Many businesses are finding themselves caught with their hands in the proverbial (internet) cookie jar. Meaning, they have been operating without fully understanding the AI systems and tools that are, more likely than not, already being used within their organizations.
Some companies have leaned in, building AI into their official workflows. Others are understandably more reticent. But even in offices with no AI policy whatsoever, employees are often using these tools constantly, sometimes without even clocking that what they’re using counts as AI. Drafting emails, summarizing documents, brainstorming marketing copy, digging through spreadsheets, knocking out routine tasks, AI-powered tools have quietly and quickly become part of the everyday workflow.
To be clear: AI itself is not the problem. The risk shows up when it’s used without any oversight, any guardrails, or sometimes even basic awareness that it’s happening at all.
For example, an employee may enter confidential business information into a public AI platform to help draft a report. A marketing manager may rely on AI-generated content without verifying its accuracy. An HR department may use AI-assisted tools during the hiring process, exposing the company to possible discrimination claims. In fact, in 2023, the Equal Employment Opportunity Commission (EEOC) issued guidance warning employers that AI-assisted hiring and employment tools may create liability under existing anti-discrimination laws if they disproportionately screen out protected groups. Likewise, the Federal Trade Commission has cautioned businesses against relying on misleading or unverified AI-generated information.
That does not mean businesses should throw the baby out with the bathwater or simply turn AI off and back on again and hope the issue resolves itself like many of us do with other technology issues.
Before even considering a formal AI policy—which the attorneys at Johnson Duffie can help develop and tailor for organizations and entities of all sizes—businesses should start with an inventory. Who’s actually using AI in your organization? Which tools? How are they being used, and what information is being typed or uploaded into them?
Getting a clear picture of where AI already lives in your business, flagging the higher-risk uses, and setting some basic ground rules for employees goes a long way toward protecting confidential information, cutting down legal exposure, and making smarter calls about where AI fits going forward.
Whether people like it or not, artificial intelligence is not going away. Businesses can either take proactive steps to understand and manage its use, or risk being carried along by technology they do not fully understand.
In our next article, we’ll take a closer look at one of the most common AI traps businesses fall into involving putting confidential, proprietary, or personal information into AI tools.
Every time information is entered into an AI tool, it is shared with a third-party vendor. That includes customer records, employee information, financial data, contracts, internal reports, and proprietary business information, which may be exposing confidential information inadvertently.
Plenty of free, consumer-grade AI tools reserve the right to hold onto what you type and use it to train their systems further. Enterprise products usually work differently, often with shorter retention windows or “closed-loop” setups where your data stays out of the training pipeline. But once information leaves your organization and lands on someone else’s platform, real questions come up about confidentiality, privacy, and what legal protections, if any, still apply.
Courts are already grappling with how traditional legal protections apply when information is shared with artificial intelligence systems. In United States v. Heppner, 820 F. Supp. 3d 292 (S.D.N.Y. 2026), a federal court held that communications with a publicly available AI platform were not protected by attorney-client privilege or the work-product doctrine. Moreover, courts have already spent years examining what happens when businesses share customer information with third-party technology vendors, even outside the scope of AI. In Popa v. Harriet Carter Gifts, Inc., 52 F.4th 121 (3d Cir. 2022), the Third Circuit allowed claims to proceed under Pennsylvania’s Wiretapping and Electronic Surveillance Control Act where customer activity was transmitted to a third-party vendor without the customer’s knowledge.
The stakes are even higher for industries with heightened confidentiality and regulatory obligations. Healthcare providers handling patient information, financial institutions managing sensitive financial records, and government contractors subject to strict cybersecurity requirements should be particularly cautious when using consumer AI tools.
Businesses looking to use AI responsibly should take a few simple precautions. Before adopting a new AI platform, review the vendor’s terms of service and privacy policies to understand whether information is retained, shared, or used to train future AI models (and disable said training features when possible). Organizations should also establish clear expectations regarding what information may be entered into AI systems. Confidential information, including customer identifiers, account numbers, medical information, financial records, and other sensitive data, should be removed or redacted before documents are uploaded.
In our final piece, we’ll dig into another common AI pitfall: trusting generative content without checking whether it’s actually accurate or usable
Generative AI does exactly what the name promises: it generates. It’s predicting the likely next word, sentence, image, or response based on patterns it picked up during training. That means it’s built to produce an answer, not necessarily a correct one. These mistakes are commonly referred to as “hallucinations,” where AI presents information that is inaccurate, fabricated, or entirely nonexistent.
Courts have already encountered this problem. In Lifetime Well LLC v. IBSpot.com Inc., attorneys submitted court filings containing multiple fictitious legal citations generated by artificial intelligence. After discovering that the cited authorities did not exist, the court issued a show-cause order and sanctioned counsel. The same risk applies in business, if an AI-generated answer is wrong, gives a customer bad guidance, or a marketing piece includes a fabricated fact, the company is still the one on the hook.
Plenty of businesses now lean on AI-generated images for websites, social posts, and marketing materials. Copyright law is still catching up to generative AI, so it’s worth being cautious rather than assuming ownership rights automatically come along with an AI-generated image just because it came from AI.
The practical takeaway is simple: trust, but verify. The bottom line is simple: trust, but verify. AI can save a business real time and money, but at this juncture accuracy, and judgment are still human responsibilities.