Most businesses adopt AI in the worst possible order. Employees start using it quietly, sensitive data drifts into chatbots, and only later does someone ask what the rules should have been. The workshop question about lawsuits is the moment that ordering problem becomes visible. So let me walk through the conversation the way it actually went.
Could AI conversations show up in a lawsuit?
Honestly, I do not know, and neither does your IT provider, because that is a legal question and we are an IT company. The attendee had heard about cases where information shared with AI applications became discoverable, treated as if it were no longer confidential. I am not in a position to confirm or deny that, and neither is anyone else without a law license. What I told him, and what I will tell you, is to talk to your attorney about it before you assume anything either way.
What I can tell you is what the company controls on its side of that question. And that starts with a document.
What is an AI acceptable use policy?
It is the company’s written decision about what information is allowed to be shared with AI, which tools are approved, and what those tools may do with your data. We keep a template for exactly this, and the template is the easy part. The hard part is the decisions behind it, because the risks are real: AI with access to your files could delete things, and data pasted into the wrong tool could end up exposed. We covered the delete-my-files category of risk in our guide to desktop AI risks and guardrails. The exposure category is what the policy exists for.
The policy works because it is specific. Not “be careful with AI,” but this data class can go to these tools, and this data class cannot.
Are all AI tools equally risky?
No, and your policy should say so explicitly. The major cloud AI vendors state that on paid accounts they do not train their models on your data. That is meaningfully less risk than a free consumer account, though the risk is still out there, and I would not tell a client otherwise.
Then there are the much cheaper models, including the Chinese ones. Your policy might allow those for narrow, harmless jobs, generating images was my example in the workshop, while drawing a hard line well before anything sensitive. And for the truly sensitive material, payroll data, confidential company financials, the right answer may be an offline model contained entirely at your office, one that cannot share data outside your walls. We run one internally for exactly that reason. Or the answer may be simpler still: some data should not work with AI at all.
At the other end of the spectrum, my favorite example of a zero-drama AI workload is my own website. It is public. Anyone can visit it, read it, copy it. Letting AI work on that costs nothing in confidentiality, which makes it a perfect job for AI. A good policy captures that whole range, from “any tool, go nuts” to “never.”
Can we just block AI at the network level?
We could, and it barely works, so do not build your protection on it. Copilot is already installed in your Microsoft 365 environment, so AI is in the building whether you invited it or not. There are countless AI websites, and blocking them is a losing chase. And the low-tech bypass beats every filter ever made: an employee who cannot paste a document can pick up their phone and photograph the screen.
This is why the signed policy matters more than the firewall rule. If an employee does something undesirable with an AI tool anyway, a policy that employee signed off on is something you can actually submit to help protect the company from exposure. It helps you remain legally defensible in court even when a person misuses a tool. Again, and I will keep saying it, have your attorney shape that document. Our job is the security controls behind it, theirs is the legal armor.
What about regulated industries and government work?
Look at the enterprise platforms built for exactly that, Amazon Bedrock and Azure AI Foundry. The big vendors know that compliance scenarios exist, so they offer locked-down, contained AI systems designed specifically to keep your data secure inside their environment. If you are working with government contracts or DoD requirements, those are the platforms to research rather than the consumer front doors, and that research should happen alongside your compliance obligations, not after.
So what should you actually do this month?
Three things, in order. First, book time with your attorney and ask the discoverability question directly, because everything else hangs on their answer. Second, sort your data into rough classes, public, internal, sensitive, and decide which AI tools, if any, each class may touch. Third, put that in a written acceptable use policy and have every employee sign it before the next quiet chatbot session, not after.
If step two is where you stall, that is the part that is genuinely our lane. Matching data classes to tools, standing up an offline model, configuring the guardrails, that is IT consulting work, and we do it for businesses across Houston. The legal advice is your lawyer’s. The plumbing is ours. Between the two, you get to say yes to AI without wondering what your team already pasted where.
