Skip to main content

AI Risk Management: A Practical Legal Roadmap for Business Owners

Artificial intelligence is no longer a technology reserved for software companies, national retailers, or large institutions with dedicated innovation departments. It is now being used by ordinary businesses to write marketing content, summarize documents, screen resumes, respond to customers, prepare internal reports, forecast demand, detect fraud, evaluate employee performance, manage inventory, draft contracts, and support daily decision-making. For many business owners, the appeal is obvious. AI tools can reduce administrative burdens, increase speed, lower costs, and help smaller businesses compete with larger companies. Yet the legal risk is just as real as the business opportunity. The same tool that helps a company move faster can also create inaccurate statements, disclose confidential information, violate privacy obligations, produce discriminatory outcomes, or generate business records that later become exhibits in litigation.

Please note this blog post should be used for learning and illustrative purposes. It is not a substitute for consultation with an attorney with expertise in this area. If you have questions about a specific legal issue, we always recommend that you consult an attorney to discuss the particulars of your case.

The central mistake many businesses make is treating AI risk as a purely technical issue. Business owners often ask whether a tool is “safe,” “secure,” or “accurate,” as though those questions can be answered by the vendor alone. In reality, AI risk management is a legal, operational, contractual, employment, privacy, cybersecurity, and governance issue. The question is not simply whether the software works. The better question is whether the business can explain why it used the tool, what data it allowed the tool to process, what human review occurred, what promises were made to customers or employees, and what safeguards were in place before the technology affected anyone’s rights, money, job, data, or reputation.

A practical legal roadmap begins with a simple proposition: a business should not allow AI tools to become invisible decision-makers inside the company. If employees are using generative AI to write emails, analyze customer data, prepare sales proposals, draft HR materials, or summarize contracts, management needs to know that. If a vendor is using AI to score job applicants, recommend loan terms, identify suspicious transactions, personalize prices, or generate customer-facing statements, the business needs to know that as well. AI cannot be managed if it is not identified. For that reason, the first legal step is to create an internal inventory of AI use. This does not need to be complicated. A business can begin by identifying each AI tool in use, the department using it, the purpose of the tool, the type of information entered into it, whether it affects customers, employees, applicants, vendors, or consumers, and whether the output is reviewed by a person before being used.

This inventory is important because legal exposure usually depends on context. A business using AI to brainstorm social media captions faces a very different risk profile than a business using AI to screen employment candidates. A company using AI to summarize public product reviews faces a different risk than a company uploading customer health information, financial records, payroll data, or confidential contracts into a third-party system. The law is increasingly focused on whether AI is being used in high-impact areas such as employment, housing, credit, insurance, education, health care, government services, biometric identification, consumer profiling, and other decisions that can materially affect individuals. Even when a business is not directly regulated by an AI-specific statute, existing laws on discrimination, privacy, consumer protection, contracts, negligence, trade secrets, cybersecurity, and unfair business practices still apply.

The second step is to assign responsibility. AI risk management cannot be left to whoever happens to be most enthusiastic about new technology. A business owner should designate a person or small committee responsible for approving AI tools, monitoring use, and maintaining the company’s AI policy. In a small business, this may be the owner, general manager, HR director, outside counsel, or IT consultant. In a larger business, it may require participation from legal, compliance, HR, information security, operations, and management. The point is not to create bureaucracy for its own sake. The point is to prevent a situation in which sales, HR, accounting, and operations each adopt separate tools without anyone understanding the combined legal exposure.

A strong AI policy should be written in plain business language. It should tell employees what AI tools are approved, what tools are prohibited, what information may not be entered into AI systems, when human review is required, and who must approve higher-risk uses. It should address confidential business information, customer data, employee data, trade secrets, privileged communications, personally identifiable information, regulated data, and intellectual property. The policy should also make clear that employees remain responsible for their work product. AI output should not be treated as automatically accurate simply because it is written confidently or appears polished. In many business settings, the most dangerous AI output is not obviously wrong. It is plausible, fluent, and partially incorrect.

The third step is to classify AI uses by risk. Not all AI use requires the same level of review. Low-risk uses might include brainstorming internal agenda topics, improving grammar in non-confidential text, or creating first drafts of general marketing ideas that will be reviewed by a human. Medium-risk uses might include customer communications, contract summaries, internal financial analysis, or vendor comparisons. Higher-risk uses include employment screening, employee discipline, compensation decisions, customer eligibility determinations, credit or financing decisions, insurance-related decisions, health or safety matters, legal compliance, biometric tools, automated surveillance, and any AI system that could materially affect a person’s rights or access to an opportunity. The more consequential the use, the stronger the documentation, testing, notice, review, and oversight should be.

This risk-based approach is consistent with the direction of major AI governance frameworks. The National Institute of Standards and Technology has emphasized that AI risk management should include governance, mapping of context, measurement of risks, and management of those risks over time.¹ That structure is useful for business owners because it translates an abstract topic into a practical process. Governance asks who is responsible. Mapping asks where and why AI is being used. Measurement asks what could go wrong and how the business will evaluate the risk. Management asks what safeguards, monitoring, and corrective actions will be used after the tool is deployed. In other words, AI risk management is not a one-time purchase decision. It is a continuing management function.

Generative AI deserves separate attention because it creates risks that many traditional software tools did not present in the same way. A generative AI tool may produce inaccurate statements, invent citations, create misleading summaries, expose confidential information through prompts, reproduce biased assumptions, generate infringing content, or produce outputs that appear authoritative but cannot be verified. NIST’s generative AI profile identifies risks that are especially relevant to businesses, including information integrity, data privacy, cybersecurity, intellectual property, harmful bias, and misuse. ² For business owners, the practical lesson is that generative AI should usually be treated as a drafting and analysis assistant, not as an unreviewed decision-maker or final authority.

The fourth step is to protect confidential and sensitive information. Many AI problems begin with the prompt. Employees may paste contracts, settlement communications, customer lists, personnel records, medical information, financial statements, or proprietary business plans into AI systems without understanding where the information goes or how it may be retained. A business should decide which categories of information may never be entered into public or unapproved AI tools. This should include trade secrets, privileged legal communications, confidential settlement discussions, nonpublic financial information, protected personal information, employee medical information, customer account information, passwords, security credentials, and regulated data. Even when a vendor claims that data will not be used for training, the business should review the terms carefully and decide whether the tool is appropriate for the type of information involved.

Data minimization is one of the most practical safeguards. Employees should be trained to use the least amount of information necessary to complete the task. If a contract needs to be summarized, names, dollar amounts, and sensitive deal terms may be removed when they are not necessary. If a customer issue needs to be analyzed, the employee may be able to describe the issue without entering the customer’s full identity or account information. If an HR policy needs to be revised, there is usually no reason to upload an employee’s medical file or disciplinary record. The goal is not to eliminate AI use. The goal is to prevent convenience from becoming a waiver of confidentiality, a privacy breach, or a future litigation problem.

The fifth step is to manage vendor risk. Many businesses will not build their own AI systems. They will buy them from software vendors, HR platforms, marketing providers, payroll companies, customer-service platforms, cybersecurity vendors, or industry-specific technology companies. That does not eliminate responsibility. A business may still face claims from customers, employees, applicants, regulators, or contracting partners if a vendor’s AI tool causes harm. Vendor contracts should therefore address AI directly. The business should ask whether the vendor uses AI, what functions the AI performs, what data is processed, whether customer data is used to train models, whether the vendor provides audit rights or documentation, what security controls apply, whether subcontractors are involved, how errors are reported, and who is responsible if the system produces unlawful or harmful results.

A well-drafted vendor agreement should include representations about compliance with applicable law, data protection obligations, confidentiality, cybersecurity, breach notification, intellectual property ownership, indemnification, limitations on data use, human review obligations where appropriate, and cooperation in audits or investigations. If the AI tool is used in employment, lending, insurance, health, safety, or other high-impact areas, the contract should also address bias testing, validation, impact assessments, documentation, explainability, and procedures for challenging or correcting adverse decisions. Business owners should be cautious about accepting broad vendor disclaimers that leave the company responsible for all consequences while giving the company little ability to understand or test the system.

The sixth step is to address employment law risk. AI is increasingly used in recruiting, resume screening, interview scheduling, skills testing, productivity monitoring, performance evaluation, and workforce analytics. These uses can create exposure under discrimination, disability accommodation, privacy, wage-and-hour, labor, and wrongful discharge theories. The Equal Employment Opportunity Commission has warned that employers may be responsible when software, algorithms, or AI tools screen out applicants or employees with disabilities, and it has separately addressed adverse impact concerns under federal employment discrimination law.⁴ The practical point for business owners is direct: an employer cannot avoid employment-law responsibility by saying that a vendor’s algorithm made the decision.

Businesses using AI in employment should require human review before adverse action is taken. They should understand what criteria the tool uses, whether those criteria are job-related, whether the tool has been tested for discriminatory impact, and whether applicants or employees can request reasonable accommodations. An AI tool that ranks candidates based on speech patterns, facial expressions, gaps in employment, zip codes, educational pedigree, or personality traits may create legal risk if those factors screen out protected groups or people with disabilities without a valid business justification. Employers should also avoid using AI-generated performance narratives, disciplinary summaries, or termination recommendations without careful review. In litigation, those documents may be discoverable, and a poorly supervised AI-generated explanation can become evidence of inconsistency, pretext, or lack of individualized decision-making.

The seventh step is to control customer-facing statements and marketing claims. The Federal Trade Commission has taken the position that companies must not exaggerate what AI products can do, must not make deceptive performance claims, and must not use AI as a cover for unfair or deceptive practices.³ This matters not only to companies selling AI products, but also to businesses using AI in advertising, customer service, pricing, reviews, endorsements, or consumer communications. A business should not claim that an AI tool is objective, unbiased, guaranteed, expert, legally compliant, or superior unless it has evidence to support that claim. AI-related hype can become a consumer protection problem when the marketing promise outruns the proof.

Customer-service AI also requires careful supervision. Chatbots and automated response systems can create legal issues if they make promises about refunds, warranties, pricing, delivery dates, contract terms, eligibility, or legal rights. A business should decide what the AI system is allowed to say and what topics must be escalated to a human. It should preserve records of important customer interactions, monitor the system for recurring errors, and make sure customers are not misled into believing they are speaking with a human when that would be material. A chatbot that gives a customer an incorrect answer may still create a business problem even if the company did not intend the mistake. From a practical legal perspective, the issue is whether the company had reasonable controls in place before the mistake occurred.

The eighth step is to address intellectual property. AI can affect ownership, infringement, confidentiality, and brand protection. Businesses using AI to create text, images, logos, code, music, videos, or marketing materials should understand that ownership and protectability may be more complicated than with traditional human-created work. Businesses should also avoid feeding third-party copyrighted materials, competitor content, licensed databases, or confidential materials into AI systems without understanding the legal and contractual implications. If a business uses AI-generated content in advertising, websites, product materials, or software, it should maintain records showing what tool was used, what prompts were entered, what human edits were made, and whether any third-party materials were used.

Trade secret protection is another major issue. A trade secret generally depends on reasonable efforts to maintain secrecy. If employees freely enter proprietary formulas, pricing strategies, customer lists, manufacturing processes, source code, or confidential business plans into unapproved AI systems, the company may create arguments that it failed to protect its own information. Businesses should update confidentiality policies, employee handbooks, vendor agreements, and internal training to make clear that confidential information cannot be entered into unapproved AI tools. This is especially important for businesses that rely heavily on client lists, proprietary processes, technical know-how, or confidential deal information.

The ninth step is to document human oversight. “Human in the loop” should not be an empty phrase. A company should be able to show what human review means in practice. Did a manager review the AI output before it was sent to a customer? Did HR independently evaluate the applicant before rejecting the application? Did a supervisor verify the facts before issuing discipline? Did legal counsel review the AI-assisted contract language before it was used? Did someone compare AI-generated financial analysis against source documents? The more important the decision, the more meaningful the human review should be.

Documentation should be proportional to risk. For low-risk uses, a simple policy may be enough. For higher-risk uses, the business should keep records of the tool’s purpose, approval, testing, limitations, training, monitoring, complaints, errors, and corrective action. This documentation may become important in litigation or regulatory review. A company that can show it had a reasonable AI governance process will be in a better position than a company that cannot identify who approved the tool, what data was used, or whether anyone checked the output.

The tenth step is to prepare for AI-related disputes before they occur. Business litigation involving AI may arise from contract disputes, employment claims, consumer claims, privacy breaches, trade secret disputes, defamation, professional negligence, discrimination, and shareholder or member disputes. Discovery may focus on prompts, outputs, internal AI policies, vendor contracts, audit logs, training records, decision records, and communications about known errors. Businesses should decide how AI-related records will be retained. They should also consider whether employees are creating unnecessary records by using AI tools informally for sensitive topics. A casual prompt asking an AI tool to “justify firing this employee” or “find a reason to deny this claim” could become damaging evidence, even if the final business decision was lawful.

Record retention policies should account for AI systems. Some AI tools preserve prompt histories. Others allow histories to be deleted. Some enterprise systems include administrative controls, audit logs, or retention settings. A business should understand these features before litigation begins. Once a dispute is reasonably anticipated, deletion of relevant AI records may create spoliation issues. For that reason, AI governance should be coordinated with litigation hold procedures. If AI is used in a decision that becomes disputed, the business may need to preserve the prompts, outputs, source materials, human review notes, vendor documentation, and communications relating to that decision.

The eleventh step is to watch emerging AI laws without waiting for perfect clarity. AI regulation is developing quickly, but businesses should not assume they have no obligations until a single comprehensive federal AI statute is enacted. Existing law already applies. In addition, the European Union has adopted a comprehensive AI Act that imposes risk-based obligations, particularly for high-risk systems, and Colorado has enacted a state AI law focused on high-risk systems and algorithmic discrimination in consequential decisions.⁵ These laws are important even for businesses outside those jurisdictions because they reflect a broader regulatory trend: lawmakers are increasingly focused on risk classification, impact assessments, transparency, human review, discrimination, documentation, and accountability.

For Michigan business owners and other U.S. companies, the lesson is practical rather than theoretical. A company does not need to wait until every AI rule is final before putting basic safeguards in writing. The same governance steps that reduce risk under emerging AI laws also help reduce exposure under existing employment, privacy, contract, consumer protection, and negligence principles. A business that inventories AI uses, restricts sensitive data, reviews vendor contracts, documents human oversight, and monitors high-impact decisions, is building a defensible position. A business that allows uncontrolled AI adoption is creating avoidable risk.

The twelfth step is to train employees. A written policy is not enough if employees do not understand it. Training should explain what AI is being used for, which tools are approved, what information cannot be entered, when AI output must be verified, and who to contact with questions. Employees should be warned that AI can produce false information, biased assumptions, and fabricated citations. They should also understand that AI output may not be confidential, may not be accurate, and may not be legally safe simply because it sounds professional. Training should be repeated as tools and business practices change.

Training should also be tailored by department. HR needs different guidance than marketing. Sales needs different guidance than accounting. IT needs different guidance than customer service. Managers need to understand the risks of using AI in discipline, performance reviews, and hiring. Marketing employees need to understand advertising claims, endorsements, and intellectual property issues. Customer-service employees need to know when automated responses must be escalated. Executives need to understand that AI governance is not merely an IT function. It is a business-risk function.

The thirteenth step is to build AI governance into ordinary business operations. AI risk management should not sit in a policy binder that no one reads. It should be part of vendor onboarding, employee onboarding, contract review, cybersecurity review, HR procedures, marketing approval, and litigation preparedness. Before a new AI tool is approved, the company should ask what the tool does, what data it uses, who will use it, what decisions it affects, what laws may apply, what vendor terms govern the tool, and how the company will monitor performance. Before AI is used in a sensitive area, the company should ask whether notice, consent, accommodation, appeal rights, or human review are necessary.

This operational approach is also consistent with ISO/IEC 42001, which provides a management-system model for responsible AI governance.⁵ The value of a management-system approach is that it treats AI as an ongoing business process rather than a one-time technology purchase. Policies, objectives, responsibilities, risk assessment, monitoring, internal review, and continual improvement are all part of mature AI governance. For many small and medium-sized businesses, formal certification may not be necessary. But the structure is still useful. It encourages owners to ask whether AI use is intentional, documented, supervised, and improved over time.

The fourteenth step is to address cybersecurity. AI can create new security risks and amplify old ones. Employees may upload sensitive data to unauthorized tools. Attackers may use AI to create more convincing phishing emails. AI systems may be vulnerable to prompt injection, data poisoning, model manipulation, or unauthorized access. Customer-facing AI tools may be tricked into revealing information or making unauthorized statements. Businesses should coordinate AI governance with cybersecurity policies, access controls, vendor due diligence, incident response planning, and employee training.

Cybersecurity review should occur before AI tools are adopted, not after a breach. The business should consider whether the tool uses encryption, access controls, logging, administrator controls, retention settings, and secure authentication. It should know where data is stored, whether subcontractors are involved, whether data is used for training, and how quickly the vendor must report security incidents. AI tools should not be allowed to bypass the company’s normal security review simply because employees can sign up with a credit card or free account.

The fifteenth step is to create a response plan for AI errors. Even well-managed systems can fail. A chatbot may provide an incorrect answer. An AI-generated report may contain false information. A hiring tool may produce biased results. A vendor may reveal that its system had a data issue. A customer may complain that an automated decision was unfair. A business should decide in advance how such issues will be reported, investigated, corrected, and documented. The response plan should identify who receives complaints, who evaluates legal exposure, who communicates with affected individuals, and who decides whether the tool should be suspended or modified.

A good response process can reduce harm and improve defensibility. Ignoring AI errors is dangerous because repeated errors may show that the company knew about a problem and failed to act. If a business receives credible information that an AI tool is producing discriminatory, deceptive, unsafe, or inaccurate results, it should investigate promptly. Depending on the situation, it may need to correct records, notify customers, revise procedures, retrain employees, contact the vendor, suspend the tool, or preserve evidence. The worst approach is to assume that AI errors are merely technical glitches with no legal significance.

The sixteenth step is to keep leadership involved. AI risk management should be discussed at the ownership, executive, or board level when the technology affects important business functions. Owners and officers do not need to understand every technical detail, but they should understand the company’s AI strategy, major use cases, high-risk applications, vendor dependencies, data practices, and legal controls. Leadership should also decide the company’s risk tolerance. Some businesses may decide that AI should not be used in hiring or discipline. Others may allow it only with documented validation and human review. Some may approve customer-service chatbots but prohibit them from discussing refunds, warranties, or legal rights. These are management decisions with legal consequences.

Leadership involvement is also important because AI adoption often occurs unevenly. One department may want speed, another may focus on cost savings, and another may worry about compliance. Without leadership, AI governance can become fragmented. A practical roadmap gives the business a consistent approach. It allows innovation, but it places boundaries around the uses most likely to create legal exposure. It also sends an important message to employees and vendors: the company is not opposed to AI, but it expects AI to be used responsibly.

The seventeenth step is to review insurance coverage. Businesses should not assume that existing policies will cover AI-related claims. Depending on the facts, AI disputes may implicate cyber insurance, technology errors and omissions coverage, employment practices liability insurance, directors and officers coverage, commercial general liability, media liability, or professional liability policies. Coverage may depend on policy language, exclusions, notice requirements, the nature of the claim, and whether the business made representations about its technology practices. Business owners should review coverage with qualified insurance professionals and counsel, particularly if AI is used in customer-facing, professional, employment, financial, or regulated functions.

The eighteenth step is to update contracts and internal documents. AI risk management should be reflected in employee handbooks, confidentiality agreements, vendor agreements, customer contracts, privacy notices, website terms, data-processing addenda, information security policies, document retention policies, and dispute-resolution procedures where appropriate. A business that uses AI materially in providing services may need to decide whether and how to disclose that use to customers. A business that prohibits employees from using public AI tools for confidential work should say so expressly. A business that relies on vendors should require AI-related cooperation and accountability in writing.

The final step is to treat AI risk management as a competitive advantage. Many businesses view legal compliance as a cost. With AI, that view is too narrow. Customers, employees, vendors, insurers, lenders, and business partners increasingly want to know whether companies use AI responsibly. A company that can explain its AI governance practices may be more trustworthy than one that cannot. A company with clear policies may avoid employee confusion. A company with strong vendor terms may reduce contract disputes. A company with documented human review may be better prepared for litigation. A company with a thoughtful AI roadmap may adopt useful tools faster because it has already built a process for evaluating them.

AI will continue to change, but the core legal principles are familiar. Businesses should know what tools they use, protect sensitive information, avoid deceptive claims, prevent discrimination, supervise vendors, preserve important records, train employees, and document reasonable decision-making. The law does not require business owners to predict every future AI development. But it increasingly expects them to act reasonably in light of known risks. The practical roadmap is therefore straightforward: identify AI use, classify risk, assign responsibility, put rules in writing, review vendors, protect data, require human oversight, monitor results, and update the process as the technology and law evolve.

For business owners, the most important decision is whether AI adoption will be deliberate or accidental. Deliberate adoption allows a company to capture the benefits of AI while reducing legal exposure. Accidental adoption allows tools, employees, vendors, and automated outputs to shape business conduct without meaningful oversight. The first path is governance. The second path is risk. A business that wants to use AI effectively should choose governance now, before a customer complaint, employee claim, privacy incident, vendor dispute, or lawsuit forces the issue later.

Contact Tishkoff

Tishkoff PLC specializes in business law and litigation. For inquiries, contact us at www.tish.law/contact/. & check out Tishkoff PLC’s Website (www.Tish.Law/), eBooks (www.Tish.Law/e-books), Blogs (www.Tish.Law/blog) and References (www.Tish.Law/resources).

Sources

1- National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1, January 2023. https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf

2- National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1, July 2024. https://www.nist.gov/itl/ai-risk-management-framework

3- Federal Trade Commission, Operation AI Comply and related FTC business guidance on deceptive artificial intelligence claims and unfair or deceptive AI practices. https://www.ftc.gov/news-events/news/press-releases/2024/09/ftc-announces-crackdown-deceptive-ai-claims-schemes

4- U.S. Equal Employment Opportunity Commission, The Americans with Disabilities Act and the Use of Software, Algorithms, and Artificial Intelligence to Assess Job Applicants and Employees; and Select Issues: Assessing Adverse Impact in Software, Algorithms, and Artificial Intelligence Used in Employment Selection Procedures Under Title VII. https://www.eeoc.gov/eeoc-disability-related-resources/artificial-intelligence-and-ada

5- ISO/IEC 42001:2023, Information Technology — Artificial Intelligence — Management System; Regulation (EU) 2024/1689, Artificial Intelligence Act; and Colorado Senate Bill 24-205, Consumer Protections for Artificial Intelligence. https://www.tuvsud.com/en-us/landing/americas/iso-42001-certification-and-auditing?utm_source=google&utm_medium=cpc&utm_campaign=a-on_iso42001-certification_us_us_ba_msc_tff_ts&utm_term=42001&utm_id=23303228294&s_kwcid=AL!14017!3!789370399857!b!!g!!42001&gad_source=1&gad_campaignid=23303228294&gbraid=0AAAAACVWkX1w9Y7JKR2IKBuymzmZ9AcBj&gclid=EAIaIQobChMIs6u-xYmllQMVx4XCCB3I1ACwEAAYAyAAEgKl5_D_BwE

This publication is for general informational purposes and does not constitute legal advice. Reading it does not create an attorney-client relationship. You should consult counsel for advice on your specific circumstances.