Artificial intelligence is no longer a distant technology reserved for large software companies. Michigan small and mid-sized businesses are already using AI to draft marketing copy, respond to customers, screen job applicants, forecast demand, analyze financial data, summarize records, generate images, monitor cybersecurity threats, and automate internal workflows. These tools can save time and reduce costs, but they also create legal, operational, and reputational risks when they are adopted without clear rules. For a Michigan business, an AI compliance checklist should not be treated as a one-time technology exercise. It should be treated as a practical governance plan that helps the company understand where AI is being used, what data is being exposed, who is accountable for the results, and whether the use of the tool is consistent with existing laws.
The most important starting point is to recognize that AI compliance does not depend on whether Michigan has enacted a single comprehensive AI statute covering every private business. Even when a law does not use the term “artificial intelligence,” ordinary legal duties still apply. A chatbot that makes misleading claims can create consumer protection exposure. A hiring platform that screens applicants in a discriminatory way can create employment law exposure. An AI tool that uploads customer data to an outside platform can create privacy, data security, and breach-notification issues. A generative AI system that produces inaccurate technical advice can create contract, negligence, warranty, or professional liability concerns. The legal question is usually not whether the business used AI, but whether the business used AI in a way that caused an unlawful, unfair, deceptive, discriminatory, insecure, or poorly supervised outcome.
A useful AI compliance program begins with an inventory. Many businesses already have “shadow AI” in use before management realizes it. Employees may be using public chatbots to rewrite emails, summarize contracts, draft social media posts, analyze spreadsheets, generate code, or create customer-facing content. Sales teams may use AI tools embedded in customer relationship management software. Human resources may use applicant tracking systems that rank candidates. Accounting teams may rely on AI-assisted fraud detection or invoice processing. Marketing teams may use AI-generated images or personalized advertising tools. Before a business can manage risk, it must know what tools are being used, who is using them, what business purpose they serve, and what information is being entered into them.
After identifying AI tools, the business should classify each use by risk. Not every AI use requires the same level of review. Using AI to brainstorm a blog title is different from using AI to decide whether a customer receives credit, whether an employee should be disciplined, or whether a patient, tenant, borrower, or consumer receives a service. A practical compliance program distinguishes low-risk internal productivity uses from higher-risk uses that affect legal rights, financial opportunities, employment decisions, access to services, safety, privacy, or regulated activity. This risk-based approach is consistent with the general structure of modern AI governance, including the NIST AI Risk Management Framework, which emphasizes mapping, measuring, managing, and governing AI risks rather than treating all AI systems as identical.¹
Michigan small and mid-sized businesses should put responsibility for AI governance in writing. In a smaller company, this does not require a large committee or expensive bureaucracy. It does require clarity. Someone in management should be responsible for approving AI tools, maintaining the inventory, coordinating legal and security review, and updating internal policies. The business should decide who can approve new AI platforms, who reviews vendor contracts, who evaluates privacy risks, who handles employee training, and who responds when an AI system produces a harmful or inaccurate result. Without assigned responsibility, AI decisions tend to occur informally, and informal decisions are difficult to defend when something goes wrong.
A written acceptable-use policy is one of the most valuable first documents a business can adopt. The policy should explain which AI tools employees may use, which tools are prohibited, and what types of information may never be entered into public or unapproved AI systems. Employees should understand that confidential business information, trade secrets, customer data, employee records, financial account information, health information, litigation materials, privileged communications, passwords, source code, and sensitive personal data should not be pasted into an AI tool unless the company has approved that use and confirmed appropriate protections. The policy should also make clear that AI output must be reviewed before it is used in business communications, customer advice, contracts, employment decisions, or public statements.
Data privacy should be at the center of AI compliance. AI systems often depend on large amounts of data, and businesses may not always appreciate that entering information into an AI platform can disclose that information to a third-party vendor. Some tools use prompts and outputs to improve their services unless the customer selects different settings or purchases an enterprise version with stronger protections. A Michigan business should know whether its AI vendor stores prompts, trains on customer inputs, shares data with subcontractors, transfers data outside the United States, or allows the business to delete information. For companies handling personal information about Michigan residents, data security and breach-notification duties remain important, including duties under Michigan’s Identity Theft Protection Act when covered personal information is accessed or acquired without authorization.⁴
Cybersecurity and AI compliance are closely connected. AI tools can increase productivity, but they can also create new attack surfaces. Employees may be tricked by AI-generated phishing emails, deepfake voice calls, fake invoices, or impersonation scams. Customer-facing chatbots may be manipulated into disclosing confidential information or generating unauthorized promises. AI coding assistants may generate insecure code if no one reviews the output. Businesses should update cybersecurity training to address AI-enabled fraud and should create verification procedures for unusual payment requests, vendor changes, wire instructions, password resets, and urgent executive instructions. The Michigan Attorney General has warned that AI can be misused to create realistic deepfake audio and video scams, which makes internal verification procedures especially important for businesses that handle payments, payroll, or customer funds.
Vendor management is another essential part of the checklist. Many small and mid-sized companies will not build AI systems themselves; they will buy or subscribe to tools from vendors. That does not eliminate responsibility. A business should review the vendor’s contract, privacy policy, security documentation, data-use terms, retention practices, audit rights, indemnity provisions, limitation-of-liability clauses, and service commitments. The contract should address who owns inputs and outputs, whether the vendor may use company data for model training, whether the vendor may share information with subcontractors, what happens after termination, what security safeguards apply, and how quickly the vendor must notify the business of a security incident. In regulated industries, vendor oversight may need to be even more formal.
Employment uses of AI deserve special caution. AI tools are increasingly used to screen resumes, rank applicants, evaluate interviews, monitor productivity, schedule workers, assess performance, and recommend discipline. These tools can create discrimination risks if they disadvantage applicants or employees based on protected characteristics or if they rely on data that functions as a proxy for protected status. The EEOC has made clear that employers remain responsible for complying with federal employment discrimination laws when they use software, algorithms, or AI in employment selection procedures.³ Michigan employers should also consider state civil rights obligations, including protections under the Elliott-Larsen Civil Rights Act, when AI tools are used in ways that affect hiring, promotion, compensation, discipline, or termination.
A Michigan employer using AI in hiring should be able to explain what the tool does and why it is job related. Blind reliance on a vendor’s marketing materials is risky. If a tool ranks applicants, scores video interviews, filters resumes, or recommends candidates, the employer should ask what factors the tool considers, whether it has been validated, whether it has been tested for adverse impact, and whether accommodations are available for applicants with disabilities. The employer should also preserve human review for important decisions. AI may help organize information, but it should not become an unreviewed substitute for lawful, individualized decision-making.
Consumer-facing AI must be managed with equal care. If a company advertises that its product is “AI-powered,” “fully automated,” “bias-free,” “guaranteed,” “expert,” or “more accurate than humans,” those claims should be truthful, supportable, and not misleading. The Federal Trade Commission has repeatedly warned businesses that AI claims must be accurate and that companies should not exaggerate what an AI product can do.² Michigan businesses should apply the same principle to websites, sales scripts, customer emails, investor materials, product descriptions, and chatbot responses. A business may be enthusiastic about AI, but marketing language should not promise more than the tool can reliably deliver.
Michigan’s Consumer Protection Act is also relevant to AI compliance because it prohibits unfair, unconscionable, or deceptive methods, acts, or practices in trade or commerce.⁴ AI does not excuse a business from those obligations. If an AI chatbot gives customers false information about pricing, refunds, availability, warranties, deadlines, eligibility, or contract terms, the business may still face consequences. For that reason, customer-facing AI should be trained or configured carefully, limited to approved topics, monitored regularly, and backed by a clear escalation path to human staff. Businesses should avoid allowing a chatbot to improvise on legal, medical, financial, refund, warranty, or contractual issues unless the system has been specifically approved for that purpose and is subject to appropriate review.
Human oversight is one of the most practical safeguards a business can implement. AI systems can produce inaccurate, incomplete, biased, or fabricated output, sometimes with great confidence. A company should decide when human review is required and what that review must include. Human oversight should be meaningful, not symbolic. The reviewer should have enough knowledge, authority, and time to question the AI output. For high-risk decisions, the reviewer should understand the basis for the decision, compare the output against reliable records, and document any override or correction. A human being who merely clicks “approve” without understanding the output is unlikely to provide the protection the company expects.
Businesses should also consider transparency. Transparency does not mean disclosing trade secrets or overwhelming customers with technical explanations. It means being honest when AI is materially involved in an interaction or decision, especially when a customer, applicant, employee, or business partner might reasonably believe they are interacting with a person or receiving a human-generated decision. In some settings, transparency may be required by law, contract, platform policy, or industry expectation. Even when it is not strictly required, disclosure can reduce confusion and preserve trust. A simple statement that an AI assistant may help generate responses, subject to human review where appropriate, can be more effective than silence.
Intellectual property risk should not be overlooked. Generative AI tools can create text, images, code, designs, and marketing materials, but questions may arise about ownership, originality, licensing, and infringement. A business should be careful when using AI-generated content in logos, advertising campaigns, product designs, software, training materials, or client deliverables. The company should avoid asking AI tools to imitate a living artist, competitor, brand, or copyrighted work in a way that creates legal risk. It should also keep records showing how important content was created and reviewed. For businesses that depend on proprietary know-how, the greater risk may be disclosure of their own confidential information into an AI tool that is not approved for that purpose.
AI compliance should also address accuracy and quality control. A company should not assume that AI output is correct because it sounds polished. AI systems can hallucinate citations, misstate legal standards, misread spreadsheets, invent facts, mistranslate technical language, or overlook context. Businesses should require verification before using AI output in important settings, including contracts, customer advice, financial reports, legal communications, product specifications, safety instructions, or public statements. The level of review should increase with the consequences of error. A typo in an internal brainstorming note is minor; an inaccurate instruction to a customer or employee may be serious.
Recordkeeping is what turns an AI policy into a defensible compliance program. A business should keep records of approved AI tools, vendor reviews, risk assessments, employee training, policy acknowledgments, testing results, incident reports, customer complaints, and major decisions involving high-risk AI systems. Documentation does not need to be excessive, but it should be sufficient to show that the business acted thoughtfully. If regulators, customers, insurers, auditors, or opposing counsel later ask what the company did to manage AI risk, the answer should not depend on memory alone.
For businesses in financial services, insurance, lending, mortgage, banking, credit unions, or other regulated financial activities, Michigan-specific guidance deserves particular attention. In 2026, the Michigan Department of Insurance and Financial Services issued a bulletin explaining its expectations for regulated financial service providers using AI systems. The bulletin emphasizes governance, risk management, internal controls, testing, bias review, vendor oversight, consumer-impact analysis, and documentation for AI systems that make or support consumer-impacting decisions.⁵ Even businesses outside the direct scope of that bulletin can learn from its structure because it reflects a broader regulatory expectation: companies using AI for consequential decisions should be able to identify risks, assign responsibility, monitor vendors, and document controls.
Incident response should be updated for AI-related events. A business should know what it will do if an AI system discloses confidential information, generates discriminatory results, provides false customer information, produces unsafe instructions, is manipulated by a user, or is involved in a cyber incident. The response plan should identify who investigates, who preserves records, who communicates with the vendor, who determines whether notice is required, and who decides whether the tool should be suspended. For privacy or security incidents involving personal information, Michigan breach-notification obligations may need to be evaluated quickly.⁴ Waiting until after a problem occurs to decide who is responsible can increase both legal exposure and business disruption.
Training is essential because most AI risk begins with ordinary employee use. Employees do not need to become AI engineers, but they should understand the company’s rules. They should know which tools are approved, what data may be entered, when output must be verified, how to identify AI-enabled scams, when to disclose AI use, and how to report concerns. Managers should receive additional training if they approve AI tools, use AI in employment decisions, handle customer complaints, or manage vendors. Training should be refreshed as tools and laws change.
Insurance and contracts should also be reviewed. Businesses should ask whether their existing cyber, errors and omissions, employment practices liability, professional liability, directors and officers, and general liability policies address AI-related claims. Some policies may exclude certain technology risks or require specific security practices. Customer contracts may also contain confidentiality, data protection, audit, subcontractor, professional standard, or deliverable requirements that affect AI use. A business that uses AI to perform contract obligations should confirm that doing so is permitted and that the tool does not compromise confidentiality or quality obligations.
An effective compliance checklist also requires periodic reassessment. AI tools change quickly, and vendors may update models, features, pricing, data practices, and terms of service. A tool that was acceptable for low-risk internal drafting may later be connected to customer data or used for automated decisions. A business should revisit its AI inventory and policies at regular intervals, especially after adopting new tools, entering new markets, changing vendors, expanding customer-facing automation, or using AI in employment or regulated decisions. Compliance should evolve with the company’s actual use of the technology.
Small and mid-sized businesses often worry that AI compliance will be too expensive. In reality, the most important controls are often practical and affordable. A business can begin by identifying AI tools, limiting use of unapproved platforms, protecting confidential data, assigning responsibility, training employees, reviewing vendors, requiring human oversight, and documenting high-risk uses. These steps do not require the company to stop innovating. They allow the company to innovate with fewer surprises and stronger defenses.
AI can be a competitive advantage for Michigan businesses, but only if it is used responsibly. The companies that benefit most from AI will not be the ones that adopt every new tool the fastest. They will be the ones that understand where AI fits in their operations, manage the risks, protect customers and employees, and preserve trust. A thoughtful AI compliance checklist gives a business that structure. It turns AI from an unmanaged experiment into a controlled business asset.
The best time to build that structure is before a complaint, breach, employment dispute, customer claim, or regulatory inquiry occurs. A Michigan small or mid-sized business does not need a perfect AI program on day one, but it does need a deliberate one. By inventorying AI use, classifying risk, protecting data, reviewing vendors, monitoring employment and consumer impacts, training employees, and documenting oversight, a business can reduce exposure while still taking advantage of the efficiencies AI offers. In that sense, AI compliance is not merely a legal obligation. It is sound business management.
Contact Tishkoff
Tishkoff PLC specializes in business law and litigation. For inquiries, contact us at www.tish.law/contact/. & check out Tishkoff PLC’s Website (www.Tish.Law/), eBooks (www.Tish.Law/e-books), Blogs (www.Tish.Law/blog) and References (www.Tish.Law/resources).
Footnoted Sources:
1- National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework, AI RMF 1.0, and related NIST AI RMF resources. https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf
2- Federal Trade Commission, Business Guidance concerning artificial intelligence, including “Keep Your AI Claims in Check” and related FTC AI advertising, deception, privacy, and consumer protection guidance. https://www.ftc.gov/system/files/ftc_gov/pdf/p241200_ftc_comment_to_copyright_office.pdf
3- U.S. Equal Employment Opportunity Commission, “Select Issues: Assessing Adverse Impact in Software, Algorithms, and Artificial Intelligence Used in Employment Selection Procedures Under Title VII of the Civil Rights Act of 1964,” and related EEOC artificial intelligence publications. https://www.theemployerreport.com/2023/05/eeocs-new-guidance-focuses-on-adverse-impact-in-ai-used-in-employment-selection-procedures/
4- Michigan Legislature, Michigan Identity Theft Protection Act, MCL 445.61 et seq., including MCL 445.72; Michigan Consumer Protection Act, MCL 445.901 et seq., including MCL 445.903. https://www.legislature.mi.gov/Laws/MCL?objectName=MCL-445-61
5- Michigan Department of Insurance and Financial Services, Bulletin 2026-03-BT/CF/CU, “Use of Artificial Intelligence Systems By Financial Service Providers,” issued January 14, 2026. https://www.michigan.gov/difs/-/media/Project/Websites/difs/Bulletins/2026/Bulletin_2026-03-BT-CF-CU.pdf
