DOES YOUR BUSINESS NEED AN AI POLICY?
Artificial intelligence has rapidly moved from a novelty to an everyday business tool. From drafting emails and summarizing documents to analyzing data, preparing marketing materials, and screening applicants, employees across Long Island and New York City are actively using tools like ChatGPT, Copilot, and Gemini.
For New York business owners, this widespread adoption raises a critical question: Should your company have a formal, written AI policy?
While the short answer is often “yes,” understanding the legal landscape behind AI usage is essential for protecting your operations and sensitive data.
The New York Regulatory Landscape
New York law does not currently impose a single, across-the-board mandate requiring private businesses to maintain a standalone AI policy. However, AI usage is far from unregulated. Existing state and local laws apply depending on how the technology is deployed, what information is entered into these systems, and whether the output impacts employees or consumers:
- Data Security & the NY SHIELD Act: The SHIELD Act requires businesses possessing private information of NY residents to maintain reasonable safeguards. An employee inputting sensitive customer, financial, or personnel data into an unapproved AI tool can create severe data privacy risks.
- Employment Decisions & Local Law 144: NYC’s Local Law 144 strictly regulates Automated Employment Decision Tools (AEDTs) in hiring and promotions, requiring independent bias audits and mandatory notices. Across NY state, AI reliance never shields an employer from anti-discrimination liability.
- AG Enforcement: The NY Attorney General has emphasized that existing laws on discrimination, privacy, and deceptive practices apply fully to AI. “The AI made a mistake” will not defend against a legal violation.
What Should a Practical AI Policy Cover?
An effective AI policy does not need to be overly dense or technical. Instead, it should provide direct guidance to help employees leverage these tools safely.
At a minimum, your policy should define:
- Permitted Tools: Which specific AI applications are authorized for company business.
- Data Restrictions: What confidential, proprietary, or personal information is strictly off-limits.
- Human Oversight: When AI-generated drafts, analysis, or contract reviews require mandatory review before release or decision-making.
- Employment Protocols: Clear boundaries on using AI for candidate screening, hiring, or performance reviews.
- Approval Process: Who holds authority to approve new AI software or vendors.
- IP & Content Review: Vetting procedures for AI-generated text or images regarding copyright and advertising compliance.
Taking Proactive Steps for Your Business
The goal of an AI policy isn’t to restrict efficiency, it’s to eliminate guesswork regarding confidentiality, accuracy, and compliance. Business owners should audit current AI usage, review how information is shared, and establish rules before informal habits become entrenched.