AI in the Workplace: Key Principles for HR Professionals

Québec Order of Human Resources Professionals has just published guidelines for the “responsible, thoughtful and compliant” use of AI in the workplace. Here are the key takeaways.

“The integration of AI creates a paradox: it opens the door to new possibilities while also introducing risks associated with use that is not informed and thoughtful.”

That is how this roughly 50-page document begins. It outlines 10 key principles tied to the professional and ethical obligations of CRHA and CRIA members. Here are some of the most important points.

1. AI Never Dilutes Accountability

This is the report’s central theme. Using AI “can in no way serve as a justification for mistakes or as an excuse for repercussions affecting individuals or organizations.”

Whether it is a communication drafted with ChatGPT, a recommendation based on predictive analytics, or a decision made using automated screening, the HR professional remains fully accountable, including from a civil liability standpoint.

The takeaway: HR professionals must always be able to explain and justify a recommendation on its own merits—not simply because “the AI said so.”

2. Get Trained Before Using It

The Order recommends acquiring a solid understanding of an AI tool’s features, limitations and risks before using it. Professionals must also have sufficient expertise in the relevant HR field to assess the quality of the output.

“AI can in no way compensate for a lack of professional expertise.”

In other words, AI should remain a supporting tool, not a substitute for missing skills or knowledge.

The guidelines therefore call for continuous development of digital and AI literacy, as well as consultation with specialists when the necessary expertise is lacking.

3. Confidentiality: A Red Line That Must Not Be Crossed

The message is clear:

“Never enter personal information, confidential data or strategic information into an AI tool unless you are certain that the data is adequately protected.”

The Order distinguishes between three scenarios:

  • Free public tools: There is generally no contractual agreement, and prompts may be used to train the model. Sensitive information should therefore never be entered.
  • Paid subscriptions: The terms of service may exclude the use of customer data for model training, but the information still leaves the organization’s environment.
  • Privately hosted, internally deployed models: These are the only option that allows an organization to retain full control over its data.

4. Always Verify the Sources

Then there is the familiar issue of AI hallucinations.

AI “is designed to provide a plausible answer even when relevant information is unavailable, which can result in content that is inaccurate or even entirely fictional.”

In short: everything needs to be corroborated against reliable sources. An AI tool’s confident tone is not a substitute for verification.

5. Professional Judgment Cannot Be Delegated

The Order is explicit: no recommendation should rely entirely on an AI-generated analysis.

Instead, AI should be treated as an assistant that produces a draft, a possible avenue to explore, or an emerging trend—something that still needs to be verified, adapted, qualified, supplemented and placed in context.

The guidelines apply this principle differently depending on the use case:

  • Text generation: Review the output and verify it against applicable collective agreements and other relevant requirements.
  • Analytics: Cross-check AI-generated findings against other sources.
  • Conversational agents: Clearly define and limit the topics they are permitted to address.
  • Agentic AI: Establish operational boundaries and monitor its performance over time.

6. Assess the Risk Before Using AI—not After

The level of risk varies considerably depending on the context. Proofreading a document is clearly not the same as recommending promotions or terminations.

The greater the volume of data being processed—such as when screening large numbers of résumés—the harder it becomes to validate the results and the more vigilance is required.

The conclusion is important: deciding not to use AI is a legitimate outcome of a risk assessment.

7. Bias: Continuous Vigilance, Not a One-Time Audit

AI can reproduce biases embedded in its training data and, in some cases, amplify them.

The document therefore emphasizes the risk of proxy discrimination: even when legally protected characteristics are excluded, an algorithm can still discriminate through seemingly neutral variables that are correlated with those characteristics, such as postal codes or educational background.

The implication for HR professionals is clear: bias cannot be treated as a box to check once and forget about. AI systems require ongoing scrutiny to ensure that seemingly neutral inputs are not producing discriminatory outcomes.


Explore our trainings