Image by geralt on Pixabay

Deepfakes and Digital Twins in Labor Law: What Companies Need to Know About Their Obligations

Deepfakes and Digital Twins: What Employers Need to Know Now About Labor and Data Protection Laws.

With the use of artificial intelligence in the workplace, the line between what is real and what is fake is becoming blurred. Deepfakes and digital twins can deceive, expose, or covertly monitor employees—thereby subjecting employers to new obligations under labor and data protection laws.

Deepfakes and digital twins—what are they all about?

Artificial intelligence now makes it possible to create images, audio, and video recordings that are deceptively realistic. The terms “deepfake” and “digital twin” are often used interchangeably, even though they describe different technologies.

A deepfake is image, audio, or video material generated or manipulated using artificial intelligence that makes a person appear to make statements or perform actions that never actually took place. This can be used to impersonate people or deliberately deceive them.

A digital twin, on the other hand, is a digital representation of a real person or a real process. Companies use digital twins, for example, for training, optimizing workflows, or simulating specific work processes. When used correctly, this technology offers great potential—but at the same time, it raises numerous questions regarding labor law and data protection.

What risks do companies face?

The use of artificial intelligence opens up new opportunities for companies, but also creates new opportunities for abuse. For example, deepfakes can be used in fraud attempts when employees receive purported video or voice messages from supervisors and are thereby tricked into making bank transfers or disclosing sensitive company data.

Similarly, manipulated content can be used to defame colleagues or managers or to damage their reputation. Such incidents not only take a toll on the individuals involved, but can also significantly disrupt workplace harmony and permanently undermine trust within the company.

Digital twins also carry risks. Since they are often based on large amounts of personal data, companies must carefully assess whether their use is permissible under data protection laws and whether employees’ rights are adequately protected.

Employers Bear Responsibility

The use of new technologies also brings with it new responsibilities. Employers are obligated to protect their employees’ personal rights under their duty of care as stipulated in employment contracts. If they become aware that employees are being disparaged, humiliated, or deceived by deepfakes or other AI-generated content, they must not stand idly by.

Rather, they must take appropriate measures to prevent further violations of the law. These include, for example, internal investigations, the removal of illegal content from company communication channels, organizational safeguards, or support for affected employees.

If employees themselves commit such violations, this may result in consequences under labor law. Depending on the severity of the individual case, a written warning or even termination for cause may be considered. Whether termination is justified always depends on the specific circumstances and a comprehensive balancing of interests.

Data protection and privacy rights must not be neglected

Deepfakes and digital twins are often based on image, voice, or motion data from real people. In many cases, this data is personal or even biometric, and its processing is subject to specific data protection requirements.

Companies should therefore assess, even before deploying such AI applications, the legal basis on which personal data may be processed and what technical and organizational safeguards are required. At the same time, employees must be provided with transparent information about which AI systems are being used and for what purpose their data is being processed.

In addition to data protection regulations, employees’ personal rights also play an important role. If faces, voices, or other personal characteristics are used without a sufficient legal basis or consent, this can result in significant legal consequences.

The works council should often be consulted

If a company implements AI systems that process personal data or are capable of monitoring employees’ behavior or performance, the works council may have co-determination rights. This applies not only to digital twins but, under certain circumstances, also to technical systems designed to detect deepfakes.

Involving the works council at an early stage promotes transparency and legal certainty. At the same time, it allows for the joint development of guidelines that promote the responsible use of artificial intelligence within the company.

New Transparency Requirements Under the EU AI Regulation

In addition to labor and data protection law, European regulation of artificial intelligence is also becoming increasingly important. The EU AI Act is gradually introducing new requirements for companies.

In many cases, anyone who uses AI-generated or AI-manipulated image, audio, or video content will be required in the future to disclose that this content was artificially created or altered. This transparency requirement is intended to prevent people from being misled by content that appears deceptively real. Companies should therefore assess at an early stage whether the AI applications they use fall under these requirements and adapt their internal processes accordingly.

Take action early rather than react later

Deepfakes and digital twins will continue to shape the world of work in the future. Companies should therefore not wait until an incident has already occurred before taking action. It is recommended that they establish clear internal guidelines on the use of artificial intelligence, conduct regular awareness training, and implement secure approval and review processes for AI-generated content.

Companies that seek legal guidance early on regarding the use of artificial intelligence reduce liability risks, protect their employees, and at the same time build trust in the responsible use of new technologies.

What is a deepfake?

A deepfake is image, audio, or video material that has been manipulated or entirely generated using artificial intelligence to give the impression that a person said or did something, even though that was not actually the case.

What is a digital twin?

A digital twin is a digital representation of a real person or process. It is used, among other things, to simulate, analyze, or optimize workflows.

What are employers’ obligations?

Employers must protect their employees from violations of their personal rights, take appropriate measures in the event of deepfake incidents, and comply with labor, data protection, and, where applicable, works council regulations when using AI applications.

Can a deepfake have consequences under labor law?

Yes. If deepfakes are used to deceive or disparage colleagues or supervisors, disciplinary measures—including termination for cause—may be considered, depending on the severity of the incident.

Why is the EU AI Regulation important?

The EU AI Regulation establishes uniform rules for the use of artificial intelligence for the first time. Among other things, companies must comply with transparency requirements and, going forward, integrate AI systems more closely into their compliance structures.

Kostenloser Newsletter

Aktuelle Urteile, Praxistipps und neue Folgen aus Marken-, Urheber-, Medien- und Wettbewerbsrecht. Kompakt per E-Mail.

Double-Opt-in. Abmeldung jederzeit über den Link in jeder E-Mail.

Contact person

Picture of Florian Wagenknecht

Florian Wagenknecht

Specialist lawyer for copyright and media law

Free newsletter

Kostenloser Newsletter

Aktuelle Urteile, Praxistipps und neue Folgen aus Marken-, Urheber-, Medien- und Wettbewerbsrecht. Kompakt per E-Mail.

Double-Opt-in. Abmeldung jederzeit über den Link in jeder E-Mail.

Search

Request