When AI Is Part of the Misconduct: How to Investigate AI in the Workplace
Internal investigations have traditionally focused on people. Someone acted, someone complained, and the investigator’s job was to determine what happened, who was responsible, and what response the facts justified. AI complicates that model because HR and compliance teams are increasingly confronting matters in which the technology plays a role in the alleged misconduct.
An employee may use generative AI to draft messages later characterized as harassing. An AI hiring tool may produce decisions challenged as discriminatory. A manager may rely on AI to prepare performance reviews that an employee later contests. Or an employee may use AI to create documents or other evidence that turns out to be false. In each of these matters, responsibility may depend not only on what the employee did, but also on what the technology produced and the circumstances in which the organization made the tool available.
The Attribution Problem
In a conventional workplace misconduct investigation, the investigator generally determines what the employee did and measures that conduct against the applicable policy. When AI mediates the conduct, the investigator must go further. What did the employee ask the tool to do? What did the tool return? Did the employee review or modify the output? Was the result foreseeable? What policies, training, or warnings existed?
Those questions matter because different findings call for different responses. An employee who deliberately prompts a tool to fabricate a document presents one problem. An employee who follows an employer-approved process and receives a flawed recommendation presents another. The investigation must determine whether the problem lies primarily with the employee’s conduct, the organization’s controls, or both.
Start With the Employee’s Use of AI
The employee’s conduct remains the starting point, but the final output is not enough. Investigators should determine how the tool was used from beginning to end: what prompts were entered, what information was provided, whether the output was reviewed or edited, and what the employee knew or should have known about the risk of error.
Consider an AI-generated message containing inappropriate language. The question is not simply whether AI wrote the words. The investigator needs to know what the employee asked for, what the tool produced, whether the employee changed it, and why the employee ultimately chose to send it. The same is true when generative AI produces inaccurate information. If an employee was responsible for verifying the work before submitting it, a failure to do so may itself be the relevant conduct.
Examine the Organization’s Role
An internal investigation involving AI should not stop with the employee. The organization may have selected the tool, integrated it into a workflow, encouraged employees to use it, or allowed widespread use without meaningful guidance. Was the tool approved for the use at issue? Did the organization have an AI policy? What did the policy require employees to verify? Had employees received training on risks such as hallucinations, bias, confidentiality, or inappropriate outputs?
Suppose a manager relies on an employer-provided AI tool to help rank employees for promotion and the recommendations appear discriminatory. Looking only at the manager’s conduct may miss the larger issue. The investigator may also need to determine how the tool was selected, what employees were told about relying on it, and what human review was expected. None of that necessarily excuses the employee, but it may show that discipline alone will not address the problem.
Account for the Technology
The AI tool itself may also be part of the explanation. Investigators should determine what they can about how the tool worked, what limitations were known, and whether the vendor had identified any relevant risks.
Investigators should also move quickly to preserve the AI interaction itself. An employee may revise the prompt, regenerate the response, or edit the AI-generated material before anyone realizes the original exchange matters. Preserving the prompt, the original response, and any later changes can help show how the final product came to be. In an AI-related investigation, that history may be just as important as the final output.
Match the Response to the Responsibility
The point is not to allocate responsibility mechanically among the employee, the organization, and the technology. It is to understand what actually happened and why. In some matters, the problem will be the employee’s conduct. In others, the employee may have used an approved tool exactly as expected, exposing a gap in training, policy, or oversight. Sometimes the tool itself may have contributed to the result.
The response should follow from that finding. An employee may need discipline or coaching. The organization may need clearer guidance or stronger review procedures. A problem with the tool may require changes in how it is used or a conversation with the vendor. The investigation should make clear not only what happened, but what needs to change as a result.
AI does not fundamentally change the investigator’s job. Investigators still have to gather the evidence, evaluate what people say, apply the relevant policies, and explain their conclusions. What AI changes is the scope of the inquiry. The question may no longer be only what the employee did, but also how the tool and the organization’s own practices contributed to the outcome.
As AI becomes embedded in more workplace decisions and communications, that question will arise more often. Investigators who can separate the employee’s conduct from the organization’s choices and the technology’s role will be better positioned to reach findings that are fair, practical, and defensible.