At an IMMERSE HR dinner in Miami, Fortinet’s Elisa Ball shared a practical framework for determining how much power organizations should give AI over different types of HR decisions

At an IMMERSE HR dinner in Miami on September 17, HR, L&D, and talent leaders gathered to talk about what responsible AI adoption looks like. Leading the conversation was Elisa Ball, Senior Director of Human Resources for Latin America at Fortinet, a global cybersecurity company.

Ball opened the discussion with a simple question: who had used AI at work that week?

Then she asked a harder one: how did you check whether the result was accurate?

The second question is at the heart of the challenge facing HR departments adopting AI technology. Giving people access is easy. Making sure they know when to trust it, when to question it, and where human judgment still belongs is not.

People first, technology second

Ball framed responsible AI adoption this way:

“Successful AI adoption isn’t about having the most advanced technology — it’s about preparing people to use it responsibly.”
— Elisa Ball, Fortinet

For HR, that preparation has several components. Employees have always needed ongoing training to help build skills they can use at work, and AI adoption is no different. Employees need AI literacy and opportunities to reskill and upskill as AI technologies change how their jobs are done.

Leaders need preparation too. They must be ready to manage AI-enabled teams as the technology becomes part of everyday work.

In addition, HR must balance innovation with employee trust. Organizations need clear ethical guidelines for who uses AI and how. Rules become especially important when AI is used to help shape important decisions.

That, as Ball pointed out, raises a new question: Where should boundaries be drawn when AI starts influencing decisions about people?

Decisions AI should never make

Ball presented a simple framework for assigning AI different degrees of decision-making autonomy depending on the situation. The appropriate level does not depend on how capable the AI is. Instead, two questions matter:

How easily can the decision be reversed, and does it affect a person’s standing at work?

For low-stakes, easily reversed HR tasks like summarizing survey comments or scheduling, Ball’s framework allows AI to decide. Conversely, decisions with serious repercussions for people, such as termination or taking disciplinary action, must never be decided by AI alone.

Some tasks fall between these two poles. These are HR tasks that can materially influence decisions about people, such as shortlisting candidates or compensation benchmarking. The framework allows AI to contribute to tasks in this category, but a person must make the actual decision.

This middle category raises tricky questions, however. When AI makes a shortlist of candidates, whoever gets left off may never get considered by the human making the decision. Compensation benchmarks suggested by AI do not determine someone’s pay, but the suggestions can influence the range a manager considers.

In such cases, is AI merely providing suggestions, or is it effectively making part of a consequential decision? Reasonable people within the same organization may answer that question differently.

Either way, organizations must ensure that human oversight means more than simply approving the AI’s recommendation. Ball calls for a trained reviewer with enough time to examine the output and real authority to disagree with it. That human decision-maker remains accountable for the result.

Ball also specifies that decisions in this middle category should always be reviewed and recorded. In her presentation, she ties responsible AI to being able to explain how decisions were made and give people a way to challenge the outcome. Meaningful review might look like checking whether the AI screened out any candidates who would have been shortlisted by a human performing the task.

Silence is not neutral

Ball’s presentation showed what employees are actually asking about AI adoption:

  • “Is this going to replace my job?”
  • “Who can see the data it collects about me?”
  • “Was this decision about me made by a machine?”
  • “If I disagree, who do I talk to?”

Many employees also have a more practical question: “Am I allowed to use these tools in my own work?”

Addressing potential concerns before the AI system is deployed can earn employee trust. Ball advises organizations to explain in advance what the AI does, what it does not do, and when it may affect decisions about them.

Every AI tool that touches decisions about people should have a clearly identified human who owns the decisions. Employees also need to know where to go if they want to question an outcome that was influenced by AI.

Organizations also need clear rules and training on which AI tools employees themselves are allowed to use at work.

Ball says HR also needs practices governing how employee data is used by AI systems. HR should have a clear accounting of what information the tools receive and where it is stored. AI should only be given the data it needs to perform its tasks, and a limit should be set on how long that data is retained in the system.

As Ball put it,

“Silence is not neutral. If HR does not explain how AI is used, employees will assume the worst version.”
— Elisa Ball, Fortinet

The rules are arriving unevenly

Governments are beginning to set rules for how AI can be used in employment decisions. Those regulations do not yet apply everywhere, and they are arriving at different times. New York City already regulates certain automated employment decision tools. The EU has adopted rules for certain uses of AI in employment, including some uses in hiring and worker management, to take effect in December 2027. Brazil is currently considering national AI legislation, including rules for some uses of AI affecting workers and employment decisions.

Organizations do not need to wait until new requirements apply to them before implementing responsible AI practices. Building transparency and accountability into deployment from the beginning is easier than trying to retrofit them later.

Ball offers a simple three-part HR to-do list:

  • Tell people when AI takes part in a decision about them.
  • Keep a record of how that decision was made.
  • Give them a real way to challenge it.

These steps won't satisfy every requirement in every jurisdiction, but they align with the direction these rules are taking and provide a practical place to start.

This is a general summary, not legal advice.

Take the first step

Ball closed her presentation with a question: “What is one action you will take after today’s conversation?”

A manageable first step is to write down which HR decisions AI is currently allowed to make in your organization, then compare each one with Ball’s three levels of decision-making authority.

That comparison reinforces a central point: what AI can do is not the same as what organizations should allow it to do.

IMMERSE runs these dinners regularly. If you’d like to be at the next one, get in touch.

FAQ

Which HR decisions should AI never make on its own?

No matter how sophisticated the AI is, it should not make consequential decisions that directly affect someone’s livelihood or standing, such as promotion or termination. AI can assist with tasks such as shortlisting candidates, but a human should make the final decision, and the review should be recorded. HR tasks like scheduling and answering policy questions can be automated.

What does "responsible AI in HR" mean in practice?

It means putting four safeguards in place: oversight by a trained person with the time to review AI recommendations and the authority to disagree with them; transparency with employees about how AI is used in decisions about them; privacy and security protections chosen when AI tools are selected; and checking for bias on a recurring basis.

Do we have to tell employees when AI is used in a decision about them?

Increasingly, yes. Specific requirements vary by jurisdiction and by how AI is used, and more jurisdictions are creating rules for how AI can be used in employment decisions. Organizations are responsible for knowing which laws apply to them. Even where notice is not currently required, they can put three practices in place now to prepare for future requirements: tell people when AI takes part in a decision about them, record how the decision was made, and provide a way to challenge the outcome.

What is NYC Local Law 144 and does it apply to us?

NYC Local Law 144 regulates certain automated employment decision tools used in hiring and promotion. When it applies, employers must ensure the tool has had an independent bias audit within the past year, publish a summary of the results, and give required notice to covered candidates or employees before using it. Whether the law applies depends on the job location and the role AI plays in hiring or promotion, so organizations should confirm their obligations with counsel.

When do the EU AI Act's HR rules take effect?

The EU AI Act is already in force, but its requirements are being phased in. Rules for high-risk AI systems used in employment, including certain systems used in hiring, promotion, termination, and performance evaluation, take effect in December 2027. Organizations should confirm which provisions apply to the AI systems they use.

Will AI replace HR roles?

According to Fortinet HR leader Elisa Ball, AI will change HR work rather than eliminate the need for HR professionals. She identifies AI literacy, critical thinking, ethical judgment, and change leadership as increasingly important skills as people work with AI.