Slow Down Road Sign

AI Has Tagalongs, and Not the Girl Scout Cookie Kind

AI can be an extraordinary business tool. Just make sure you know what’s coming along for the ride.

[A quick note: This is an issue-spotting guide, not an exhaustive legal analysis. Whether a particular risk applies to your business depends on your actual AI uses, the technologies and vendors involved, your contractual obligations, and the laws applicable to your business. Identifying these issues is the starting point. Evaluating and addressing them requires a business-specific legal analysis.]

AI Has Tagalongs. (And Not the Girl Scout Cookie Kind.)

The legal risks that come along with using AI in your business — and what to do about them.

I love Tagalongs.

The Girl Scout cookie kind, that is. 😉

The other kind? Not so much.

Because as businesses race to adopt AI, there are some very real legal issues tagging along for the ride.

And unlike the cookies, these aren’t necessarily something you signed up for.

I’m a fan of AI. I use it in my own business, and I think it creates extraordinary opportunities for entrepreneurs.

But using AI isn’t just a technology decision.

It’s also a legal, operational, and risk-management decision.

And whether you’re using AI to generate content, assist with client work, manage customer communications, analyze data, screen job applicants, or simply make your team more productive, there are some important legal questions you should be considering.

And heads up for small businesses: some of these risks you may not be able to afford to take on.

Let’s look at exactly what may be coming along for the ride.

1. Data Privacy: What Information Is Going Into Your AI Tools?

One of the most immediate legal concerns surrounding business use of AI is what happens to the information being entered into these systems.

Issues to consider:

  • Are employees or contractors entering customer information, personal data, financial records, health information, or other sensitive information into AI tools?
  • Does the business have a lawful basis to process that information for the intended purpose, where required?
  • Are AI vendors retaining, sharing, or using submitted information for model training or other purposes? Have you reviewed and properly configured your account settings?
  • Are appropriate contractual protections, security measures, and vendor agreements in place?
  • Are cross-border data transfers, retention practices, or deletion requirements implicated?
  • Do existing privacy disclosures accurately describe relevant AI-related data processing?

Potential exposure: Privacy-law violations, unauthorized disclosures, security incidents, contractual breaches, regulatory investigations, and customer claims.

2. Confidentiality & Trade Secrets: Are You Giving Away Information You Should Be Protecting?

Not all confidential information is personal information.

Businesses also possess valuable proprietary information, including internal processes, pricing strategies, customer relationships, business plans, software, methodologies, and trade secrets.

Issues to consider:

  • Are employees, contractors, or clients uploading confidential business information into third-party AI platforms?
  • Do existing NDAs, client agreements, or confidentiality obligations restrict that use? When did you last update your agreements to address AI?
  • Could disclosure to an AI provider undermine the reasonable measures required to protect trade secrets?
  • Are contractors using personal AI accounts outside the business’s approved systems?
  • Do AI vendors provide adequate confidentiality protections and controls?

Potential exposure: Loss of confidentiality, weakened trade-secret protection, breach of contractual obligations, and disclosure of competitively sensitive information.

3. Intellectual Property: Who Owns What AI Creates?

AI raises a particularly interesting collection of intellectual property questions.

Businesses are using AI to create marketing materials, educational content, images, software, presentations, client deliverables, and even proprietary methodologies.

But the rules surrounding ownership and protection are not necessarily what business owners expect.

Issues to consider:

  • Are you relying on AI to generate significant portions of content you intend to protect through copyright? If so, do you understand which elements may – and may not – qualify for copyright protection?
  • Is there sufficient human authorship in the final work? Under current U.S. Copyright Office guidance, material AI-generated content generally must be identified and excluded from the copyright claim in a registration application, while sufficiently original human-authored contributions may remain protectable.
  • What use, ownership, or other rights does the AI vendor grant users under its terms?
  • Could AI-generated content infringe someone else’s copyright, trademark, or other intellectual property rights? (Hint: Yes, it can. And depending on your vendor agreement, you may bear significant responsibility for that infringement.)
  • Are contractors incorporating AI-generated materials into work they are contractually required to assign to the business? If so, has that use been properly disclosed, and have the ownership and liability implications been addressed?
  • Are businesses inadvertently uploading their own protected intellectual property into systems without appropriate safeguards?
  • Can the business accurately represent that it owns or has the right to license the deliverables it creates?

Potential exposure: Unprotectable content, disputed ownership, infringement claims, licensing problems, and diminished value of business IP assets.

4. Accuracy, Professional Responsibility & Liability: Who Is Responsible When AI Gets It Wrong?

AI can produce remarkably convincing outputs.

Unfortunately, convincing and correct are not the same thing.

Issues to consider:

  • Are AI-generated statements, recommendations, calculations, citations, or analyses being independently verified?
  • Have you established appropriate disclaimers, contractual provisions, policies, and — most importantly — processes for identifying and addressing inaccurate AI outputs?
  • Are employees relying on AI outputs in areas requiring specialized professional judgment?
  • Could inaccurate AI-generated content cause financial harm, reputational damage, or other injury?
  • Are businesses using AI-generated materials in advertising, client communications, or professional deliverables without adequate review or disclosure?
  • Do client agreements impose accuracy, performance, confidentiality, or other obligations that AI-assisted work could violate?
  • Who bears responsibility when an AI tool produces an incorrect or harmful result?

Potential exposure: Negligence claims, breach of contract, misleading advertising, professional liability, defamation, and other claims depending on the circumstances.

Key principle: Outsourcing a task to AI does not necessarily outsource the business’s legal responsibility for the result.

And a disclaimer is not a substitute for human review, verification, and appropriate quality-control procedures.

5. Bias, Discrimination & Employment: Is AI Making Decisions About People?

AI is increasingly being used in recruiting, hiring, employee evaluations, customer screening, financial services, and other decision-making processes.

These uses can introduce significant legal concerns, particularly where AI affects people’s rights or opportunities.

AI systems trained on historical data can reproduce or amplify existing biases, including patterns of discrimination that may be difficult to detect without appropriate testing and oversight.

Issues to consider:

  • Are automated tools being used to screen applicants, evaluate employees, or make employment-related recommendations?
  • Have those tools been assessed for discriminatory impacts? Depending on the circumstances, discriminatory outcomes can violate existing laws even when the business did not intend to discriminate.
  • Are applicable notice, consent, audit, or human-review requirements being satisfied? Certain jurisdictions impose specific requirements when automated tools are used to evaluate candidates or make employment-related decisions.
  • Are vendors providing adequate information about how their tools operate?
  • Is there a process for identifying and correcting inaccurate or biased outcomes?
  • Does the business understand which federal, state, local, or international AI-specific rules may apply?

Potential exposure: Employment discrimination claims, civil-rights violations, regulatory enforcement, and liability associated with automated decision-making.

6. Consumer Protection, Marketing & Transparency: What Are You Telling Your Customers?

Some businesses are using AI in ways their customers can clearly see.

Others are using it extensively behind the scenes.

Both scenarios can raise disclosure, privacy, and consumer-protection questions.

And this is an area where I think businesses need to be especially careful.

Customer-facing AI tools — including chatbots, automated messaging systems, and AI-powered customer-service platforms — can create significant legal exposure when deployed without appropriate disclosures, consent mechanisms, and vendor due diligence.

Depending on how these technologies operate, they may implicate federal and state wiretapping, electronic interception, recording, and privacy laws.

For example, website chat technologies that capture, transmit, or allow third parties to access visitor communications have been the subject of litigation under federal and state interception statutes. Whether a particular deployment violates those laws depends on the technology, the parties involved, the applicable jurisdiction, and the nature and timing of consent.

Issues to consider:

  • Are customers interacting with AI-powered chatbots, customer-service systems, scheduling assistants, or other automated tools?
  • Are those systems recording, capturing, transmitting, or allowing third-party access to customer communications? Have you evaluated applicable wiretapping, interception, and consent requirements?
  • Are appropriate disclosures and consent mechanisms in place before communications are captured or transmitted, where required?
  • Is AI being used to generate product descriptions, marketing claims, testimonials, compile product data, or create other consumer-facing content?
  • Could AI-generated representations be misleading or deceptive?
  • Are customers being told how their information is used in relevant AI systems?
  • Are website terms, privacy policies, and other disclosures consistent with the business’s actual practices?
  • Are AI-generated images, voices, likenesses, or other synthetic media being used in ways that raise consent, publicity-rights, or deceptive-marketing concerns?
  • Are applicable AI-specific transparency or disclosure requirements being satisfied?

Potential exposure: Federal or state interception and recording claims, FTC enforcement, state consumer-protection claims, privacy violations, deceptive-marketing allegations, and violations of applicable AI transparency requirements.

And remember: a general privacy policy disclosure is not necessarily a substitute for obtaining legally required consent.

7. Contracts & Vendor Risk: What Did You Agree To When You Clicked ‘Accept’?

One frequently overlooked area of AI risk is the contractual relationship between the business and its AI providers.

Not all AI tools offer the same protections.

And the difference between a free consumer account and a negotiated enterprise agreement can be substantial.

Issues to consider:

  • What rights does the AI vendor claim regarding inputs and outputs? Many AI providers place substantial responsibility for inputs, outputs, and downstream use on the customer while limiting their own liability. Some commercial plans offer additional protections, including qualified IP indemnities. Do you know which protections actually apply to your account?
  • What confidentiality and data-security commitments does the vendor provide?
  • Does the vendor use business data for training or product improvement? Is there a setting for controlling or disabling this use?
  • What warranties, indemnities, limitations of liability, or exclusions apply?
  • Does the vendor offer meaningful remedies if something goes wrong?
  • Are employees or contractors adopting AI tools without authorization?
  • Do existing client agreements permit the business to use AI or subcontract relevant processing to AI providers?
  • Could AI use violate contractual restrictions, professional obligations, or customer commitments?

Potential exposure: Unanticipated contractual obligations, vendor-related data exposure, uncovered liability, breaches of client agreements, and disputes over rights to AI-generated work.

So What Should Businesses Actually Be Doing?

First, I would strongly recommend that you find out exactly where and how AI is already being used throughout your business.

Because you cannot effectively manage risks you haven’t identified.

Step 1: Find Out Where AI Is Already Being Used

Start with an inventory of the AI tools and systems operating within your business.

That means understanding:

  • Which AI tools employees and contractors use, including personal accounts and unapproved tools.
  • What business, customer, client, or confidential information enters those systems.
  • Which AI-generated outputs are incorporated into client deliverables, marketing, products, or other business assets.
  • Which AI tools interact directly with customers or influence important decisions.
  • What vendor agreements, client contracts, and existing policies govern those activities.

You may discover that AI is being used in considerably more places than you realized.

And that is exactly why this exercise matters.

Step 2: Establish External AI Disclosures & Website Policies

Businesses should assess how they use AI in customer-facing interactions and behind-the-scenes operations.

Depending on the nature of that use, applicable law, and the information involved, appropriate disclosures and consent mechanisms may belong in:

  • Website AI disclosures or a standalone AI Use & Transparency Policy
  • Privacy policies
  • Terms and conditions
  • Client or customer agreements
  • Chatbot notices and consent interfaces
  • Point-of-interaction disclosures, including where required for AI-generated or AI-assisted content

The objective is to ensure that the business’s representations and disclosures accurately reflect its actual AI practices and satisfy applicable legal requirements.

And importantly, where affirmative consent is required, simply adding language to a privacy policy may not be sufficient.

Step 3: Establish Internal AI Use Policies

Separately, businesses should establish clear rules governing how employees, contractors, and other team members may use AI.

An effective internal policy should address:

  • Approved and prohibited AI tools
  • Permitted and restricted uses
  • Confidentiality and personal-data safeguards
  • Intellectual property protection
  • Use of AI in client work and deliverables
  • Human review and verification requirements
  • Disclosure and approval obligations
  • Personal versus company AI accounts
  • Accountability, oversight, and incident reporting

And critically, those rules should be reflected where appropriate in contractor agreements, employment policies, client agreements, vendor arrangements, and operational practices.

A policy alone is not enough if the business isn’t actually following it.

The Bottom Line: AI Is Not Going Away. Neither Are Its Legal Tagalongs.

I’m not interested in telling business owners to stop using AI.

Though I do strongly recommend being intentional, ethical, and appropriately limited in how you use it.

Because even within those boundaries, I believe AI can be an extraordinary tool for businesses of all sizes.

But as businesses evolve and adopt new technologies, including AI, their legal infrastructure needs to keep pace.

You don’t need to eliminate every conceivable risk.

You do need to understand what you’re using, what information is involved, what obligations apply, and where the important gaps may exist.

The goal isn’t to make AI harder to use. It’s to make sure you’re using it intelligently — with the right protections in place.

And if your business is actively using AI but hasn’t addressed the legal side of that use, this is a good time to change that.

Reach out if you need help.

It doesn’t have to be hard. But it should be DONE.

Warmly,

Heather