The Growing Risk of Digital Harassment in the Workplace
AI, Deepfakes and the New Duty of Care for Employers
For decades, workplace harassment policies were built around physical spaces, identifiable perpetrators, and observable behaviour. The assumptions were simple: misconduct happened in offices, at work events, or through traceable messages sent on company systems.
Those assumptions no longer hold.
Artificial intelligence has fundamentally altered the risk landscape. Today, harassment can be created anonymously, distributed instantly, and persist indefinitely, often without the knowledge of the organisation until harm has already occurred. Deepfakes, AI-generated nudification, manipulated images, and synthetic audio are no longer fringe technologies. They are widely accessible tools that can be deployed by anyone with a smartphone and an internet connection.
For employers, this creates a profound challenge: how do you meet your duty of care when misconduct may be fabricated, decentralised, and technically difficult to detect, yet deeply real in its impact?
This article explores what digital harassment looks like in practice, why existing policies are failing, and what organisations must do now to protect people, reputation, and governance integrity.
Case Study
A client reported that a co-worker had shared a photo of her on social media which had been digitally manipulated. She hadn’t been “nudifed,” but her professional outfit substituted for a skimpy bikini. A collegeague shared this information with the client who reporrted it to HR. The post as taken down and the client was told “it was just a bit of fun and to get over it.”
Was this sexual harssment the CHRO asked? For sure I responded.
What Is Digital Harassment, and Why AI Changes Everything
Digital harassment is not simply “online bad behaviour.” In the workplace context, it includes conduct that:
- Sexualises, humiliates, threatens, or intimidates a worker
- Targets an individual because of protected or personal characteristics
- Undermines dignity, safety, or psychological wellbeing
- Occurs using digital tools, regardless of device ownership or time of day
AI intensifies this risk by enabling fabrication rather than just communication and we are seeing increasingly  increasingly workplace investigations include:
- AI-generated images depicting an employee nude or in sexualised scenarios
- “Nudified” images created from ordinary photographs
- Deepfake videos or audio impersonating a colleague or manager
- Synthetic messages designed to damage reputation or credibility
None of these require the target’s participation and above all none require consent and all can be created without leaving obvious forensic traces.
Crucially, the harm is not theoretical. Targets often experience trauma, anxiety, shame, fear of exposure, withdrawal from work, and long-term psychological distress. The impact on a targets’ well being and career are significant and result in absenteeism, reduced productivity where careers go off track and stall. An organisations credibility and trust suffer.
Why “It Wasn’t on a Work Device” Is No Defence
One of the most persistent misconceptions in organisations is that personal devices or off-platform activity fall outside employer responsibility which is not the case. Employer duty of care is not defined by device ownership. It is defined by impact on the employment relationship.
If digital harassment:
- Targets a colleague
- Affects someone’s ability to work safely
- Creates a hostile or degrading environment
- Involves co-workers, managers, or reporting lines
Then it is a workplace issue, regardless of whether it occurred:
- On a personal phone
- Outside working hours
- On a private messaging platform
- Off company premises
Tribunals and regulators increasingly focus on risk anticipation and response, not technical boundaries.
The question is no longer “Was this work-related?” but “What did the employer do once risk was known, or should reasonably have been known?”
The Psychological Impact: Why This Is Not “Just an Image”
AI-enabled image abuse is often minimised because “nothing physically happened” and can even be dismissed as “a bit of fun” which is a dangerous and misleading path to go down.
Research into image-based abuse shows that targets experience trauma responses similar to those associated with sexual harassment and assault. The loss of control over one’s likeness, particularly in sexualised form, creates a persistent sense of exposure and vulnerability.
In the workplace, this is compounded by:
- Fear of reputational damage
- Power imbalances with perpetrators
- Dependence on the organisation for income and status
- Anxiety about not being believed
- Increases chances of Moral Injury and legal exposureÂ
Many targets do not report immediately and some never report at all but silence is not an indicator that nothing untoward is happening. It is usually a sign of fear and lack of psychological safety.

Where Traditional Policies Fail
Most anti-harassment policies were not written with synthetic media in mind. Common gaps include:
- No reference to AI-generated or manipulated content
- Narrow definitions focused on “messages” rather than fabricated material
- Over-reliance on intent rather than impact
- Lack of clarity on investigation thresholds
- No guidance on trauma-informed handling
- Focus on compliance focused awareness training and not protecting individuals.
As a result, organisations improvise responses to incidents that require precision, speed, and sensitivity which results in inconsistency follows and the erosion of trust.
From a governance perspective, this is high-risk territory. Digital harassment now sits at the intersection of:
- Employment law
- Data protection
- Psychological health and safety
- Reputational risk
- Board oversight
Treating it as an “HR issue” alone is no longer sufficient but a critical leadership risk mitigation challenge that needs guardrails
Leadership role: Oversight, Not Micromanagement
Boards don’t need to become technical experts in AI to effectively handle this new development, but they do need assurance that the organisation understands and manages this risk.
Key questions boards should be asking include:
- Do our policies explicitly cover AI-generated and manipulated content?
- Are managers trained to recognise and escalate digital abuse?
- Do we have clear thresholds for investigation and external reporting?
- Are we confident our response minimises harm to targets?
- How would we evidence reasonable steps if challenged?
Silence or ambiguity at board level sends an unintended signal: that this risk is emerging, optional, or hypothetical. It is none of those things.
Manager Capability: The Weakest Link
In many cases, the first disclosure of digital harassment is made to a line manager, not HR, legal, or compliance.
Yet managers are often unsure what constitutes evidence and are afraid of over-reacting. Thye focus on interpersonal resolution rather than safeguarding and quite often react with untrained in trauma-informed responses
This is where organisations most often fail well-intentioned employees. A line manager or HR professional who delays escalation, questions credibility, or frames the issue as “personal conflict” and other DARVO and minimising tactics can inadvertently compound harm, and expose the organisation to liability.
Clear guidance matters and removing discretion where risk is high will play a key role in this. Organisations need to make it mandatory to escalate issues through established protocols.
Check out the 3Plus Resource Hub – Understanding DARVOÂ
What Good Practice Now Looks Like

Organisations responding well to this shift are taking several decisive steps:
1. Updating Policy Language
Policies explicitly reference:
- AI-generated images, video, and audio
- Image manipulation and nudification
- Distribution, possession, and threat of sharing
- Zero tolerance regardless of device or platform
It’s important to avoid ambiguity which in a time of crisis will only serve to complicate matters so clarity around policy and values eliminates debate.
2. Establishing Escalation Thresholds
Not all misconduct is equal but digital sexualised abuses should be considered severe enough to trigger:
- Immediate safeguarding consideration
- Senior HR / legal involvement
- Preservation of evidence
- Consideration of external reporting obligations
3. Training Managers for First Response
Managers are trained in trauma informed responses to:
- Listen without judgement
- Avoid investigative questioning
- Escalate promptly
- Prioritise wellbeing over process
Check out the 3Plus Workshop Trauma Informed Response to Grievance ReportsÂ
4. Taking a Trauma-Informed Approach
This includes:
- Minimising repeated retelling
- Allowing choice and agency where possible
- Avoiding language that implies blame or consent
- Recognising delayed disclosure as normal
Current urgency
AI capability is advancing faster than workplace norms, policy cycles, and legal clarity. Waiting for perfect regulation is not a defensible strategy. From a risk perspective, digital harassment represents: A an anticipated risk, a governance issue and a known challenge to organisational values.
From a human perspective, it is about employee protection in terms of well being and dignity. Organisations that respond early, clearly, and compassionately will not only reduce liability, they will also strengthen trust, psychological safety, and credibility in a changing world of work.
Leadership Challenge
It’s important that leaders understand technology amplifies any pre-existing challenges and shares them at scale. The question for employers is no longer whether AI-enabled harassment will appear in their organisation, but how prepared they are when it does.
In light of the rapid escalation of this trend, policy, training, and leadership alignment are not optional upgrades, they need to be the new minimum standard.
 Does your harassment policy cover AI-generated abuse? Request a Digital Harassment Policy Gap Review





