Sensitive HR Cases: Where AI Stays Out
AI at HR / Recruiting / Step 4
AI Privacy Rule
Keep sensitive information out of general AI prompts, including names, family details, email addresses, phone numbers, account data, customer records, employee files, financial records, legal documents, medical information, and confidential business details. Use placeholders, redacted examples, or approved systems when needed, and keep human review before important actions. AI Privacy Rules
Some HR Work Should Never Enter an AI Tool
Most HR AI guidance is about using AI carefully. This article is about the cases where the answer is simpler: don’t. Sensitive cases combine the most protected data with the highest personal stakes — and AI involvement creates risks around privacy, bias, discoverability, and broken trust that no efficiency gain covers. When in doubt, treat the case as sensitive.
The Stay-Out List
- Investigations: harassment, discrimination, misconduct — notes, interviews, and findings never enter AI tools
- Discipline and termination: the reasoning, documentation, and communication are human work product
- Medical and accommodation cases: disability processes, medical documentation, and leave details
- Legal matters: anything involving counsel, claims, charges, or litigation holds
- Individual compensation decisions: specific people’s pay, especially in dispute
- Whistleblower and ethics reports: confidentiality is the entire system
Why These Stay Out
- The data is maximally sensitive and often legally protected
- AI involvement may be discoverable in litigation — including the prompts themselves
- Pattern-based suggestions are exactly wrong for cases that demand individual judgment
- A confidentiality breach here harms a person, not a process
- Trust in HR depends on people knowing their hardest moments aren’t fed to software
The Escalation Boundary in Practice
The moment routine work touches a sensitive case, AI use stops. A request summary workflow is fine — until the request is a harassment complaint. An onboarding checklist is fine — until it involves an accommodation plan. Train the team on the transition: recognize the trigger words and case types, stop the AI-assisted workflow, and route the matter to the qualified owner — HR leadership, legal counsel, or the formal investigation process. The boundary is not about the tool; it is about the case.
What’s Still Allowed Nearby
AI may help with the general layer: drafting policy language, building training materials about these processes, and organizing anonymized process documentation. The line is specificity — the moment a real case, person, or incident is involved, the work moves to humans working in approved systems. A template for investigation documentation is acceptable AI work; the documentation of an actual investigation is not.
Quick Reference
- Investigations, discipline, medical, legal, individual pay, ethics reports: no AI
- Recognize the transition: routine workflows stop when a sensitive trigger appears
- Prompts can be discoverable — treat them like written records
- General policy and training drafting is fine; real cases are not
- When unsure, treat it as sensitive and escalate
Example in Practice: The General Layer, Not the Case
The prompt: “Draft a one-page training note for our HR team titled ‘When AI Use Stops.’ Cover the six case types where AI tools are off-limits (investigations, discipline/termination, medical and accommodation, legal matters, individual compensation, ethics reports), the trigger signs that a routine workflow has crossed into one of them, and who to route each case type to. No real cases, names, or incidents — this is a general training document.”
What you get back: A training one-pager about the boundary — the kind of general-layer work AI is allowed to do — that helps the team recognize the moment a real case appears and the AI-assisted workflow must stop.
Check before using: Have HR leadership and legal confirm the routing owners and case definitions match your actual escalation process before the note is circulated.
Sources & Further Reading
- OWASP Top 10 for LLM Applications — the standard reference on sensitive-information disclosure, the core risk that keeps these case types out of AI tools.
- NIST AI Risk Management Framework — framework guidance that includes deciding when the right risk response is not to use AI at all.
Prompt Pack Resource
Ready-to-Use Prompts for Review-First HR Workflows
The HR / Recruiting Prompt Pack includes tested prompts for drafting HR materials with built-in fairness checks, privacy filters, and human review requirements — with the escalation boundaries covered in this article built in.
Get the HR / Recruiting Prompt Pack