Generative artificial intelligence (GenAI) tools are becoming increasingly utilized by employees in the workplace to enhance productivity. However, employees are frequently leveraging these tools without formal approval or oversight. While the benefits of GenAI tools may be substantial, use of GenAI may pose significant risks to organizations, including legal liabilities, data breaches, and reputational damage. This article explores certain key concerns associated with employee use of GenAI tools and essential components of an AI use policy.
Understanding the Risks
Data Privacy and Security
One of the most significant risks with the use of GenAI is that information entered into prompts or uploaded to common GenAI platforms may reveal to the AI tool sensitive or confidential company information or information about clients or customers, including information the company may have contractually agreed to keep confidential. Similar risks exist with inputs of personally identifiable information, such as email addresses or other identifiers. Typically, on publicly-available versions of such tools, data that is entered is used to train the AI or may otherwise be stored or used by the AI tool developer.
To mitigate risks of exposing potentially sensitive company data or potentially breaching customer confidentiality agreements, companies may want to consider purchasing enterprise versions of GenAI tools that operate in a closed-loop system, meaning the developer is not permitted to use or store inputs for purposes other than to provide the GenAI tool. Companies may also want to have an approved list of AI tools, which might include enterprise versions of common GenAI tools. Also helpful is employee training and raising awareness of these risks.
Another significant and emerging risk is that GenAI tools are increasingly being used as a tool for cybercriminals, including through the orchestration of complex injection attacks that exploit the fact that these tools do not think, but rather, simply follow instructions. For example, attackers can embed instructions in publicly available links that, when uploaded to the GenAI tool, tell the tool to maliciously attack the host system and override instructions. Alternatively, the embedded instructions in public links could produce PDFs or other outputs that themselves contain malicious code. Companies should consult with their security team about the risks unique to their business and implement recommended controls if applicable. In addition, companies may want to consider working with external cybersecurity training providers to ensure their materials include AI tool injection attacks in any employee training modules.
Intellectual Property Concerns
Companies should seriously consider the significant intellectual property (IP) risks posed by employees’ use of GenAI tools. These IP risks arise from two factors - (1) the material used as “input” to train the AI models; and (2) the material generated by the AI model as “output”. AI models are frequently trained on vast datasets which include copyrighted material used without the author’s permission. Furthermore, use of such copyrighted material may cause the GenAI tool to generate outputs that replicate or closely resemble the copyrighted material, further exposing the user to potential copyright infringement claims.
Another IP risk associated with employees’ use of GenAI tools is the lack of IP protection for works and innovations created using GenAI. In the United States, works and innovations created solely by AI without human contribution are not eligible for copyright or patent protection. Without such protections, a company’s competitive advantage may fall into the public domain, where anyone can use it for free.
Use of GenAI may also compromise trade secret protection of a company’s proprietary information. If an employee inputs confidential proprietary information into GenAI tools without proper contractual protections, such information may be used to train the underlying AI models. As noted above, GenAI tools may generate outputs that replicate or closely resemble the inputs, in this case, the proprietary information, potentially exposing the trade secret to other users and compromising the company’s trade secret protection of the information.
Hallucinations and Bias
AI systems, particularly generative models, can produce outputs that appear plausible but are factually incorrect or nonsensical, a phenomenon known as “hallucinations.” These inaccuracies can lead to misguided business decisions, flawed reports, and erosion of trust in AI tools. For instance, an AI-generated report might cite non-existent studies or fabricate data, potentially leading to compliance issues or reputational damage.
Shadow AI Usage
Employees may use unauthorized AI tools (sometimes referred to as “shadow AI”) without the knowledge or approval of IT departments. This practice can result in data security breaches, compliance violations, and loss of control over sensitive information. For example, inputting confidential company data into unvetted AI platforms could inadvertently expose proprietary information. Companies should implement strict policies around shadow AI use and consider limiting access to popular AI tools on workplace computers.
Regulatory Compliance Challenges
The rapidly evolving landscape of AI regulations, such as the European Union’s AI Act, presents compliance challenges for organizations. Failure to adhere to these regulations can result in legal penalties and hindered innovation. Organizations must stay informed about regulatory changes and implement robust governance frameworks to ensure compliance.
DO’S & DON’TS:
Legal Compliance & Policy Design
DO:
- Establish a clear, tailored AI usage policy in collaboration with legal, IT, and compliance teams.
- Define “AI” in plain language, and specify which tools are approved.
- Include a mission or purpose statement to ground the policy in transparency, fairness, and innovation.
- Update the policy regularly to reflect evolving laws (e.g., EU AI Act, state legislation like Colorado’s).
DON’T:
- Don’t use one-size-fits-all policy templates. Each policy should reflect specific business risks and use cases.
- Don’t treat the AI policy as a one-time exercise. Legal exposure grows without active maintenance.
Data Security & Confidentiality
DO:
- Prohibit inputting sensitive, proprietary, or customer data into public AI tools unless specifically authorized.
- Include clear confidentiality provisions related to AI use in employee and vendor contracts.
- Conduct vendor due diligence to confirm AI platforms’ compliance with privacy laws and data handling standards.
- Consider using enterprise versions of AI tools to keep data inputs confidential.
DON’T:
- Don’t assume that AI tools won’t retain user input; review each tool’s terms of service and retention practices.
- Don’t allow shadow IT (e.g., unauthorized browser plugins, personal-use tools) without approval or audit trails.
Intellectual Property & Ownership
DO:
- Review AI vendor agreements to ensure the vendor has proper rights to use training data to use training data and vendor provides adequate protections if infringement claims arise.
- Implement human review processes for AI-generated materials to identify potentially infringing content.
- Document human contributions in connection with the development of AI-assisted works and innovations.
DON’T:
- Don’t allow employees to generate customer-facing or public materials without review for potentially infringing content.
- Don’t use AI models trained on unlicensed data without understanding the risk of potential IP infringement claims.
- Don’t allow employees to input confidential proprietary information into AI tools without proper confidentiality and use restrictions.
Training, Governance & Oversight
DO:
- Require regular employee training on the capabilities, limits, and risks of AI tools.
- Designate responsible roles (e.g., AI Compliance Lead, Tool Vetting Committee) to oversee implementation and approvals.
- Monitor AI tool usage, audit outputs periodically, and solicit user feedback to improve policies.
DON’T:
- Don’t deploy AI tools enterprise-wide without pilot testing, user education, and risk assessment.
- Don’t assume all departments or roles should have equal access to AI tools—access should be role-specific.
Ethical Use & Bias Prevention
DO:
- Embed fairness, transparency, and accountability principles into your AI governance framework.
- Monitor AI systems for evidence of bias, particularly in HR, marketing, or customer interaction tools.
- Require disclosures when AI is used to create or assist in work product—internally or externally.
DON’T:
- Don’t use generative AI content without fact-checking—misleading outputs could carry reputational or legal costs.
- Don’t let AI output go unlabeled in sensitive contexts (e.g., client deliverables, compliance filings).
