The Company That Runs on AI: Governing Employee Use Before It Costs You the Privilege
Defending the Algorithm® AI and Corporate Law Series | Edition 1
Welcome back to Defending the Algorithm® - a LinkedIn newsletter from Pittsburgh law firm, Houston Harbaugh, PC, helping defense attorneys, insurance professionals, employment lawyers, corporate counsel and clients to navigate the intersection between artificial intelligence and the law. This newsletter series is specifically targeted to the defense of employment law claims against employers and their vendors and was written and edited with assistance from Claude Opus 5.0 from Anthropic and Google Gemini 3.0 Pro and with research confirmation by Westlaw Advantage AI with Co-Counsel. It is a companion to our podcast and blog series, available at: Defending the Algorithm® created by Henry M. Sneath, Esq.
In cooperation with the DRI Center for Law and Public Policy. All content was reviewed, edited, and verified by the authors.
Launching a new series on AI and corporate law — written from the chair of the lawyer who forms the company, counsels it, and closes its deals. We start where most companies already are: using AI every day, with no policy that would survive a courtroom.
Welcome to the first edition of Defending the Algorithm®: AI and Corporate Law, a LinkedIn newsletter for the business owners, general counsel, and boards we serve. It is written from the transactional lawyer’s chair — the lawyer who forms the company, counsels it as outside general counsel, identifies its IP, runs diligence, and papers the transactions it enters. Where our Employment series views AI through alleged hiring discrimination and our Insurance series through coverage, this one follows a company across its whole life cycle and its relationship with AI: forming it, running it, valuing it, “diligencing” it, and ultimately, closing the deal.
We begin where nearly every closely-held business already stands — not at formation, not at an exit, but in the middle of ordinary operations, using AI every single day. Your sales team uses AI to draft proposals. Your controller reconciles spreadsheets with AI. Your engineers debug using AI. And — as far as we know — not one of them read the terms of service including the confidentiality provisions on whatever platform they are using.
That is the exposure. Not the AI. The absence of a policy that would survive a courtroom challenge.
The Everyday Problem is a Governance Problem
For the corporate lawyer who serves as outside general counsel, AI is not an incident to respond to — it is a standing condition to be governed. The board that treats AI oversight as an IT matter has already made its first mistake, because two doctrines that decide real cases now run through the employee’s keystroke: confidentiality and the duty of oversight. Consider what a company stands to lose the moment an employee pastes a draft settlement memo, a customer list, or a signed term sheet into a consumer chatbot, that is sharing information to further train its language learning model behind the scenes.
What Heppner Should Teach Every GC
Earlier this year, in United States v. Heppner, a federal court in the Southern District of New York held that documents a non-lawyer defendant generated with a commercial AI tool were neither privileged nor protected work product. The reasoning is what matters for the corporate reader: the AI tool is not a lawyer, so an exchange with it is not a privileged attorney-client communication. And there was no reasonable expectation of confidentiality, because the platform’s own privacy policy contemplated that the content could be disclosed.
Heppner arose in a criminal case, about a defendant’s own use of a public tool — so read it for its principle, not its facts. The principle should stop a general counsel cold: when a platform’s terms let the provider access, review, or disclose what your employees type, the company may have no reasonable expectation of confidentiality in any of it. Every proprietary term, every privileged strategy, every trade secret typed into a consumer-grade tool is a candidate for that same finding.
Here is the part that matters even more — the fix. The court expressly left open the questions it did not have to reach — whether a company’s deployment of AI with contractual confidentiality changes the analysis, and whether AI use directed by counsel falls within the Kovel doctrine[1] that extends privilege to an attorney’s agents. It drew the line precisely where good corporate governance would: between the consumer tool with permissive terms and the enterprise instrument bought under a confidentiality agreement and deployed at counsel’s direction.
The difference between a waiver and a privilege can be the difference between a free account and a procurement contract.
[1] The Kovel Doctrine stems from the 1961 Second Circuit case, United States v. Kovel, which extends attorney-client privilege to third-party experts when they are hired to assist a lawyer with complex client matters – like accountants working with a lawyer to review financial statements and valuations– in order to assist the lawyer with legal advice.
The Trade Secret You Are Quietly Giving Away
The confidentiality problem is also a trade-secret problem. A trade secret is a trade secret only if the company took reasonable measures to keep it secret — that is the statutory hinge under the Defend Trade Secrets Act and its state analogues. In the pending OpenEvidence v. Pathway Medical litigation in the District of Massachusetts, a company asserts that its AI system prompts are protectable trade secrets. This case is testing whether terms of use alone amount to reasonable measures. That question is not yet decided and this may not be the case that gives us the answer. But you do not need a ruling to see the operational lesson: a company whose employees routinely feed proprietary information into tools with permissive terms will struggle to tell a court, later, that it took reasonable measures to protect anything. You cannot credibly claim you guarded the vault while your team left the door open every afternoon.
The Board's Problem is Older Than AI
None of this is new law. It is old law — Caremark and its progeny — meeting a new tool. Under Delaware’s Caremark doctrine, directors have a duty to make a good-faith effort to put a reporting system in place and then to monitor it. A board that cannot show it even considered AI risk — no policy, no inventory, no reporting line — is a board assembling the elements of an oversight claim for some future plaintiff. The defense to a Caremark claim is not a good outcome after the fact. It is a functioning system you can prove existed before anything went wrong.
What Outside General Counsel Should Deliver
So what does governing AI actually look like when a corporate lawyer does it well? Four things — and none of them is a memo that lives in a drawer.
- An acceptable-use policy with teeth. Not aspirational language — enforceable rules. Which tools are approved, which data may never be entered, who may deviate and how, and what happens when someone violates it. A policy with no enforcement mechanism is not a control; it is the document a plaintiff enters as Exhibit A to show you knew and did nothing.
- Enterprise procurement over consumer accounts. The most protective move most companies can make is to shift employees off free, consumer-terms tools onto enterprise deployments governed by a contract with confidentiality, no-training-on-your-data, and access terms your lawyers have actually read. Heppner draws the line here; put the company on the right side of it.
- An incident-escalation path. When proprietary or privileged information does go into the wrong tool — and it will — the company needs a fast, defined route to counsel, so privilege and trade-secret positions can be preserved while that is still possible.
A board reporting routine. A short, regular AI-risk report to the board or its audit committee — an inventory of tools in use, incidents logged, and mitigation underway. It is the Caremark record you hope never to need and will be very glad to have.
Update Your Priors
Before Heppner, a general counsel might have rated the odds that casual employee AI use would cost the company a privilege or a trade secret as low. After Heppner, that prior should move — not to certainty, but upward, and far enough to change what you do Monday morning. That is the discipline this series runs on: update your priors as the courts rule, and let the revised risk drive the governance.
What Comes Next
This edition started in the middle of the company’s life, because that is where the risk already lives. Upcoming editions work the rest of the lifecycle: owning what you build (AI, IP ownership, and entity formation); valuing and licensing the AI asset; buy-side diligence, where these questions become the buyer’s problem to inherit; and papering the deal, where diligence findings become representations, warranties, and indemnities.
A note on lanes: this series governs the company’s own use of AI — confidentiality, trade secrets, acceptable use. Where AI touches hiring and discrimination, that is the province of our AI and Employment Law Series, and we point you there rather than repeat it.
Defense-minded. Practical. Written from the deal lawyer’s chair.
Read, Follow and Subscribe to get these newsletters as they are released.
Connect With Us
Lead Author / Editor: Jaclyn E. Faulds, Esq., Director, Business Law — Corporate & Commercial Transactions, M&A. Email: fauldsje@hh-law.com Phone: 412-288-2212
Series Editor: Henry M. Sneath, Esq., Chair, IP Practice Group, Houston Harbaugh, P.C., sneathhm@hh-law.com, 412-288-4013.
To discuss AI governance, corporate AI policy, entity and IP-ownership questions, or AI issues in your next transaction, contact us at Houston Harbaugh, P.C., 412-281-5060, or click here to visit our website.
Defending the Algorithm® is a federally registered trademark of Houston Harbaugh, P.C. This newsletter is informational only and does not constitute legal advice or create an attorney-client relationship. The views expressed are those of the authors and do not necessarily reflect the views of Houston Harbaugh, P.C. or its clients.
Sources Verified
United States v. Heppner, No. 1:25-cr-00503-JSR (S.D.N.Y.) (Rakoff, J.) (bench ruling Feb. 10, 2026; Memorandum Opinion Feb. 17, 2026, Dkt. 27) (AI-tool exchanges neither privileged nor work product; no reasonable expectation of confidentiality where the platform’s privacy policy contemplates disclosure; enterprise-deployment and Kovel-agency questions expressly left open). United States v. Kovel, 296 F.2d 918 (2d Cir. 1961) (privilege extends to an attorney’s agents). OpenEvidence, Inc. v. Pathway Medical, Inc., No. 1:25-cv-10471 (D. Mass.) (Joun, J.) (voluntarily dismissed pending mediation; asserting AI system prompts as trade secrets and testing whether terms of use alone are “reasonable measures”). In re Caremark Int’l Inc. Derivative Litig., 698 A.2d 959 (Del. Ch. 1996) (director oversight duty). Defend Trade Secrets Act, 18 U.S.C. § 1836 et seq. (“reasonable measures” requirement).