Announcer: Welcome to the Ogletree Deakins podcast, where we provide listeners with brief discussions about important workplace legal issues. Our podcasts are for informational purposes only and should not be construed as legal advice. You can subscribe through your favorite podcast service. Please consider rating this podcast so we can get your feedback and improve our programs. Please enjoy the podcast.
Lauren Hicks: Thank you for joining us today. My name is Lauren Hicks. I’m a shareholder in Ogletree’s Indianapolis office. I’m here today with my colleague, a shareholder in our St. Thomas office, Simone Francis. Simone, thanks for joining me.
Simone Francis: Thank you for having me, Lauren. I am very excited about our conversation today.
Lauren Hicks: Me too. Today we’re talking about AI ethics in the workplace and specifically what happens when AI tools go wrong. I don’t mean wrong in the abstract kind of theoretical sense. I mean a CEO who followed ChatGPT’s legal strategy advice step-by-step deleted the logs and then kind of watched it all blow up in court.
Simone Francis: I love that we’re starting there because I think a lot of people hear AI ethics and think it’s going to be dry or hypothetical. It very much is the opposite.
Lauren Hicks: It’s not even a little bit dry. So, here’s what we’re covering today. First, the ethics rules that already apply to AI use and then we’re going to get into some cautionary tales, the real cases with real consequences and then some practical notes, specifically what you need to be thinking about in the AI and policy space.
So, let’s start with the rules. In July 2024, the ABA dropped Formal Opinion 512, which is the first formal ethics opinion on generative AI. And the key message, which I think is incredibly savvy, is no new rules are needed. The existing model rules already cover this.
Simone Francis: And that’s elegant in a way, isn’t it? It means that nobody gets to say, “Well, there’s no rule about AI as an excuse.” Also, the theme of existing rules already apply is something you will hear us repeat today because it is a key point to remember as you navigate this space.
Lauren Hicks: Exactly. So, let’s hit the big ones. Rule 1.1, competence. There’s a duty to keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology.
That means understanding how AI tools work, what data they ingest, how they score candidates if they’re being used in hiring, for example, and other places where bias enters the picture. Kind of the days of saying, “I don’t do technology,” are over. You have to be savvy in this space.
Simone Francis: Absolutely. Gone, retired, no longer available as an excuse, at least if you want to comply with ethical obligations.
Lauren Hicks: Absolutely. And then, Simone, we’ve got Rule 1.6, confidentiality. Lawyers cannot reveal information relating to the representation of a client and there’s a duty to make reasonable efforts to prevent inadvertent or unauthorized disclosure. And that applies to every single piece of client information typed into an AI tool.
Simone Francis: And that’s where it really gets practical. Consumer AI tools and others typically collect and store your inputs and they may use those inputs for model training and reserve the right to disclose data to third parties.
The North Carolina State Bar actually issued a formal ethics opinion in 2024 saying that lawyers should avoid inputting client-specific information into publicly available AI tools.
Lauren Hicks: Simone, while we’re on this point of confidentiality, what about the AI note-taker issue? Because that one is sneaking up on people pretty frequently.
Simone Francis: Lauren, that’s a great one. Think about all those AI-enabled meeting note takers that people are activating in call automatically. You need to think about permissions for activating them, policies for storing the transcripts, reviewing them for accuracy, and limiting who gets access to them. And here’s the kicker. What happens when litigation arises? Those notes are potentially subject to litigation hold and discovery by an opposing party.
Lauren Hicks: It’s kind of this thing that’s convenience now but headache later, I think.
Simone Francis: Exactly. I get concerned every time a note taker enters the room. And then just to round it out, Rule 1.4, communication. Means that if you’re using AI tools in your legal work, the client should know. For in-house folks, that means making sure that every member of leadership understands how AI is deployed in legal operations.
Rules 5.1 and 5.3 on supervisory responsibilities means that you need written AI use policies and human review of all AI-assisted work product. Let’s say that again, human review of AI-assisted work product. And Rule 3.3, candor, means if AI generates a legal citation, you are personally responsible for verifying it exists before you file a pleading.
Lauren Hicks: Which brings us perfectly to the cautionary tales because some people have not necessarily verified. So, let’s start with a couple of quick cautionary tales on the citation front.
Zachariah Crabill, a lawyer in Colorado, texted his paralegal, “I think all of my case citations from ChatGPT are garbage. I can’t even find the cases in Lexis.” Although the problem here, he’d already filed the motion. As a result, he was suspended and found to have violated several rules.
And of course there are other cases, that’s not the only one. For example, there was one in the Southern District of New York where attorneys filed a brief with six non-existent ChatGPT-generated case citations and were sanctioned and fined $5,000. And by the way, there is a growing list of these. They’re actually popping up on a weekly basis. So, Simone, what do you think about those?
Simone Francis: Those are very rough, but the case you teased at the top of our discussion is on a completely different level.
Lauren Hicks: Yeah, it really is. So, let’s talk about that one. That is Fortis Advisors v. Krafton, Inc. Decided in Delaware in March 2026. Krafton acquired a video game studio, and it was called Unknown Worlds for 500 million, plus up to 250 million additional in earned payouts depending on meeting some bonus eligibility requirements.
The CEO decided that paying the earnout would make him look like, and I quote, “a pushover.” So, what does he do? He turns to ChatGPT for legal strategy to avoid making those payouts under the contract instead of listening to his own team.
Simone Francis: So, you’re telling me that instead of listening to his own lawyers and corporate development people, he relied on ChatGPT? How did that work out for him?
Lauren Hicks: Yeah. This is not a strategy I would advise. Interestingly, his head of corporate development had specifically warned him. She said that dismissal without cause would not eliminate the earnout obligation and would expose Krafton to lawsuit and reputational risk, but he did not like, I think, that commentary from her. He wanted a different opinion. So, he went to ChatGPT and ChatGPT on the other hand prepared a whole response strategy to a no-deal scenario. And it had things like a pressure and leverage package and an implementation roadmap by scenario.
Simone Francis: Yeah. Sounds impressive, I guess, if you don’t know what you’re looking at.
Lauren Hicks: And I think you and I agree that’s the danger, right? That’s the thing that kind of concerns us. So indeed, he followed it because it sounded impressive and it sounded like a smart strategic recommendation. He followed every step and ChatGPT suggested some sort of preemptive framing.
Krafton even posted a message on Unknown World’s website without the studio’s knowledge kind of trying to present a certain story. And ChatGPT recommended locking down the stream publishing rights and that did, in fact, happen. They did lock down Unknown Worlds out of its own publishing platform amongst other things.
Simone Francis: Lauren, let me ask you something here. When you first read this case, what was your reaction as an employment lawyer?
Lauren Hicks: I was pretty shocked because he also had ChatGPT help prepare what were essentially pretextual justifications for firing people for trying to break this contract. And when the negotiation stalled, Krafton’s head of strategy told the CEO it might be easier to just do a takeover. And he responded with, “Set a date.”
On July 1, 2025, they ended up firing three key employees. The reason they stated was premature release of the game, but of course that was abandoned at trial.
Simone Francis: And so, as someone who does a lot of litigation, there’s certainly a discovery angle here and I think it’s critical for everyone listening. The CEO admitted at trial that he had deleted specific relevant ChatGPT logs and here’s what everyone needs to understand. Those conversations are electronically stored information or ESI. And so, deletion of relevant AI conversations may constitute spoliation and that’s something employers want to think about. Does the company have a litigation hold policy that covers AI tool conversations? Because many do not.
Lauren Hicks: Right. Many do not. And we’re also finding what Simone and I have kind of taken to referring to as magical thinking bubbles surrounding AI. Sometimes we are seeing that folks who probably know better and might not put the exact same language into an email are putting it into AI thinking somehow that there’s a magical bubble of confidentiality. And the outcome here was pretty devastating.
The court found every termination was pretextual. They reinstated the CEO of the acquired studio with full operational authority and extended the earnout deadline. So, damages are pending still. They’re looking not to be headed to a good space.
Simone Francis: Yeah. I believe it was a determination that the earnout could be worth up to $250 million.
Lauren Hicks: Perhaps the most expensive ChatGPT session in history to date.
Simone Francis: And I think this case illustrates something that we always like to emphasize. AI and its legal risks are still new and largely unknown. And it seems that as you have said, we’ve started to create a false sense of security. People are putting things into AI tools that they would know better than to put into a text message or an email.
In fact, one court recently said, and I love this because I think it is so on point, that, “These tools invite candid and significant disclosure of information. They stimulate empathy, foster trust, and interact in a way that feels genuine and intimate.”
Lauren Hicks: That is actually a really good summary. I like that too. So, we’re seeing a lot of this and it is important for folks to understand that the legal guardrails will develop and the risks just aren’t clear yet. They’re starting to develop or at the infancy stages of that. They’ll become clearer over time because our litigation system in the U.S. is just slow, so it takes years for these risks to become more clear.
Therefore, a key takeaway if you’re listening is don’t take the absence of significant litigation right now to mean that a system, whether it’s applicant scoring AI or a chatbot or performance monitoring software, is in some kind of special protective bubble. There is no magical protective bubble that exempts AI from employment laws or other litigation. And there are even state laws now that are AI specific. That is important. A lot of companies are working to comply with those, but AI also remains an employment law risk under state and federal statutes that have been around for decades, Simone, like Title VII, ADEA, ADA, and others.
So, getting back to our earlier theme of existing rules already apply, the risks are already there, even if it’s going to take some time for them to kind of crystallize to society legally.
Simone Francis: Absolutely. And that makes it all the more important to get ahead of those issues now.
Lauren Hicks: Another takeaway for employers is that this is not just a C-suite problem. HR managers and hiring managers and recruiters are putting kind of stream of consciousness thoughts into AI chatbots right now to rank applicants or to draft PIPs or to draft performance reviews and evaluations, build termination justifications, summarize interviews. We’re seeing a lot of different uses and every one of those inputs is discoverable and none of it’s privileged.
Simone Francis: Speaking of the privilege question, that is where it really gets interesting. There have been a few cases, as you said, we’re still in the infancy, but one of them was United States v. Heppner out of the Southern District of New York in February 2026.
In that matter, a criminal defendant used Claude to prepare legal arguments and claimed the conversations were protected by attorney-client privilege. The court disagreed and said, “No, AI is not a lawyer and cannot form an attorney-client relationship.”
Lauren Hicks: And so, Simone, walk me through why did the court say there was no privilege?
Simone Francis: So, in that case, the court reason that the AI platform’s privacy policy permitted data collection, model training, and disclosure to third parties including the government. And so there was no reasonable expectation of confidentiality when using a consumer AI tool. And here’s the scary part, sharing privileged materials with a consumer AI tool may actually waive the privilege over the underlying attorney-client communications.
Lauren Hicks: So, just to translate this into real life, you could possibly destroy privilege just by pasting something into an AI agent like GPT, Claude, Gemini?
Simone Francis: Absolutely. But there is a flip side and some good news. In Warner v. Gilbarco out of the Eastern District of Michigan also decided in February 2026, the court denied a motion to compel production of a pro se litigant’s AI interactions.
There, the court was looking at the work product privilege and determined that that privilege applied because the plaintiff was pro se and did not upload any confidential documentation. And so, in that circumstance, the court said that generative AI programs are tools not persons.
Lauren Hicks: So, two cases, both interesting but different outcomes here. So, help us reconcile them.
Simone Francis: Well, it comes down to structure. The Heppner problem in some ways points to the solution. If you conduct AI use on a secure enterprise platform with contractual confidentiality protections and it’s directed by counsel, you may be able to preserve privilege.
Lauren Hicks: That sounds like a lot of ifs and reservations, right? So pretty limited situations that that could plausibly apply. Again, this is a very developing area, but can you walk us through what that privilege framework might look like?
Simone Francis: Yeah, absolutely. I think that based on what we’re seeing from these cases, you need several elements in order to button up a potential viable claim of privilege. First and foremost, attorney direction. The usage must be legal and initiated or supervised by counsel for the purpose of providing legal advice. So again, we’re going back to our basics of what supports a claim of privilege.
Second, a secure platform, an enterprise AI with contractual confidentiality protections, not a consumer tool like ChatGPT. Third, the Kovel–Upjohn structure that many are familiar with, that is third-party analysts engaged as agents of counsel. And fourth, documentation to support those claims, engagement letters, clear labeling of all materials is privileged. All of those measures, they may sound tedious, but will help to support a claim of privilege later on.
So with that, let’s shift gears into the discrimination landscape. You mentioned that earlier, but that is the next wave of litigation as well. And what we have started to see and expect to continue to see is litigation challenging AI employment tools is accelerating based on theories such as Title VII, ADEA, ADA, the normal panoply of laws that we’re all familiar with. And there’s the developing concept of the agent theory where AI vendors themselves may ultimately be held liable as agents of the employer.
Lauren Hicks: So, I think one of the more interesting holdings in discrimination right now is an EEOC matter out of the Eastern District of New York in 2023. The AI was alleged to have auto rejected women over the age of 55 and men over the age of 60. No surprise that that one would end up in a settlement for about $365,000.
There’s active litigation in the District of Michigan, Eastern District of Michigan from 2025 where an AI hiring system allegedly used ZIP Codes and schools as racial proxies. So that’s pending. And, Simone, there’s a great quote that really captures why this matters. One federal judge wrote, and I really love this, “Drawing an artificial distinction between software decision-makers and human decision-makers would potentially gut anti-discrimination laws in the modern era.”
Simone Francis: That’s exactly right. The law doesn’t care whether the discrimination was committed by a person or by an algorithm. If the tool produces a disparate impact, the employer is on the hook. And as you’ve said, Lauren, in many conversations, the challenge with these tools is that they are capable of making many, many more decisions than any human decision-maker. And so that amplifies the potential legal risks.
Lauren Hicks: Definitely agree. And sometimes, Simone, what we more frequently see is a mix of decision making between both the human and the AI. And I think that gives some impression that, well, if it’s not determinative and it’s just suggestive, it’s just giving me recommendations or information, maybe that’s low to no risk. And that is really not correct. If it’s contributing in some way to a legal problem, then it is a legal risk.
Simone Francis: Absolutely. So, let’s switch to another scenario. A CHRO says that the company wants to implement an AI tool to screen resumes. We’ve seen several different versions of those types of tools. And the vendor has said to the CHRO or your procurement team that the tool is bias free and EEOC compliant. What are some considerations there, Lauren?
Lauren Hicks: So, we’re going to want to dig deeper than vendor assurances. Questions that we might want to ask include what data was the model trained on? What protected characteristics is it using for evaluation and potentially as proxies? Whether there is any adverse impact testing that has been done and if so, on what population, when was it done? How frequently is it done? Those types of things.
So, employers will want to dig deeper than vendor assurances, right? Those are not going to serve as a valid legal defense. They are important for background purposes and so that you understand what the vendor is doing, but questions you might want to consider asking include, what data was the model trained on? What protected characteristics did you consider in building the model? What protected characteristics do you evaluate? What kind of adverse impact testing has been done on those characteristics? How frequently? What specific pool has been tested?
And again, those do not relieve the employer of their risk and obligation and burdens, but they help you understand the validity or some of what is going on with the underlying model to give you some sort of assurance in a way that these important legal issues are being taken into account.
It might be worth considering a bias audit, of course, before you deploy a new system, always structured under privilege using the framework described. So, a vendor essentially must represent, if it expects anyone to buy its product, right? That there isn’t bias. So, this is not surprising that they all make this representation. I will tell you in reality, when we run privileged analyses on the data on the backend for companies, the findings on the employer’s actual applicant data is generally not as clean as what the vendor is going to represent. And sometimes we find really interesting or really serious problems there.
So, the representations that the vendors make are important in having some assurance that they’re taking legal factors into account, but I want to be clear that from a legal standpoint, it doesn’t really provide any defensibility for the employer who’s utilizing the system.
Simone Francis: Well, thanks for that, Lauren. I think if the vendor has tested run tests on synthetic data that that’s not enough and we need to consider our actual data from our respective organizations.
And for bias testing, another consideration of course is going to be mapping against state requirements because we are seeing an explosion of state laws. Right now, we have new legislation in Colorado and Connecticut as well as existing laws in Illinois, New York City, California, and Texas. And again, it’s an area of multi-state mayhem. There are different rules and different state notice and disclosure requirements that employers have to map.
Lauren Hicks: All right. Let’s get to some practical takeaways. What might a good AI use policy cover?
Simone Francis: Absolutely. I think this is really important. First of all, approved tools. Which AI tools are authorized consumer versus enterprise? Secondly, prohibited inputs. You want to restrict client confidential information, privileged material, personal identifying information from going into those AI consumer tools.
Third, human review. Employers may want to require as part of their policies that all AI-generated work product be reviewed before it is used. And fourth, documentation. Consider logging AI-assisted decisions, creating frameworks, especially when it relates to HR or employment actions. And five, I cannot stress enough the issue of scope. The policy, you may wish to ensure that that policy covers everyone. Executives, HR managers, individual contributors, everyone else in your organization.
Lauren Hicks: That one is very important, and I think it goes to both the policy issue and probably the training and awareness issue. For example, the Krafton case, that was a CEO. It wasn’t a junior employee, yet we are also seeing all levels of employees input sort of risky or concerning prompts into especially AI agents or use them in ways that can be concerning. So yes, policy, but also I think training and general awareness.
Simone Francis: Yes. Training is absolutely important. And for AI employment tools specifically, there are some things employers may want to consider. You mentioned one before and that is before deployment, consider conducting a privileged bias audit under attorney direction. For vendor diligence, you may also want to seek algorithmic transparency rather than just accepting those vendor assurances at face value.
Lauren Hicks: Yes. And consider doing ongoing monitoring, right? Auditing outcomes for disparate impact by protected classes and documentation. It’s going to be prudent to maintain records showing human oversight, not just the outputs themselves, which we’ve talked about that record retention, but also showing and demonstrating the human oversight of the AI-assisted decisions.
Then you also want to think about state compliance. It’s very important, as Simone mentioned, to map your operations against these state laws that are popping up Colorado, Illinois, New York City, California, Texas, and everywhere else you operate. And these are changing very routinely. We’ve even seen new ones in the last week.
Simone Francis: Certainly, if you’re a global employer, then there are laws and regulations outside of the United States that you would need to consider. And just going back to the ESI piece that I mentioned here because that one can get overlooked, AI chatbot conversations are likely discoverable. The ones that survived in the Krafton case were devastating, as we’ve talked about, and the fact that the CEO then deleted those records only made things worse. So, employers may wish to think carefully about their policies on usage and access rights and really understand what the chatbots retain, for how long. It’s important to think about all of those things before litigation arises, not after you receive notice of a claim.
Lauren Hicks: Absolutely. So, let’s kind of summarize our key points today. Simone, you start.
Simone Francis: Okay. Number one, the ethics rules already apply to AI. Competence, confidentiality, supervision, candor. There’s nothing new that you need to wait for.
Lauren Hicks: Number two, consumer AI tools are generally not privileged. Enterprise platforms with attorney-client direction might in some instances be privileged. This is a developing area. Precautions and being cautious in this area is definitely warranted. I would say assume things are discoverable until we know otherwise.
Simone Francis: Absolutely. That’s great advice. And number three, AI employment tools are the next wave of discrimination litigation. So, consider auditing before you deploy. And of course, as you mentioned, Lauren, the auditing is not one and done. It needs to be done regularly as you continue to use those tools.
Lauren Hicks: Fourth, all levels of employees, including your managers and maybe even your C-suiters are using AI for business and legal strategy right now. So, you have to have a policy that reaches them, but one thing you might consider is monitoring activity. We know, again, that there seems to be some impression of a magical bubble surrounding AI agents. And so having a backend monitoring system might be one way to get a good understanding of how these tools are actually being used in your organization.
Simone Francis: That’s an excellent thought. And to wrap it up, number five, AI conversations are generally going to be discoverable ESI, so treat them accordingly and as we’ve spoken about, train your stakeholders so that they understand that those inputs can later become seen by adversaries, agencies in litigation, or administrative context.
Lauren Hicks: Thanks, Simone, and thank you, everyone, for listening.
Announcer: Thank you for joining us on the Ogletree Deakins podcast. You can subscribe to our podcast on Apple Podcasts or through your favorite podcast service. Please consider rating and reviewing so that we may continue to provide the content that covers your needs. And remember, the information in this podcast is for informational purposes only and is not to be construed as legal advice.