Michigan’s small businesses are embracing artificial intelligence in ways that would have sounded far-fetched only a few years ago. A small manufacturer in Jackson uses an AI assistant to draft supply contracts. A real estate brokerage in Ann Arbor leans on generative tools for listing descriptions and social media posts. A dental practice in Lansing experiments with automated chart summarization, while a restaurant group in Detroit adds a chatbot to handle reservations and customer questions. Most of these tools are “off the shelf”: cloud services that you access through a browser, an app, or a plug-in to software you already use. They promise speed, efficiency, and cost savings, and in many cases they deliver. But they also carry a set of legal risks that are easy to overlook when you are focused on keeping the doors open and the payroll funded. For a small Michigan business, understanding those risks has become part of basic risk management, not a luxury reserved for large corporations.
When people talk about off-the-shelf AI, they often mean general-purpose tools that were not built with your particular business, your particular contracts, or your particular state’s laws in mind. These tools might include chatbots that draft emails and contracts, AI features embedded in office suites, automated customer service agents that “learn” from past interactions, analytics systems that promise better demand forecasting, or website plug-ins that generate content on the fly. They are designed to scale across industries and jurisdictions, which is part of their appeal. That same generality, however, means their terms of service and default settings are rarely tailored to the legal landscape you face in Michigan. The choices an engineer in California made about how data flows through the system may not fit comfortably with the promises you have already made to your customers, employees, or patients here at home.
One of the most immediate and underappreciated legal issues is loss of control over data. Many AI vendors reserve broad rights to use “customer content” for purposes such as improving their services, training models, or developing new products. If your team pastes a customer list, internal pricing model, draft contract, or even detailed notes about a client matter into an AI interface, that information may be copied, stored, and processed on servers you do not control, in locations you cannot easily identify, under terms that give the vendor wide latitude. Regulators have already warned that AI providers must stand by their privacy and confidentiality commitments, and that using customer data for undisclosed training or profiling can be an unfair or deceptive practice. But from the perspective of a Michigan business, it is not enough to hope the vendor complies with its own promises. You are often the one who will answer to customers and regulators if the handling of personal information does not align with what you told people when you collected it.
Michigan’s own data breach and identity theft laws turn that abstract concern into specific obligations. Under the Identity Theft Protection Act, Michigan businesses that own or license databases with certain kinds of “personal information” must provide notice if there is a breach that is likely to cause substantial loss or injury or could result in identity theft for one or more state residents. That duty can be triggered even when the compromised system belongs to a vendor rather than to your company directly. If an AI provider experiences a security incident that affects your customers’ data, you may still be responsible for sending notices, dealing with inquiries, and facing potential scrutiny. Many small businesses only discover at that stage that their vendor contracts are vague about who must notify whom, how quickly, and with what information, or that they never asked what security standards the AI provider actually follows. “We assumed they had good security because they are a big tech company” is not a satisfying answer when you are explaining a breach to your customers or to the Attorney General.
Meanwhile, Michigan is moving toward a more comprehensive privacy framework that will further shape how small businesses can collect, use, and share data. Senate Bill 359, the proposed Personal Data Privacy Act, would create the state’s first broad consumer privacy law, introducing new rights for residents such as rights of access, deletion, and correction and new obligations for businesses that process personal data about Michigan consumers at scale. The bill borrows from other state privacy regimes but is tailored to Michigan’s economy and policy choices. Even though legislation is still in progress, its trajectory is clear enough that businesses should assume the bar for responsible data handling will rise. Choices you make now about what you feed into AI tools, how long you keep data, and how you structure vendor relationships may determine how painful or smooth your eventual compliance will be. Treating privacy as an afterthought in your AI strategy virtually guarantees that you will be playing catch-up when the new rules become enforceable.
Some of the most sensitive risk arises when AI tools touch biometric and other highly personal information. Time-and-attendance systems, security platforms, and marketing tools increasingly incorporate facial recognition, fingerprints, voice analysis, or behavioral pattern tracking. Across the country, dedicated biometric privacy laws have led to waves of litigation, especially when companies collect or store biometric identifiers without clear consent, transparent policies, or adequate security. Several proposals in Michigan have sought to regulate private entities’ collection and use of biometric data, and even in the absence of a comprehensive statute, mishandling biometric information can support claims under more general privacy and consumer protection theories. A small business that deploys a convenient AI-powered camera system in a retail space, or voice-analysis software in a call center, may discover that a seemingly simple technology decision has created a sophisticated legal problem if it has not implemented notice, consent, retention, and deletion practices that match emerging norms.
Employment decisions are another area in which off-the-shelf AI can create more legal risk than it appears to eliminate. Tools that automatically screen résumés, rank candidates, analyze video interviews, or track employee productivity are marketed as objective, efficient, and data-driven. In reality, they can encode and amplify existing biases in their training data, leading to patterns in which members of protected groups are disproportionately rejected or downgraded. When an applicant or employee alleges discrimination based on age, race, sex, disability, national origin, or other protected characteristics, Michigan and federal law focus on results and processes, not on the marketing claims of the software vendor. “The algorithm did it” is not a defense. If an AI-driven system consistently filters out older workers or applicants from particular neighborhoods, that pattern can support a discrimination claim regardless of whether anyone at the company intended that outcome. For small employers who may not have in-house HR or legal departments, it is particularly important to treat these tools as aids to human judgment, not replacements for it, and to monitor their outcomes for unintended disparities.
AI-enabled marketing and customer service bring their own set of pitfalls under consumer protection law. Many businesses now rely on chatbots to answer customer questions, recommend products, or explain services. Others use AI to generate blog posts, social media content, and even “expert” explanations of complex topics such as tax planning or legal rights. The Federal Trade Commission has been explicit that there is no special exemption for AI under its existing authority to police unfair or deceptive practices, and its “Operation AI Comply” enforcement sweep is squarely aimed at companies that abuse AI hype or use AI tools to mislead consumers. For a Michigan business, that means you need to be careful about how you describe your AI-powered offerings. If your website suggests that an AI tool provides individualized legal, financial, or medical advice that has been reviewed by professionals when in fact no such review occurs, or if you exaggerate what your AI-based product can do, you may be inviting an enforcement action or private litigation. The more your customers rely on AI-generated information to make important decisions, the more critical it becomes that your disclosures are accurate, clear, and not buried in fine print.
At a quieter but equally important level, contract law is the backbone of your relationship both with AI vendors and with your own customers. Off-the-shelf tools are typically governed by standard terms of service that are written to favor the provider. They dictate who owns the inputs you upload and the outputs the system generates, what rights the vendor has to reuse your content, how liability is allocated if something goes wrong, and where any disputes will be resolved. A small Michigan business that simply clicks “accept” may be agreeing to send disputes to a court across the country, to accept strict limits on damages, and to grant the vendor broad rights in confidential or proprietary material. At the same time, you may already have promised your own customers, clients, or patients that you will keep their information confidential, store it in particular ways, or avoid using it beyond specific purposes. If your contract with the AI provider conflicts with your promises to your customers, for example, by allowing the provider to use their data for model training you may be setting yourself up for breach-of-contract claims or allegations of deception.
Intellectual property is intertwined with those contractual questions. Many small businesses rely heavily on creative assets such as branding, logos, website text, and marketing campaigns. Generative AI tools now offer to create all of these at the click of a button, but the legal status of AI-generated content is still evolving. U.S. copyright law generally requires human authorship, which means that purely machine-generated output may not enjoy the same level of protection as something created through traditional design processes. At the same time, if the AI model was trained on copyrighted material belonging to third parties, some uses of its output may raise questions about whether it is too close to an existing work. While most routine business use is unlikely to draw immediate litigation, a company that invests heavily in an AI-generated logo or builds its contract library largely from AI-drafted forms could find itself in murky ownership territory. The safest path often involves combining AI assistance with meaningful human contribution and documenting that contribution, while also confirming in the vendor’s terms that you receive the rights you need to use the outputs in your business.
Security expectations form another thread that connects these legal issues. Michigan’s data breach statute implicitly assumes that businesses will take “reasonable” steps to safeguard personal information, and that standard is increasingly informed by national and industry-specific guidance. One widely cited resource is the National Institute of Standards and Technology’s Artificial Intelligence Risk Management Framework, AI RMF 1.0, which offers a structured way to identify and manage AI-related risks, from privacy and security to explainability and fairness. Although the framework is voluntary and not specific to any one state, it gives small businesses a useful checklist of questions: What AI systems do we use? What data do they touch? What could go wrong if they are compromised, misused, or produce erroneous outputs? What safeguards and governance mechanisms do we have? A Michigan business that can show it paid attention to recognized standards and treated AI risk as part of its overall cybersecurity program is in a stronger position to argue that it acted reasonably if an incident occurs.
Good vendor management is where these abstract concerns become practical action. Adopting an AI tool should not be treated as casually as installing a new mobile game. Before turning a system loose on sensitive data or customer interactions, a small business should, at a minimum, understand what categories of information the tool collects, where that data is stored, whether it is used for training or shared with third parties, how long it is retained, and what happens when the business terminates the service. Contracts should require timely notice of security incidents, specify applicable security standards, and clarify who has to do what if there is a breach involving Michigan residents’ personal information. If you are in a regulated sector such as health, education, or finance, you may also need the AI vendor to sign specialized agreements that reflect your particular legal obligations. The more mission-critical the AI tool is say, a system that touches patient records rather than a simple internal idea generator the more careful you should be about performing due diligence, negotiating terms, and documenting your decision-making.
None of these measures will be effective unless your own people understand how to use AI tools safely. Many small businesses introduce AI informally, when a single employee begins using a chatbot to draft emails or summarize documents and others follow suit. That organic adoption is understandable, but it means AI often arrives before policy. A short, plain-language internal policy can make a dramatic difference. It can explain, for example, that employees must never paste Social Security numbers, driver’s license numbers, full payment card details, detailed health information, or sensitive HR records into public AI systems; that they must treat AI-generated content as a draft that requires human review, particularly in high-stakes or regulated contexts; and that any plan to rely heavily on an AI tool for customer-facing communication or employment decisions needs management approval. Training should reinforce that AI is a powerful assistant, not an infallible authority, and should encourage employees to raise concerns when something about a tool’s behavior or output feels wrong.
For Michigan small businesses in particular, it is also important to keep an eye on how state-level legislation develops. As privacy proposals like the Personal Data Privacy Act move through the legislature, the obligations and enforcement mechanisms they contain will eventually come into focus. Some bills may impose thresholds based on the number of consumers whose data a business processes; others may create specific duties around data minimization, transparency, and profiling. Even if a given statute ultimately exempts the smallest entities, it will contribute to a broader expectation that companies of all sizes handle personal information responsibly. Federal enforcement activity, such as the FTC’s Operation AI Comply, will continue in parallel, sending a clear message that regulators will use existing legal tools to police misuse of AI rather than waiting for a dedicated “AI law” to be passed. In that environment, businesses that can show proactive attention to AI governance will likely be better positioned than those that ignore the issue until a crisis arrives.
The good news is that responsible AI use does not require a Fortune 500 budget. Many of the most important steps are more about discipline than dollars: knowing which AI tools you use and why; understanding the data that goes in and the content that comes out; reading and, where possible, negotiating key contract terms; training your staff; and revisiting these decisions as the legal environment evolves. When you treat AI as a serious outsourced service rather than a shiny toy, you are more likely to ask the questions that prevent unpleasant surprises. You will be quicker to identify where you need targeted legal advice and better prepared to show, if challenged, that you approached AI in a thoughtful, risk-aware way.
Ultimately, the promise and peril of off-the-shelf AI for Michigan small businesses are two sides of the same coin. The same tools that help you punch above your weight in marketing, operations, and customer service also create new channels through which data can leak, biases can spread, and expectations can be disappointed. The law will continue to evolve, but the core responsibilities will likely remain familiar: tell people the truth, keep your promises, protect sensitive information, avoid unfair treatment, and act reasonably in light of foreseeable risks. If you can frame your AI decisions in those terms and document how you are meeting them you will be far better positioned to enjoy the benefits of AI while avoiding its most serious legal pitfalls.
Contact Tishkoff
Tishkoff PLC specializes in business law and litigation. For inquiries, contact us at www.tish.law/contact/. & check out Tishkoff PLC’s Website (www.tish.law/), eBooks (www.tish.law/e-books), Blogs (www.tish.law/blog) and References (www.tish.law/resources).
Sources:
- Michigan Compiled Laws, Identity Theft Protection Act, Mich. Comp. Laws §§ 445.61–445.79d (including § 445.72 on security breach notification). https://law.justia.com/codes/michigan/chapter-445/statute-act-452-of-2004/
- Michigan Senate Bill 359, “Personal Data Privacy Act,” 102nd Legislature, State of Michigan (privacy bill materials and legislative analysis). https://legiscan.com/MI/research/SB0359/2023
- National Institute of Standards and Technology, “Artificial Intelligence Risk Management Framework (AI RMF 1.0),” NIST AI 100-1, 2023. https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf
- Federal Trade Commission, business guidance and press materials on artificial intelligence and consumer protection, including “AI Companies: Uphold Your Privacy and Confidentiality Commitments” and “Operation AI Comply.” https://skywork.ai/skypage/en/Progress-in-the-US-AI-Regulatory-Framework-An-Analysis-of-Data-Use-and-Algorithm-Transparency/1947841989537775616
- Practitioner commentary on Michigan privacy and biometric legislation, such as law firm client alerts discussing pending Michigan consumer privacy and biometric information bills and their implications for businesses. https://termly.io/resources/articles/michigan-personal-data-privacy-act/
