Wrivio
Get Wrivio
7 min readBy Wrivio Team

The UK Is Consulting on Workplace Monitoring Rules, and Email Counts

Most people assume their work email and chat messages are visible to someone in IT, and mostly stop thinking about it there. The UK government’s current consultation is worth a second look because of how wide it draws that category, and because it puts communications monitoring in the same bucket as biometric access badges and algorithmic shift scheduling.

On 8 July 2026 the government opened a consultation on regulating “workplace monitoring technologies,” part of the wider Employment Rights Act 2025 reform programme. It closes on 30 September 2026. Nothing in it is law yet, but the scope it proposes to regulate is broader than the phrase suggests, and it is worth understanding now rather than after a code of practice lands.

What Counts As Workplace Monitoring Technology

The consultation groups three things that most workplaces treat as unrelated. First, what it calls standard monitoring: access control, attendance tracking, and email and communications monitoring. Second, algorithmic management, meaning software that assigns tasks, schedules shifts, or scores performance. Third, solely automated decision-making, where an outcome affecting a worker is reached without meaningful human involvement.

Bundling those together is the interesting part. A company that reads outgoing email for compliance reasons is now discussed under the same heading as one using software to auto-assign shifts. That framing is likely to stick, because it reflects how these tools actually get bought: a platform that does attendance tracking picks up communications logging as a feature later, and nobody re-classifies it.

Three Options, None Of Them Decided

The consultation sets out three ways the government could intervene, and it has not picked one. A statutory code of practice with supporting guidance. A new legal duty to consult trade unions or elected staff representatives before introducing workplace monitoring technology. Or non-statutory guidance alone, with no new legal duty attached.

Those are meaningfully different outcomes. A consultation duty backed by a legal right would require engagement before a rollout rather than a notice after it. Guidance alone changes almost nothing enforceable. The official consultation document is the place to read the actual proposed text, rather than a summary of it, including this one.

What The Government Says Already Applies

The consultation also sets out principles it says should already underpin responsible use of these systems, several of which restate existing UK data protection and employment law rather than propose new rules. Two show up consistently across coverage: employers should have a clear, justifiable reason before introducing a monitoring tool, and workers should be given clear, accessible information about how it works and what it does. A third, worker engagement before rollout, is the part most contested, since it is the one the consultation is specifically weighing whether to make a legal duty rather than a stated expectation.

That matters even under the weakest of the three options. If transparency is already an expectation under existing law, the practical requirement for anyone deploying a new tool, AI-based or not, is the same regardless of which option the government picks: write down what the tool does and collects, and tell people before you turn it on.

Where AI Writing Tools Actually Sit In This

“Communications monitoring” in this consultation means logging or reviewing messages a person already sent. That is a different thing from a tool that helps you write the message before you send it, and the distinction is the same one that matters for how AI writing tools intersect with US state employment rules: does the software make or record a decision about a person, or does it sit upstream of a human who decides what to send.

It still matters where a drafting tool’s traffic goes, because that traffic can itself become something IT monitors. A cloud AI tool that sends every draft to a third-party server is one more data flow to disclose under the transparency principle above. A tool that runs the model on the device, with nothing to log because nothing left the machine, is a shorter answer to give when someone asks what data a new tool moves. That is the practical version of “can your employer see what you type into AI”: the honest answer depends on where the text actually goes, not on the tool’s name.

If you are the one introducing a writing tool to a team, that disclosure is worth drafting deliberately rather than mentioning in a standup.

Before:

Hey team, heads up we’re using an AI thing for emails now, it’s fine, HR knows.

After:

We are rolling out Wrivio for drafting and rewriting work messages. Local mode runs on your own machine and sends no text anywhere; Cloud mode sends the text you submit through Wrivio’s backend to generate a rewrite. You choose which mode to use per message. No message content is stored by IT as part of this rollout.

The second version answers the two questions a worker in this consultation’s frame would actually have: what does it do, and where does my text go. Neither answer requires legal language, just precision about the two engine modes.

A Wrivio Context for a monitoring or tooling disclosure could say:

Rewrite this as a short, plain-language notice to staff about a new workplace tool. State what the tool does, whether it sends any data off the device and to where, and what choice the worker has, if any. Keep every product name, mode name, and technical claim exactly as written. Do not soften or omit the data flow.

Press Ctrl+Shift+Space, paste the draft, and check the diff. The failure mode in this kind of notice is a rewrite that makes the tone friendlier by cutting the specific sentence about where the data goes, which is the one sentence a monitoring consultation would actually ask about.

What This Does Not Change Yet

Nothing here is binding. The consultation closes 30 September 2026, and the government has not indicated which of the three options it favours, or when a code of practice might follow. Treat any claim about a firm implementation date, including this post’s, as provisional until the government publishes its response.

Common Questions

Is workplace monitoring illegal in the UK right now?

No. Employers can already monitor workers subject to existing UK GDPR and employment law obligations, mainly around necessity, proportionality, and transparency. This consultation is about whether to add a specific code of practice or legal duty on top of those existing rules, not about banning monitoring.

Does this consultation specifically target AI tools?

Not primarily. It targets a broad category called workplace monitoring technology, covering access control, attendance tracking, communications monitoring, and algorithmic management or automated decision-making. AI-based monitoring and scheduling tools fall inside that scope, but so does non-AI keystroke logging or badge tracking.

When does the consultation close and what happens after?

It closes 30 September 2026. The government will review responses and publish its conclusions, which could take the form of guidance, a statutory code of practice, new legislation, or some combination, though no timeline for that has been set.

Does using a local AI writing tool avoid workplace monitoring rules?

Not automatically, and it is not a compliance strategy on its own. What it does change is the disclosure you have to write: a tool that never sends text off the device has one less data flow to explain to workers or auditors under the transparency principle the consultation restates.

Download Wrivio for Windows so drafting a message and monitoring what happens to it are two separate questions, not one.