How can employers safeguard confidential information in the age of AI, and what should they do when an employee's use of AI tools puts that information at risk?
At our recent AI Agenda conference on 16 September, Carla Watling and Alistair Hayes led a breakout session on managing AI risk in the workplace. Using a case study, the session looked at how employers should respond to data misuse, investigate employee activity and preserve evidence.
One theme ran through the discussion was that AI no longer sits at the edge of workplace disputes. It’s often evident at each stage: in the evidence that first raises suspicion, in the investigation meeting and in the grievance that follows. Here are our key takeaways from the discussion.
Prompts and outputs are evidence…
In our case study, the first sign of misconduct came from prompts typed into the employer's own AI tool: suspicious requests to adapt a pitch for a new competing business, and questions about getting a business loan for a side venture. AI prompts and outputs can be a valuable source of evidence, but only if you know where to find them and act quickly. It’s also important to remember that they are "documents" for the purposes of the CPR, and that will be relevant when disclosure duties come into play.
…but don’t forget the basics
A detailed AI log can result in investigators overlooking the basics. Standard IT searches, such as emails and print logs, still matter. Early questions include what the employee accessed, whether the AI tool was open or closed, and whether personal data was involved, which could amount to a data breach.
The duty to preserve begins before any claim is issued
The duty to preserve documents is triggered once litigation is "in contemplation". From that point, routine document destruction must stop, and that includes GenAI logs. In practice, this means suspending relevant deletion processes, notifying employees of the documents to be preserved, and taking steps to prevent third parties from destroying material held on the employer’s behalf.
GenAI prompt and output logs are an easily overlooked category: they may sit outside the systems that IT teams instinctively think to preserve, be subject to shorter retention periods or automatic deletion, or be stored on the AI vendor’s infrastructure. If a litigation hold does not expressly extend to these systems, there is a real risk that relevant material is lost.
We have written in more detail about the fundamentals of document preservation and how they interact with GenAI tools in the workplace here.
Covert recording meets AI
Investigating this kind of misconduct is likely to involve face to face investigation meetings. In our case study, that presented an all too common risk of a covert recording by the employee.
Although this is not a new risk, linking the recording to an AI note-taking app - which transcribes and summarises the discussion and may send the data to a third-party server – adds a new dimension. This places confidential and sensitive data at risk, with the use of the tool potentially placing the recording in the public domain. Employers should check whether their disciplinary policy deals with covert recording and decide whether to treat it as a separate act of misconduct.
Our practical advice for employers
- Restrict and record access: limit who can see confidential information, and keep access logs.
- Set clear rules on AI use: a GenAI policy covering acceptable use, public tools and confidential information carries more weight when AI literacy training backs it up.
- Know where your data goes: understand how your internal AI tools store prompt and output data, and who can access it.
- Check your vendor terms: make sure third-party AI vendors can put a litigation hold in place when required.
These steps cost far less before a dispute begins than after it.
Explore more from AI Agenda 2026
On 16 September 2026, we hosted AI Agenda 2026 for senior leaders, legal experts and innovators exploring what it takes to deploy AI safely, strategically and at scale. Explore all the insights from other sessions - covering topics from agentic AI and governance to IP, procurement, litigation and leadership.





