AI at Work: What Your Employer Can Require, and What a Policy Cannot Reach
An AI policy is a work rule, so labor law decides its edges. Three tracks govern what it can require, what AI can decide about you, and what stays yours.
Your employer sends out a new “AI Use Policy.” It runs four pages: no consumer chatbots for company work, no entering customer data or source code into any tool that has not been approved, disclose when AI helped produce a deliverable, and a closing line stating that AI-generated output carries the same confidentiality obligations as anything else you make at work.
The instinct is to read it as one document with one set of rules. It is actually three separate legal questions wearing the same letterhead, and they do not give the same answer. What your employer can require of you is broad. What it can let AI decide about you — hiring, promotion, discipline — is narrower and moving quickly at the state level. And a small set of things the policy cannot reach stays yours, even in a job you can be fired from for no reason at all.
The rule that decides the third track is not about AI. It is ninety-one years old.
The policy is a work rule, so labor law decides its edges
Most of an AI policy is ordinary workplace governance. Your employer owns the systems, sets the work, and can tell you which tools to use and how. That is not a special feature of AI; it is how employment works.
What makes AI policies worth reading closely is that they mix two kinds of instruction that are governed by different bodies of law:
- Instructions about the tools — which models you may use, what data may go into them, whether you must disclose their use. Governed mainly by the employment relationship and the employer’s confidentiality interests.
- Instructions about what you may say and to whom — for example, a rule against discussing the system’s outputs, or a confidentiality clause that reaches how the system affects your job. Governed, in addition, by federal labor law, whether or not a union is involved.
The second kind is where policies most often overreach, and where the average employee assumes there is no recourse. There is.
Track one: what the policy can require
Assume the narrow, tool-facing instructions are enforceable, because they usually are:
- Restricting which AI tools you may use for work, including banning consumer chatbots on company devices and on work time.
- Prohibiting confidential data from entering unapproved tools — customer lists, source code, financial figures, deal terms, personal data, anything under a confidentiality agreement. This is the most defensible clause in the document, for reasons covered below.
- Requiring disclosure of AI assistance in certain deliverables, or requiring human review before AI output is used.
- Requiring you to use an employer-provided tool for a task.
An employer’s power here traces to two things: it can direct how the job is done, and it has a genuine interest in protecting information. When a company cannot show it took reasonable steps to keep a trade secret secret, it can lose the legal protection entirely — so a clear, enforced AI policy is not busywork. It is one of the “reasonable measures” that trade-secret law asks for.
That does not mean every tool-facing clause is valid. A blanket ban that sweeps up the ordinary conduct of the job — or that is paired with monitoring so total it discourages any candid conversation — can still be challenged. Which brings us to the track most people do not know exists.
Track two: what AI can decide about you
This is the part of the subject that changed most in the last two years, and it splits cleanly into a stable federal layer and a fast-moving state layer.
The federal layer has not moved. Title VII, the ADA and the ADEA prohibit discrimination in employment whether the decision is made by a manager or a model. They reach not only intentional discrimination but also neutral practices that produce a discriminatory outcome. And using a third-party vendor’s hiring tool does not move the liability off the employer.
One thing did change, and it is the kind of change that makes older articles wrong. In May 2023 the EEOC published technical assistance explaining how Title VII applied to AI in hiring. On January 27, 2025, the agency removed that document from its website after a new executive order rescinded the prior administration’s AI policy. If you find a guide citing that document as current EEOC guidance, it is describing a page that no longer exists. The statutes it described were never amended, and the EEOC’s enforcement plan for 2024-2028 kept technology-related discrimination on its priority list — but the guidance itself is gone. The rules stayed; the signpost was taken down.
The state layer is where the obligations are. This is a “varies by state” area in the strongest sense — the duties attach based on where the applicant or employee is, not where the company is:
| Jurisdiction | What it requires | Status |
|---|---|---|
| New York City | Annual independent bias audit of an automated employment decision tool, public summary, and at least ten business days’ notice to candidates | In effect since July 2023 |
| Illinois | Notice when AI is used in an employment decision; no discrimination, including unintentional disparate impact; no ZIP codes as a proxy | Effective January 1, 2026 |
| Illinois (video interviews) | Notice to and consent from the applicant before AI analyzes a recorded interview | In effect since January 2020 |
| California | Ongoing monitoring of automated decision systems used in employment decisions for adverse impact | Effective October 1, 2025 |
| Connecticut | Anti-discrimination duty and a bar on using AI as a defense; applicant/employee disclosure follows | October 1, 2026, with disclosure phasing in 2027 |
| Colorado | Notice, adverse-outcome explanations and record retention for automated decisions | January 1, 2027 |
| Texas | Prohibits using AI with the intent to discriminate; disparate impact alone is not enough, and private employers carry no notice duty | Effective January 1, 2026 |
If you are applying in one of these places, the practical right you gain is usually notice that a tool is being used, and sometimes a way to ask for human review. What you generally do not get is the model’s reasoning. That gap — you are told a tool decided, but not why — is the thing the newer laws keep trying to close.
Treat the newer dates as start-of-a-process, not settled law. Illinois has required notice since January 1, 2026, but the state human rights department postponed the rulemaking that would have specified the form and timing in June 2026, so employers there are working from the statute alone. Colorado’s attorney general proposed implementing rules in August 2026 and is taking comments into late October, ahead of a January 1, 2027 start.
Track three: the part the policy cannot reach
Here is the rule that is not about AI, and it applies whether or not your workplace has ever seen a union.
Section 7 of the National Labor Relations Act gives most private-sector employees the right to engage in concerted activity — acting together, or on each other’s behalf, for mutual aid or protection about wages and other terms and conditions of employment. The National Labor Relations Board states plainly that this covers employees who are not represented by a union. “Concerted” does not require a formal campaign: two coworkers comparing notes about pay, or one employee bringing a group concern to a manager, can be enough.
“Working conditions” is broader than it sounds. How a new system changes your workload, how it scores your performance, whether the AI policy is fair, what it means for staffing — these are the terms and conditions of your job, and talking with each other about them is the activity the law protects.
Now put the policy back on top of that. A rule that says “do not discuss the AI system’s outputs with anyone” is facially neutral — it names no protected right. But under the Board’s Stericycle standard (2023), a facially neutral work rule is presumptively unlawful if a reasonable employee, one who depends on the job and might be thinking about raising a group concern, could read it as chilling that activity. The employer’s good intent does not enter into it, and ambiguity counts against the rule, because the employer wrote it.
The standard is not frozen. As of this writing it is still the controlling Board rule — but on August 26, 2026, the NLRB’s General Counsel issued Memorandum GC 26-04, which argues against Stericycle in a live case and directs the Board’s regional offices to stop building charges on generalized Stericycle violations alone. That does not change the rule today: a General Counsel memorandum states a prosecutorial position, and only the Board itself can overrule Board precedent — which, as of this writing, it has not. The direction of travel is still worth knowing if you plan to rely on the standard.
One related correction, because a lot of material still cites it as current: the 2022 General Counsel memo on electronic monitoring and algorithmic management (GC 23-02) — which proposed a framework for treating pervasive workplace surveillance as presumptively unlawful — was rescinded on February 14, 2025. Its framework was never adopted by the Board, so its withdrawal changed no precedent, but the memo no longer states the agency’s enforcement position. Its inventory of the monitoring technologies that Section 7 analysis can reach is still a useful checklist; its legal weight is not what older articles claim.
The mistake the policy is right to forbid
Of all the clauses in an AI policy, the one that is most defensible is the one more people are tempted to ignore: do not put confidential or personal data into a public AI tool.
Two separate bodies of law explain why.
Trade secrecy. Under the Defend Trade Secrets Act, a company can protect a secret only if it took reasonable measures to keep it secret. An employee pasting a customer list, a pricing model or source code into a consumer chatbot may put that information beyond the company’s control — and the platform’s terms may permit it to be retained, used for training, or disclosed. A disclosure like that can be enough to weaken a later trade-secret claim.
Confidentiality generally. On February 17, 2026, a federal court in New York held that a defendant’s exchanges with a public AI platform were protected by neither the attorney-client privilege nor the work-product doctrine. The reasoning was structural: the platform is not a lawyer, and its own terms let it collect, train on and disclose what users enter, so there is no reasonable expectation of confidentiality — and forwarding the output to a lawyer afterward does not retroactively create privilege. United States v. Heppner is not the last word, and the split is real: Warner v. Gilbarco protected a pro se litigant’s ChatGPT-assisted preparation under the work-product doctrine, and a Colorado court followed that approach in Morgan v. V2X in March 2026. But read what the disagreement is about. The courts that protected the material were shielding a party’s own litigation preparation from discovery — none of them held that a public platform keeps your input confidential, because it does not. That is why the rule of thumb survives the split: treat a public AI tool like a conversation in a crowded room. If it belongs in a confidential memo, it does not belong in the prompt box — and the policy is not being unreasonable when it says so.
The distinction that matters is between a consumer tool and an enterprise one. Enterprise versions are sold precisely on the promise that inputs are isolated and not used for training. If your employer wants you to use AI on sensitive work, that is the type it has to provide; the question to ask is not “is AI allowed” but “which AI, under what data-handling terms.”
If they are watching, notice may be required
AI at work also means being observed by it. The federal baseline is permissive: the Electronic Communications Privacy Act generally bars intercepting communications, but it contains exceptions for a party’s prior consent, and for equipment a communications provider furnishes for use in the ordinary course of business, and the Stored Communications Act does not reach access authorized by the provider of the service. In practice, that lets an employer monitor its own email, network and devices — which is why archived copies of company email can sit in a system for years.
What federal law does not require is that they tell you. Several states do:
- Connecticut requires prior written notice and conspicuous posting before electronic monitoring, with an exception where the employer has reasonable grounds to believe employees are breaking the law or creating a hostile work environment. Penalties run up to $500, $1,000 and $3,000 for first, second and later offenses.
- New York requires written notice at hiring and a conspicuous posting, with the same penalty structure.
- Delaware requires either a one-time written notice the employee acknowledges, or electronic notice each day the employee accesses the employer’s email or internet.
- Maine (since July 2026) bars audio or video monitoring in an employee’s residence, personal vehicle or property unless the job duties require it, and lets employees decline monitoring apps on personal devices.
If you are in one of these states, notice is a duty, not a courtesy — and a monitoring program that skips it is exposed regardless of what it was watching for.
What to do with this
- Separate the two halves of the policy. The tool rules — approved tools, no confidential data in public models, disclose AI use — are largely enforceable. The speech rules are the ones to read twice.
- Assume the prompt box is public. Use only the enterprise tool your employer provides for anything sensitive, and when in doubt, leave it out.
- Know that talking is protected. Discussing how the AI policy or an AI-driven process affects your work with coworkers is the kind of activity Section 7 protects, whether or not there is a union. A rule that reads as forbidding it is the kind that gets challenged.
- If you are in a state with an AI hiring or monitoring law, the duty usually runs to your employer. Notice, audits and explanations are obligations on them; knowing which one applies to you is how you tell a real requirement from a suggestion.
The useful frame is not “can my employer do this” — for most of the document, they can. It is “which track does this clause sit on,” because the tool rules, the decision rules and the speech rules are answered by three different laws, and only one of them is about AI.
Byte is the technology site of the Omni Mundi Compendium network. For the wider picture of how US privacy law is layered by data type and industry rather than by person, see What US Privacy Law Actually Protects.
This article is general information about US workplace law, not legal advice, and it is not a substitute for advice about your own situation. Employment rules vary by state and change often. It is AI-written and independently AI-reviewed before publication; the review standard and this article’s findings are recorded in the network’s editorial review policy.
Frequently asked questions
- Can my employer ban me from using ChatGPT for work?
- Yes. An employer can restrict which tools you use on its systems and on work time, and it can prohibit entering company, customer or client data into any tool it has not approved. That part of an AI policy is ordinary workplace governance and is generally enforceable. What it cannot do is write the rule so broadly that a reasonable employee would read it as forbidding protected discussions with coworkers about wages or working conditions.
- My workplace has no union. Do the labor rules still apply to me?
- Yes. Section 7 of the National Labor Relations Act covers most private-sector employees whether or not a union exists. It protects 'concerted activity' — two or more employees acting for their mutual aid or protection about terms and conditions of employment, which includes talking with each other about pay, safety, and how a new system is affecting your work.
- Can my employer use AI to decide whether to hire or promote me?
- It can use the tool, but the anti-discrimination statutes apply the same way whether a human or a model makes the call. Title VII, the ADA and the ADEA all prohibit both intentional discrimination and practices that produce a discriminatory outcome, and using a vendor's tool does not transfer the liability. A growing number of states and cities add their own notice, audit or explanation duties on top.
- Is it safe to paste my company's documents into an AI tool?
- Assume not, unless the employer has provided an enterprise tool with a data-handling agreement. A February 2026 federal ruling held that exchanges with a public AI platform are neither privileged nor confidential, because the platform's own terms let it collect, train on, and disclose what you enter. Separately, feeding confidential material to an outside service can undermine the company's own trade-secret protection.
- Does my employer have to tell me if it is monitoring me?
- Federal law does not require it. The Electronic Communications Privacy Act allows an employer to monitor its own systems under the business-use and consent exceptions. But Connecticut, Delaware, Maine and New York require notice before electronic monitoring, and the penalties for skipping it are real. If you work in one of those states, notice is a legal duty, not a courtesy.
Sources
- National Labor Relations Act, Section 7, 29 U.S.C. § 157 — the right of employees to self-organize and 'to engage in other concerted activities for the purpose of collective bargaining or other mutual aid or protection'; Section 8(a)(1), 29 U.S.C. § 158(a)(1) — it is an unfair labor practice for an employer to interfere with, restrain or coerce employees in the exercise of those rights
- National Labor Relations Board, 'Employee Rights' and 'Protected Concerted Activity' — the Board's statement that employees who are not represented by a union still have rights under the Act, and that concerted activity means two or more employees acting for their mutual aid or protection regarding terms and conditions of employment (with a single employee covered when acting on the authority of others, bringing a group complaint, or preparing for group action)
- Stericycle, Inc., 372 NLRB No. 113 (Aug. 2, 2023) — a facially neutral work rule is presumptively unlawful if it has a reasonable tendency to chill employees from exercising Section 7 rights, judged from the perspective of an employee who is economically dependent on the employer; the employer may rebut by showing the rule advances a legitimate and substantial business interest that cannot be served by a more narrowly tailored rule; the employer's intent is not considered
- NLRB General Counsel Memorandum GC 25-05 (Feb. 14, 2025) — the rescission of a set of General Counsel memoranda issued by the prior General Counsel, including GC 23-02 on electronic monitoring and algorithmic management; a General Counsel memorandum states a prosecutorial position and does not itself change Board precedent, and the framework GC 23-02 proposed was never adopted by the Board
- NLRB General Counsel Memorandum announced August 26, 2026 — the General Counsel's list of precedents she will urge the Board to re-examine, including Stericycle; a General Counsel memorandum states a prosecutorial position and cannot itself change Board precedent, which only the Board can overrule, so the standard remains controlling until the Board rules otherwise
- Title VII of the Civil Rights Act of 1964, 42 U.S.C. § 2000e-2; Americans with Disabilities Act, 42 U.S.C. § 12101 et seq.; Age Discrimination in Employment Act, 29 U.S.C. § 621 et seq. — the prohibitions on disparate treatment and disparate impact that apply to employment decisions regardless of whether the decision is made by a person or an algorithm; a vendor's tool does not shift liability away from the employer
- U.S. Equal Employment Opportunity Commission — removal of the May 2023 technical assistance document on artificial intelligence and Title VII from the agency's website on January 27, 2025, following the January 2025 executive order; the underlying statutes were not amended, and the EEOC's Strategic Enforcement Plan for Fiscal Years 2024-2028 continued to identify technology-related employment discrimination as an enforcement priority
- New York City Local Law 144, N.Y.C. Admin. Code §§ 20-870 to 20-874 — annual independent bias audits, publication of a summary of results, and at least ten business days' notice to candidates before use of an automated employment decision tool; civil penalties of $500 for a first violation and $500-$1,500 for each subsequent violation per day, in effect since July 5, 2023
- Illinois Public Act 103-0804 (HB 3773), amending the Illinois Human Rights Act, 775 ILCS 5/2-101 and 5/2-102 — effective January 1, 2026, prohibiting the use of artificial intelligence in employment decisions in a way that discriminates against a protected class, including through disparate impact, requiring notice to applicants and employees, and barring the use of ZIP codes as a proxy for protected characteristics
- Illinois Artificial Intelligence Video Interview Act, 820 ILCS 42 — effective January 1, 2020, requiring notice to and consent from an applicant before AI analysis of a recorded video interview, and limiting how the resulting data may be shared
- California Civil Rights Department, automated-decision-system regulations under the Fair Employment and Housing Act, finalized June 2025 and effective October 1, 2025 — requiring ongoing monitoring of automated decision systems used in employment decisions for adverse impact
- Connecticut Public Act No. 26-15 (2026), Senate Bill 5, the state's AI responsibility and transparency act — the automated-employment-related-decision-technology provisions take effect October 1, 2026, including the rule that using such a system is not a defense to an employment discrimination claim and a duty on developers to give deployers the information they need to comply; deployer notice to applicants and employees, correction rights and adverse-decision disclosure phase in on October 1, 2027; a violation is an unfair or deceptive trade practice under the Connecticut Unfair Trade Practices Act, enforceable only by the Attorney General, with a 60-day cure period
- Colorado Senate Bill 26-189 (2026), signed May 14, 2026 — repeals and reenacts the Colorado Artificial Intelligence Act (SB 24-205), effective January 1, 2027: pre-use notice, a plain-language adverse-outcome disclosure within 30 days, correction rights, meaningful human review to the extent commercially reasonable, three years of record retention, and a 60-day pre-enforcement cure period; enforcement is exclusively by the Attorney General through the Colorado Consumer Protection Act, with no private right of action, and the implementing rules are due on or before January 1, 2027
- Texas Responsible Artificial Intelligence Governance Act, HB 149, 89th Legislature (2025), signed June 22, 2025 and effective January 1, 2026 — prohibits developing or deploying an AI system with the intent to unlawfully discriminate against a protected class; the Texas Attorney General's own guidance states that 'a disparate impact alone is not sufficient to demonstrate an intent to discriminate'; the transparency duties run to government entities and health care providers rather than private employers; enforcement is exclusively by the Attorney General, after a 60-day cure period, with no private right of action
- Maine, 'An Act to Regulate Employer Surveillance to Protect Workers,' Public Law ch. 524 (L.D. 61), adding subchapter 1-E to Title 26, chapter 7 of the Maine Revised Statutes — effective July 2026: an employer may not use covered electronic surveillance before notifying the employee, must inform job applicants during the interview process, and must give current employees written notice at least once per calendar year; audio or video monitoring in an employee's residence, personal vehicle or property is barred unless the job duties require it; an employee may decline to install data-collection applications on a personal device; civil fines of $100 to $500 per violation, enforced by the Maine Department of Labor
- Illinois Department of Human Rights, proposed amendments to Title 44, Part 2520 of the Illinois Administrative Code, published May 15, 2026 — the rulemaking that would have specified the circumstances, timing and means of the notice required by Public Act 103-0804 was temporarily postponed on June 2, 2026, which leaves the statutory notice duty in force without rule-level detail on its form
- Electronic Communications Privacy Act — Title I (Wiretap Act), 18 U.S.C. § 2511, and its exceptions for a party's prior consent, § 2511(2)(d), and for equipment used by a provider in the ordinary course of business, § 2510(5)(a)(i); Title II (Stored Communications Act), 18 U.S.C. § 2701, and the exception for access authorized by the provider of the communication service, § 2701(c); civil damages under 18 U.S.C. § 2520
- Connecticut General Statutes § 31-48d — prior written notice to all employees subject to electronic monitoring, conspicuous workplace posting, an exception permitting monitoring without notice where the employer has reasonable grounds to believe employees are violating the law, violating the legal rights of the employer or other employees, or creating a hostile work environment, and civil penalties of up to $500, $1,000 and $3,000 for the first, second and each subsequent offense; § 31-48b(b) — the separate prohibition on operating surveillance devices in areas designed for employees' health or personal comfort, such as restrooms, locker rooms or lounges; Delaware Code Title 19, Chapter 7, § 705 — one-time written or electronic notice acknowledged by the employee, or electronic notice each day the employee accesses the employer's email or internet; New York Civil Rights Law § 52-c — written notice upon hiring, acknowledged in writing or electronically, and conspicuous posting, with the same $500/$1,000/$3,000 penalty structure, in effect since May 7, 2022
- Defend Trade Secrets Act of 2016, 18 U.S.C. § 1836 — federal civil cause of action for misappropriation of a trade secret; the definition at § 1839(3)(A) requires that the owner have taken reasonable measures to keep the information secret
- United States v. Heppner, No. 1:25-cr-00503-JSR (S.D.N.Y. Feb. 17, 2026) — a defendant's exchanges with a public generative AI platform were protected neither by the attorney-client privilege nor by the work-product doctrine: the platform is not an attorney, its privacy terms permit collection, training use and disclosure of user inputs, and forwarding the outputs to counsel later does not retroactively create privilege. Note the split: Warner v. Gilbarco, Inc., 820 F. Supp. 3d 629 (E.D. Mich. 2026), protected a pro se litigant's AI-assisted preparation under the work-product doctrine, reasoning that work-product waiver follows a different test because a tool is not a third party; Morgan v. V2X, Inc., 2026 U.S. Dist. LEXIS 67939 (D. Colo. Mar. 30, 2026), followed it, holding that Rule 26(b)(3) protects materials prepared by or for a party and that a pro se litigant is both. None of the three held that a public platform keeps user input confidential. (Sources differ on the precise day of the Heppner ruling — the written opinion is dated February 17, 2026, and some reports describe an oral ruling on February 10 — so the article states the cases and their dates without ranking them in time.)