

**Tidy the documents first.** One current version per topic, a named owner for each, a review date. This is dull and it's the single biggest thing you can do, because the assistant will faithfully repeat whatever mess you feed it. If you're not sure which policies you should have in the first place, start with our [guide to HR policies for small businesses](/guides/hr-policies-small-business-uk/) and the [policy checklist](/templates/uk-small-business-policy-checklist/).

**Test it properly.** Run your most-asked questions through it and check the answers against the source. Then throw in a few awkward ones: something your handbook doesn't cover, something ambiguous, something emotional. The ICO's advice when buying AI is that ["you should examine and test any claims made by third parties as part of the procurement process."](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/what-do-we-need-to-know-about-accuracy-and-statistical-accuracy/) Whatever a supplier tells you it does, try it yourself.

**Check what happens when there's no answer.** This is the test that matters. Ask it something that isn't in your documents and watch. Does it say so, or does it improvise? If it improvises, you've found the problem before your staff did.

**Decide the handover.** Who's the named person when it can't help? What happens to the question, and does the employee get to say yes first?

**Tell staff.** What it's for, what it isn't for, and what happens to what they type. ACAS says ["Employers should develop clear policies regarding the use of AI at work and should consult workers and any representatives on its introduction."](https://www.acas.org.uk/one-third-of-employers-think-ai-will-increase-productivity) Asking before launch is a lot easier than explaining afterwards why nobody did.

## Questions to ask anyone selling one

- Where do the answers come from, and can it be limited to our approved documents only?
- Does every answer show the source document, its date and its owner?
- What does it do when the answer isn't in our documents?
- How does a question get to a person, and does the employee choose whether it goes?
- Who can read conversations, and is every read recorded?
- How long are conversations kept, and can we change that?
- Is our content used to train AI models?

If the answers are vague, that tells you something.

Do all that, and you've got a small, dependable tool that answers the boring questions well and knows when to stop. Skip it, and you've got a very confident stranger speaking on behalf of your company. [Forematter, onboarding software for UK companies, is built around these rules](/how-it-works/).

This is general information, not legal advice, so check the ICO, ACAS or GOV.UK for your own situation.

## Questions people ask

### What is an HR chatbot for employees?

A tool staff can ask about policies and processes in plain English. A good one answers only from your own approved documents, shows where each answer came from, and hands anything it can't answer to a named person.

### Can an AI assistant answer questions about HR policies?

Yes, if the answer is in your documents and those documents are current. It's good at finding and explaining what your policy says. It shouldn't fill gaps from general knowledge, advise on someone's personal situation, or make decisions.

### What questions should an HR chatbot not answer?

Anything that needs a person: grievances, harassment, health, pregnancy, disability, pay disputes and anything about a specific individual. It should say it can't help and offer to pass the question on, with the employee's agreement.

### Can employers read what staff type into an HR chatbot?

Decide that before launch and tell staff. The ICO says employers must tell workers about monitoring "in a way that is accessible and easy to understand", and HR questions can reveal health or union details that need extra protection.

### Do you need a DPIA for an AI HR assistant?

Probably. The ICO says that in "the vast majority of cases" using AI will trigger the legal requirement for a DPIA, assessed case by case. If you decide you don't need one, write down how you reached that decision.

### How do you stop an HR chatbot giving wrong answers?

Limit it to approved documents, keep one current version of each with an owner and a review date, show the source under every answer, and test what it does when the answer isn't there. ACAS says AI outputs "should be checked for accuracy, tone and bias".
