Skip to main content

44% of Managers Feed Employee Names Into Public AI Tools While Only 45% of Employers Have a Policy

44% of managers have put employee names and performance details into public AI tools, and only 45% of employers have a written policy covering it.

44% of Managers Feed Employee Names Into Public AI Tools While Only 45% of Employers Have a Policy

According to HR Dive, 44% of managers have entered employee names and performance details into public AI tools, and only 45% of organisations have a formal written policy on AI use in performance management. The figures come from The Predictive Index, which surveyed 399 managers and 208 CEOs and business leaders across various industries. At Metaintro, we look at what actually happens to workers inside a process rather than what the policy says should happen, and this is a case where the gap between the two is measurable. If you have had a performance conversation recently, there is a reasonable chance a public chatbot helped script it.

What did managers actually put into these tools?

Employee names and performance details. That phrasing matters, because it is the combination rather than either element that creates exposure. A generic question about how to deliver difficult feedback carries no risk to anyone. A named individual attached to a performance assessment is personal data about a specific person, entered into a system their employer does not control.

The underlying motivation is not carelessness, and it is worth being fair about that. Close to 3 in 4 managers surveyed, 72%, said public AI tools are useful for preparing for difficult conversations. Only 1 in 5 said they preferred to prepare for such conversations on their own rather than with a framework, a coaching guide or input from HR. Managers reported struggling most with delivering constructive criticism, anticipating employee reactions and staying objective. These are people looking for help with a genuinely hard part of the job and reaching for the tool nearest to hand. An I/O psychologist at The Predictive Index put it as managers being more aware of where they need support than their leaders are, and said addressing those needs starts with understanding what is driving them.

Why does the missing policy matter so much?

Because without one, the individual manager carries the risk personally. Only 45% of organisations surveyed have a formal written policy regarding AI use in performance management, despite reported concern about employee information being put into public platforms. That is an organisation aware of a problem and not addressing it, which in practice transfers responsibility down to whoever typed the prompt.

The wider worker data supports how common this has become. A survey of 500 employed US adults conducted through the Pollfish platform for a California business-litigation firm found 38% had entered at least one type of work information into a personal AI account their employer does not control. Broken down, 23% pasted internal emails, memos or documents, 11.8% shared customer or client information, 11.4% pasted contracts or legal documents, and 10.6% shared employee and HR information. Among those who had entered company data into personal accounts, internal documents led at 60.5%. This is not a fringe behaviour confined to managers.

Do people know this can be illegal?

Mostly not, and that is the most striking finding in the whole picture. Only 35.6% of workers surveyed knew that entering confidential company information into a personal AI account can be against the law, with 44.4% uncertain and 64.4% unaware the conduct could potentially violate laws. Roughly two thirds of a workforce is engaging in a behaviour without knowing its legal status. That is a training failure rather than a discipline problem, and it is worth naming as such before anyone reaches for a sanction. Awareness gaps of this size are fixed with a briefing, as Metaintro found in the workplace rights most workers never learn until they need them.

For employees, the practical exposure is more immediate than a legal abstraction. Data protection rules in most jurisdictions treat an identifiable person's performance information as sensitive, and the obligation usually sits with the employer as the data controller. When a manager routes that data through a personal account, the employer often cannot demonstrate where it went, which is precisely the failure a regulator penalises. The person who pasted it becomes the identifiable cause. Metaintro has covered how quickly the accountability question lands on individuals rather than systems in what front line workers say they want from AI at work, where the consistent request was simply to be told how the tools are used.

What should you do if you are the employee being discussed?

You have more standing here than most people realise, and the reasonable move is procedural rather than confrontational. In a performance conversation, it is legitimate to ask how the assessment was prepared, what evidence it rests on and whether any tools were used to draft it. Framed as wanting to understand the reasoning, that question is difficult to refuse and it produces a record.

Ask for the substance in writing as well. If feedback has been shaped by a system that generates fluent, confident language regardless of evidence, requesting the specific examples behind each point tends to reveal how much is actually there. That is a fair request in any performance process. It also protects you from a documented pattern that is really a generated one. If the review is the basis for a promotion decision, that evidence trail matters more still, as Metaintro sets out in what actually moves a promotion case forward and in how to negotiate when the salary itself will not move. Metaintro has looked at the related danger of confident output substituting for real assessment in how AI hides a learning debt that can stall a career, and at what candidates should ask about AI in what to check before taking an AI job title.

What should you do if you are the manager?

Separate the help you need from the data you disclose, because the survey shows the need is real and the disclosure is optional. Nothing stops a manager from asking a tool how to structure difficult feedback, how to anticipate a defensive reaction or how to stay objective, which are the three things managers said they struggle with most. What creates the risk is attaching a name and a performance record to that question. Strip identifying detail and describe the situation generically, and almost all of the value survives.

Second, ask whether your employer is among the majority with no written policy on this, and if so, ask for one in writing. That request protects you twice. It establishes that you raised the issue, and it usually produces guidance that limits your personal exposure. Third, use the internal support that 4 in 5 managers say they would rather have than working alone. HR input and a coaching framework carry no data risk at all. Metaintro's guides to training and development jobs in human resources and the types of human resources jobs set out who inside most organisations owns that support, and it is often a shorter route than managers assume.

What should HR and employers take from this?

That the absence of a policy is itself a decision, and currently the more common one. With only 45% of organisations having formal written rules on AI in performance management, the majority are relying on individual judgment for a task that carries legal and reputational consequences. Given that 72% of managers already find these tools useful for the work, a prohibition is unlikely to hold. The realistic options are a sanctioned tool with appropriate controls, or an unsanctioned one being used anyway with employee names in it.

There is also a quality problem sitting underneath the compliance one. Performance documentation shapes promotions, pay and dismissals, and it is often the evidence an employer relies on if a decision is challenged. Documentation generated by a tool that produces plausible language on thin input is weak evidence, and it is weak in a way that is hard to detect until it is tested. Leaders surveyed said they trust their managers, but as the research put it, trusting a manager and knowing they are set up for a specific hard conversation are different things. Metaintro has tracked the same gap between confidence and capability in the burnout that arrives with managing AI agents and in the hours workers lose to checking machine output.

What does a workable policy actually look like?

Specific enough to follow on a Tuesday afternoon, which most policies are not. The failure mode here is a document that bans AI in performance management outright, because 72% of managers already find these tools useful for preparing difficult conversations and a ban simply moves the behaviour out of sight. A policy that acknowledges the need and channels it will be followed. One that pretends the need does not exist will not.

Four elements do most of the work. The first is a named, approved tool, so managers are not choosing between an unsanctioned public account and no help at all. The second is a clear rule on identifiers, stating plainly that names, employee numbers, health information and specific performance records do not go into any tool outside the organisation's control. Given that 44% of managers have already entered names and performance details, this is the line that most needs writing down. The third is a rule about evidence, requiring that any documented assessment rest on examples the manager observed, whatever tool helped structure the wording. The fourth is a route to human support, since only 1 in 5 managers prefer to prepare alone and the other four fifths are looking for a framework, a coaching guide or HR input.

The reason to move now is that the alternative is already running at scale. Across the wider workforce, 38% of surveyed workers had entered work information into a personal AI account, 36.8% rely partly on personal accounts for work tasks, and 57.6% use AI tools for work generally. Policy is not deciding whether these tools enter the workplace. They are in it. Policy decides whether the organisation can say where its employee data went, which is the question that gets asked after something goes wrong rather than before. For HR teams weighing who should own this, Metaintro's guide to how benefits and compliance certifications strengthen a career is a useful map of where that responsibility usually sits, and the career development gap most workers blame on their manager shows what happens when the support layer is missing entirely.

What does this mean for your career?

Two things, depending on which side of the table you sit. As an employee, treat your performance record as something you should be able to interrogate, because a meaningful share of it may now be drafted rather than observed. Keep your own record of what you delivered, with dates and outcomes, so that a conversation about your performance can be grounded in evidence you control. That habit is useful in every review, and it is decisive in one built on a generated summary.

As a manager or an HR professional, this is a chance to be early on something that is about to become standard. Written AI policy covering performance management is currently a minority practice, and the people who write and implement those policies now will own a capability their organisations will need within a year. That is a genuine specialism forming in real time, sitting at the intersection of HR, data protection and operations. Anyone who can hold all three has an unusually strong position, precisely because most organisations have not yet decided who owns the problem.

Related Articles

People Also Asked

Q: Is it illegal for a manager to put employee data into ChatGPT or a similar tool?

A: It can be, depending on jurisdiction and the data involved, and most people do not know that. Only 35.6% of surveyed workers knew entering confidential company information into a personal AI account can be against the law, while 44.4% were uncertain. The obligation usually sits with the employer as data controller, but the manager who entered the data is the identifiable cause.

Q: How common is this at work?

A: More common than most policies assume. Among managers, 44% have entered employee names and performance details into public AI tools. Across the wider workforce, 38% of surveyed US workers had put at least one type of work information into a personal AI account, including 10.6% who entered employee and HR information.

Q: Can I ask whether AI was used to write my performance review?

A: Yes, and it is a reasonable question to put in a review meeting. Asking how the assessment was prepared and what specific evidence supports each point is standard practice in any fair process. Given that only 45% of organisations have a written policy on AI in performance management, your employer may not yet have a settled answer, which is useful to know.

Performance records shape pay, promotion and exits, so it is worth working somewhere that treats them seriously. Metaintro surfaces verified roles from employers who are actively hiring, including the HR, compliance and people operations jobs being created to solve exactly this problem. Create a free profile to see which of them match your experience.

Share this article

For job seekers

Ready to find a role that actually fits?

Upload your résumé, start a Job Search Thread, and let Metaintro rank real openings against your experience — then guide you from search to offer.

Match

Compare live roles against your current evidence.

Position

Turn proof projects into role-specific applications.

Improve

Use market feedback to keep the skill plan current.

Return to navigation