Blog

Using AI Tools in the Workplace: Understanding Your Legal Responsibilities, Rights and Obligations

Written by Tara Swaminatha | Aug 6, 2026, 11:00:00 AM

AI, Cybersecurity & Data GovernanceMany workplaces are deploying AI tools before learning the legal obligations that surround their use. It is important to tap the brakes on AI tool integration so the appropriate due diligence can take place. 

Before users start typing data into an AI tool, certain basic questions must be answered: what are we legally allowed and obligated to do with this data? And how do we maintain those responsibilities or restrictions as we use the tool?

As the founder and principal attorney at ZeroDay Law, I explore the legal obligations that come with workplace AI use in my latest podcast episode from Decoding Cyber Law.

Here’s how to create an environment to ensure that your organization is compliant when using AI tools.

Prefer to listen to the 6-minute podcast? Tune in here.

How to Find AI Laws, Regulations and Contracts 

While it may seem logical to look at AI-specific laws, some legal exposure occurs with laws and regulations that predate AI technology. 

For example:

  • Using AI to make hiring decisions could introduce discriminatory hiring practices, which are governed by employment laws. 
  • (Undisclosed) AI use in chatbots could misrepresent products or services, misleading consumers in a way that could violate consumer protection laws.

Start by reviewing existing customer, partner and/or grantee contracts for promises you've already made about data handling. Then, add those obligations and requirements to must-dos from current regulations and emerging AI rules. This process requires a broad review of AI-specific legislation and other kinds  of regulations that may be relevant. 

Depending on your type of business, industry and even your organization, the review could include:

  • AI-specific laws at the state, federal and international levels
  • Employment and anti-discrimination laws (especially around hiring decisions)
  • Consumer protection laws addressing misrepresentation of product capabilities or security & privacy features
  • Product liability and safety laws
  • Sector-specific regulations tied to particular services or data types
  • Government contracts-related laws
  • National security regulations

A review of all applicable legal and regulatory areas will provide a foundation for cross-checking your AI vendors’ terms, and any of their third-party vendors, that provide you with a good or service.

Unsure of where to start? Read our blog, U.S. State Privacy Acts: Which Apply to Your Organization (2026), which provides a comprehensive state-by-state breakdown.

Now, let’s turn to how your rights, obligations and exposure are affected by the language in standard contracts from your AI vendors.

What To Look For In An AI Vendor’s Terms of Service 

The terms of service provided by AI vendors vary widely. However, the default language in many AI contracts may:

  • Grant vendors broad rights to use your data to train models
  • Grant the right to share your input and output with third parties
  • Claim an ownership interest in your inputs or outputs

Business and enterprise AI license contracts typically prevent vendors from using your data to train models. If you have employees who are using free or personal versions of AI tools, those terms of service need to be carefully reviewed, as their default position is usually that the data can not only be used for model training, but is available for any other purposes designated by the AI vendor.

Data inputs and outputs are often treated differently in an AI vendor’s terms of service. One area where you should be particularly diligent is in reviewing ownership of outputs.

Understanding AI Output Ownership

AI-generated content, also known as “output,” sits in an ownership and infringement gray area for two distinct reasons. The first reason is contractual: your AI vendor contract should clearly state who owns the output your team generates. Ideally, ownership rests with the licensee (your organization, hopefully), with no residual rights or claims left with the vendor.

The second reason is operational. AI tools may generate their responses by drawing on training data the vendor often hasn't licensed properly, which means an output your team relies on may unknowingly incorporate unlicensed copyrighted material from third parties. User training and education can help staff understand whether AI output is an original work in the legal sense and that anything generated may need to be reviewed for outside ownership before it's published, distributed or relied on for important decisions.

We discuss inputs, outputs and contract ownership language more deeply in Episode 4 of Decoding Cyber Law. Read that blog post or listen to the podcast for a deeper discussion of this topic.

Though an acceptable AI vendor contract may be in force, it’s possible that the AI tool itself may be problematic due to the tool settings active at the time your organization uses it. Now, let’s look at why settings should also be reviewed on a regular basis.

Check AI Tool Admin Settings Regularly, Even Weekly

AI tools and enterprise tools with integrated AI include tool settings that control everything from whether output is saved to whether users can share data. Depending on the vendor, tool settings can change frequently, sometimes weekly or several times in a given week. 

Our team has experienced these AI tool setting changes first-hand:

  • We saw the AI tool admin settings change twice in one week.

  • An AI tool for which the licensing agreement says the AI vendor will not use our data to train models had an opt-in/opt-out setting for allowing our data to be used to train models, and the default setting was toggled to opt-in to model training. We had to manually opt out again.

A manual review of admin settings is a must to ensure that data is not exposed to unnecessary risk in an AI tool. To avoid any inconsistency between AI vendor contract terms and actual AI tool settings, build a recurring admin setting review cycle into your AI governance program. 

Practice Data Minimization Before Granting AI Access

Another way to minimize risk is to focus on data minimization to reduce unnecessary data exposure to AI tools. AI workplace usage certainly introduces some new workflow efficiencies, and those can’t happen without data access. But AI tools, including in major platforms like Gemini in Google Workspace or Co-Pilot in Microsoft 365, 365 E5 or SharePoint, most likely have no need for broad, unfettered access to your entire data repository to function properly. 

AI tools are marketing themselves as the solution for synthesizing, analyzing and organizing corporate data. Somehow, providing this access will ensure your business magically becomes faster, better and smarter, but that’s just a marketing campaign for these AI tools. 

At Zero Day Law, we recommend a data minimization approach when integrating AI tools. Instead of just broadly opening up your data repository to a new tool, test it first. See what happens when you provide AI tools limited access to a set of data and work through any ripple effects in your organization’s cybersecurity and privacy posture. Consider setting up a separate data repository, locked down via controls in your environment so that AI tools cannot more broadly access content than you intend them to.

Testing AI tool access may result in access control mismatches, where folders and document permissions don’t correctly carry over into the AI tool. If there are misalignments, internal users can end up seeing files and folders that they never had access to before.

How can you find these mismatches? Do an audit of access controls in the AI tool against access controls in your source system. Once this baseline is established, include an access control audit as part of a recurring review cycle in your AI governance program. 

Learn more about the importance of limiting AI access with our blog post, “Can Your AI Tool See Too Much? File & Folder Permissions, Access and Internal Risk.”

A Working Data Governance Checklist for AI

Before allowing AI use in your organization, make sure you have:

  1. A mapped view of applicable laws, regulations and contractual obligations
  2. A clear definition of which data types are acceptable (and unacceptable) for your organization as AI input
  3. An understanding of output ownership and permitted uses
  4. Verified input and output permissions in your vendor terms of service
  5. A recurring review of admin settings inside each AI tool
  6. Validated access control alignment between your source data and the AI tool

Following this checklist will help minimize overall risk when integrating AI tools into your workplace. This checklist will also ensure you are taking appropriate responsibility for any applicable rights and obligations.

For additional help in understanding the implications of AI tool use in the workplace, reach out to our team at ZeroDay Law.

Listen to the Decoding Cyber Law podcast for our complete discussion on the legal rights and obligations involved in AI tools.

Read more: