Compliance in Intelligent Work: Modernizing HR Risk and Governance

Artificial intelligence (AI) adoption in the Philippines is accelerating, with 250,000 businesses, or 21% of all companies nationwide, already using AI as of 2024. 

However, as AI adoption grows in the country, so do the risks that organizations must manage carefully. This matters because the Philippines currently lacks comprehensive AI‑specific regulations, meaning employers using AI tools must still rely on existing laws like the Data Privacy Act of 2012.

So, how can organizations harness AI’s efficiency while managing the risks that come with it?

At Sprout’s HR & Business Leaders Forum 2026, the panel Compliance in Intelligent Work: Modernizing HR Risk and Governance brought together Philippine business leaders to talk about using AI responsibly while managing HR and compliance risks.

  • Jackie Barrios, Vice President of Human Resources at Genpact Philippines
  • Joseph Gatchalian Jr., Global Head of Legal and Compliance Group Corporate Counsel at Emerhub
  • Rene Cuartero, Chief Executive Officer of AHG Lab

In case you missed out, you can check out our on-demand recording here: 

Human and AI in Action: The New Workforce Amplifier | Sprout Solutions 

The Core Challenge: Balancing AI-Driven Efficiency with Responsible Governance

AI in HR brings clear benefits for Philippine organizations. It can streamline HR management, provide data-driven insights, and improve the candidate and employee experience. However, these advantages also come with real risks. 

The 2025 KPMG and University of Melbourne study found that 66% of respondents rely on AI-generated outputs without verifying their accuracy, and 48% admitted uploading sensitive company data into public AI tools. These findings highlight the urgent need for AI literacy and robust governance: a concern that Philippine businesses increasingly face as AI adoption grows.

During the panel, Jackie Barrios shared how employees using AI tools could unintentionally submit AI-generated work or upload sensitive information, creating potential compliance issues under the Philippines’ Data Privacy Act. 

She explained, “The risk is really multiple folds. The first one is releasing personal data without consent… the second one is releasing confidential information, which can affect the business, especially if you’re publicly traded.”

Joseph Gatchalian pointed out the challenges of oversight and accountability. “The biggest challenge for AI in the legal perspective is, when you do incorporate data into AI tools… where does it go, and how do you maintain visibility of that record?”, he said. 

What does this mean?

AI adoption should go hand in hand with clear governance and human oversight. This includes setting guidelines, defining responsibilities, and training employees. When implemented correctly, AI can improve efficiency and enable smarter decisions while maintaining compliance and trust.

A Three-Part Framework for AI Risk in the Philippines

As Philippine workplaces accelerate AI adoption, leaders need a practical way to think about the risks that come with these powerful tools. The three-part framework below helps Filipino executives structure their approach to responsible AI use.

 

  • Technical & Data Risks: Poor or unsecured data can lead to biased, inaccurate, or unsafe AI outputs.
  • Ethical & Cultural Risks: AI decisions must align with fairness and Filipino workplace values to maintain trust and engagement.
  • Legal & Compliance Risks: Organizations must follow data privacy laws and maintain transparency to avoid legal and reputational risks.

 

1. Technical & Data Risks: Securing Your Most Valuable Asset

AI systems are only as good as the data they use, and that creates a major concern in HR. In the Philippines, AI tools are increasingly used for recruiting, screening, and workforce planning, but they also raise risks around data privacy, security, and algorithmic bias. 

For example, Philippine employers using AI for hiring must still comply with the Data Privacy Act of 2012 and face legal exposure if sensitive employee or candidate information is mishandled.

Jackie Barrios shared real examples from her organization where AI‑generated responses and employee use of public AI tools led to deeper questions about data handling and compliance. She highlighted that beyond efficiency, HR teams must be vigilant about what data goes into AI systems and how outputs are used.

Technical risks also include algorithmic bias, where AI models trained on incomplete or unrepresentative data can produce unfair decisions. 

In the Philippine context, AI used in recruitment and HR could inadvertently disadvantage candidates from rural areas, underrepresented communities, or non‑standard educational backgrounds if models aren’t locally calibrated.

Mitigating technical and data risks starts with strong data governance, secure platforms, and human oversight. A secure HRIS and payroll system ensures a consistent foundation of clean, compliant data before introducing AI layers.

People-First HR Software Built to Scale. Explore Sprout HR

2. Ethical & Cultural Risks: Preserving the ‘Human’ in Human Resources

We’ve highlighted this many times: AI cannot replace human judgment or relationship‑building. This matters because these two qualities are especially important in the Filipino workplace where personal connection and “malasakit” matter.

Over-reliance on AI, or lack of transparency, can erode trust, create anxiety about job displacement, and weaken employee engagement.

As Rene Cuartero put it, “It stopped becoming a checklist when you realize there’s no policy to guide it… leadership has to understand the risks and ensure that AI complements human decisions, not replaces them.”

This means leadership and culture play a central role in responsible AI adoption. To preserve ethical and cultural values, AI tools should be transparent, explainable, and introduced in ways that respect employees’ dignity, promote equity, and reinforce the organization’s human‑centered culture.

3. Legal & Compliance Risks: Mastering the Philippine Regulatory Landscape

As mentioned earlier, the Philippines does not yet have comprehensive AI‑specific legislation, which means companies must navigate AI governance under existing frameworks like the Data Privacy Act of 2012 and guidance from the National Privacy Commission (NPC). Employers remain fully liable for how AI tools collect, process, and store personal data.

Joseph Gatchalian Jr. explained that compliance can’t simply be reactive. He said, “Compliance has to be treated as a living system. Set guardrails, ensure human verification, and maintain transparency.”

For HR leaders, this means:

  • Ensuring AI systems do not process personal data without informed consent
  • Providing candidates and employees with clear information about how AI is used in decision‑making
  • Retaining human oversight, especially in significant personnel decisions

Key Recommendations for AI Readiness

By now, it’s already clear: AI adoption is not just a technical challenge but a leadership and governance challenge. Below are some recommended steps to build a responsible, effective, and future-ready AI strategy for your organization.

Form a Cross-Functional AI Governance Council

AI impacts multiple areas of the business: from HR decisions to data handling and compliance. A smart strategy is to build a council of key stakeholders, including HR, IT, Legal, and Operations, to oversee AI adoption, assess risks, and make decisions collaboratively.

Take note: compliance alone is not enough. 

As Attorney Joseph explained, traditional compliance frameworks were built for control, not rapid innovation. Leadership judgment is essential where policies are still evolving, making a governance council crucial to balance speed, accountability, and safety.

Demand Transparency from Technology Partners

Not all AI solutions are created equal. Organizations must ask critical questions before adoption:

  • How is employee and client data protected?
  • How are AI outputs generated, and can they be audited?
  • Does the vendor comply with Philippine data privacy regulations?

Jackie Barios shared that employees experimenting with AI could inadvertently expose personal or confidential data, creating liability under the Philippine Data Privacy Act. That said, transparency from partners helps ensure tools are used responsibly and safely within your governance framework.

Prioritize Change Management and Employee Upskilling

AI adoption is ultimately a people-focused initiative. The panel reiterated the importance of preparing employees to understand, trust, and work alongside AI. Clear communication, training, and guidelines help employees use AI responsibly without exposing the organization to compliance or data risks.

And again: human oversight remains indispensable. Even the most capable AI tools require someone accountable for final decisions.

Preparing for a Smarter Future of Work

AI will continue transforming the workplace. New tools will emerge, adoption will accelerate, and organizations will keep exploring new ways to use automation and data insights.

But as the panel discussion made clear: successful AI adoption depends on strong governance. Companies must address technical risks, ethical considerations, and regulatory obligations at the same time. 

Perhaps the most important insight from the panel is that:

Judgment is still important. You still need a human to finally review what the outcome is, and you have to own that outcome.

In line with this, Sprout is ready to guide organizations through this journey. From AI-ready HR workflows to tools that promote transparency, accountability, and employee trust, our ecosystem is designed to help Philippine companies adopt AI safely, efficiently, and confidently.

Ready to build your future-ready HR foundation? Let’s talk. Schedule a free consultation with a Sprout expert today!

Get Expert HR Guidance When It Matters Most. Explore Sprout HR Advisory

Related Articles
Scroll to Top