Using an AI tool in your business isn't illegal, and nothing about the technology itself creates new legal duties out of thin air. What it does is put you - fast, and without much friction - into situations that existing law already covers: confidentiality, copyright, truthful advertising, and fair hiring. The tool doesn't take on that risk for you. You do. This guide walks through the five places that exposure shows up in an ordinary small business, at a practical level, and flags where the law is still unsettled rather than pretending it's all been decided.
Confidentiality: once you paste it in, you may not control it anymore
The single most common way small businesses get into trouble with AI tools is pasting something sensitive into a public, consumer-facing chatbot to get help drafting an email, summarizing a document, or debugging a problem. The risk isn't hypothetical:
Client and customer confidentiality. If you signed a nondisclosure agreement, or you're bound by a professional duty of confidentiality (common for attorneys, accountants, financial advisors, and consultants), pasting a client's information into a tool outside your controlled systems can itself be the breach - regardless of what the tool does with it afterward.
Health information. If your business is a healthcare provider, health plan, or a vendor that handles health data on their behalf, pasting patient information into a general-purpose AI tool can violate HIPAA. This is a federal rule with real enforcement teeth; confirm your obligations at hhs.gov before you use any AI tool that touches patient data.
Trade secrets. Trade secret law only protects information you've taken reasonable steps to keep secret - a formula, a customer list, source code, pricing logic, an unreleased product design. Feeding that into a tool whose terms let it use your input to improve the model can undercut your ability to later claim the information was a protected trade secret, because you shared it outside your controlled circle.
What to do: before you type anything sensitive into an AI tool, check its terms of service for what it does with your input - specifically whether it's used to train the model and whether you can opt out. Many business or enterprise tiers of popular AI tools offer no-training terms that consumer or free tiers don't. When in doubt, treat a public AI tool the same way you'd treat posting something on a public forum: assume it isn't private.
Copyright: what the AI makes for you may not be yours to protect
The U.S. Copyright Office's position, set out in its registration guidance for works containing AI-generated material and applied in its own registration decisions, is that copyright protects only material with human authorship. Output that comes entirely from an AI system, with no meaningful human creative contribution, is not registrable. Work that combines human creativity with AI-generated elements can be registered, but only the human-authored parts are protected, and applicants have a duty to disclose the AI-generated content in the registration application and describe the human's actual contribution.
This matters most if you plan to sell, license, or build a brand around what the AI produced - a logo, product copy, an illustration, a training course. If there's no human authorship worth registering, you may not be able to stop a competitor from copying it. On the flip side, lawsuits over whether AI models were trained on copyrighted material without permission, and whether AI output itself infringes existing copyrighted works, are actively working their way through the courts as of this writing, and courts have not all landed in the same place. That means the rules around what you can safely generate and reuse from an AI tool are still developing - don't assume something is legally clean just because a machine produced it. For registration questions specific to your situation, copyright.gov is the current, authoritative source, and observed.org's copyright coverage goes deeper on ownership and infringement basics.
Accuracy: the tool's mistake is your liability
AI tools generate confident-sounding text that is sometimes simply wrong - a fabricated case citation, a misstated statute, an invented fact, a wrong phone number or price. Courts have already sanctioned attorneys for filing briefs with fabricated AI-generated citations, and the same exposure applies to any small business: a marketing claim you can't back up, a contract clause that doesn't say what you think it says, an accounting summary with an error, a client-facing answer that turns out to be false.
The vendor's terms of service almost always disclaim responsibility for the accuracy of what the tool produces. That disclaimer protects the vendor - it does nothing for you. If your business publishes it, sends it, signs it, or files it, the liability is yours, whether the claim is a breach-of-contract dispute, a false-advertising problem, professional malpractice, or simple reputational damage with a customer. Treat AI output the same way you'd treat a draft from a junior employee: useful, often good, never final without your own review.
Employment: screening tools don't get a pass from existing law
If you use an AI tool to screen resumes, score candidates, analyze video interviews, or evaluate current employees, you're still fully subject to the federal laws that already govern hiring and employment - Title VII's ban on discrimination, and the Americans with Disabilities Act's requirements around disability and accommodation, both of which apply once your business reaches 15 employees. An automated tool that screens out applicants over a protected characteristic, or that can't be reasonably adjusted for a disability, creates the same legal exposure as a human decision-maker doing the same thing - intent isn't required for a disparate-impact claim.
Two more layers to know about:
The Fair Credit Reporting Act. If you use a third-party vendor's report or score to help decide whether to hire, promote, or keep someone, that vendor may count as a consumer reporting agency under the FCRA - including AI-driven screening and scoring tools built on data pulled from multiple sources. That generally means you need the applicant's consent before ordering the report and a proper notice before you take an adverse action based on it. Federal agency guidance specifically addressing AI screening tools has shifted in recent years, and some of it has been withdrawn - but the underlying FCRA duties come from a statute, not from guidance, and they haven't gone anywhere. The safest approach is to keep following them.
State and local AI-hiring laws. This is the fastest-moving layer, and the one most likely to have changed since this was written. New York City, for example, requires an independent bias audit and public disclosure before certain automated employment decision tools can be used for jobs there. A growing number of states and cities have adopted or are phasing in their own notice, disclosure, or bias-audit duties for AI use in hiring and employment decisions - and more than one has had its effective date pushed back or its text rewritten while businesses were preparing for it. Because both the requirements and their start dates keep moving, don't rely on what a rule said last year: confirm the current requirement with the state labor or civil-rights agency, or the city agency, that enforces it before you use an automated tool for a hiring decision. Observed.org's guidance on classifying and hiring employees covers the underlying federal framework these tools sit on top of.
Advertising: fake testimonials and unproven "AI-powered" claims
Two FTC concerns apply directly here, and only one of them is an AI rule.
The first is a specific FTC rule on the use of consumer reviews and testimonials. It bans writing, buying, or spreading a review or testimonial that misrepresents that the reviewer exists, that the reviewer actually used the product or service, or what the reviewer's experience was - which squarely covers a review invented by an AI tool and presented as a genuine customer's. The same rule limits review suppression, though more narrowly than people often assume: you can't use unfounded legal threats or intimidation to force a negative review down, and you can't display a hand-picked set of reviews while representing that it reflects most or all of the reviews you've received when you've been holding back the negative ones because they're negative.
The second isn't a standalone AI rule at all - it's the ordinary law against deceptive advertising. If your marketing describes your product or service as "AI-powered," "AI-driven," or similar, the FTC expects you to be able to substantiate that claim - what the AI actually does, and how well it actually does it - the same way you'd need to substantiate any other advertising claim. The agency has brought enforcement actions against businesses that used "AI" as a credibility hook for claims the product couldn't back up. Truthful, provable claims about how you use AI are fine; vague hype is where the exposure sits. The FTC's business guidance at ftc.gov is the authoritative source on both points.
What to do: a short, usable AI policy
You don't need a long document. A short, written policy that your team can actually follow beats an elaborate one nobody reads. At minimum:
No confidential inputs. Client data, patient information, trade secrets, financial account numbers, and anything covered by an NDA don't go into a public AI tool unless you've confirmed its terms protect that input from training and disclosure.
Human review before anything goes out. No AI-drafted contract, marketing claim, client communication, or filing goes out under your business's name without a person checking it for accuracy first.
Disclose where required. If a testimonial, review, or endorsement isn't from a real customer's real experience, don't publish it as one. If a platform, contract, or regulator requires you to disclose AI use, disclose it.
Know which tool you're using and why. A paid business-tier tool with no-training terms is a different risk profile than a free consumer chatbot - match the tool to how sensitive the information is.
Put it in writing and revisit it. Add a short AI-use section to your employee handbook or contractor agreements, and update it as the law in this area keeps moving - it's changing quickly, especially at the state and city level.
None of this requires avoiding AI tools altogether. It requires treating their output the way you'd treat any other draft or vendor product: useful, not authoritative, and your responsibility to check before it becomes your business's word.
This article is general business information, not legal, tax, or financial advice, and reading it doesn't create an attorney-client relationship. AI regulation is moving quickly and the rules described here can change. For a specific confidentiality obligation, hiring decision, or advertising claim, talk with a qualified attorney, and for questions about a particular AI tool's data-handling terms, read that tool's terms of service directly. Free general help for small businesses is available through the SBA at sba.gov, SCORE, and your state's Small Business Development Center.
Frequently asked questions
Can I get sued for something an AI tool wrote for my business?
Yes, in the sense that you're responsible for what your business publishes, sends, or files, regardless of what tool produced the draft. If an AI-written contract clause, marketing claim, or client email is wrong, misleading, or infringing, the legal exposure runs to you and your business, not to the AI vendor - unless your specific vendor contract says otherwise, which most consumer-facing tools' terms don't.
Is it illegal to use AI to write client emails or marketing copy?
No, there's nothing inherently illegal about using AI to draft communications. The legal risk comes from what you do with the output before it goes out: whether it's accurate, whether it discloses what needs to be disclosed (like a paid endorsement), and whether you reviewed it rather than sending it unchecked.
Does pasting client information into a public AI chatbot violate my NDA?
It can. Most nondisclosure agreements and many professional-conduct rules (for attorneys, accountants, healthcare providers, and others) require you to keep client or patient information within a defined, controlled circle. A public AI tool - especially one whose terms allow your input to be used for training - generally falls outside that circle. Read the tool's terms of service and your NDA's language before you paste anything confidential into it.
Do I have to tell customers I used AI to write a review or testimonial?
The real question is whether you can publish it at all. Under the FTC's rule on consumer reviews and testimonials, you can't write, buy, or spread a review that misrepresents that the reviewer exists or that they actually used your product - so an AI-written review presented as a real customer's experience is a problem that no disclosure fixes. Genuine customer reviews are fine. Separately, some platforms and some state laws require disclosure when a customer-facing communication is AI-generated; check your platform's rules and confirm current state requirements where you do business.
Can my state or city stop me from using AI to screen job applicants?
Not outright, but a number of states and cities now impose specific duties - notice to applicants, bias audits, or both - before you can use an automated tool to screen, score, or rank candidates or employees. This is a fast-moving area where effective dates have been delayed and rules rewritten more than once, so confirm the current rule with your state labor or civil-rights agency, or your city agency, before you rely on one of these tools for hiring. The federal baseline doesn't move, though: Title VII and the ADA apply to an automated decision exactly as they would to a human one.
This article is general legal information, not legal advice, and may not reflect the most current law or the law in your jurisdiction. Laws vary by state and change over time. For advice about your specific situation, consult a licensed attorney.
Knowing your rights is the first step
Join thousands committing to calmly and consistently exercise their constitutional rights.