Strategy · Risk

AI and Employee Monitoring: What Small Businesses Can and Cannot Do

AI note-takers, productivity dashboards and sentiment scoring have quietly turned most small businesses into employee monitors — here is what is banned outright, what is allowed, and the one-page policy that keeps you on the right side of it

B Biztrategy Published 09 October 2026 · 9 min read
Detailed view of a computer screen displaying code with a menu of AI actions, illustrating modern software development.

Almost every small business in Europe is now an employee monitor, and most did not decide to be one. It happened quietly: an AI note-taker switched on for client calls started joining internal one-to-ones. A productivity dashboard appeared in the admin console of software you already pay for. A support tool added "sentiment scoring" in an update nobody read. There is a new AI tool every week, and each one arrives with a tab full of numbers about the people who work for you.

That matters more than it used to. Since 2025 the EU AI Act has banned some workplace AI outright, and employment-related AI systems now sit in its high-risk tier with duties falling on the business using the tool, not just the company that built it. The UK route differs in detail but not in substance. Below: what is genuinely prohibited, the four tests any monitoring decision has to pass, where small businesses trip up, and a one-page policy you can write this week. This is practical guidance, not legal advice — take anything contested to an employment solicitor in your jurisdiction.

What counts as AI employee monitoring

Owners picture keystroke loggers and webcam screenshots. The real exposure in a 5-to-50-person business is more mundane, and usually already switched on:

  • AI note-takers recording and summarising meetings, including one-to-ones, grievance conversations and interviews.
  • Productivity dashboards inside your email, chat and document suite — active hours, response times, collaboration scores.
  • Call and chat analysis scoring conversations for tone, sentiment, script adherence or "empathy".
  • CV screening tools that shortlist candidates before a human sees them.
  • Scheduling and task-allocation systems that rank staff by throughput or adherence.
  • AI performance summaries built from tickets, commits or CRM activity.

The legal question is not whether AI is involved. It is whether you are processing personal data to evaluate a person — which you are, in all six cases. What AI changes is scale and inference: these systems do not merely record what someone did, they produce a judgement about them, at volume, with no visible working. That is what regulators have moved to tighten.

The three things you cannot do at all

Most monitoring is a proportionality question. These three are not — and no amount of consent or policy wording buys you past them.

1. Inferring emotions from your staff. The EU AI Act prohibits AI that infers emotions in the workplace, and has done since February 2025. A tool claiming to detect frustration, stress, enthusiasm or engagement from an employee's face, voice or typing patterns is on the wrong side of that line. The narrow carve-outs are medical and safety — a fatigue-detection system in a vehicle, not a morale score in a dashboard. Note the asymmetry vendors gloss over: analysing a customer's sentiment on a call is treated differently from scoring the agent's emotional state on the same recording.

2. Biometric categorisation that infers protected traits. Systems that sort people by biometric data to deduce race, political opinions, trade union membership, religion or sexual orientation are prohibited — which sounds exotic until a "team analytics" vendor offers demographic breakdowns nobody was asked to declare.

3. Letting the algorithm decide alone. Under the GDPR, a decision based solely on automated processing with legal or similarly significant effects — dismissal, discipline, pay, rejecting an applicant — needs a specific legal footing and meaningful human involvement. "The system flagged them" is not a defensible reason for ending someone's employment. A human has to see the evidence, be able to disagree with it, and sometimes actually disagree. Rubber-stamping is not oversight.

Two more worth knowing. Employment-related AI — recruitment, task allocation, promotion and termination, and monitoring or evaluating performance — is classified as high-risk under the Act, which puts duties on you as the deployer, including informing affected workers and their representatives before you put such a system to work. And covert monitoring is off the table outside a documented investigation into suspected serious wrongdoing.

The four tests every monitoring decision has to pass

For everything that is not banned, the question becomes whether you can justify it. Four tests, and you want the answers written down somewhere before a dispute, not after.

Lawful basis. For workplace monitoring it is almost always legitimate interests, not consent — consent in an employment relationship is treated as unreliable, because the person asking controls your pay. Write a short legitimate interests assessment instead: the interest pursued, why monitoring is needed for it, and why it does not override the rights of those affected. Half a page is fine.

Necessity and proportionality. Use the least intrusive method that achieves the purpose. If the purpose is "know whether the support queue is staffed well enough," team-level volumes answer it; individual keystroke counts do not become legitimate because the tool offers them. Sampled beats continuous, and aggregate beats individual.

Transparency. Tell people in plain language, before it starts: what is collected, why, who can see it, how long it is kept, how to object. A clause in an induction pack signed eighteen months ago does not count.

A documented impact assessment. Systematic monitoring of employees is one of the clearest triggers for a data protection impact assessment. For a fifteen-person business that is two pages with a named owner, not a consultancy project — but it has to exist. Our AI and GDPR guide walks through the paperwork, and the EU AI Act guide covers which tier your tools fall into.

An underrated fifth: retention. Most disputes are not about collecting data but keeping it — a year of transcripts in a shared drive "just in case" is a liability with no owner and no purpose.

Where small businesses get this wrong

The failures are consistent, and none involve a business deliberately spying on anyone.

The note-taker that joins everything. Set up for client calls, it default-joined a one-to-one where someone discussed a difficult situation at home, and the transcript now sits in a folder half the company can open. Scope recording tools by meeting type, default off for internal conversations.

Buying monitoring without noticing. "We have got four tools and nobody knows what any of them actually do" is a sentence we hear constantly — and one of those tools is usually generating per-person metrics in a tab nobody has opened. Review admin consoles when you buy, not when you are challenged.

Using a number nobody was told about. A manager opens a review with an activity score the employee did not know existed — a transparency failure and an employee-relations failure at once. Our guide to using AI for performance reviews covers the defensible version.

Ignoring where the data goes. A tool hosted outside the UK or EEA means transfers, and transfers need a mechanism before rollout.

A proportionate monitoring policy you can write this week

Every article says "use AI responsibly" but nobody says how. Here is the sequence. Budget two hours.

  1. Inventory, 30 minutes. List every tool that records, transcribes, scores or ranks a person, including ones bundled free with software you already pay for. Note what each captures, who sees it, and how long it is kept.
  2. One sentence of purpose per tool. If you cannot write a specific business purpose in one sentence, switch that feature off. This step alone usually removes a third of the list.
  3. Dial each one down. Aggregate not individual, sampled not continuous, summaries not full recordings, retention of 30 to 90 days not forever, internal meetings excluded by default.
  4. Write the one-page notice. Plain language, one table, one row per tool. This is the document you will be glad exists.
  5. Put the human-in-the-loop rule in writing. Name the role that reviews any AI output used in a decision about pay, promotion, discipline or hiring, and state that the output is evidence, never the decision.
  6. Tell people before you switch anything on, and consult employee representatives or your works council where you have one. Then diary a six-month review — the tools will have changed by then.

A prompt that does most of step 4:

You are an employment-privacy specialist drafting for a business in
[country] with [N] employees. Write a one-page employee monitoring
notice covering these tools: [for each — name, what it records, who
sees the output, how long it is kept].

For each tool, state: the business purpose, the lawful basis, who can
access the data, the retention period, and how an employee objects or
requests their own data. Plain language, no legal jargon, under 600
words, British English.

Then flag any tool where the data collected looks disproportionate to
the stated purpose, and say what a less intrusive setting would be.

Treat the output as a first draft, not a finished policy, and fold it into your wider AI policy rather than letting it live as an orphan document.

When an employee challenges your monitoring

This is the scenario that turns an abstract compliance question into a real week of work, and it usually arrives attached to a grievance, an exit, or a dispute about a review.

A subject access request gives you roughly one calendar month to hand over the personal data you hold about that person: transcripts they appear in, call scores, activity metrics, and the AI summaries built from them. The practical question is not whether you may hold it, but whether you can extract one person's data from six tools, redact third parties and ship it inside a month. Test that once, on yourself, while nothing is at stake. A business that cannot answer a request is in a worse position than one that monitored slightly too much and documented it properly.

You should also be able to explain any decision an AI output fed into: what the system measured, what the human reviewed, why the conclusion followed. If the honest answer is "the tool gave a number and we went with it," you have found the gap before a tribunal did.

The quieter cost is trust. Staff who believe they are scored by something they cannot see stop experimenting with AI, stop reporting its mistakes and start working around it — the exact behaviour that makes a rollout fail. Monitoring and adoption pull against each other, and adoption is worth more.

The bottom line

You are probably already monitoring, so the question is not whether but whether you can justify it. Three things are off-limits: inferring employees' emotions, biometric categorisation, and letting an algorithm make a consequential decision alone. Everything else must clear four tests — a documented lawful basis, the least intrusive method that works, telling people in advance, and a written impact assessment. Spend two hours this week on an inventory, a one-page notice and a human-in-the-loop rule, and you are not just better protected than your competitors. You are the business whose staff will still tell you when the AI gets something wrong.

Where does your business stand on AI?

Take the free 3-minute AI Readiness Quiz and get a personalised score with your next steps.

Take the Free Quiz →