AI in the Marketing Workplace - Communicate Online
Share

AI in the Marketing Workplace

By Communicate Staff

|

By Samuel Moore

Marketing teams can save time and improve creativity by using AI tools such as ChatGPT and image generators to develop campaign ideas, draft social media posts, translate content, create images, analyse customer trends, and personalise advertising. However, legal risks can arise from both the information entered into the tool and the content it produces, such as when an employee uploads customer data, confidential client material, or unpublished campaigns.

Can Employees Enter Company or Client Information into AI Tools?

Employees should not enter confidential company or client information into an AI tool unless the organization has approved its use.

The UAE Labour Code requires employees to “maintain the confidentiality” of information accessed through their work and “not disclose Work secrets”.

Uploading a client brief, pricing strategy, internal report or unreleased campaign may disclose that information to the AI provider, even if it is never published. Employers should therefore identify what information employees must not include in AI prompts.

What If the Prompt Contains Personal Data?

Entering personal data into an AI tool is itself a form of data processing. The UAE Personal Data Protection Law (“PDPL”) defines personal data as information that identifies someone “directly or indirectly”, including names, photographs, contact details, locations and online identifiers. It also defines processing broadly to include the collection, storage, sharing, use and disclosure of personal data.

Before approving an AI tool, organizations should check:

  • how the provider protects personal data; 
  • where the data is stored;
  • how long data is retained;
  • whether prompts are used to train the system; and 
  • whether data is transferred outside the UAE.

It is important to note that, although the PDPL is in force, its Executive Regulations have not yet been issued, and the full compliance framework is therefore not yet operational. Organizations should nevertheless align their AI policies with the PDPL in preparation for its full implementation. 

What Risks Can Arise from AI Image Generators?

AI image generators create copyright risks. Employees may upload photographs, logos, artwork or product designs that the organization does not have permission to use. The UAE Copyright Law protects photographs, drawings, illustrations and audiovisual works. It provides that only the author or relevant rights holder may authorise uses such as reproduction, modification and publication. 

Organizations should therefore control both: (1) what employees upload, and (2) how generated images are used. Outputs should be reviewed to ensure they do not copy protected material, misuse a brand, misrepresent a product or use a person’s image without appropriate permission.

Who Is Responsible for AI-Generated Marketing Content?

The organization that publishes AI-generated content remains responsible for it. Responsibility does not shift to the AI provider simply because the tool created the wording or image.

AI-generated marketing may include false product claims, invented statistics, incorrect prices or misleading descriptions. Under the UAE Cybercrime Law, promoting goods or services online through misleading advertisements or false statements may result in detention and/or a fine ranging from AED 20,000 to AED 500,000.

All customer-facing content should therefore be reviewed before publication. Claims, figures, translations, offers and images should be checked against reliable sources to ensure they are accurate and not misleading.

Should Employers Ban Employee Use of AI?

A complete ban on workplace AI is unlikely to be effective and may have unintended consequences, such as employees turning to personal accounts or unapproved tools without the organization’s knowledge.

Employers should instead introduce AI into the workplace with controls that reflect the level of risk involved, for example:

  1. Low-risk activities – General brainstorming or improving non-confidential wording is permitted without any oversight.
  2. Medium-risk activities – Public-facing content and AI-generated images should require human review and approval before use.
  3. High-risk activities – Employees are prohibited from entering confidential information or sensitive personal data into unapproved AI tools.

This allows organizations to benefit from AI without applying unnecessary restrictions to every use.

How Should Organizations Govern Employee AI Use?

Organizations should introduce a clear workplace AI policy supported by practical employee training. The policy should, at a minimum:

  • identify approved AI tools; 
  • explain what information must not be entered; 
  • distinguish between permitted, controlled and prohibited uses; 
  • require approval for higher-risk activities; 
  • set rules for personal data and confidential information; 
  • require fact-checking and human review; 
  • include copyright and image-clearance procedures; and 
  • explain how employees should report mistakes or data breaches. 

What Does This Mean Going Forward?

AI is likely to become a normal part of everyday marketing work. Organizations should therefore move from informal use to controlled adoption.

The aim should not be to hinder innovation, but to manage the risks by setting clear limits around confidential information, personal data, image generation, and public-facing content. With approved tools, employee training, and meaningful human review, businesses can benefit from AI without weakening legal compliance or customer trust.

(Samuel Moore is Senior Paralegal at BSA LAW)