Somewhere in your office right now, an employee pastes a client contract into ChatGPT to summarize it. They also feed a spreadsheet of customer data into an AI tool to build a quick report. Without a clear policy, employees are already using AI tools on their own. You may have little visibility into the activity.

What “Invisible AI” Actually Means

Security researchers call this shadow AI, and the scale of it is bigger than most business owners assume. Industry surveys put the share of employees using AI tools without formal company approval well above half, and one study found that companies with as few as 11 to 50 employees average close to 270 unsanctioned AI tools in use per 1,000 employees. Most of it happens for a simple reason: it works, and asking permission slows people down.

This is not a future risk you can plan for later. It is already happening inside your business today, whether or not you have addressed it.

Why This Creates Real Liability, Not Just an IT Headache

Without a clear policy, employees are already using AI tools on their own, and this creates risk when they paste a client’s contract, a candidate’s resume, payroll data, or proprietary information into a free public tool. That data may not stay private. Depending on the tool, it may be stored, reviewed, or used to train the underlying model, meaning your confidential information could become part of a system other companies are using.

One industry report found that roughly 60 percent of organizations have already experienced at least one data exposure event tied to an employee’s use of a public generative AI tool, and only about 15 percent of companies have actually updated their acceptable use policies to address AI at all. That gap, between how much AI use is happening and how little of it is governed, is exactly where liability lives.

New State Laws Are Adding Another Layer

On top of the data privacy concern, a growing number of states have started regulating how AI can be used specifically in employment decisions. Illinois amended its Human Rights Act, effective January 1, 2026, to require employers to notify employees when AI is used in decisions around hiring, promotion, discipline, or pay, and to prohibit AI use that results in discrimination against a protected class. Colorado and Texas have each moved on similar fronts in 2026 as well, though the specific requirements and effective dates have shifted more than once as the laws work their way through each state legislature.

The pattern is the same one we have seen with pay transparency law. This is not a single national rule you can check once and forget. It’s a patchwork that keeps expanding, and if your business uses AI in any tool that touches hiring, scheduling, performance review, or compensation, even indirectly through a vendor’s software, that use may already fall under one of these laws.

A Blueprint for a Basic, Safe Use AI Policy

You do not need a 40 page technology governance document to close most of this risk. A workable AI use policy for a small or mid-size business generally needs to cover five things:

  • An approved tools list. Name the specific AI tools employees are cleared to use for work, and note which ones require IT or management sign off first.
  • A clear list of what never goes into an AI tool. Client personal information, employee records, financial data, health information, passwords, and anything covered by a signed confidentiality agreement should be explicitly off limits.
  • A human review requirement. Anything AI assisted that goes out externally, an email, a proposal, a report, should get a human review before it’s sent, both for accuracy and for tone.
  • A disclosure process. If AI plays any role in a hiring, promotion, discipline, or pay decision, document it and notify the employee, in line with the states now requiring this.
  • A short training requirement. A 30 minute walk-through of the policy for every employee closes most of the gap between “we have a policy” and “employees actually follow it.”

Why Banning AI Outright Usually Backfires

A common first instinct is to ban AI tools altogether. In practice, this tends to just push the behavior further out of sight rather than stopping it. Employees who find a tool genuinely useful for their job will often keep using it quietly if there is no approved, sanctioned alternative, which leaves you with the exact same risk and zero visibility into it.

The more effective approach, and the one most security and HR professionals now recommend, is to govern rather than ban. Give employees a clear, approved way to use AI productively, and the incentive to go around the policy mostly disappears. This also does something for morale that a flat ban does not: it treats employees like professionals who can be trusted with clear guidelines, rather than treating the technology itself as something to be afraid of.

Rolling This Into Your Employee Handbook

An AI use policy works best as its own short, standalone section in your handbook, not buried inside your existing technology or confidentiality policy where employees are unlikely to read it closely. It should sit next to your data privacy and confidentiality language, reference your existing disciplinary process for violations, and get revisited at least twice a year, since both the tools and the state laws around them are changing quickly.

A Quick Gut Check

  • Do you know which AI tools your employees are actually using day to day?
  • Does your handbook currently say anything at all about AI?
  • Would your team know what information is off limits to paste into a chatbot?
  • If AI touches any part of your hiring or performance review process, have employees been notified?

If you answered no to more than one of these, that’s a policy gap worth closing before it becomes an incident.

Frequently Asked Questions

Should we just ban AI tools until we have a full policy written?

A temporary pause can buy you time, but a full ban tends to push usage underground rather than stopping it. A short, clear interim policy, even a one page version, closes more risk than an outright ban that employees quietly ignore.

Does this apply to us if we’re a small business without an IT department?

Yes. Data exposure risk and the new state notice requirements are not limited to large employers. A five person team using AI without guardrails carries the same category of risk as a five hundred person company, just at a different scale.

What counts as an “employment decision” under these new state laws?

Generally, anything involving hiring, promotion, discipline, termination, scheduling, or pay. If any software you use touches these areas and has AI or automated scoring features built in, it likely qualifies, even if you did not think of it as “AI” when you bought it.

How often should our AI policy be updated?

At minimum twice a year right now, given how quickly both the tools and the state laws are changing. A policy written a year ago is very likely already missing something current.

How HRDelivered Helps

HRDelivered can build and integrate an AI use policy directly into your existing employee handbook, written in plain language your team will actually read, and structured to satisfy the notice requirements now appearing in state employment law. Our HR consulting team works with you to identify where AI already touches your hiring, performance, or payroll processes, even the parts you may not think of as “AI,” and our compliance team keeps that policy current as new state requirements roll out.

If you’re not sure where your business currently stands, request a free HR audit and we’ll walk through your existing handbook with you directly.

Request Your Free HR Audit

Have a specific AI tool or use case you’re unsure about? Talk to an HR specialist before rolling it out company wide.

Share this article