AI in the Workplace — Legal Risks Employers Aren’t Thinking About

Artificial intelligence has arrived in the workplace. Not in a distant, theoretical sense — it is already here, running quietly in the background of everyday work. Employees are using ChatGPT to draft emails, Microsoft Copilot to summarise contracts, and a growing constellation of sector-specific AI tools to accelerate tasks that once took hours.

Most employers know this. What most employers don’t know is that every one of those interactions carries legal risk — risk that arises not from some future AI regulation, but from laws that are already in force and already apply.

AI is not a legal problem waiting to happen. It is a legal problem already happening. The question is whether your business is prepared.

The Compliance Gap.

There is a structural problem at the heart of how most businesses approach AI: technology adoption is moving far faster than legal awareness. This is not a new phenomenon — it is the same gap that appeared with the internet, with social media, and with cloud computing. But the stakes with AI are higher because the tool is more powerful, more pervasive, and more capable of creating liability in ways that are genuinely hard to detect until something goes wrong.

Having spent years working in the RegTech space — where the relationship between technology and regulation is the central problem — I have seen this pattern play out repeatedly. The businesses that fare worst are not those that adopt technology aggressively, but those that adopt it without a legal framework to match.

The Eight Risks.

1. Privacy and data protection.

This is the most immediate and widespread risk. Employees routinely input client data, commercially sensitive business information, and personal data into AI tools — often without any awareness that this data may be processed offshore, stored by the platform provider, or used to train the underlying model.

Under the Privacy Act 1988 (Cth), Australian businesses have obligations around how personal information is collected, used, stored, and disclosed. Feeding personal data into a third-party AI tool without appropriate controls is likely to constitute a breach of those obligations, particularly where the data is transferred outside Australia to a provider whose privacy practices have not been assessed.

The incoming Privacy Act reforms will tighten these obligations further, introducing stronger consent requirements, a right to erasure, and significantly increased penalties. Businesses that have not addressed AI-related data flows now will face a more difficult problem once those reforms take effect.

Separately, if the information fed into an AI tool is subject to confidentiality obligations — for example, under a non-disclosure agreement with a client or counterparty — its disclosure to a third-party platform may constitute a breach of contract, regardless of what the Privacy Act requires.

2. Intellectual property ownership.

A deceptively simple question: who owns the output of AI-generated work?

If an employee uses an AI tool to draft a report, write marketing copy, generate a design, or produce software code, the answer under Australian law is not straightforward. Copyright in Australia requires human authorship. Work that is generated autonomously by an AI system — without sufficient human creative input — may not attract copyright protection at all. That means the business cannot assert ownership of it, cannot prevent competitors from using it, and cannot license it.

Even where there is sufficient human input to establish copyright, questions arise about who holds it. Does it belong to the employer (as work created in the course of employment)? To the employee? To the AI platform provider, under the terms of their licence agreement? The answer depends on the specific facts and the terms of the relevant agreements — and most businesses have not asked the question.

For businesses whose competitive advantage depends on the IP they create — software companies, creative agencies, professional services firms — this is not a theoretical concern. It is a structural risk to the value of the business.

3. Discrimination and bias in hiring and performance management.

AI tools are increasingly being used to screen job applications, rank candidates, assess employee performance, and inform promotion decisions. The appeal is obvious: speed, consistency, and the appearance of objectivity.

The problem is that AI systems learn from historical data — and historical data reflects historical bias. A recruitment AI trained on the hiring decisions of a firm that has historically employed predominantly male engineers will tend to favour male engineering candidates. A performance management tool that penalises employees who take parental leave will have a disproportionate impact on women.

These outcomes create exposure under the Fair Work Act 2009 (Cth), the Sex Discrimination Act 1984 (Cth), the Racial Discrimination Act 1975 (Cth) and their state equivalents. The employer will not be able to deflect liability by pointing to the algorithm. Courts and tribunals look at the effect of a decision, not the mechanism by which it was made.

The risk is compounded by the fact that algorithmic bias is often invisible. Employers may be making systematically discriminatory decisions without anyone in the organisation being aware of it.

4. Workplace surveillance and monitoring.

AI-powered monitoring tools are proliferating rapidly: keystroke loggers, productivity trackers, email sentiment analysis, video monitoring, and systems that flag when employees are inactive or off-task. Employers are deploying these tools — sometimes covertly — in the belief that they are entitled to monitor what happens on company systems.

This belief is only partially correct. Workplace surveillance legislation exists in most Australian states and territories and places significant restrictions on the covert monitoring of employees. The Privacy Act also applies where monitoring involves the collection of personal information. And the psychosocial work health and safety framework — which now gives psychological safety the same legal weight as physical safety — is directly engaged by surveillance that creates a culture of anxiety, distrust, or excessive scrutiny.

Employers who deploy monitoring tools without legal advice, transparent policies, and genuine employee consultation are taking on risk on multiple fronts simultaneously.

5. Liability for AI errors.

AI systems make mistakes. They hallucinate — producing confident, plausible-sounding output that is factually wrong. They misread context. They apply patterns from their training data in ways that are inappropriate to the specific situation.

When an employee relies on AI-generated output without checking it, and that output turns out to be wrong, the employer is not insulated from liability simply because a machine produced the error. If the error causes loss to a client, a contractual counterparty, or a third party, the legal exposure falls on the business.

This risk is particularly acute in professional services — legal, financial, medical, engineering — where the standard of care is high and the consequences of error are significant. But it applies in any context where AI output is used to make decisions or produce deliverables that affect others.

6. Work Health and Safety — psychosocial hazards.

The psychosocial work health and safety framework, now embedded in model WHS legislation and adopted across most Australian jurisdictions, requires employers to identify and manage psychosocial hazards with the same rigour as physical hazards.

AI in the workplace creates a range of psychosocial hazards that are only beginning to receive attention: the anxiety of working alongside systems that monitor and evaluate performance; the pressure of being benchmarked against AI output speeds; the erosion of skill and autonomy that comes from over-reliance on AI tools; and the displacement anxiety that arises when employees see AI taking over functions they previously performed.

Regulators are watching this space. Employers who have not considered the psychosocial dimensions of their AI deployment are not meeting their WHS obligations.

7. Consultation obligations under awards and enterprise agreements.

This is perhaps the most overlooked risk of all. Many modern awards and enterprise agreements contain consultation obligations that are triggered when an employer introduces a “major change” to the workplace — including significant changes to work processes or the tools employees use.

Deploying an AI system that materially changes how employees do their jobs may trigger a requirement to consult with affected employees (and, where relevant, their union) before the change is implemented. Failure to consult can constitute a breach of the award or enterprise agreement, giving rise to underpayment claims, dispute proceedings, and industrial action.

Most employers rolling out AI tools are not thinking about their industrial relations obligations at all – but should be.

8. Legal professional privilege and confidentiality.

For law firms, in-house legal teams, and any business that relies on legally privileged communications, the use of AI tools creates a specific and serious risk.

Legal professional privilege protects confidential communications between a lawyer and client made for the dominant purpose of obtaining or providing legal advice, or to use in existing, pending, or reasonably anticipated litigation. That privilege (which belongs to the client) can be waived — including by voluntary disclosure to a third party. Feeding privileged communications into an AI tool that is operated by a third-party provider is likely to constitute such a disclosure.

Once privilege is waived, it cannot be restored. The document becomes discoverable in litigation. This is a risk that is barely being discussed in the profession, but it is real and it is immediate.

What employers should do now.

The good news is that these risks are manageable. They require attention, not alarm. The starting point is an honest assessment of how AI is currently being used in the business — not how the business thinks it is being used, but how it actually is. The gap between those two things is often significant.

From there, a structured response should address the following:

  • Implement a clear AI use policy that defines which tools are permitted, what they may be used for, and — critically — what must never be input into them.
  • Conduct a privacy impact assessment before deploying any AI tool that processes personal data, and review existing tools against this standard.
  • Take legal advice on intellectual property ownership in the specific context of your business and ensure employment contracts and engagement terms address AI-generated work product.
  • Review hiring and performance management processes for algorithmic bias, and ensure any AI-assisted decisions can be explained and justified.
  • Audit workplace monitoring practices for compliance with surveillance legislation, the Privacy Act, and psychosocial WHS obligations.
  • Check consultation obligations under applicable awards and enterprise agreements before rolling out AI-driven workflow changes.
  • Train managers on the legal risks associated with AI — not just the technical operation of the tools.

© Praetorium Law 2026. This article is intended as general information only and does not constitute legal advice. You should seek specific legal advice for your circumstances.