As artificial intelligence (AI) becomes embedded in everyday work, employers are increasingly adopting policies governing how employees can use the technology. But a written policy does not eliminate the risks created when workers ignore it — particularly when they feed confidential company information, employee records, or customer data into unauthorized AI tools.
The consequences can extend well beyond an employee disciplinary issue. Depending on what information was exposed and how it was handled, an employee’s unauthorized AI use can create privacy and cybersecurity obligations, threaten intellectual property and trade-secret protections, and expose the employer to litigation or regulatory scrutiny.
And the existence of an AI policy does not necessarily insulate the company from liability.
An AI Policy Is Not a Liability Shield
One of the most significant risks arises when employees enter sensitive information into generative AI systems without understanding what happens to the data afterward.
“The likelihood and impact of legal risk from employee use of AI when sensitive information is involved depends on many factors,” said Joseph Lazzarotti, an attorney with Jackson Lewis in Tampa, Fla. According to Lazzarotti, these factors include the organization’s regulatory environment, the volume and subject matter of the information, and who gains access to the data.
“One of the biggest risks perhaps is unauthorized disclosure,” he explained. He described this as information entered or uploaded into an AI tool which can then be retained and used to improve the provider’s models. That date could also be made accessible to third parties.
Such disclosures could potentially implicate privacy and data-security laws, confidentiality agreements, contractual obligations or intellectual property protections. They could also jeopardize trade-secret protection or attorney-client privilege, Lazzarotti said.
Employers, however, should not assume that showing an employee violated company rules resolves those problems.
“An AI policy is an important control, but it is not a liability shield,” Lazzarotti cautioned. “In general, the company may remain responsible when the employee was acting within the scope of employment, appeared to have authority, used the output for company business, or when management knew of and accepted the conduct.”
Companies may also face direct liability if they failed to implement appropriate safeguards, training, supervision or access controls, he added. Certain laws impose obligations directly on employers or other regulated entities, meaning an employee’s policy violation may not eliminate the organization’s underlying compliance responsibilities.
Discipline Can Create Risks of Its Own
Employers that discover unauthorized AI use also need to consider how they respond. Before imposing discipline, HR should establish what happened, what the policy actually prohibited, and whether the employee received and understood it. Employers should also examine what information or systems were affected, the employee’s intent, the potential harm, and how comparable violations have previously been handled.
Consistency can be particularly important when termination or other significant discipline is on the table. “Inconsistent enforcement can support claims that the stated AI violation was a pretext for discrimination or retaliation,” Lazzarotti said.
An unclear, outdated, or overly broad policy can create additional problems, he added. These include potentially interfering with protected conduct involving whistleblowing, accommodation requests, or employees acting collectively regarding working conditions.
That makes AI enforcement much like enforcement of other workplace policies: employers should investigate before acting, apply comparable standards to comparable conduct, and document legitimate reasons when circumstances warrant different disciplinary outcomes.
And when sensitive information may have been exposed, HR should not treat discipline as the end of the matter. The company may need to separately trigger its privacy, cybersecurity, or incident-response procedures.
Look Beyond the Employee Handbook
Effective AI governance begins before an employer writes its policy. “Before putting pen to paper on a policy, organizations should at a minimum inventory their AI tools and establish permissible use cases,” Lazzarotti recommended.
A strong policy should tell employees which tools and uses are approved, which are prohibited, and what information should never be entered into an AI system. It should also address human review of AI-generated material, accuracy, bias, intellectual property, confidentiality, privilege, and record retention, according to Lazzarotti.
Higher-risk applications — such as using AI for employment decisions or customer-facing communications — may warrant additional approval requirements.
But employers should avoid treating the policy as a stand-alone compliance document. Governance may also require vendor assessments, privacy and security reviews, employee training, monitoring, incident-reporting procedures, and coordination among HR, legal, IT, cybersecurity, privacy, and procurement teams.
Employers also need to account for “shadow AI.” This happens when workers use tools that the organization has never formally approved, as well as AI capabilities quietly incorporated into software the company already uses.
“The most effective policies are clear enough to guide daily decisions, flexible enough to address new tools, and supported by controls that make compliance realistic,” Lazzarotti said.
For HR, that may be the central lesson. A policy can establish expectations and strengthen an employer’s defenses, but managing AI risk requires knowing how workers are actually using the technology — and building the training, technical controls, and enforcement practices needed to turn rules on paper into meaningful safeguards.
Was this resource helpful?