The AI Reckoning: Companies that skip legal guardrails now are taking a gamble

Companies can expose themselves to legal, security and compliance risks if policies aren't in place regarding AI use in the workplace

“Businesses today are encountering AI-related challenges on virtually every front — legal, operational and regulatory,” said Brandon Robinson, of Maynard Nexsen. Photo by Will Dickey.

Business leaders worried about artificial intelligence need to know three things — it’s inevitable, you need policies in place now and it’s good to get legal advice.

Several experts who work at the intersection of AI, law and business operations agree that businesses need to be prepared for functioning in this complex and constantly changing environment.

“Businesses today are encountering AI-related challenges on virtually every front — legal, operational and regulatory,” says Brandon Robinson, who works on cybersecurity and privacy issues at the Maynard Nexsen law firm in Birmingham.

“One of the biggest issues I see with clients is navigating the sheer complexity of the compliance landscape,” Robinson says.

Because there is no comprehensive federal AI law, he says regulation arises from a patchwork of international, federal and state laws, agency guidance, enforcement activity and executive orders. 

- Sponsor -

States’ new laws cover everything from algorithmic discrimination to transparency, content-disclosure requirements and safeguarding high-risk decisions, he says. Lawmakers in 45 states introduced more than 1,500 AI-related bills in the first three months of this year.

“For a business operating across state lines, that creates a moving target,” he says.

“Alabama lawmakers have introduced bills touching on AI in healthcare, content-disclosure requirements, age verification and deepfake-related deceptive content,” he says.

“Governor Ivey’s 2024 GenAI Task Force submitted its final report to the governor’s office in November 2024, which was released in March 2025, and we continue to track how those recommendations are being implemented across state agencies,” Robinson says.

Attorneys in their cybersecurity and emerging technologies practice attend conferences, industry working groups and training sessions to obtain special certifications.

With 57% of Alabama’s small businesses now using an AI platform, according to the U.S. Chamber of Commerce, many are adopting these tools quickly without fully appreciating the legal exposure.

“AI is going to touch every corner of your business, and your entire leadership team needs to be willing to engage with it — not just delegate it,” said Tiffany deGruy, of Bradley Arant Boult Cummings.

“AI is going to touch every corner of your business, and your entire leadership team needs to be willing to engage with it — not just delegate it,” says Tiffany deGruy, a partner at the Bradley Arant Boult Cummings law firm in Birmingham.

 Tools like ChatGPT, Google Gemini and Claude are revolutionizing content creation, customer interaction, healthcare, contract proposals, finances, analytics and so much more.

Even the U.S. Army is dealing with the speed of AI issues in human-machine collaboration, ethics, data quality, operational limits and security. That naturally spills over into defense contracting. In January, the U.S. Department of War launched its own Artificial Intelligence Acceleration Strategy.

Robinson says specific challenges for business include how AI tools collect, store and process personal information, customer data and confidential business information, whether those practices align with existing privacy and security obligations and what transparency and consumer protection obligations may follow.

Intellectual property is another concern.

“For example, who owns the outputs — the AI user, the AI vendor or the business customer if the output is or supports a service or deliverable, or the third party who may have licensed data used as an input?” Robinson asks. “Do the inputs violate contractual or IP licensing restrictions?”

Robinson says questions about accuracy and liability for AI-generated output are growing as AI agents learn how to execute transactions and make decisions.

Most businesses are buying — not building — AI tools, he notes. That carries its own challenges.

“Companies may be inheriting risks from commercial third-party tools whose data practices, security controls, model training, contractual terms, indemnities, audit rights and model behaviors they may not fully understand or control,” Robinson says.

Meanwhile, all sorts of issues continue to mount in the workplace.

They include so-called shadow AI use by employees using personal accounts or uploading company or personal information into public tools; legal requirements around using AI for decisions on employment, housing, credit, insurance and benefits eligibility; and the practical task of training employees to use AI tools responsibly.

DeGruy is seeing shadow AI use as well.

“Employees use AI tools without organizational oversight, often before companies have established appropriate guardrails around their use,” she says.

Companies can expose themselves to legal, security and compliance risks when employees enter sensitive or proprietary information into non-enterprise AI platforms and when AI capabilities are introduced into software products faster than organizations can assess and govern them, says deGruy.

On the positive side, these wonder tools can streamline operations and unlock efficiencies that weren’t possible just a few years ago, says deGruy.

Robinson says there is pressure for companies to use AI to increase productivity, efficiency and revenue while keeping costs down.

All the while, their information security officers and cybersecurity teams are facing AI-enabled threats.

As a member of Bradley’s AI team and a self-described “AI legal nerd,” deGruy has found that the best way to stay current is to use available AI tools, make mistakes and learn.

“Over the last several years, I’ve made AI a central focus of my practice because the legal questions surrounding these tools are no longer theoretical — they’re showing up in boardrooms, contracts, regulatory inquiries and litigation,” deGruy says.

Even though AI is an extraordinary tool, it can spit out information that is “confidently incorrect,” she says.

Without transparent conversations and defined processes for verification, businesses risk relying on information that may be inaccurate, incomplete or lacking critical nuance.

“AI remains a tool, not a substitute for human judgment,” says deGruy.

Robinson says AI threats for business clients fall into four main categories. The first is regulatory enforcement. State attorneys general are becoming aggressive. Federal agencies can use existing laws to address AI misuse.

“Businesses need to understand that ‘we bought the tool from a vendor’ is not a defense. Regulators are scrutinizing anyone who deploys AI in ways that produce harmful outcomes,” he says.

The second risk area is cybersecurity. Bad guys move aggressively and quickly. Deepfakes can compromise emails, impersonate executives and commit financial fraud.

One engineering firm lost $25 million after an employee authorized wire transfers during a video call where every other participant was an AI-generated deepfake, Robinson notes.

“Businesses also need to watch for AI-enabled phishing, voice cloning, prompt-injection risks, data leakage and attacks on AI systems themselves,” he adds.

Cyber insurance carriers are increasingly focused on whether companies have appropriate controls for vendor access and sensitive data.

The third threat area he sees is particularly relevant in Alabama — algorithmic bias and discrimination.

Federal civil rights laws such as Title VII and the ADA apply to AI-driven employment decisions. Others may apply in lending, housing or insurance.

“For example, if a company uses an AI recruiting tool that systematically (but unintentionally) disadvantages candidates based on race, gender, age, disability or another protected characteristic, that company may be on the hook — not just the software vendor.

“You can’t simply ‘blame the algorithm,’” says Robinson.

The fourth threat is competitive risk.

“Businesses that fail to thoughtfully adopt AI risk falling behind, but those that adopt it recklessly risk regulatory penalties, lawsuits, cyber incidents, operational disruption and reputational harm,” he says.

DeGruy agrees, saying the biggest threat for businesses is “moving faster than you can govern.”

Robinson likes a “Goldilocks approach” — coordinated implementation with safeguards adopted and enforced across the board.

“It takes a village, but the businesses that will come out ahead are the ones building governance frameworks now — inventorying their AI tools, training their people, building in accountability testing and monitoring high-risk uses, and working with counsel and other experts who understand this space,” says Robinson.

DeGruy gives the same advice to any business leader: “Don’t outsource your AI literacy to a single employee or department.”

Many organizations are focused on what AI can do but spend too little time determining what AI should be allowed to do, what data it can access and what decisions require human oversight, she says.

Organizations need clear policies, training and transparent expectations around AI use before adoption becomes widespread.

The businesses that will be most successful with AI are “the ones putting the right guardrails in place early so they can capture AI’s benefits without creating unnecessary risk,” says deGruy.

Deborah Storey and Will Dickey are freelance contributors to Business Alabama. She is based in Huntsville and he in Birmingham.

This article appears in the August 2026 issue of Business Alabama.