An Amsterdam ruling shows why clear data boundaries matter before workplace trust starts to break.
Imagine the morning of a difficult employee exit. Negotiations are under way, trust is thinning, and a senior colleague still has broad access to company records. Before breakfast, the security system detects an attempt to move the contents of a business computer into Gemini.
That scene sits behind an Amsterdam District Court ruling of 9 June 2026, published as ECLI:NL:RBAMS:2026:8257. The court held that the summary dismissal of a senior director was valid. He had sent several company files to a private email address and attempted the Gemini upload while the parties were negotiating the end of his employment.
The employer had set a clear boundary. The employment contract and Code of Business Conduct Policy prohibited the conduct. The security system blocked the attempted transfer. When questioned about the private-email activity, the director did not disclose the Gemini attempt. The court treated that lack of openness as part of the loss of trust.
AI changes the exit route
It is tempting to call this an AI case. The deeper issue is control over company information when an employment relationship comes under pressure.
A decade ago, management might have watched for a USB stick, printed customer lists or emails sent to a competitor. An external AI service offers another route. A user can attach, paste or upload large amounts of material in minutes. That action may not feel like removing company records, even though it can have the same practical effect.
The distinction matters in a small business. A departing manager may see proposals, contact lists or working notes as “my documents” because they created or used them. The company sees customer history, pricing logic, contracts and correspondence that belong inside a controlled environment. That gap can become expensive quickly.
Dutch summary dismissal has a high threshold. It requires an urgent reason, swift action by the employer and swift communication of the reason. An employee can ask the subdistrict court to review the dismissal and seek compensation. Each case turns on its facts, including the rule, the role, the conduct and the employer’s response.
Rules need to survive contact with work
The wider workplace picture deserves attention. In Alert Online research cited by the Dutch government in 2025, 36 percent of employees said they were very or extremely familiar with generative AI. Only 26 percent agreed that their organisation had clear guidelines for managing risks such as data security.
That gap has a familiar shape. Employees may know how to use the tools while the employer has not explained what may enter them. “Use AI responsibly” gives little guidance to someone who wants to summarise a complaint, translate a contract or analyse a customer spreadsheet.
A usable boundary names the approved tools and the information that must stay out. Customer records, personnel details, prices, margins, legal correspondence and internal disputes deserve particular care. Staff also need to know who can approve an exception. Without that detail, the real policy becomes whatever each person decides at the keyboard.
The Dutch government’s generative-AI guide, written for public organisations, follows the same control logic. It stresses clear responsibilities, end-user rules and a sound legal basis before personal or sensitive information enters a generative-AI system. Private employers face their own circumstances, but the discipline is recognisable.
When the security alert appears
The difficult moment begins after a system detects unusual activity. Management may feel betrayed and want an immediate answer. Speed without order can weaken the response.
A technical alert records what the system observed. The employer still needs a clear picture of what happened, which rule applied, what information was involved, who knew the rule and how the employee responded when asked. Legal, technical and management records need to describe the same event.
That is why the Amsterdam ruling matters. The company could point to an explicit prohibition, a senior employee, system evidence, sensitive timing and the director’s response. The court could see the boundary and how it had been crossed.
For a founder, the work begins long before an incident. Employment terms, the staff handbook, access settings and daily practice need to agree. A rule buried in an unread policy cannot carry the whole weight. Software cannot compensate for a workplace where employees routinely send documents to private accounts for convenience.
Protect the business behind the records
Return to that difficult exit morning. While attention turns to the laptop, ordinary business continues. Customers still expect answers. Projects need handovers. Invoices need approval. Supplier bills are waiting.
When one senior person holds too much access or knowledge, a data incident can become a continuity problem. The issue is no longer only the file that may have left. Work may stall when access changes, customer history sits in one inbox or financial tasks depend on one person’s memory.
An exit process therefore reaches beyond returning equipment. It connects access rights, customer work, shared mailboxes, confidential information and unfinished financial tasks. Reviewing broad access when a role changes or negotiations begin is ordinary care for both sides.
The same calm discipline applies to AI. A blanket ban can push use out of sight. Unrestricted access leaves too much to personal judgment. The workable middle ground is clear: approved tools, restricted data, named responsibility and a place to ask before material is uploaded.
The Amsterdam case carries a clean warning without requiring panic. Technology changed the route, but the central questions remain familiar. Who owns the information? Who may move it? What was clearly agreed? What can the company show when trust breaks?
A small employer does not need a grand AI programme to answer those questions. It needs rules people can understand, controls that match real work and an exit process that protects customers, staff and cash flow. The best time to settle those boundaries is while trust is still intact.
If your employment terms, AI rules and exit controls do not yet draw the same clear boundary, now is the time to align them.
The data, sourcing, and analysis behind this article were conducted by Paolo Maria Pavan. AI was not used to identify sources, build the factual basis, or produce the analytical judgment contained here. AI was used only as a drafting aid. The final English text was personally reviewed, edited, and approved by Paolo Maria Pavan before publication.
References
- Rechtbank Amsterdam / Rechtspraak — ECLI:NL:RBAMS:2026:8257
- Ontslag op staande voet voor werkbestanden sturen naar privémail en uploaden bestand zakelijke computer · Salaris Vanmorgen
- Rijksoverheid — Dutch framework for summary dismissal
- Rijksoverheid — Confidentiality breaches as an employment-law issue
- Rijksoverheid — Workplace use of generative AI and missing internal rules
- Rijksoverheid — Responsible handling of confidential information in generative-AI tools
- Rijksoverheid — Current AI regulatory setting
