The short answer: it depends on where you work and what you were told
Employer monitoring using AI is not uniformly permitted or prohibited. The legal position varies significantly by jurisdiction, and critically, by whether you were informed. In most major jurisdictions, your employer can monitor you using AI tools on employer systems, but only with adequate disclosure, proportionate purpose, and compliance with data protection law. Covert AI monitoring without your knowledge is unlawful in most jurisdictions.
What AI monitoring actually looks like now
Workplace monitoring has evolved well beyond tracking internet use and counting keystrokes. Contemporary AI monitoring tools can: analyse email and message content for sentiment, topics, or compliance risk; monitor computer activity including applications open, websites visited, and documents accessed; track productivity through document creation, communication frequency, and task completion; score call centre and customer service quality by analysing recorded calls; assess meeting participation and engagement through video analysis; measure physical location and movement in warehouse and retail settings; analyse biometric data (fatigue detection, emotion recognition in some contexts); and aggregate all of the above into employee risk scores or performance profiles.
Tools like Microsoft 365 Copilot, when deployed with full permissions, can analyse an employee's entire digital footprint across email, Teams, documents, and calendars. This capability is transformative, it means AI monitoring is now available to any organisation with a Microsoft enterprise licence, not just those who specifically procure monitoring software.
Jurisdiction-by-jurisdiction: what is and is not permitted
Australia: The Privacy Act requires open and transparent management of personal information (APP 1), though the Act's employee records exemption (s 7B(3)) means the APPs largely do not apply to private-sector employers' handling of existing employee records, so state surveillance laws are the main source of notice obligations. The Workplace Surveillance Act 2005 (NSW) requires at least 14 days' written notice of surveillance and an existing, communicated computer-surveillance policy (ss 10, 12). The ACT has a similar regime under the Workplace Privacy Act 2011; other states, including Queensland and South Australia, rely only on general surveillance devices laws with no NSW-style notice regime. Covert monitoring, monitoring without telling you, requires a magistrate-issued covert surveillance authority in NSW, with a similar regime in the ACT; most other states have no workplace-specific covert surveillance authorisation requirement. AI monitoring that collects sensitive information (biometric data, health information) requires your consent or a statutory exception.
UK: The ICO's Employment practices and data protection: Monitoring workers guidance (October 2023, replacing the earlier draft Monitoring at Work guidance) requires disclosure of monitoring in your employment contract, staff handbook, or privacy notice. A DPIA is legally required under UK GDPR Article 35 whenever monitoring is likely to result in a high risk to workers' rights, which biometric and AI-driven monitoring normally will, and the ICO goes further in guidance, saying it expects a DPIA before any worker monitoring even where one is not strictly required. UK GDPR requires a lawful basis, typically legitimate interests, which must be balanced against employee privacy rights in a legitimate interests assessment. The balance is harder to strike the more intrusive the monitoring. Covert monitoring is justifiable only in exceptional circumstances, which the ICO frames as necessity to prevent or detect suspected criminal activity or gross misconduct where no less intrusive means is available, and even then it must be covered by a DPIA, authorised by senior management, strictly targeted, time-limited and stopped once the investigation ends.
EU: GDPR applies to employee monitoring data. Most EU member states impose additional requirements. In workplaces with a works council, German law (BetrVG s 87(1) no. 6) gives it co-determination rights over performance-monitoring technology, with disputes resolved by a conciliation committee. France's Labour Code (Article L.1222-4) requires transparent disclosure of monitoring, with CNIL guidance stressing proportionality and periodic review. Spain's Labour Law requires employee representatives to be informed about AI control mechanisms before deployment.
United States: Federal law (ECPA) has a broad employer exception permitting monitoring of employer-owned systems during work hours where employees have been notified. Several states require written notice, New York's Electronic Monitoring Law (effective 2022) requires employers to notify new employees at hiring and display a posted notice. Connecticut and Delaware have similar requirements. There is no federal prohibition on AI monitoring of employees on employer systems with notice. However, using AI monitoring to identify or retaliate against employees engaged in union organizing violates the NLRA regardless of disclosure.
What your employer cannot do regardless of jurisdiction
Across all major jurisdictions, there are limits. Your employer generally cannot: monitor your personal email accounts or personal devices without your specific, informed consent; use AI to monitor union organizing activity or retaliate against employees for engaging in protected concerted activity; monitor you using biometric technology without adequate disclosure and, in many jurisdictions, consent; use monitoring data for purposes beyond those disclosed (for example, using welfare monitoring data in performance management without disclosure); or use AI to infer your emotions in the workplace, which Article 5(1)(f) of the EU AI Act has prohibited outright in the EU since 2 February 2025, except where the use is intended for medical or safety reasons. Other biometric monitoring at work is not banned outright by the AI Act. It is treated as high-risk under Annex III, and Regulation (EU) 2026/1744, in force since 27 July 2026, deferred standalone Annex III high-risk obligations to 2 December 2027, so GDPR Article 9 and national employment law remain the operative constraints in the meantime.
Your practical rights
In all major jurisdictions: read your employment contract, IT acceptable use policy, and privacy notice for disclosure of monitoring; make a subject access/data access request for your personal data including monitoring data; raise concerns with your employer's Data Protection Officer or HR department; contact the relevant supervisory authority (ICO in UK, OAIC (Office of the Australian Information Commissioner) in Australia, national DPA in EU member states) if you believe monitoring is unlawful; and in the US, contact the NLRB if you believe monitoring is being used to interfere with protected union activity.
Related reading
- Do I Have to Use AI at Work? Your Rights When Your Employer Introduces AI Tools
- Is AI Reading My Work Emails? What Employers Can and Cannot Do
- AI and Your Rights at Work: A Global Guide for Employees
- A Practical Guide to AI Tools: What You Need to Know Before Using ChatGPT, Copilot, or Any AI
Further reading: OECD AI and Work