Hasta la vista, confidentiality: when AI use breaches workplace obligations

Stephen Silvapulle, Bianca Weiss, John Dieckmann, Allison Shannon
19 Aug 2026
8 minutes

When an employee uploads confidential workplace documents to an AI tool to assist them with a personal workplace matter, the consequences can extend well beyond the relevant dispute.

The recent Fair Work Commission decision in Baker v Macquarie University [2026] FWC 3054 provides a striking illustration of the growing role artificial intelligence can play in workplace disputes. A computing academic with no formal legal training used AI agents (primarily ChatGPT Pro) to run his casual conversion case against a well-resourced employer, and won the first successful decision under the Albanese government's new casual conversion laws.

Although the outcome in that case turned on the evidence rather than the AI-generated materials produced by Mr Baker in support of his case, the case has attracted widespread attention because it signals a potential future where every worker has access to sophisticated AI legal assistance.

But what happens when an employee puts confidential workplace information into an AI tool to get that assistance?

"Come with me if you want to live": when might employees turn to AI for professional assistance?

The temptation to seek assistance from ChatGPT may be irresistible for any employee involved in a performance management, disciplinary or termination process. They might, for example:

  1. upload an investigation report and ask for arguments against the findings;

  2. upload discovery received in a litigation matter and ask for an analysis of those documents;

  3. if facing bullying or harassment at the workplace, they may upload a meeting transcript or company emails to ChatGPT and ask the AI-model to draft a complaint or response; and/or

  4. upload a contract or workplace policy and ask whether their employer has breached the Fair Work Act 2009 (Cth).

The machines are listening: has the employee disclosed confidential information?

From the employee's perspective, this may look like a harmless and increasingly ordinary use of technology. However, from the employer's perspective, it can raise a very different set of questions: what information has just left the organisation, where has it gone, who can access it, and has the employee breached a workplace policy or obligation by doing so?

A performance management file might contain information about an employee's health, family circumstances, remuneration, complaints, allegations about colleagues or assessments of their performance. A disciplinary investigation may contain witness statements, allegations concerning other employees and highly sensitive personal information about the affected employee and others.

The Office of the Australian Information Commissioner (OAIC) has expressly warned organisations about the risks of entering personal information into publicly available generative AI tools, particularly sensitive information. Its guidance notes that once personal information has been entered into a GenAI system, it may be difficult to track or control how it is subsequently used (and potentially impossible to remove it).

That creates an important distinction between asking an AI tool a general question (for example, "What are the principles governing unfair dismissal?") and uploading the actual documents from an employment dispute regarding a dismissal.

The latter may involve disclosure of information concerning not only the employee using the tool, but also colleagues, managers, complainants, witnesses and customers without their consent or knowledge.

Judgment Day: when AI use may warrant disciplinary action

Once the employer becomes aware that an employee has uploaded company material to an unauthorised AI model, the AI use itself may become evidence in a subsequent disciplinary process warranting the employee's dismissal.

All organisations should now have policies dealing with confidentiality, information security, acceptable use of technology, data protection and the use of AI models. Those policies should expressly prohibit employees from entering confidential or personal information into unapproved external systems.

Where such policies exist, an employee who uploads an employer's confidential documents to a public AI service may have breached multiple workplace obligations. Depending on the circumstances, the conduct could involve:

  1. breach of an express confidentiality obligation;

  2. breach of an information security or acceptable-use policy;

  3. misuse or unauthorised disclosure of confidential or personal information;

  4. unauthorised disclosure of information belonging to the employer or third parties;

  5. failure to comply with a direction concerning the handling of information; and

  6. conduct inconsistent with the employee's contractual obligations or company duties under the Corporations Act 2001 (Cth).

The seriousness of the conduct will obviously depend on the circumstances: there is a substantial difference between asking ChatGPT to improve the grammar of a document containing no confidential or personal information (or information which has been redacted and from which the individual cannot be re-identified) and uploading an entire investigation report containing allegations about multiple employees.

The Fair Work Act 2009 (Cth) recognises serious misconduct as a basis for summary dismissal, but whether particular AI-related conduct reaches that threshold will depend on the circumstances.

Relevant considerations could include the nature, volume and sensitivity of the information affected, the employee's knowledge of the relevant policies, whether the conduct was deliberate, whether the employee was authorised to use the particular AI tool in the course of their employment and the risk created for the organisation or affected individuals.

An employer will be in a stronger position to argue serious misconduct where it has clearly told employees not to enter confidential information into unapproved AI systems, provided training on the relevant policies, and directed employees to use only approved AI systems.

Conversely, disciplinary action may be more difficult to sustain where the employer has no AI policy, its confidentiality and/or privacy policies are ambiguous or the employee had a reasonable basis for believing that the particular use of AI was permitted (for example, being able to access a remote AI system using a work-issued device or network without restriction).

What happens if use of Generative AI isn't visible?

In Baker, the applicant openly disclosed to the Commission that he had used ChatGPT extensively in preparing his case. Notably, the ChatGPT terms of use prohibit a user from representing that outputs are human-generated when they are not. He explained that he had uploaded case material, including emails, conversations and meeting records, and tasked the AI with analysing those documents to assist his case. His disclosure put the Commission and the employer on notice of the role AI had played in his case.

In many workplace disputes, however, an employer may have no way of knowing whether an employee has used GenAI, what material they have uploaded or what instructions they have given the AI tool.

Unless the employee discloses that use, or the employer is actively reviewing for such use through regular monitoring of employer-issued technology, the employer may never know that those documents have been provided to an external AI system.

This creates a difficult problem for employers. It may be possible to identify that an employee has used AI (for example, because of the style or provenance of material produced) without knowing what information was uploaded, what prompts were used or what the AI system did with that information.

That uncertainty can be particularly significant where the material contains personal or sensitive information concerning other employees, witnesses or third parties.

A liquid metal situation: Shifting risks for employers

  1. Workplace

Depending on the circumstances, disciplinary action against an employee who has raised a grievance may give rise to allegations of victimisation, bullying, or adverse action in breach of the general protections provisions of the Fair Work Act 2009 (Cth). An employee may contend that the disciplinary process was motivated, at least in part, by their complaint or other exercise of a workplace right.

An employee may also allege that an employer has used an alleged confidentiality breach as a pretext to punish, silence or discredit them after they raised concerns.

The risk is particularly acute where the AI use emerges only after the employee has made a complaint, or where the employer has tolerated similar conduct by other employees but acts against the employee who raised a grievance.

That does not mean employers should ignore genuine breaches of confidentiality simply because the employee has made a complaint, but it does mean that the investigation and decision-making process needs to be carefully managed.

Employers should be able to demonstrate that the concern about GenAI use arose independently of the employee's complaint, that the alleged breach is supported by evidence, that comparable conduct has been treated consistently and that the disciplinary decision was based on legitimate workplace considerations rather than the employee having spoken up.

In appropriate cases, employers may also wish to consider separating the investigation of the underlying grievance from any investigation into the employee's conduct, ensuring that the decision-maker is appropriately independent and carefully documenting the reasons for any disciplinary action.

  1. Privacy Breach

While the use of AI systems in managing employee information may fall under the "employee records" exemption, the exemption does not cover all personal information held about employees - only those relating to a current or former employee relationship. Further, the exemption only applies where the information is used for a purpose directly related to those records or the broader employment relationship. If one employee uses another's details to pursue a separate claim against the employer, that use is unlikely to be protected.

Where the exemption does not apply, the Privacy Act 1988 (Cth) requires entities and organisations to take reasonable steps to implement practices, procedures and systems to ensure compliance with the Australian Privacy Principles (APPs). These steps must also address inquiries or complaints about compliance with the APPs. The OAIC has made it clear that organisations must take proactive steps to establish and maintain these practices, procedures, and systems. When determining what is reasonable, organisations cannot avoid taking action simply because it may be inconvenient, time-consuming, or costly. Whether a step is unreasonable will depend on whether the burden is excessive in the circumstances.

Accordingly, entities and organisations should evaluate what measures can be taken to minimise the use of unapproved AI systems. This may include measures such as ongoing employee training, periodic reminders, monitoring network activity, implementing network configuration controls, and configuring approved AI systems at an enterprise level to restrict the upload of certain documents or prompts. It is also important to document these steps to demonstrate efforts to meet privacy obligations under the Privacy Act.

Poor management of AI-related risks could lead to unauthorised access, loss, or disclosure of personal information, potentially triggering a notification obligation of a privacy breach to the OAIC.

  1. Other risks

The release of confidential information into an AI system may breach contractual and / or equitable obligations of confidence. It may involve the unauthorised reproduction of material in which a third party IP rights subsist.

Come with me if you want to mitigate: Lessons for the future

AI, and specifically GenAI, has become an increasingly important tool through which employees understand their workplace rights and participate in workplace disputes. This is not a temporary phenomenon.

However, it is vital that employers distinguish between approved enterprise AI environments, which may be subject to contractual and technical safeguards, and publicly available AI services.

The decision in Baker serves as a reminder for employers to:

  1. First, have a clear AI policy. Employees should know whether they can use AI models at work, which tools are approved, what information can be entered and what information must never be uploaded. Policies should clearly define appropriate use cases for different areas of the business and specify the tools suitable for each.

  2. Secondly, make confidentiality obligations explicit. An employee should not have to guess whether an investigation report, performance warning or witness statement can be pasted into ChatGPT. Employers should consider updating relevant contract clauses or policies (for example governing confidentiality or AI/IT use). Where possible, they should also use enterprise level configuration of AI systems to limit the types of information and/or prompts that the AI system can process.

  3. Thirdly, embed use of GenAI into information-security and privacy training. Traditional confidentiality training may have been written before employees could instantly upload a document to an external AI-model and receive a detailed analysis of it.

  4. Fourthly, consider AI when investigating potential misconduct. If an employee appears to have used AI in connection with a workplace dispute, an employer may need to establish what information was provided to the AI tool, which tool was used, when it was used and whether the employee was authorised to use it.

  5. Finally, do not overlook procedural fairness. If AI use is being relied upon as a disciplinary allegation, the employee should be given a proper opportunity to respond to the allegation. The employer should also carefully distinguish between authorised and unauthorised AI use and assess the seriousness of the conduct in its particular context.

Disclaimer
Clayton Utz communications are intended to provide commentary and general information. They should not be relied upon as legal advice. Formal legal advice should be sought in particular transactions or on matters of interest arising from this communication. Persons listed may not be admitted in all States and Territories.