AI Meets Payroll: The Hidden Risk Behind the Efficiency Gains

Who's Looking at Your Pay Slip? The Hidden Risk of AI
A new survey reveals 85% of Israeli payroll accountants uploaded a pay slip to an AI tool this past year - some to unsecured public tools. The risk: leaked sensitive data, targeted phishing, and salary theft, alongside a violation of Amendment 13 to the Privacy Protection Law, punishable by up to 5 years in prison.

Payroll professionals in Israel have embraced artificial intelligence at remarkable speed – but some are doing it in a way that exposes their organizations, and their employees, to real legal and security risk.

The numbers behind the trend

According to a survey conducted by Oketz Systems, 85% of payroll accountants uploaded a pay slip to an AI tool over the past year to get help with a professional question. This shift didn’t happen in a vacuum – it’s replacing the profession’s traditional support channel: professional Facebook groups. A review of four leading groups in the field found activity had dropped by roughly 45%.

Where AI actually helps

The most meaningful change isn’t happening at the calculation stage itself – it’s happening before it. At the start of every month, payroll accountants are flooded with client data: attendance records, commissions, car benefit values, and expense reimbursements, scattered across Excel files, emails, and various systems. Until now, pulling all of this together required manual collection and data entry.

Today, a well-crafted prompt is enough for an AI tool to consolidate all these sources into a single table that feeds directly into payroll software – and even investigate anomalies on its own: comparing figures month to month, spotting unexpected jumps or drops, and flagging the likely cause, without the accountant having to dig through the numbers manually. The result: fewer errors, workload spread more evenly across the month instead of piling up on payslip-issuance days, and accountants freed from data entry to focus on genuine oversight and professional judgment.

The problem: not all AI tools are created equal

This is where the critical gap emerges. Organizations that implement the technology properly do so through dedicated, secured AI agents – enterprise-grade tools that operate under organizational control and don’t use submitted data to train models. But the survey reveals that a large share of payroll accountants simply uploaded pay slips to ordinary, public AI tools – and that’s where the real risk begins.

The moment a pay slip is uploaded to a tool like ChatGPT under a standard personal account, the document leaves the organization’s systems entirely and lands on the servers of external commercial companies – sometimes with subcontractors scattered around the world. On personal accounts, the default setting often permits that content to be used for training future models, unless the user explicitly opts out.

The risk chain in practice

From the moment the data is entered, the organization is exposed to several parallel risk paths: stolen login credentials that expose an entire chat history; provider-side bugs (as happened in 2023, when chat titles and partial billing details were leaked); and even a model unintentionally memorizing and later reproducing personal training data.

Information such as salary, employer identity, wage garnishments, and pension fund details becomes a weapon in the wrong hands once it leaks. The most well-documented method: targeted phishing that leads to actual salary theft, by altering the bank account details a paycheck is deposited into.

What the law says

Beyond the security risk, this is also a clear legal violation. Amendment 13 to Israel’s Privacy Protection Law defines payroll data as information of special sensitivity, requiring an elevated level of security. Section 16 of the law prohibits disclosing information beyond what’s necessary for the job, carrying a penalty of up to five years in prison; Section 17 places personal liability for data security on the individual. On top of that, the law requires a prior agreement with any external party handling the data, under Regulation 15 of the Data Security Regulations – a condition consumer-grade AI providers simply don’t meet.

The Privacy Protection Authority added another layer in 2025, with guidance requiring informed consent for processing personal data through artificial intelligence. The bottom line: using AI tools themselves is entirely permitted – but feeding them identifying information from pay slips is not.

What it looks like on the ground

Haim Molcho, CEO of Oketz Systems, describes a two-sided picture. In his view, AI is already creating a fundamental shift in how payroll accountants work – not a minor add-on, but a basic change in method. But realizing that potential without running afoul of privacy law, he says, requires dedicated professional guidance – which is why the company launched a course on the subject.

Molcho points to a dual risk: legal exposure from improper use of AI on one hand, and flawed output from running generic tools that haven’t been adapted to payroll work on the other. According to him, the rules set by law and extension orders are already built into payroll software itself – but every office operates in its own environment: different client files, different spreadsheet structures, different intake formats and closing checks. A tool that hasn’t been taught these specifics can produce output that doesn’t get accepted correctly into the system – and the accountant discovers the problem only when it’s too late.

What this means for your organization

The payroll accountants’ story isn’t an isolated case – it’s a clear example of a much broader phenomenon: employees adopting AI tools on their own, without a formal organizational policy, and without knowing how to distinguish a consumer tool from a secured enterprise one. This is happening today not just in payroll, but in nearly every department that handles sensitive data – HR, finance, customer service, and more.

The real solution isn’t banning AI use (that’s neither realistic nor a wise way to give up the competitive edge the technology offers), but implementing it correctly: enterprise AI tools that operate under organizational control and don’t train models on your data, a clear usage policy for employees, and training that spells out exactly what can and can’t be entered.

This is precisely the kind of work we do at TOM – from defining an AI usage policy, through deploying secured tools suited to the organization’s needs, to meeting the requirements of Amendment 13 to the Privacy Protection Law.

Want to check where your organization stands against these risks? Feel free to fill out a short questionnaire here.


Based on an article by Daniel Cohen, Walla! Finance (original article: finance.walla.co.il)

The First Step Starts Here
Professionalism
Our primary asset lies in our human capital, delivering real-time solutions on-site. Therefore, our IT technicians undergo continuous training and certification to ensure top-quality service.
Quality Assurance and Reliability
We implement high-standard quality processes that include clear procedures, documented monitoring, extensive control systems, and thorough inspections.
Availability and Teamwork
We understand the importance of maintaining the continuous operation of our clients' computer systems. Our team ensures full availability to support you whenever needed.
Integrity and Reliability
Integrity and reliability are our guiding principles, serving as a solid foundation for productive and successful collaboration.
Data Protection
T.O.M is committed to maintaining the confidentiality of information and utilizing advanced technological means to safeguard the assets of the organization and, of course, all its clients.

IT solutions designed for your peace of mind

How can we assist you?

This site uses information collection technologies such as Cookies, including by third parties, in order to provide you with a better browsing experience as well as for statistical, profiling and marketing purposes. Continued browsing of this site constitutes your consent to this. For more information and the option to manage the use of these tools, please see our updated Privacy Policy