What Are Your Employees Telling AI?

The water cooler moved inside an AI interface. Unlike the water cooler, it has a log file.
By Jacqueline Lombardo
Facilitator, Operations Manager
Boomer Consulting, Inc.
For the past few years, firms have focused heavily on what employees should and shouldn’t put into AI. Don’t enter client data. Don’t upload confidential information. Don’t include personally identifiable information. Use approved tools. All of that matters, but I think we’re missing another side of the conversation: what are employees telling AI about themselves?
Marc Staut, CITO & Shareholder of Boomer Consulting, and I recently presented on this topic at Boomer Circle Summit, and the conversations afterward reinforced something for me: many firms simply haven’t thought about this yet. We tend to think about AI as a productivity tool employees use to summarize documents, draft emails, brainstorm ideas and get work done faster. But people are also using AI to work through much more personal questions.
An employee might ask how to tell their manager they’re overwhelmed, whether ADHD could be affecting the way they prioritize work, how to handle an uncomfortable interaction with a coworker or whether they’re being treated fairly. Those are conversations that historically happened with a friend, spouse, coworker, mentor, manager or HR. Increasingly, they may be happening with AI first.
Why AI Can Feel Safer Than HR
As someone who works in HR, I understand why. Bringing a difficult issue to another person comes with perceived risk. Employees may wonder whether their manager will think differently about them, whether HR will need to document the conversation or what happens once they say something out loud.
AI removes much of that friction. There’s no facial expression to read, no difficult meeting to schedule and no perceived power differential. Someone can open a tool at 11 p.m., type what they’re actually thinking and get an immediate response. That can make the interaction feel incredibly private. The challenge is that feeling private and being private aren’t necessarily the same thing.
The Water Cooler Has Moved
Depending on the platform, account type and firm configuration, AI interactions may be logged, retained or accessible. That creates a very different situation from an informal conversation between coworkers.
Consider an employee who uses AI to think through a medical condition they haven’t disclosed to the firm, a workplace concern involving several team members or a conflict with their manager. The same issue exists on the other side: a manager could use AI to work through a difficult employee situation and include information they would never put into an email.
At that point, the questions get much bigger. Who can see those conversations? How long are they retained? What happens when someone deletes one? Could they become relevant during an investigation or litigation? And, perhaps most importantly, does anyone at the firm actually know the answers? Because “I think this is how it works” is probably not the AI governance strategy we want to rely on.
This Isn’t Theoretical Anymore
We’re already seeing AI conversations surface in litigation. In 2026, an expert retained by 3M in litigation related to the deadly Watson Grinding explosion used ChatGPT while developing his expert report. Plaintiffs’ attorneys ultimately obtained 365 pages of his prompts and ChatGPT’s responses. One prompt asked the tool to help “show how 3M is 0% at fault.” That language did not remain in the final report, but the underlying prompt history did, and plaintiffs’ counsel later used those conversations to question the expert.
That distinction matters. The finished document showed what the expert ultimately decided to say. The AI history showed part of the thinking that happened along the way.
This does not mean every AI conversation is automatically discoverable. Questions involving relevance, privilege, retention, control and the specific circumstances still matter. But the case demonstrates that AI conversations can become part of litigation and may reveal context, assumptions or intent that never appear in a final document. For firms, that should be enough to move this conversation out of the “someday we should think about that” category.
Most AI Policies Are Solving for Only Half the Problem
Most AI policies understandably focus on input: what employees can put into AI, what data is prohibited and which tools are approved. Those policies are primarily designed to protect client and firm information. But what happens when the information an employee is entering is about themselves?
That exposes three gaps many firms need to examine. First is data retention: does someone at the firm know how long AI conversations are retained and under what circumstances they are deleted? Second is employee transparency: do employees understand what may be logged, retained or accessible when they use firm-approved AI tools? Third is HR and IT alignment: has HR actually sat down with IT to map who can see what, when information may be reviewed and who owns the decision if something sensitive surfaces?
IT may understand exactly how the technology is configured without considering what happens if an administrator encounters sensitive employee information. HR may understand the employee-relations implications while having no idea what administrators can actually see. Leadership may assume someone else has figured all of this out. That is how gaps form.
Start With Visibility, Not Another Policy
When a new risk emerges, the instinct is often to update the policy. I’d start one step earlier. Before writing another paragraph about AI use, HR, IT, leadership and legal counsel should map the actual environment: which platforms employees are using, what each platform retains, who has administrative access, what those administrators can see, what happens when conversations are deleted and how AI records would be handled during litigation or a legal hold.
You may find that your written AI policy and your actual technology environment are telling two very different stories. That’s much better to discover during an internal conversation than during a deposition.
The Next AI Governance Conversation Is About People
The answer is not to scare employees away from AI or tell them never to use it for anything personal. These tools can be incredibly useful for organizing thoughts, preparing for a difficult conversation or figuring out what questions someone needs to ask. The goal should be informed use.
Employees need to understand the environment they’re operating in, and firms need to understand the environment they’ve created. We’ve spent a lot of time asking what AI knows about our clients. Now we need to start asking what AI may know about our employees.
Because AI isn’t only changing how people work. It’s changing where people think out loud. That means AI governance can’t belong exclusively to IT, HR or leadership. Each sees a different part of the risk, and firms need all three perspectives in the room.
So before scheduling another AI policy refresh, start with a simpler conversation: What can our employees tell our AI today, what does that interaction leave behind, who could potentially see it and what would we do if something sensitive surfaced? You may not love every answer, but it’s far better to find them now than when someone else is asking the questions.





Comments