
Samuel E. Granderson
sgranderson@kmksc.com
(414) 962-5110
Artificial intelligence (“AI”) has rapidly evolved from a novel technology into a common workplace tool. Businesses increasingly use AI-powered platforms to draft correspondence, analyze information, generate reports, summarize documents and perform routine administrative tasks. For business and law firms alike, these tools can increase efficiency and productivity. However, the increased use of AI also creates legal and operational risks that businesses should consider before incorporating AI into their daily operations.
One of the most significant concerns is the handling of confidential and sensitive business information. Employees may enter information into publicly available AI platforms without fully understanding how that information may be stored, processed or used. When employees input confidential business information into an AI system, they may unintentionally disclose client information, financial records, internal company documents, business strategies or other sensitive information.
This concern is particularly relevant to businesses that regularly handle financial and customer information. For example, a company involved in collecting outstanding accounts may possess customer account information, payment histories, contractual documents and other sensitive financial records. Entering that information into an AI platform without appropriate safeguards could create confidentiality, contractual or data-security concerns.
The use of AI poses particularly thorny concerns with respect to attorney-client privilege—the bedrock legal protection granting broad confidentiality to communications between lawyers and their clients. If a client shares information received from her attorneys with a chatbot to assist in her legal case, does that constitute a “waiver” of attorney-client privilege that subjects the shared information to disclosure to the opposing party?
Courts around the U.S. are just starting to grapple with this question. In February, a New York federal judge held that a criminal defendant’s discussions with Anthropic’s Claude chatbot about his potential defense strategy must be turned over to the government. United States v. Heppner, 820 F. Supp. 3d 292, 294 (2026). In holding that the documents were not protected by attorney-client privilege, the court noted that the defendant engaged with Claude on his own volition, rather than at the direction of counsel, and that Claude’s privacy policy (which permits Anthropic to use customer inputs to “train” Claude) belied any expectation of confidentiality the defendant may have had. Id. at 296-97.
However, around the same time as the Heppner decision, a Michigan federal judge ruled that a plaintiff representing herself in a civil action did not need to turn over ChatGPT logs to the defendants, saying that AI programs “are tools, not persons,” in finding that confidentiality remained after information related to the case was fed to ChatGPT. Warner v. Gilbarco, Inc., 820 F. Supp. 3d 629, 636 (2026). While the Warner decision relied on the related work product doctrine (as opposed to attorney-client privilege), the inconsistent reasoning of the two decisions counsels caution when entering any information into a chatbot that is related to ongoing litigation, or which is relevant to a dispute that could escalate to litigation.
Businesses should therefore establish clear policies governing the use of AI in the workplace. These policies should identify what information employees may and may not enter into AI systems and should address which AI platforms are approved for business use. Employee training is equally important. A written policy is only effective if employees understand the risks associated with improper AI use and know how to follow the company’s requirements.
AI can also create risks when businesses rely on inaccurate or incomplete information. Generative AI systems can produce information that appears reliable but is factually incorrect. In a business setting, reliance on inaccurate AI-generated information can result in contractual errors, inaccurate financial information, incorrect customer communications, regulatory compliance issues and reputational harm.
These concerns are particularly important in commercial collections. Collection activities often depend upon accurate information concerning the amount owed, the identity of the debtor, payment history, contractual obligations and communications with the parties involved. An AI system may assist with drafting a collection letter or summarizing an account, but the output should not be treated as automatically accurate. An error concerning the amount owed, applicable contractual terms, or the status of the account could create unnecessary disputes or expose a business to legal risk.
Accordingly, businesses should treat AI-generated material as a starting point rather than a final product. Employees should verify factual statements, financial information, contractual provisions and other important information before relying on AI-generated materials. Human review is especially important when preparing communications that will be sent to customers, debtors, business parties or other third parties.
AI may nevertheless provide meaningful benefits to businesses engaged in commercial collections. Properly implemented AI tools may assist with organizing large amounts of account information or preparing drafts of routine correspondence, identifying information for further review and streamlining administrative tasks. These efficiencies may allow employees to devote more time to matters requiring professional judgment and direct attention.
However, efficiency should not come at the expense of accuracy or appropriate human oversight. Businesses should establish review procedures for AI-assisted work, particularly when the work involves financial information, contractual rights, customer communications or potential legal disputes. AI can assist with routine tasks, but it should not replace the human judgment necessary to determine how a business should address a particular account or legal issue.
Businesses should also remain attentive to the developing regulatory landscape surrounding AI. Although Wisconsin has not enacted comprehensive legislation specifically governing workplace AI, existing laws concerning areas such as consumer protection and other business activities may still apply to a company’s use of AI. Businesses should therefore avoid viewing AI governance as solely a technology issue. It is also a business and risk-management issue.
A formal AI governance program can help businesses address these concerns by establishing written AI-use policies, identifying approved AI tools, providing employee training, implementing data-protection safeguards, and requiring human review of higher-risk AI-assisted tasks. Businesses should periodically review these policies as their use of AI evolves and as applicable laws and regulations develop.
AI offers businesses opportunities to improve efficiency and productivity. However, responsible implementation requires businesses to understand that AI is a tool—not a substitute for appropriate oversight and professional judgment. By establishing thoughtful policies protecting confidential information, verifying AI-assisted information and maintaining human oversight of important business activities, companies can take advantage of AI’s benefits while reducing unnecessary legal and operational risks.
For questions regarding AI governance, workplace policies or other business law matters, please contact KMK Attorney Samuel E. Granderson by phone at (414) 961-4856 or by e-mail at sgranderson@kmksc.com.
