Barry Phillips (CEO) BEM founded Legal Island in 1998. He is a qualified barrister, trainer, coach and meditator and a regular speaker both here and abroad. He also volunteers as mentor to aspiring law students on the Migrant Leaders Programme.
Barry has trained hundreds of HR Professionals on how to use GenAI in the workplace and is author of the book “ChatGPT in HR – A Practical Guide for Employers and HR Professionals”
Barry is an Ironman and lists Russian language and wild camping as his favourite pastimes
As so much of AI use is now switching to tokens Barry Phillips asks how HR should be regulating it.
Transcript:
Hello Humans!
And welcome to the weekly podcast that aims to summarise in around five minutes an important AI development relevant to the HR professional.
Somewhere in your organisation, right now, there could be an AI agent talking to itself.
Nobody is reading its output. Nobody has looked at it in weeks. And it is billing to a company card.
On the AI Daily Brief recently, Nufar Gaspar told a story about exactly this. Her own AI assistant — set up by an expert, by the way — quietly ran up fifteen hundred dollars in a fortnight while she was on holiday and not using it at all.
So here's today's question, and it's a genuinely awkward one for HR : when does wasteful AI usage stop being a training issue and start being a conduct issue?
But first what is a token and why has token usage suddenly become a thing because HR can't write policy on something it can't define.
Well, a token is a chunk of text — usually a bit less than a word. Everything an AI model reads and writes is billed in these things. Roughly a page of text is a thousand tokens. As the era of free use of leading LLMS such as ChatGPT and Claude comes to an end token usage and how to manage it will come to the fore.
And the cost of drafting an email? Just a few hundred tokens. Genuinely trivial. A deep research task? Tens or hundreds of thousands of tokens. But what about employee use or expenditure of tokens?
Should token usage sit in policy at all? I think yes — but not where your instinct puts it.
The wrong home for this is the disciplinary policy. The right home is your acceptable use and expenses framework. Because that's the honest analogy. Compute is now a consumable company resource, like a corporate card, like mileage, like a phone contract. And we already know how to govern those without treating everyone like a suspect.
So let's be precise about the spectrum, because HR gets into trouble when it isn't.
At one end: a good-faith experiment that fails. That is not waste, it's learning, and if you discipline it you’ll ensure no useful experimentation with AI happens anywhere.
In the middle: carelessness. The badly-configured agent. The immortal chat session dragging six weeks of history into every message. That is overwhelmingly a capability gap, not a character flaw. The remedy is enablement, defaults, and a decent onboarding — not a warning letter. If you haven't taught it, you can't sanction it.
And at the far end: yes, there is genuine misconduct territory. Deliberately circumventing a cap that's been set. Running personal side-projects on company compute. Concealing spend. Setting something running with reckless disregard after being told. That isn't "wasting tokens" — that's the same misuse-of-resources conduct your policy already covers, just wearing new clothes. You very likely don't need a new rule. You need to name AI compute explicitly as a company resource in the rule you've already got.
To finish three practical guardrails.
One: you cannot sanction what you haven't communicated. If there's no published budget, no cap, no guidance on which model to use for what, then any enforcement is retrospective rule-making. Publish first.
Two: visibility is monitoring, and monitoring has obligations. Dashboards showing individual consumption are employee monitoring. Transparency, proportionality, a clear purpose, and consistent application. And be very careful about league tables — the moment usage becomes a visible performance signal, you've built a system people will game, and you've punished the careful.
Three: budget by workload, not by headcount. The person building reusable skills for forty colleagues should have a far bigger allowance than the person using AI as a fancier search engine. Flat, equal caps feel fair and are actually the opposite: they subsidise low-value use and tax the people doing the most valuable work in the building.
If you take one thing away from today, make it this: spend tokens wisely, not sparingly.
Until next week by for now.
Get the Most from Copilot (Level 2): A Practical Guide for HR