AI tools don’t own the risk, your organisation does – Key risks when using generative AI in workplace investigations
As AI becomes part of everyday business, employers are increasingly using it to assist with analysing and summarising information in workplace investigations and disciplinary processes. When used appropriately, it can assist with reviewing data and lead to increased efficiency.
However using generative AI as a substitute for human analysis creates real legal risks.
Key takeaways for employers
- Update workplace policies to clearly address how AI can, and cannot, be used by employees.
- Understand how your organisation’s AI platforms store, process and use information.
- Never upload confidential employee information or legal advice into open source AI platforms.
- Verify all AI-generated material before relying on it, particularly if used in support of a decision making process following a workplace investigation.
Scenario
Consider this situation: You have just finished gathering evidence into a bullying complaint. To save time, you upload witness statements, interview notes, and legal advice you had received about a similar matter into an AI platform and ask it to summarise the evidence and generate a show cause letter. The task takes minutes instead of hours. The summary looks comprehensive. The letter seems persuasive. So, you sign it and send it.
But in the process, you may have exposed confidential employee information, waived legal professional privilege, and relied on AI-generated content that will later need to be explained if that employee brings an unfair dismissal or general protections claim.
Risk 1 – Disclosure of personal information
Information provided by employees during these processes is often subject to obligations of confidentiality, whether under privacy legislation, workplace policies, or commitments made by the employer during the investigation.
Employees provide this information on the understanding that it will be treated confidentially and only shared on a need-to-know basis.
While it can be tempting to use AI to summarise a document or draft a response, uploading employee information risks breaching these obligations, particularly where the employer does not understand or cannot control how the platform stores, processes, or uses that information.
The risks extend beyond privacy concerns. Uploading sensitive information to an AI platform may undermine employee trust and compromise the integrity of workplace investigations. Employees who discover that their complaint or personal information has been uploaded to an AI platform may lose confidence in the employer’s processes, and be less willing to participate in future investigations or raise concerns if they do not trust the organisation to handle their information appropriately.
This creates a practical problem for employers. Management of psychosocial hazards and effective workplace investigations rely on employees being willing to speak up. If trust in the process is undermined, issues that could have been resolved early may go unreported until they become much larger problems.
Risk 2 – Waiver of legal privilege
Many employers seek legal advice during workplace investigations and disciplinary processes to ensure that the processes they follow are defensible and procedurally fair.
That advice is generally protected by legal professional privilege, meaning it cannot be compelled to be disclosed. However, that protection depends on the advice remaining confidential.
Uploading legal advice or documents drafted for the purpose of court proceedings to open source AI platforms is inconsistent with maintaining confidentiality, and there have been cases where this has been held to have waived privilege.
The safest approach is to ensure that you do not upload legal advice or privileged documents into public AI platforms.
Risk 3 – Adoption of AI-generated output without verification
Some AI tools can be useful for summarising information and identifying patterns in data. Generative AI however cannot “think”, and should not be used as a substitute for proper human analysis.
This is particularly important when making findings following a workplace investigation, deciding whether to commence disciplinary action, or determining whether a person’s employment should be terminated. An AI-generated response might appear to be plausible and confident, but be totally wrong: An investigation summary may omit important contextual information. A chronology may contain errors. A show cause letter may refer to evidence that does not exist.
This will become an issue if a claim is later made. In the unfair dismissal context, the Fair Work Commission will make findings of fact about whether a ‘valid reason’ for dismissal exists. In the general protections context, the inquiry is what was exercising the mind of the decision maker. In either case, mere reliance on AI-generated output without proper verification is not going to be a good for employers.
Final thoughts
The question for many employers is no longer whether to use AI, but how to do so safely.
AI can assist employers to analyse information and prepare documents, but it does not own the consequences of its outputs. If sensitive employee information or legally privileged documents are no longer confidential, or a workplace decision cannot be properly explained, it is the employer that will be held accountable, not the AI platform.

