AI in the Workplace and What Florida Businesses Need to Know
Artificial intelligence has quickly become part of how businesses operate, but adoption is outpacing many companies’ rules for using it.
Employees are using AI to draft documents, research subjects, analyze information, communicate with customers and complete administrative work. Businesses are also incorporating the technology into recruitment, employee management and other decisions affecting their workforce.
Recent Gallup research into AI use in the U.S. workplace shows how widespread AI use has become. As of mid-2026, 52% of U.S. employees used AI at work, 30% at least a few times a week, and 47% said their organization had integrated AI tools.
For Florida businesses, AI can save time and improve productivity, but it can also raise legal issues that center around employment decisions, confidential information, privacy concerns, customer data, contracts, and intellectual property.
Understanding where AI is used—and putting appropriate safeguards around higher-risk uses—can help businesses benefit from the technology without creating avoidable legal problems.
Contents
- How are businesses using AI in the workplace?
- Why does workplace AI create legal issues for employers?
- Can Florida employers use AI when making employment decisions?
- Can employees put confidential information into AI tools?
- What does AI mean for customer data and privacy?
- Who owns work created with generative AI?
- What should businesses look for in AI vendor contracts?
- What AI laws apply to Florida businesses?
- What should an AI workplace policy include?
- What should Florida businesses do now?
- Key takeaways
- Frequently asked questions
How Are Florida Businesses Using AI in the Workplace?
For many companies, AI adoption hasn't started with a formal company-wide technology project. It has happened one employee or department at a time.
For instance, marketing teams may use AI to refine proposals and other written materials, while salespeople use it to draft emails. Managers can summarize meetings, analysts can work through large datasets, and HR teams may use AI-powered software to screen, sort, or rank job applicants.
According to Gallup's July 2026 workplace research, writing and editing were the most common uses among employees who use AI, at 51%. Search and research followed at 49%, while 39% used AI for general assistance or problem-solving.
Other workplace applications include:
- Data analysis and identifying patterns;
- Developing or editing presentations;
- Writing and troubleshooting software;
- Automating repetitive processes;
- Scheduling and task management; and
- Screening or assessing job candidates.
Employees also report productivity benefits. Gallup found that 77% of employees using AI for coding or automation said it had an extremely or somewhat positive effect on productivity. The figure was 76% for presentation creation or slide deck creation, 75% for data science or analytics. Sixty-eight percent of employees who use AI for writing and editing say it has improved their productivity, as do 65% of those using it for search or research.
The challenge for employers is that adoption can happen without much oversight. An employee can open a publicly available AI application and start using it within minutes, without necessarily knowing what happens to information entered into the system, whether the output is reliable or what contractual terms govern its use.
Indeed, management can then find itself with AI being used across the business without a clear picture of which tools are involved or what company information they are receiving.
Why Does Workplace AI Create Legal Issues for Employers?
Regina M. Campbell, Esq., Managing Partner at The Campbell Law Group, has spent years advising business owners on legal issues involving employees, contracts, confidential information and company operations. Drawing on that experience, Regina explains that adopting new technology does not remove a business’s underlying legal responsibilities:
“Technology can change the way a company operates, but it doesn't shift responsibility away from the business. If an AI system influences an employment decision, handles confidential information or becomes part of how a contractual obligation is performed, the company still has to answer for the decisions it makes and the obligations it owes. You can't outsource that responsibility to the technology.”
Using AI doesn't change a business's existing legal obligations. Employment discrimination laws still apply when software helps screen or select candidates. For instance, employment discrimination laws still matter when software supports hiring decisions. Confidential information must still be safeguarded when employees enter it into outside AI tools. And contractual duties remain in place whether the work is done by people, by AI, or by both.
The level of risk depends heavily on what the technology is being asked to do. Tasks such as routine drafting or administrative assistance generally presents fewer concerns than applications involving job applicants, employee performance, confidential records, or sensitive customer information.
The National Institute of Standards and Technology's voluntary AI Risk Management Framework (the “NIST”) was developed to help organizations identify and manage risks associated with artificial intelligence. NIST has also published a Generative AI Profile that addresses risks specific to generative AI systems.
For businesses, the underlying principle is relatively simple: as the consequences of an error increase, so should human review and oversight.
Can Florida Employers Use AI When Making Employment Decisions?
Florida employers can use AI-assisted employment tools, but federal employment discrimination and disability laws still apply when those tools influence employment decisions.
AI and automated technologies may be involved in:
- Recruiting and advertising vacancies.
- Screening résumés and applications.
- Assessing candidates.
- Conducting or analyzing video interviews.
- Monitoring employees.
- Measuring productivity or performance.
- Setting or recommending compensation.
- Identifying employees for promotion.
- Informing termination decisions.
The U.S. Equal Employment Opportunity Commission's guidance on AI specifically identifies recruiting, screening, hiring, employee monitoring, productivity assessment, wage setting, promotion, and termination as employment activities in which AI or automated technology may be used.
AI Can Still Lead to Employment Discrimination
Federal employment discrimination laws continue to apply even when AI is involved.
A seemingly neutral system can create legal problems if its use produces an unjustifiable discriminatory effect on people with a protected characteristic.
Consider a Florida company receiving several hundred applications for a position. It purchases software that automatically ranks candidates, expecting the technology to make recruitment more objective. Before relying on those rankings, the employer should understand how the system reaches its recommendations and whether it could disadvantage particular groups.
Relevant questions include:
- What information does the system consider?
- Is that information genuinely relevant to the job?
- Has the tool been tested for adverse effects on protected groups?
- How much weight does management give its recommendation?
- Can a person review or challenge the result?
- How does the process handle applicants who require a reasonable accommodation?
Disability discrimination presents another concern. The Department of Justice enforces disability discrimination laws with respect to state and local government employers. The Equal Employment Opportunity Commission (EEOC) enforces disability discrimination laws with respect to employers in the private sector and the federal government. The obligation to avoid disability discrimination in employment applies to both public and private employers. There are three main ways an employer's use of algorithmic tools can violate the ADA: 1) failing to provide reasonable accommodations needed for a fair and accurate assessment, 2) using a tool that screens out a disabled person who could do the job with accommodation, or 3) using a tool that makes improper disability-related inquiries or medical examinations. A single tool can be unlawful for one or several of these reasons.
AI is only one area where changing workplace practices can affect an employer's legal responsibilities. Read our update on recent developments in employment law for more on issues that Florida employers need to consider.
Can Employees Put Confidential Company Information Into AI Tools?
Employees should not put confidential or sensitive company information into public or unapproved AI tools unless the business has specifically authorized that use.
This is one of the most immediate AI risks because it can arise without a company formally adopting the technology.
For example, an employee may be asked to review a lengthy client document and prepare a summary. To save time, they copy the document into a generative AI tool. The document may contain confidential client information, financial details, or other sensitive material that has now been shared with an external provider.
Regina M. Campbell, Esq. sees an important distinction between what the employee intends to do and what may actually happen to the company's information:
“The employee may be trying to save 30 minutes of their day, but in doing so they could put confidential business or client information into the hands of a third party. Once that information leaves the company's control, the consequences aren't determined by whether the employee meant any harm. Businesses need clear rules about what can be shared with AI systems because protecting confidential information can't depend on employees recognizing every legal or contractual risk in the moment.”
Sensitive information could include:
- Customer or client information.
- Non-public financial results.
- Pricing and margin information.
- Confidential contract terms.
- Business plans.
- Employee information.
- Proprietary methods or processes.
- Source code.
- Trade secrets.
- Information the company has contractually agreed to keep confidential.
What happens to information entered into an AI system depends on the product, account type, settings and contractual terms governing the service.
Employers should therefore know which AI products employees may use and establish clear rules about what information they can provide.
Existing confidentiality provisions, employment agreements and contractor agreements may also need review. Agreements written before generative AI became commonplace may prohibit unauthorized disclosure without specifically addressing how employees now interact with third-party AI systems.
Contracts need to reflect how the company actually operates. Changes in working practices, including the growing use of generative AI, can make older contractual language worth revisiting.
AI is another reason businesses may need to revisit agreements written before their working practices changed. Our guide to implied terms in business contracts looks more closely at how written and unwritten obligations can affect commercial relationships.
What Does AI Mean for Customer Data and Privacy?
When an AI system receives personal information about customers, employees or other individuals, businesses need to understand how that information will be handled.
Before personal data is processed through an AI system, consider:
- What information the system receives.
- Where that information is processed.
- How long the provider keeps it.
- Whether the provider can use it for other purposes.
- Whether the provider shares information with other parties.
- What security protections apply.
- What happens to the information when the business stops using the service.
The Florida Digital Bill of Rights became effective in 2024. Its application is narrower than its title may suggest and depends on statutory definitions and thresholds.
For businesses within its scope, Florida law requires covered controllers to limit personal data collection to information that is adequate, relevant, and reasonably necessary for the disclosed purpose. Covered controllers must also establish, implement and maintain reasonable administrative, technical and physical data security practices appropriate to the information involved.
Businesses outside the scope of that law may still have privacy obligations under other state or federal laws, industry-specific requirements or contractual duties.
A Florida-based company with employees, customers or operations, in other states may also encounter requirements outside Florida.
AI data handling should therefore form part of the company's broader privacy and information-security practices, not simply its IT strategy.
Who Owns Work Created With Generative AI?
The ownership and copyright status of AI-generated work depends partly on how the material was created and the extent of human authorship involved.
For instance, businesses are already using AI to assist with:
- Marketing copy,
- Illustrations and graphics,
- Software code,
- Reports,
- Training materials,
- Presentations,
- Website content, and
- Product concepts.
If a company intends to treat that material as an intellectual property asset, the creation process can matter.
In its report on copyrightability and artificial intelligence, the U.S. Copyright Office concluded that generative AI outputs may receive copyright protection when a human author contributes sufficient expressive elements. Human selection, arrangement or modification may qualify depending on the circumstances. Merely providing prompts, however, doesn't automatically provide the human authorship required for copyright protection.
The commercial consequences may only become apparent later. For example, a company may pay an employee or contractor to create an important visual asset that is produced almost entirely using generative AI. If the business later wants to license the material or prevent a competitor from copying it, questions may arise over whether the work qualifies for copyright protection and which elements are protected.
Businesses also need to consider potential third-party intellectual property issues when they use AI-generated material publicly or commercially.
Contracts with employees, agencies and contractors may therefore need to address:
- Whether generative AI may be used,
- When AI use must be disclosed,
- Who owns AI-assisted work,
- Responsibility for reviewing outputs,
- Restrictions on entering company intellectual property into external systems, and
- Responsibility for third-party intellectual property claims.
Businesses should consider these issues when reviewing commercial agreements and business contracts.
What Should Businesses Look for in AI Vendor Contracts?
An AI subscription can look like any other piece of office software. The contractual consequences may be very different when the product receives sensitive information or becomes involved in important business decisions.
Before connecting an AI product to company systems or allowing it to process commercially sensitive information, businesses should examine the terms governing the relationship.
Relevant questions include:
- Company data – Who owns information entered into the system?
- Training – Can the provider use company data to train or improve its AI models?
- Outputs – What rights does the business have over material generated by the system?
- Security – What commitments does the vendor make concerning security and data breaches?
- Confidentiality – How does the agreement protect confidential company information?
- Liability – What happens if inaccurate output causes financial or legal harm?
- Intellectual property – Does the vendor provide protection or indemnification for certain third-party claims?
- Changes to terms – Can important contractual terms be changed without the company's agreement?
- Termination – What happens to company information after the relationship ends?
The level of review should reflect how the product will be used. A writing tool used to improve non-confidential internal emails may require relatively limited scrutiny. A system with access to HR records, customer databases or financial information warrants considerably more.
As an AI system becomes more closely connected to key business operations, both the technology and the vendor contract deserve greater scrutiny, especially when the system handles sensitive information or plays a role in significant business decisions.
What AI Laws Apply to Florida Businesses?
As of August 2026, Florida doesn't have a broad private-sector workplace AI statute regulating the everyday use of artificial intelligence by all employers.
That doesn't mean Florida businesses have no legal obligations. Existing laws and contractual duties may apply in areas including:
- Employment discrimination and disability discrimination,
- Privacy and data protection,
- Intellectual property,
- Consumer protection,
- Confidentiality, and
- Employment and commercial contracts.
Florida lawmakers have also considered broader AI legislation during 2026. Two proposals are particularly relevant:
- CS/SB 482, the Artificial Intelligence Bill of Rights, passed the Florida Senate during the regular legislative session before dying in the House in Messages on March 13, 2026.
- SB 2-D, another Artificial Intelligence Bill of Rights, passed the Senate during a subsequent special session but died in the House Information Technology Budget & Policy Subcommittee on April 29, 2026.
Neither proposal became law. Florida businesses should therefore avoid treating provisions contained in those bills as current legal requirements. Notwithstanding, Florida regulates AI through several targeted laws and court rules rather than one comprehensive AI act. Current requirements address deceptive AI-generated political advertising, nonconsensual sexual deepfakes, generated child sexual abuse material, consumer-data profiling, AI-assisted court filings, government AI oversight, and certain AI tools used through a K–12 grant program. Their introduction does show that AI regulation remains an active issue in Florida.
Businesses operating across state lines may also encounter AI requirements enacted elsewhere that apply to employees, applicants, customers or other activities outside Florida.
For Florida companies, the immediate priority is ensuring current AI use complies with existing laws and contractual obligations.
Because AI issues can cross employment, privacy, contract and corporate governance matters, companies without an internal legal department may find that AI becomes an ongoing governance issue. This can form part of outside general counsel support as a company's use of the AI technology develops.
What Should an AI Workplace Policy Include?
A workplace AI policy should tell employees what they can and can't do with artificial intelligence while performing work for the company.
For many businesses, banning AI altogether may be unrealistic. Employees may already be using it, and legitimate applications can save time and improve productivity.
A useful policy establishes boundaries employees can understand and management can realistically enforce.
1. Approved AI Tools
Employees should know which AI systems the business has reviewed and approved.
A policy should explain:
- Which tools are approved,
- Who can approve a new tool,
- Whether employees can create accounts themselves, and
- When IT, management or legal review is required.
This helps prevent employees from creating accounts across numerous platforms using company information without management knowing where business data is being processed.
2. Confidential and Sensitive Information
Employees need clear guidance on what information they must not enter or upload into public or unapproved AI systems.
For instance, a policy should provide practical examples rather than relying solely on the phrase “confidential information.” These might include customer records, contracts, pricing, financial information, passwords, employee information, source code, and unreleased business plans.
Employees should understand the restriction without making a legal judgment every time they use an AI tool.
3. Human Review of AI Output
Generative AI can produce inaccurate information while presenting it confidently.
Employees remain responsible for checking work before publishing it, sending it to a customer, or using it to make an important business decision.
Areas requiring particular care can include:
- Financial analysis,
- Customer-facing advice,
- Contractual language,
- Employment decisions,
- Legal or regulatory material, and
- Public statements made on behalf of the company.
The U.S. Department of Labor's published AI best practices for employers and developers have also identified human oversight for significant employment decisions, transparency, worker training and protection of worker data as relevant considerations. The Department notes that its 2024 material may not reflect current federal policy so businesses should treat it as reference material rather than a statement of current legal requirements.
4. Employment Decisions
Managers and HR teams need clear rules governing when AI may be used in decisions concerning applicants and employees.
Where automated systems are involved, the company should understand how the AI tool works, review outcomes, and have a process for handling accommodation requests.
A software recommendation shouldn't substitute for appropriate management judgment.
5. Intellectual Property and AI-Generated Work
The policy should explain when AI-generated material can be used commercially and when it requires further review.
Depending on the business, this may include rules covering:
- Copyrighted source material,
- Company intellectual property entered into prompts,
- AI-generated software code,
- Images and marketing assets,
- Disclosure of AI use to customers, and
- Ownership of work created with AI assistance.
Clear rules in these areas can help businesses avoid uncertainty over ownership and reduce the risk of creating, publishing or selling AI-assisted work that may infringe on someone else's intellectual property rights.
6. Accuracy and Verification
Employees need to know when information generated by AI requires independent verification.
This is particularly important for statistics, quotations, legal information, financial information, citations and other factual claims. AI systems can produce plausible information or sources that are inaccurate or don't exist.
Notwithstanding, the employee and the business remain responsible for the finished work.
7. Approval and Responsibility
Responsibility for AI use needs to be clearly assigned.
In a larger organization, responsibility may be divided between legal, HR, IT, security, and management. A smaller Florida business may assign it to a senior manager or owner and obtain outside advice when necessary.
Employees should know who can answer questions, approve new tools, and decide how uses outside the existing policy should be handled.
AI policies work best as part of a business's wider approach to workplace rules rather than as a document employees rarely see. Read our guide to why businesses need an employee handbook for more on establishing clear policies and expectations for employees and management.
What Should Florida Businesses Do About AI Now?
A sensible starting point is to find out how AI is already being used inside the business.
1. Audit Current AI Use
Ask employees and department leaders which AI systems they use and what they use them for.
Regina M. Campbell, Esq. advises business owners to establish the facts before deciding what their AI policies should look like.
“You can't create an effective policy around assumptions. I would first want to know which AI tools are actually being used, who is using them, what information employees are putting into those systems, and whether AI is influencing important decisions. Once you understand what is happening inside the business, you can decide where controls are needed instead of writing rules for risks you think you have.”
The audit should identify:
- The name of each AI product,
- Which employees or departments use it,
- What tasks it performs,
- What information is entered into it,
- Whether it connects to company systems, and
- Whether its output affects customers or employees.
This gives management a factual starting point for deciding which uses require a greater oversight.
2. Separate Low-Risk and High-Risk Uses
Routine administrative tasks may require relatively little oversight. Uses involving confidential data, personal information, customers, financial matters, or employment decisions generally warrant closer review.
A risk-based approach lets employees use approved tools for routine work while applying stronger controls where an error could have significant consequences.
3. Review Important Contracts
Review the terms governing AI systems that handle important company information or form part of significant business processes.
Customer, employment, and contractor agreements may also need review if AI has changed how work is performed or confidential information is handled.
The objective is to identify gaps between existing contractual obligations and current business practices.
4. Put the Rules in Writing
Once the business understands how AI is being used, it can create a written policy that reflects its actual operations.
Generic templates have limits. A construction company, professional services firm, retailer and technology business may use AI differently and hold different types of sensitive information.
The policy should address the company's actual risks and working practices.
5. Train Employees
A policy stored in an employee handbook won't accomplish much if nobody understands it.
Training doesn't need to turn employees into AI experts. They should know:
- Which tools they may use,
- Which information they must keep out of AI systems,
- When AI-generated work needs checking,
- Which uses require approval, and
- Who to ask when they aren't sure.
Regular, practical training helps employees apply the policy to their day-to-day work and gives them a clear process to follow when they encounter a situation the policy doesn't specifically address.
6. Review the Policy Regularly
AI products and working practices change quickly.
Businesses should revisit their policies when they introduce an important new system, change how AI is used, begin processing new types of information or encounter relevant developments in the law.
For companies without an internal legal or compliance team, periodic AI review can be part of broader TCLG Advisory services outside general counsel.
Key Takeaways for Florida Businesses Using AI
AI can bring real workplace benefits, but businesses need visibility into where the technology is used and appropriate safeguards for higher-risk applications.
For Florida business owners, the main points are:
- AI is already part of everyday work. Gallup found that 52% of U.S. employees were using AI in their role by mid-2026, while 47% said their organization had integrated AI tools.
- Existing laws still apply when AI is used. Employment discrimination, disability, privacy, confidentiality, contract and intellectual property issues can arise even without a law specifically labelled as an "AI law."
- AI-assisted hiring requires care. Employers should understand how automated tools assess applicants and employees rather than relying solely on a vendor's claims.
- Employees need clear rules about confidential information. Businesses should identify which information must never be entered into public or unapproved AI systems.
- AI vendor agreements shouldn't be treated as routine software terms. Data use, confidentiality, security, ownership and liability provisions can matter considerably when a system becomes part of important business operations.
- Human review should reflect the consequences of an error—the more important the decision or output, the greater the need for independent checking.
- An AI policy should reflect how the company actually works. Businesses should understand current employee use before deciding what rules are appropriate.
- Florida's AI laws may continue to change. Proposed legislation failed to become law in 2026, but businesses should continue to watch state and federal developments.
The practical approach is to understand how AI is already being used, identify the greatest risks, and put appropriate policies and oversight in place.
Preparing Your Florida Business for AI in the Workplace
Responsible AI use starts with understanding how the technology fits into existing operations, employment practices, contracts and legal obligations.
Business owners need visibility into which AI systems employees use, what information those systems receive, and where automated tools influence decisions affecting customers, employees, or the company itself. Policies, agreements and management oversight can then be updated accordingly.
At The Campbell Law Group, we advise Florida companies on business law, contracts, employment matters, corporate governance, and risk management. If AI has already become part of your company's day-to-day work, reviewing those practices now can help identify potential problems before they develop into disputes, compliance issues, or unnecessary business risk.
If you're already using AI in your business, introducing new AI tools, or aren't sure whether your current policies and agreements provide enough protection, contact The Campbell Law Group. Our attorneys can review how AI is being used across your company, identify potential legal concerns and help you put the right safeguards in place.
Frequently Asked Questions
Does a Florida Business Need an AI Policy?
As of August 2026, Florida has no general law requiring every private business to maintain a workplace AI policy. However, a written policy can set clear rules for approved tools, confidential information, human review, and employment decisions.
Can Florida Employers Let Employees Use ChatGPT and Other Generative AI Tools at Work?
Yes. Employers can allow generative AI at work but should establish which tools and uses are permitted and what company, customer or employee information must not be entered into external systems.
Can an Employer Be Liable if an AI Hiring Tool Discriminates Against an Applicant?
Potentially. Federal employment discrimination laws still apply when employers use AI or automated technology in employment decisions. Using a third-party AI vendor does not automatically remove the employer's legal responsibilities.
What Information Should Employees Never Put Into an AI Tool?
Employees should not enter confidential, proprietary or sensitive information into public or unapproved AI systems. This may include customer records, contracts, financial information, employee data, source code, trade secrets and other information the business is required to keep confidential.
Who Owns Content Created by AI for a Business?
It depends on how the work was created. Copyright protection generally requires sufficient human authorship, so businesses should not assume that material generated primarily by AI receives the same copyright protection as conventionally created work.