Internal approval procedures for AI follow a pattern designed for software: inspect, agree, sign. Applied to systems in continuous change, that pattern creates a backlog.
This piece works through German law and German cases. The mechanism it describes is not specific to Germany, the legal detail is.
A works agreement at the chemicals group DuPont contains this provision: updates must be submitted to the central works council six weeks before the release date, the body must give its consent, and if a dispute arises the update process can be aborted. A written, enforceable veto over model changes. In the Böckler Foundation’s account, the clause is presented as a template to follow.
Set that against the vendor’s documentation. Workday issues two feature releases a year, makes preview tenants available “approximately five weeks in advance of the feature release”, and deploys that release to all customers on the same date. On top of that come weekly fixes in the maintenance window.
Six weeks of mandatory lead time against five weeks from the vendor. The clock runs before there is anything to show. Anyone attempting to comply must judge a version they have not seen. Anyone taking the rule seriously cannot deploy the update. A works council representative at another group stated the problem plainly in 2020: his body meets three times a year, and calling a special session every time a release update is due “is not proportionate”.
What came out of it
At DuPont, the procedure did not end with rules for using AI. It ended without it. The Hans Böckler Foundation presents this as a success: the central works council was able to prevent the use of AI, and the works agreement prohibits its application. Specifically excluded were automated decisions, suggestion features in personnel administration, AI in reports on personal data, and the automated pre-selection of applications, including internal ones.
You can consider that the right outcome. You should only know that a technology question was settled from its outcome backwards, and that getting there took almost two years. In the same document, the chairman of the central works council states what it takes: all parties must be willing to enter a conflict lasting eighteen months.
Who wrote the text
These rules were not drafted by the council itself. The same source outlines how it works: given the technical complexity, external experts handle most of the substantive work, particularly in negotiations with the employer. On the decision against AI features, the account states simply that the impulse came from the external experts.
Here the procedure loses its balance. Under section 80 (3) of the Works Constitution Act, in force since June 2021, the need for an external expert is legally presumed whenever a works council has to assess artificial intelligence. The whether is no longer in dispute. The employer pays. For what the expert drafts, he does not answer: his contractual partner is the works council, and towards the company whose personnel system he helps shape he bears no liability. There is no documented case of an employer holding such an adviser liable for commercial consequences.
The result is an adviser at the table with influence over how the system is built, whose fees are paid by the other side, and who carries no risk. In any other setting, that would be called a design fault.
Two qualifications belong here, if only to forestall the obvious objections. No works council has an open chequebook: it must still agree the choice of expert and the terms with the employer, going to the labour court if necessary. Moreover, the fees are lower than public debate suggests. In 2021, the legislator calculated 833 euros for a day of consulting, while the employers’ association countered that experts advising works councils charge “day rates of up to 1,700 euros” in some cases. Both sides are estimating. The bill states its own source plainly: internet research.
What the procedure really costs
The expensive part is time. In a case that later reached the Federal Labour Court, a corporate group began introducing Workday in April 2017. A toleration agreement of 3 July 2017 expressly forbade one thing: during the test period, the system was not to be used for standard HR processes such as performance appraisal, hiring, dismissal or pay. That provisional arrangement was extended several times. Final agreement was reached on 23 January 2019, in a conciliation committee. For eighteen months and twenty days, a system already introduced could not be used for its purpose.
Why it took that long, the decision does not say; it had a different question to settle. The duration is in the text regardless.
Behind all this stands a codetermination provision from 1972. Section 87 (1) no. 6 of the Works Constitution Act applies to technical devices “designed to” monitor employee conduct or performance. Case law turned that into: objective suitability suffices, no intention required. For punch clocks, that was a sensible reading. Applied to modern software, it means virtually every system requires consent, because virtually every system logs.
What speaks against this
Stopping here would make it too easy. Three findings speak against the argument, and they hold.
The OECD surveyed employees in seven countries in 2022. Where employees or their representatives had been consulted, they were 18 percentage points more likely in finance and 19 points in manufacturing to say AI had improved their performance. The OECD itself notes that no causal claim follows from this.
The ZEW used administrative data to examine what works councils did to the introduction of industrial robots. The finding: they did not prevent it. Where a works council existed, higher-quality machines were installed, more training was given, and productivity subsequently grew faster. The authors mark precisely this part as descriptive and expressly make no causal claim for it. And it was about robots.
The DuPont case is also a success story. The same account records that the system proves clear and easy to use, and that user feedback is positive.
A German case in which an AI project finally failed because of codetermination is not documented. Neither is a blocked security update. What can be shown is friction, not damage.
What belongs in its place
The fault lies in the object of approval. What gets approved today is a version, and versions change faster than committees meet. What should be approved is the purpose: what a system is used for, which data it sees, which decisions it must not take, and how anyone can tell that those limits are holding.
The update reservation then dissolves by itself. A release that does not change the purpose needs no consent. One that brings new capabilities is measured against the agreed limits. Control runs continuously against the actual effect, with the body’s own access to evaluations, rather than once beforehand on paper.
That is more codetermination than today. It simply starts in the right place. A body asked to judge a version it has not seen, six weeks before an update, protects nobody. It holds things up.