Artificial Intelligence and Emerging Litigation Risks for Businesses

Artificial Intelligence and Emerging Litigation Risks for Businesses

AI is no longer a distant prospect. The National Artificial Intelligence Centre reported that 40% of Small and Medium Sized Enterprises (‘SMEs’) have adopted AI for business use as at Q4 2024, and growth appears to be building quarter-on-quarter. 

With development moving at pace, governments and businesses are grappling with how to best regulate this emerging technology without denying the opportunities and benefits it brings.

National AI Plan 

On 2 December 2025, the Australian Government released its National AI plan, a comprehensive roadmap to building an AI-enabled economy that harnesses the full potential of artificial intelligence for the benefit of all Australians. The Plan outlines three broad goals: capturing the opportunities, spreading the benefits, and keeping Australians safe. 

This article focuses on the third goal and examines the Australian Government’s regulatory approach to AI. We’ll discuss some of the ways that SMEs are currently using AI in their businesses, the new litigation risks emerging, and practical steps that can be adopted to mitigate these risks.

What Laws Regulate AI Use? 

On 5 September 2024, the Australian Government published a proposals paper exploring mandatory guardrails for AI use in high-risk settings (an approach broadly consistent with the EU model) and invited public consultation. 

However, the National AI Plan that was subsequently released does not appear to further this proposal. The Plan reflects a lighter-touch approach, by referencing existing laws, regulators and agencies in addressing and mitigating AI-related harms. It remains to be seen whether this will be sufficient as the technology develops, and whether the Government will proactively introduce dedicated AI laws in the future. 

The Legal Profession and AI

The legal profession offers a useful lens for understanding how institutions are working to set boundaries around AI use, while allowing the profession enough flexibility to fully benefit from what the technology has to offer.

Australian Courts have taken steps to regulate how lawyers may use AI tools in proceedings. The New South Wales Supreme Court Practice Note SC Gen 23 came into effect on 3 February 2025. It sets out general guidance as well as imposes prohibitions, including an explicit ban on using AI to draft affidavits, witness statements, character references, or any material intended to reflect a deponent’s or witness’s evidence or opinion, or other material tendered in evidence or used in cross examination. 

The Federal Court of Australia published the Generative Artificial Intelligence Practice Note (GPN-AI) on 16 April 2026. It identifies circumstances where particular caution is required, provides guidance on handling confidential, suppressed or private information, and sets out the consequences that may follow if Generative AI is used in a way that is inconsistent with the Practice Note or the Court’s orders or directions. 

While Courts are generally perceived to be guardians of tradition, it is too simplistic to interpret that to mean an outright resistance to new technology. A recent speech given by Chief Justice Stephen Gageler revealed that the High Court will be trialing a single approved Generative AI tool for use under strict internal guidelines. 

This spirit of cautious engagement is playing out across the broader regulatory landscape. Businesses should check whether their industry or professional body has issued specific guidance on AI use, as regulators are increasingly stepping in to govern this space.

Common AI Use Cases for Small and Medium Enterprises (‘SMEs’)

  1. Everyday Knowledge Tasks

Businesses commonly use AI for everyday knowledge tasks, including summarising content, drafting reports and undertaking research. These uses are commonplace because they do not require significant retraining or system integration before AI tools can be used. The Australian Government’s six-month whole-of-government trial of Microsoft 365 Copilot, found that the tool was predominantly used to summarise information and rewrite content. Participants estimated time savings of up to an hour on tasks such as preparing first drafts and searching for information.

Main Regulatory and Litigation Risks

The main risks associated with using AI tools for everyday knowledge tasks is breach of privacy and reliance on inaccurate AI-generated information. Both these risks were the subject of an investigation into the use of ChatGPT by a Child Protection Worker (‘investigation’) conducted by the Office of the Victorian Information Commissioner. 

The investigation found that a Child Protection worker entered a significant amount of personal and delicate information into ChatGPT, including names and information about risk assessments relating to a child. The worker asked ChatGPT to assist in drafting a Protection Application Report, a report that is submitted to the Children’s Court to inform decisions about whether a child needs protection. Specifically, the Large Language Model played a role in describing the risks posed to a young child if they continued to live at home with their parents, and it contained inaccurate information which had the effect of downplaying the risks to the child. 

Breach of Privacy

The investigation identified a serious breach of the Information Privacy Principles. When personal and sensitive information was entered into ChatGPT, it was considered ‘disclosed’ to OpenAI. This is because it had left the effective control of the Department of Families, Fairness and Housing (‘DFFH’) and Open AI now holds that information and can determine how it is used. 

In a similar way, an employee who enters personal and/or sensitive information (potentially some types of customer data) into publicly available Generative AI tools risks breaching Australian Privacy Principles (‘APPs’). This information could be considered ‘disclosed’ to a third party when it leaves the organisation’s effective control. As well as reputational damage and brand erosion, businesses may also be subject to determinations and orders from the The Office of the Australian Information Commissioner (‘OAIC’) or in the most serious of cases, potentially be sued for a serious invasion of privacy under the new statutory tort that was introduced in 2024. 

Risk Mitigation Strategies

To manage privacy risks associated with the use of AI tools, businesses should consider the following: 

  • OAIC recommends that organisations do not enter personal information and in particular, sensitive information into publicly available generative AI tools. 
  • Adopt a Privacy by Design approach when considering and selecting the use of AI products for their business. This may include conducting a Privacy Impact Assessment to assess whether the use of AI is necessary and the best solution in the circumstances.
  • Provide training to all staff on privacy obligations specifically as they relate to AI use.

Reliance on Inaccurate AI-Generated Information

Generative AI models can produce outputs that are inaccurate but appear highly credible. The predictive nature of the model means it does not ‘understand’ the data it handles. Cases of ‘hallucinations’, where a Large Language Model perceives patterns or objects that are non existent, have been well documented. Inaccuracies can have significant flow-on effects which may result in harm, misinformation or unfair decisions. 

In the investigation referred to above, the Protection Application Report contained inaccurate information generated by ChatGPT, which had the effect of downplaying the severity of the actual or potential harm to the child. This had the potential to impact decisions made about the child’s care. Fortunately, the investigation found that the deficiencies in the report did not ultimately change the decision-making process in this case. However, the potential risk of harm that may result from relying on inaccurate information generated by AI tools is very real. 

Risk Mitigation Strategies:

Businesses can mitigate the risk of relying on inaccurate AI generated information (and the potential harm and litigation exposure that may follow), by selecting fit-for-purpose tools, understanding and communicating the system’s limitations, verifying data inputs, and maintaining human oversight throughout. 

  1. Using AI Tools for Note-Taking and Minutes

It is increasingly common for AI assistants to attend meetings, take notes, summarise content, draft action items and to circulate notes to attendees. Sometimes these functionalities are turned on by default without consideration of whether the tool is appropriate for the meeting in question. This is especially problematic for Board or Committee meetings, or in any meeting where sensitive information is discussed. Further, notes are sometimes automatically distributed without a review process in place to ensure the minutes or notes are accurate and/or suitable for circulation. 

Main Regulatory and Litigation Risks

Businesses should be aware that notes taken by AI may be required to be produced and could be used as evidence in court proceedings, like any other meeting notes.

The main risks associated with using AI for note-taking purposes include inaccuracies and hallucinations (notes may appear authoritative but contain errors or fabricated details), bias and distortion (nuanced discussions can be difficult to summarise), potential loss of legal professional privilege (businesses may unintentionally waive their legal professional privilege by uploading privileged documents to a third party AI tool) as well as cyber security and privacy concerns (the storage of notes on the cloud or similar may expose organisations to data breach). 

Risk Mitigation Strategies:

The Australian Institute of Company Directors (‘AICD’) and the Governance Institute of Australia’s joint statement on “Effective Board Minutes and the Use of AI” addresses some of the risks and limitations associated with using AI tools to generate meeting records. 

While the statement does not adopt the position that AI tools should never be used for minute-taking, they put forward recommended measures to safeguard the integrity of minutes if produced with the assistance of AI. These measures include:

  • Establishing clear policies and processes for the use of AI in drafting minutes and related document preparation
  • AI tools may need to be limited or disabled for certain portions of the meeting such as in-camera discussions or where legal advice or privileged information is discussed
  • A governance professional should always review and refine any output generated by an AI tool
  • Where third-party AI providers are used, there should be a clear understanding of where information is stored and what security/encryption measures are in place
  • Training for staff on AI use, risks and oversight
  • Regular review, audit and testing of the performance of AI tools and related processes

By treating AI-generated notes with the same level of review and scrutiny as manually prepared notes, businesses can better ensure that these records accurately reflect what was discussed and decided.

  1. Use of AI Tools in Recruitment

AI Tools are sometimes used in recruitment processes for tasks such as resume screening, candidate scoring and short listing, online pre-screening assessments and automated interviews. While these tools can improve efficiency, businesses should recognise that they may have an influence on which candidates are progressed. 

Main Regulatory and Litigation Risks

The primary risk of using AI tools in recruitment is algorithmic bias, where machine learning models produce systematic, unfair and discriminatory outcomes as a result of the biases embedded in the training data.

Recruitment processes are subject to anti-discrimination laws, and these laws likely apply irrespective of whether the decisions are made by humans or machines. If Courts take a purposive approach to interpreting these Laws (that is, the purpose of these laws is to prevent unfair exclusion from employment), then the use of AI as the decision-making mechanism is unlikely to serve as a defence. 

Risk Mitigation Strategies:

Businesses looking to leverage AI tools in recruitment should consider strategies to help ensure the processes remain lawful, non-discriminatory and defensible. 

The Inclusive AI at Work in Recruitment Employer Guidelines released by the Diversity Council of Australia (‘DCA’) outlines a 5-step process called T.R.E.A.D, which assists employers to venture carefully when considering the deployment of AI tools in recruitment. 

Broadly speaking, they suggest businesses should:

  • Team Up to assess Diversity and Inclusion impact 
  • Reflect on your readiness for inclusive AI recruitment
  • Educate your team about bias in recruitment 
  • Acquire expertise on how bias plays out in AI recruitment
  • Decide how to proceed inclusively in AI recruitment

The DCA has also developed a reflective assessment checklist for use at the ‘Decide’ stage of the process to help ensure any deployment of AI tools helps rather than harms workforce diversity. 

  1. Use of Chatbots on Commercial Websites

AI powered customer service chatbots are increasingly common on commercial websites, as they reduce purchase friction and help to improve customer experience. However, AI generated responses that mislead customers may expose businesses to litigation. 

Main Regulatory and Litigation Risks

The primary regulatory and litigation risk associated with using a chatbot for customer services is the potential for providing incorrect or misleading information, which exposes businesses to liability under Australian Consumer Law. The use of a chatbot is unlikely to provide a defence as consumer protection law generally focuses on the effect of the conduct on consumers, and not the mechanism by which it was delivered. 

Bunnings recently introduced an AI chatbot for customer service, which was later suspected to have provided instructions for completing electrical work that should only be performed by a licensed professional (without alerting the customer to this fact). This serves as a cautionary example of how even a well established business can be caught out when deploying AI tools if they do not have a full understanding of the capabilities, limitations and its potential for unintended consequences. 

Risk Mitigation Strategies

To mitigate the risk of chatbots providing incorrect or misleading information, businesses should build appropriate guardrails into any AI system that they deploy. Guardrails are the rules and boundaries that govern what an AI tool can do and say (as well as what it cannot do and say). Any limitations in the chatbot’s capabilities should be clearly disclosed to consumers, although disclaimers alone will not always be sufficient to avoid litigation. Customer interactions should be also actively monitored so that any issues can be identified and escalated early. 

Key Takeaways:

  • Existing laws, including privacy laws, competition and consumer laws, directors duties and workplace laws already apply to the development and use of AI.  
  • Businesses should conduct a thorough assessment of how these laws apply to their use of AI tools and seek legal advice where appropriate.
  • Consider whether any guidance issued by regulatory activities is relevant to your business or profession. 
  • Adopt an AI governance framework as a blueprint for how to design, deploy and oversee AI systems throughout its lifecycle. These may include technical guardrails, ethical guardrails and regulatory and legal guardrails. 

While litigation risks can never be eliminated entirely, businesses that take a proactive and informed approach to AI governance are well placed to minimise their exposure and adapt as the legal landscape continues to evolve in this space. 

This publication contains general information only and does not constitute legal advice. You should obtain professional advice tailored to your circumstances before acting on any information contained in this article.

Share this post: