A short glossary for AI at work, in plain English
The terms that keep coming up across this series, defined in plain English, without assuming you already know them.
Automation
A rule applied consistently. Given the same input, an automated process gives the same output every time, and you can trace exactly why. A payslip calculation or a leave balance are automation's natural territory. It is not artificial intelligence, and calling it that muddies exactly the distinction this series keeps coming back to.
Artificial intelligence (AI) and generative AI
Software that produces an answer, or a piece of text, image or recommendation, based on patterns learned from data, rather than following a fixed rule. The output is plausible, not guaranteed correct, which is the opposite trade-off to automation. Generative AI, tools like chatbots and drafting assistants, is the specific kind most people mean when they say "AI" at work.
Automated decision-making (ADM)
A decision made without meaningful human involvement, using automated processing of someone's data. UK law gives people specific rights over solely automated decisions that have a legal or similarly significant effect on them, covered under Articles 22A to 22C of UK GDPR since 5 February 2026.
Significant decision
The legal term for a decision serious enough to trigger the ADM safeguards: one with a legal effect, or an effect similarly significant to the person it concerns. A recruitment rejection or a disciplinary outcome would typically qualify. A minor scheduling adjustment typically would not.
Meaningful human involvement
The legal standard for what stops a decision counting as solely automated. It requires a real person with genuine authority, and enough information and time, to actually change the outcome, not someone approving a screen without the power or the context to say no.
A glossary is not decoration. It is what stops "AI-powered" meaning whatever the seller wants it to mean this week.
Profiling
Using someone's data to evaluate or predict something about them: their performance, their reliability, their likely fit for a role. Profiling can feed into an automated decision, or simply inform a human one, but either way it is worth knowing when it is happening, since it is a specific, defined activity under data protection law.
Algorithmic bias
A pattern in a tool's output that systematically disadvantages a group of people, usually because the data it learned from already contained that pattern. The clearest documented example is Amazon's scrapped recruiting tool, which downgraded CVs mentioning women's colleges after learning from a decade of male-dominated hiring data.
Automation bias
The human habit of trusting a system's output simply because a system produced it, and checking it less carefully as a result. It is the reason "a person checked it" is not automatically reassuring: the checking itself can be shallow if the checker assumes the tool is probably right.
Hallucination
When a generative AI tool produces an answer that sounds confident and plausible but is simply wrong, invented rather than retrieved. It is not a bug in the traditional sense, it is what these tools do by design when a pattern-based guess is asked to stand in for a fact.
Subject access request (SAR)
A request by an individual for a copy of the personal data an organisation holds about them, including any profiling or automated scoring outputs. UK employers have one calendar month to respond, extendable by up to two further months if the request is complex.
Bias audit
A structured check of a tool's outputs against protected characteristics, looking for a pattern of disadvantage. Government guidance on recruitment recommends doing this both at the point a tool is bought and roughly every six months afterwards, since a clean result once is no guarantee it stays clean.
Workplace monitoring technology (WMT)
Any tool that collects data on how someone works in order to make a judgement about them: keystroke logging, webcam or productivity software, algorithmic scoring, or location tracking. It is the subject of a live UK government consultation running until 30 September 2026.
Legitimate interests
One of the lawful bases a business can rely on to process personal data under UK GDPR, alongside consent, contract and others. Since February 2026 it has become available for a wider range of significant automated decisions than before, which is why the safeguards around those decisions matter more, not less.
Data Protection Impact Assessment (DPIA)
A structured assessment a business carries out before starting a type of data processing likely to be high risk, working through what data is used, why, and what could go wrong. Recruitment tools using automated scoring are a common example of processing the ICO expects a DPIA for.
Shadow AI use
AI tools staff use at work without the business knowing, approving, or governing them, usually because no policy or approved alternative exists. It is less a technology problem than a communication one, and a usage policy is the direct fix for it.
One more definition, our own
Jamie HR is automation, not AI. It runs on configurable workflows that do the same, explainable thing every time, for the reasons set out across this whole series. If a future feature ever changes that, we will say so as plainly as everything defined above.