AI HR Tools 24 min read

AI That Writes, and Who Signs It

The risk is in the destination, never in the draft. Six things teams generate, what each costs when it is wrong, and what happens when text moves through a process with no author.

James Carter James Carter 24 min read
AI That Writes, and Who Signs It

TL;DR

  • The core decision: who is answerable for the version of generated text that reaches a person.
  • When doing nothing is right: when a knowledgeable person rewrites everything before it goes.
  • What has to be true: a named human owns the final version, not the process that produced it.
  • How the options split: by who reads the output and what it costs them if it's wrong.
  • Decision rule: the risk is in the destination, never in the quality of the draft.
  • Outcome to expect: faster drafting, and one named owner per thing that goes out.

Nobody Decided This

Somebody on your team started using AI to draft things. Then somebody else did. Nobody announced it, nobody approved it, and it's now part of how several people work.

That's not a scandal, it's how useful tools spread, and most of what's being drafted is fine. The interesting question isn't whether people should be doing it. It's that a category of document now moves through your organisation with no author, and nobody has noticed, because the documents look exactly like documents.

Here's why that matters more in HR than in most places. The text you produce is read by the person it's about. A job advert is read by somebody deciding whether to apply. A review summary is read by the person being reviewed. A message about somebody's situation is read by them. When any of those contains something that isn't true, it isn't an inaccuracy in a document, it's something an employee was told by their employer.

So the reframe: stop evaluating the draft and start tracing the destination. Nobody cares whether the first version was good. What matters is who read the final version, what they did on the strength of it, and whether a named person was answerable for it going out. The quality question is about convenience. The destination question is about somebody's working life.

Everything below sorts the common cases by that second question, because a generated job advert and a generated message about somebody's performance are completely different risks wearing the same clothes.

One boundary. Whether you owe anybody a disclosure that text was machine-generated, and what obligations attach to it, differs by jurisdiction and is changing. Nothing here tells you what applies to you. Establish it with local advice, and take the policy framing from the AI in the workplace material, which owns acceptable use.

Free Weekly Briefing Stay ahead of what's changing in HR and people ops.

Join 4,200+ leaders getting practical insights every week — no fluff, just signal.

Join Free →

When You Genuinely Do Not Need to Act Yet

A knowledgeable person rewrites everything. The draft is raw material and somebody who knows the subject produces the version that goes out. That's a working arrangement and it needs nothing added.

People are drafting and nobody has discussed it. Extremely common. Worth naming rather than policing, because the practice is usually sensible and the gap is only that nobody owns the output.

Generated text is reaching people lightly edited. Somebody skims and sends. At that point the editing isn't a check, and whatever the draft contained has effectively been sent by your organisation.

The edge case that forces it. Something went out with a detail nobody can account for, and tracing it back there's no author, only a process. That's the position this piece exists to prevent.

Five Questions This Reader Asks at 11pm

Should we use AI to write HR content? For drafts, usually yes, and the productivity gain is real because starting is the expensive part of writing. The thing to settle alongside it is who owns the final version of anything that reaches a person, because that ownership is what tends to dissolve when a draft arrives ready-made.

Who's responsible for what it produces? Whoever sent it, from the reader's point of view, and that's the view that matters when somebody is upset. Internally it needs to be somebody by name rather than a team or a workflow, because documents with no author are the ones that go out unchecked.

Can AI write performance reviews? It can produce text that reads like one. Whether that's appropriate is a question about what a review is for, and the answer for most organisations is that the thinking is the point and the writing is the residue. A summary generated from notes somebody else took is a different thing from a manager's considered view, and the person being reviewed can usually tell.

Should employees be told? A reasonable question with no universal answer, because obligations differ by jurisdiction and are changing, and expectations differ by context too. Establish what applies to you with local advice. Separately from any obligation, it's worth deciding what you'd be comfortable having known, because that's usually the more useful test.

What's the actual risk? Specific invented detail reaching somebody who acts on it. Not tone, not style, not whether it sounds machine-written. A date, a figure, a policy reference or an entitlement that was never true, delivered fluently, to somebody with no reason to doubt it.

What Each One Costs When It Is Wrong

The artefact Who reads it What a wrong version does
A job advert Someone deciding whether to apply Attracts the wrong people, or deters the right ones
A review summary The person being reviewed Attributes things they didn't do, on their record
A message to an individual That person, about their situation They act on something untrue
Policy or handbook text Everybody, eventually A stated position nobody agreed
An answer to a question Whoever asked, who trusted it A decision made on a wrong basis
A translation People reading only that version A different policy in another language
An offer or contract summary Somebody deciding to join Expectations you didn't intend to set
Internal notes about a person Whoever reads the file later An unverified statement becomes the record

The second and third rows are where the real damage sits and they're both about individuals. Text describing a specific person, sent to that person, containing something that isn't true, is not a documentation error. It's an experience they have of their employer, and it doesn't get undone by a correction.

The fourth row is the slow one. Generated policy text that nobody formally adopted can end up in a handbook, quoted back to you by an employee, and treated as your position. Whether it actually is your position is a question you'd rather answer before the conversation than during it.

The last row is the one people miss entirely. A generated note added to somebody's file becomes part of their record, is read later by people who weren't there, and carries no indication that nobody verified it. It's the quietest entry on this list and the most durable.

Five Diagnostic Questions You Can Self-Assess Against

What's being generated right now, that you know of? Ask openly rather than investigating. People will tell you if it isn't framed as a compliance exercise, and the list is usually longer and more sensible than expected.

For each one, who owns the final version by name? Not the team, not the process. A person. Anything without a name is what goes out unedited.

Does anything reach a person unedited? Trace one path end to end. The answer is frequently yes in at least one place, and usually it's something routine that nobody thought of as writing.

The routine ones are worth listing precisely because nobody classes them as writing. An automated acknowledgement, a standard notification, a templated response: each is text your organisation sent to somebody, whatever it's called internally.

Who would catch an invented specific? Somebody has to know the subject well enough to spot a date or figure that was never true. If the editor doesn't know, the editing isn't a check.

Would you be comfortable if the reader knew? A useful test that sidesteps the whole disclosure debate. If the honest answer is no, that's worth examining regardless of what any obligation requires.

Run these five with the people actually drafting rather than with whoever owns the process. They know which outputs go straight out, which get rewritten properly, and which they've quietly stopped generating because it didn't work.

Six Things Teams Generate, Reviewed

A job advert

Drafting a role posting. It earns its place because adverts are formulaic, teams write a lot of them, and a first draft from a role description saves genuine time.

Where it falls short is invention about the role and the organisation. Generated adverts readily produce responsibilities nobody intends, benefits you don't offer, and a description of your culture that nobody would recognise. Candidates then apply on that basis, which is a problem that arrives later, in interviews.

Fine as a draft. The hiring manager has to confirm that every stated responsibility and benefit is real, and that's a specific check rather than a read-through.

The other thing generated adverts do is flatten. Fed a role description, they produce something that reads like every other advert for that role, and the details that would have distinguished working for you get smoothed into standard phrasing nobody remembers.

Worth keeping whatever was specific in the original. The unusual detail about the team, the honest note about what the job is actually like: those are the parts a candidate responds to and the parts most likely to be edited away.

A summary of somebody's performance review

Turning notes into a written assessment. It earns its place where the manager has done the thinking and the writing is genuinely a transcription task.

Where it falls short is that the writing frequently isn't a transcription task. Where notes are thin, generated text fills gaps with plausible material, and what fills them is generic performance language attributing things that may not have happened. The person reading it can usually tell, and being described in language that isn't about you is a particular kind of insult.

Only where the notes are substantial and the manager rewrites in their own words. The document goes on somebody's record, which makes an invented specific durable.

There's a second problem worth naming, which is what this does to the manager. Writing an assessment is part of forming one, and a manager who generates the text has skipped the thinking that the writing was doing, which tends to show in the conversation that follows.

The person being reviewed is also unusually well placed to detect it. They know what they did that year, and language describing a generic version of their role reads as evidence that nobody paid much attention.

A message to an individual employee

Writing to somebody about their situation: a change, an answer, a decision. It earns its place for routine, factual, low-stakes messages where the content is settled and the writing is formality.

Where it falls short is that individual circumstances are exactly what a generating feature has least access to. It produces the general case, fluently, applied to a person whose arrangement may differ, and they receive it as a statement from their employer about them specifically.

The one to be most careful with. Anything about a particular person's situation needs somebody who knows that situation to write or substantially rewrite it.

The trap is that these messages look routine, which is exactly why they get generated. A note about a change to somebody's arrangements reads like administration, and for most recipients it is, and for the one person whose circumstances differ it's a statement from their employer that isn't true.

It's worth being specific about which messages are genuinely identical for everybody and which only appear to be. That distinction is usually obvious to whoever handles the cases and invisible in any process description.

Policy or handbook text

Drafting or updating formal statements about how things work. It earns its place for structure and completeness, because generated text is good at producing an organised document covering the expected sections.

Where it falls short is that it describes what organisations typically do, not what yours does, and the difference is invisible in fluent prose. It also produces confident statements in areas where the correct answer depends on jurisdiction and on your own arrangements.

Structure only. Every substantive statement needs confirming against what you actually do, and anything touching obligations needs local advice rather than a plausible paragraph.

The particular danger is fluency in exactly the areas where you should be least certain. Generated policy text will state a position on notice, entitlement or process with complete assurance, and the assurance is a property of the writing rather than of anybody having checked what applies to you.

Mark clearly which sections were drafted and not yet confirmed. Documents of this kind get circulated early and quoted before anybody intended them to be final.

A response to a question somebody asked

Drafting an answer to a query from an employee or a manager. It earns its place on volume, since many questions are routine and the answers are genuinely standard.

Where it falls short is the questions that aren't routine and don't announce themselves. A query that looks standard but turns on the asker's specific arrangement gets a general answer, and the asker acts on it. The generated response also tends to be more confident than the underlying position warrants.

Reasonable for genuinely standard questions with a person checking. The check is whether this question is actually the standard case, which is different from whether the answer is well written.

That distinction is the whole control here and it's easy to lose. Somebody reviewing a drafted answer naturally reads it for correctness as a general statement, which it usually is, rather than asking whether this particular asker falls outside it.

A question phrased in an unusual way is frequently the signal. People with non-standard arrangements tend to ask non-standard questions, and the phrasing carries information that a generated answer discards.

A translation of something into another language

Rendering a policy, message or document in another language. It earns its place because the alternative for many organisations is that people simply don't get the document in a language they read well.

Where it falls short is that nobody in the organisation may be able to check it. A translation that shifts the meaning of an entitlement or an obligation produces a different version of your position for one group of people, and it can persist indefinitely because the people who'd notice are the people receiving it.

Worth having somebody who reads the language check anything that states a position. For informational text the risk is lower, and it's worth marking which is which.

The asymmetry of detection is what makes this persistent. The only people positioned to notice a shifted meaning are the ones reading that version, and they have no reason to think it differs from anything else, so they'll act on it rather than query it.

Where no internal reader exists for a language, that's worth knowing before you publish rather than after. It's a reasonable thing to say plainly: we can produce this, and we can't verify it.

The Decision Table

Situation Scale Setup Primary Pain Recommended Starting Point
Knowledgeable person rewrites everything Any Any None Change nothing
Nobody knows what's being generated Any Informal No visibility Ask openly, without policing
Text reaches a person unedited Any Any A statement from the employer Name an owner for that path
Editor doesn't know the subject Any Any Editing isn't checking Move the check to somebody who knows
Review summaries from thin notes Any Any Invented specifics on a record Substantial notes, or don't generate
Messages about individual situations Any Any The general case, applied to a person Somebody who knows them writes it
Policy text drafted this way Any Any A position nobody adopted Structure only, confirm every statement
Translations nobody can check Any Any A different policy in one language A reader of that language, for positions
Generated notes on a person's file Any Any Unverified becomes the record Mark what was verified

The third row is the one to find and fix first, because it's the point where the question stops being internal. Everything upstream is drafting. That row is your organisation telling somebody something.

The fourth row is the failure that looks like a process working. Somebody edits every draft, which sounds like a control, and if they don't know the subject they're editing for readability while the invented specifics pass through untouched. Fluency survives editing by somebody who can't check it.

The ninth row is the one with the longest tail. Anything landing on a personal record outlives the situation entirely, gets read by people with no context, and carries no marker distinguishing what was verified from what was merely produced.

The Draft Nobody Owns

Ready-made text dissolves authorship. When a draft arrives complete, the natural act is to review rather than to write, and reviewing produces a different relationship to the content. People who'd never send an unchecked document they wrote themselves will send a polished one they didn't.

Editing for readability isn't checking. These two get conflated constantly. Improving the flow of a paragraph doesn't verify anything in it, and the specifics that carry the risk survive a style edit completely intact.

A polished draft invites less scrutiny, not more. Rough text gets rewritten and therefore read properly; something already well written gets approved, which is the opposite of what you'd want.

The specific detail is where the risk concentrates. A date, a figure, a policy reference, a named entitlement. Those are the parts a reader treats as solid, and they're the parts most likely to have been produced rather than retrieved.

A name beats a process. Workflow approval produces a record. A person who considers themselves the author produces a different level of attention, and the difference is visible in what goes out.

Being named changes what people do. Somebody who expects their name attached to a document reads it differently from somebody clearing a queue item, and that shift costs nothing to arrange.

Volume changes behaviour. Somebody producing a handful of drafts a week checks them. The same person producing many will develop a faster method, and the faster method is reading for plausibility.

Convenience is the point, and it's also the risk. These tools make producing text cheap, which means more text gets produced, which means the checking has to scale with it or quietly stop happening.

The reader can't tell, and that's the point. Generated text doesn't announce itself, which means the recipient extends it the same trust they'd extend anything else from you. That trust is the thing you're spending, and it's worth spending deliberately.

Sounding machine-written is the least of it. People worry about tone because it's the visible property, and tone costs you very little. An invented entitlement in an otherwise natural paragraph costs a great deal, and nothing about how it reads will flag it.

The practical conclusion is narrow and cheap. You don't need a policy about generated text so much as a name against each thing that reaches a person, and a specific instruction about what the named person checks. Both take an afternoon and neither requires anybody to stop using the tools.

That narrowness is what makes it likely to survive. Rules that cover everything get ignored quietly because following them is impractical, while a short list of named paths with named owners tends to hold, because each person can see exactly what is being asked of them and why it's them.

Where These Arrangements Go Wrong

The failure How it shows up What would have to change
No named owner for what goes out Documents with no author A name per path
Editing mistaken for checking Polished text, invented specifics Verify the specifics, by name
Thin notes filled with plausible content A person described in language not about them Substantial notes, or write it yourself
General answer to a specific situation Somebody acts on something untrue Somebody who knows them checks
Policy text nobody formally adopted A position quoted back at you Confirm every substantive statement
Translation nobody could verify A different position in one language A reader of that language for positions

The third row is the one that lands hardest on an individual. Being described in generic performance language, on your own record, by somebody who evidently didn't have much to say, is a specific and memorable experience, and people do notice.

The fifth row accumulates rather than arriving. Generated policy text gets pasted into a document, the document becomes the reference, and a position nobody debated becomes what your organisation says. The moment it matters is when somebody relies on it.

The first row is the precondition for the rest. Without a name against an output path, every other control on this list is being asked of nobody in particular, which is the same as not being asked.

What to Put in Writing

Artefact Who owns it When it is written What it prevents
What's being generated, and by whom Whoever owns the process Now, by asking openly No visibility at all
A named owner per output path Whoever owns the process Now Documents with no author
What the owner checks, specifically Whoever owns the process With the name Editing standing in for checking
Which paths reach a person unedited Whoever owns the process Now Statements you didn't intend
Which translations state a position Whoever owns the process Before publishing any A different policy per language
What applies to you, per jurisdiction You, with local advice Before disclosure decisions A position you assumed

The third row is the one that makes the second row worth anything. A named owner who's been told to check it is a formality; a named owner who's been told to confirm that every date, figure and entitlement appears in the source is doing something real, and can tell you when they've done it.

The fourth row is worth producing early, because it's usually short. Most generated text goes to colleagues and stays internal, and the handful of paths that end at an employee or a candidate are the ones deserving all of the attention.

Questions to Ask Before You Commit

On destination. Who reads the final version? A bad answer is it depends.

On ownership. Who's answerable by name? A bad answer is the team.

On checking. What specifically do they verify? A bad answer is that they review it.

On knowledge. Could the editor spot an invented detail? A bad answer is that they're experienced.

On volume. How many per person per week? A bad answer is as many as needed.

On records. Does any of this go on somebody's file? A bad answer is only summaries.

What Getting This Wrong Costs

The first cost is somebody being told something untrue about their own situation. A generated message applying the general case to a person whose arrangement differs, sent under your name, read by somebody with no reason to doubt it and every reason to act on it. The correction, when it comes, doesn't restore the position: they now know their employer sent them something wrong, and they'll read the next message differently.

It spreads, too. Somebody who receives a wrong answer tells colleagues, and the story that circulates is rarely the careful version with the correction attached.

The second cost sits on a record and stays there. Generated notes and review summaries become part of somebody's file, get read later by people who weren't present, and carry nothing indicating that nobody verified them. Years afterwards an unverified plausible statement is indistinguishable from a documented fact, and it can affect decisions about a person who never knew it was there.

It's also the cost with no natural moment of discovery. A wrong message gets queried by its recipient within a day; a wrong line on a file is read by people who have no way to know it's wrong and every reason to treat it as established.

The third cost is a position you never took. Policy text drafted this way, pasted into a handbook, quoted back to you by an employee who relied on it. Whether it's actually your position is now a live question, and answering it with hindsight is much worse than confirming each statement when the document was written.

The awkwardness compounds if the employee acted reasonably on what they read. Telling somebody that the document they relied on was never really your position is a poor conversation, and the fault sits with the process rather than with them.

So do three things, none of which involves stopping anybody from using these tools. Ask openly what's being generated. Put a name against every path that reaches a person. And tell that person specifically what to verify, because being asked to review something is not the same as being asked to confirm the figures are real.

When You Are Ready to Go Further

Start by asking, openly and without any suggestion that people are in trouble. What's being drafted this way, by whom, for what. The list will be longer than expected and mostly sensible, and you can't make any decisions here until you have it. Framed as an investigation, you'll get a shorter and less accurate list.

It helps to say plainly that nothing is being taken away. The fastest route to an incomplete picture is people suspecting that an honest answer will end with the tool being withdrawn.

Then work through the paths that end at a person rather than at a colleague. Those are the ones that matter, they're usually a small subset, and each needs a named owner and a specific instruction about what they confirm. Everything else can be left alone, which is what makes this tractable.

Leaving the rest alone matters as much as fixing the subset. A blanket rule covering every draft produces either widespread quiet non-compliance or a lot of unnecessary checking, and both erode the attention you need on the paths that count.

Finally, look at anything that lands on a record. Review summaries, file notes, anything durable. Those outlive the situation that produced them and get read by people with no context, so they deserve a higher bar than a message that's read once. Marking what was verified, at the time, costs a line and solves the problem permanently.

It's worth deciding what happens to material already on file that was produced this way. You probably can't audit it all, and knowing roughly when the practice started is enough to tell a later reader how much weight a given entry deserves.

HROpsLab publishes independent comparison work across HR tooling. We sell nothing, we take no vendor money, and we publish no paid placements. If the next step is understanding what your current tooling generates, our comparison work is one place to start.


Frequently Asked Questions

Should you use AI to write HR content?

For drafts, usually yes, because starting is the expensive part of writing and a first version to react to genuinely saves time. What needs settling alongside it is who owns the final version of anything that reaches a person. Authorship is what quietly dissolves when a complete draft arrives: people move from writing to reviewing, and reviewing produces a different relationship to the content. The productivity gain is real and it comes with a specific gap that needs closing deliberately.

Who is responsible for AI-generated text in HR?

From the reader's point of view, whoever sent it, and that's the perspective that matters when somebody is upset about what they received. Internally it needs to be a named person rather than a team or a workflow, because anything owned by a process is what goes out unchecked. The distinction matters more than it sounds: a workflow approval produces a record, while somebody who considers themselves the author produces a different quality of attention.

Should AI write performance reviews?

It can produce text that reads like one, which isn't the same question. Where a manager has done the thinking and taken substantial notes, generating a tidy version is largely transcription and reasonably safe. Where the notes are thin, the generated text fills the gaps with plausible generic performance language, attributing things that may not have happened, and the person reading it can usually tell. That document also goes on their record, which makes any invented specific durable in a way a message isn't.

Is it safe to use AI for job adverts?

As a draft, yes, since adverts are formulaic and teams write many of them. The specific failure to watch for is invention about your organisation: responsibilities nobody intends to assign, benefits you don't offer, a description of your culture that nobody would recognise. Candidates apply on that basis and the mismatch surfaces later in interviews or after somebody joins. The check is the hiring manager confirming that each stated responsibility and benefit is real, which is a different activity from reading it through.

Should you tell employees when text was AI-generated?

Obligations differ by jurisdiction and are changing, so establish what applies to you with local advice rather than adopting a general rule. Separately from any requirement, a useful test is whether you'd be comfortable if the reader knew. If the honest answer is no for a particular kind of document, that discomfort is usually pointing at something worth examining about how that document is produced, regardless of what any obligation turns out to require.

What should you check in a generated draft?

The specifics, not the prose. Dates, figures, policy references, named entitlements, stated responsibilities: those are the parts a reader treats as solid and the parts most likely to have been produced rather than retrieved. Editing for readability is a different activity entirely and leaves invented details completely intact, which is why polished text can carry a wrong figure straight through a careful review. Verify each specific against a source, which takes a minute and catches nearly everything.

Is AI translation safe for HR documents?

It depends on whether the text states a position. For informational material the risk is modest and the benefit real, since the alternative is often that people don't receive the document in a language they read comfortably. For anything stating an entitlement, an obligation or a policy, the danger is that a shifted meaning creates a different version of your position for one group of people, and it can persist indefinitely because the only people who'd notice are the ones receiving it. Have somebody who reads the language check those.

How do you stop generated text going out unchecked?

Not with a policy, mostly. Ask openly what's being drafted this way, then identify which output paths end at a person rather than at a colleague, which is usually a small subset. Put a named owner on each of those, and tell them specifically what to confirm rather than asking them to review it. That combination takes an afternoon, requires nobody to stop using the tools, and closes the gap that actually produces harm, which is a document reaching somebody with no human answerable for it.

The draft is convenience. The version that reaches somebody is you.

Share on X Share on LinkedIn

What to do next?

Explore More Articles

Dig deeper into HR Ops strategy, tools, and workflows built for real teams.

Browse the blog →
Join the HROpsLab Community

Connect with People Ops practitioners sharing real workflows, tools, and challenges.

Join now →