An employee pastes a customer file into a chatbot. A recruiter uses an automated ranking tool. A founder publishes AI-generated marketing copy without checking its claims. Each action can create legal exposure, even when the software seems routine. For California businesses, the question is not simply whether AI saves time. It is whether the company understands where information goes, who reviews the output, and who bears responsibility when something goes wrong. Here are the AI legal risks business owners should assess before expanding workplace use.
Confidential data can leave your control
Information entered into an AI tool may be stored, reviewed, shared with service providers, or used to improve models, depending on the product, account settings, and contract. A consumer account and an enterprise account may offer very different protections. Do not assume that a paid subscription makes confidential information private.
For businesses covered by the California Consumer Privacy Act, collecting, using, and disclosing personal information can trigger notice, purpose-limitation, and contractual obligations. California Civil Code § 1798.100 addresses core collection, notice, purpose, and use requirements, as well as certain contractual requirements. Service-provider and contractor relationships are also governed by other CCPA provisions, including Civil Code § 1798.140. Sending customer or employee information to an AI vendor does not automatically make that vendor a qualifying service provider or contractor; the agreement and actual use matter.
- Review retention, training, deletion, and access settings before approving a tool.
- Keep personal information, passwords, and sensitive business records out of unapproved accounts.
- Confirm that vendor terms fit your privacy notices and customer commitments.
Trade secrets need attention too. California Civil Code § 3426.1 defines a trade secret to include information that derives independent economic value, actual or potential, from not being generally known to the public or to others who can obtain economic value from its disclosure or use, and that is subject to efforts reasonable under the circumstances to maintain its secrecy. Uncontrolled disclosure can undermine those efforts. Removing names alone may not make a document anonymous or safe to upload.
AI errors become business decisions
An AI system can produce an answer that sounds authoritative but contains invented facts, outdated rules, or nonexistent sources. If your business relies on that answer when advising a customer, calculating a payment, or sending a demand letter, the resulting problem remains yours to address.
Set review requirements according to the consequences of an error. Brainstorming an internal meeting agenda is different from drafting a customer warranty, interpreting an employment obligation, or deciding whether to pursue an individual for a debt.
- Check factual claims against reliable source material.
- Require qualified review of legal, financial, medical, and safety-related output.
- Do not let a tool invent contract terms, citations, or representations about your products.
- Keep records of significant inputs, revisions, and approvals without unnecessarily duplicating sensitive data.
AI-generated customer communications can also create false advertising or contract disputes. Calling content “AI-generated” does not excuse misleading statements. A review process should identify both inaccurate claims and promises your business cannot support.
Hiring tools can create discrimination exposure
California’s Fair Employment and Housing Act prohibits specified employment discrimination under Government Code § 12940. Using a vendor’s software does not remove an employer’s obligations. A screening or evaluation tool may disadvantage applicants because of biased training data, unsuitable scoring criteria, or features that correlate with protected characteristics.
Before using AI to rank applicants, evaluate employees, or recommend promotions, ask what the system measures and whether those measures relate to the job. A vendor’s general statement that its product is fair is not a substitute for examining your particular use.
- Provide a way to request accommodations where required.
- Review whether screening criteria exclude qualified applicants unnecessarily.
- Give reviewers enough information and authority to question automated recommendations.
- Document the reasons for decisions rather than relying only on a numerical score.
A person clicking “approve” is not meaningful oversight if that person cannot assess the recommendation. California’s FEHA regulations concerning automated decision systems, effective October 1, 2025, require covered employers to maintain relevant employment records, including automated-decision-system data, for at least four years. Businesses should also evaluate applicable notice, accommodation, discrimination, recordkeeping, and privacy requirements before deploying employment technology.
Ownership and vendor contracts need separate review
Do not assume your business owns exclusive rights to everything an AI tool produces. Copyright protection generally requires human authorship. A work containing AI-generated material may protect qualifying human contributions without protecting the machine-generated portions. The result depends on how the work was created.
Output can also raise questions about copied material, trademarks, publicity rights, or confidential information. A vendor’s permission to use output is not a legal conclusion that the output infringes no one’s rights.
Review the contract before integrating AI into a business process:
- Data rights: What may the vendor do with prompts, files, and outputs?
- Risk allocation: Are indemnity obligations limited or subject to exclusions?
- Liability limits: Could a contractual cap leave substantial losses with your company?
- Continuity: Can you retrieve records if access ends or the service changes?
Compare those terms with your own obligations to customers. Your customer contract may promise protections that the AI vendor does not provide.
Build an AI policy employees can actually use
A useful policy identifies approved tools, permitted tasks, prohibited inputs, and required reviewers. It should cover employees, contractors, and personal accounts used for company work. Make the rules concrete: “Do not upload customer contracts to an unapproved chatbot” is more useful than “Use AI responsibly.”
Assign responsibility for approving new tools and reporting mistakes. Reassess approval when a vendor changes its terms, data practices, or features. Training should explain when employees must stop and ask for help, especially before disclosing confidential information or making decisions about individuals.
Itkin Law’s regulatory compliance counsel can help California businesses connect AI policies with privacy obligations, employment practices, and contractual commitments.
Talk to a California business attorney
If your business is adopting AI tools, a free consultation with Itkin Law can help identify the legal questions to resolve before broader use. Schedule a free consultation or call (424) 603-8888.
This article is attorney advertising and provides general information only. It is not legal advice and does not create an attorney–client relationship. The law changes, and this article reflects the law as of its publication date. Every situation is different — contact us to discuss how the law applies to your exact circumstances. See our full disclaimer.

