RatedWithAI

RatedWithAI

Accessibility scanner

AI Legal & ComplianceAugust 5, 2026

An Engineer Emails You About the Model. What Happens in the Next Two Weeks Is the Legal Case.

AI risk reports from employees are protected activity under a widening set of laws — and under several older ones that already covered most of what people actually report. In nearly every case that becomes litigation, the liability comes from what the company did after the report, not from the concern itself.

Belief, not proof
Reasonable good-faith belief is usually the standard — being wrong stays protected
The NDA itself
Agreements that impede regulator contact are their own violation
Old statutes reach
Securities, consumer protection and civil rights law cover most AI reports already

The Report Companies Are Least Prepared For

Most compliance programs are built around financial misconduct and workplace behavior. The reporting channels, the training and the investigation playbooks all assume a category of complaint that predates machine learning by decades. Then an engineer writes that the evaluation results were presented selectively to a customer, or that a known failure mode was shipped anyway, or that the model's outputs skew in a way nobody wants to look at — and the organization has no route for it.

What happens next is predictable and expensive. The report goes to the person the employee reports to, which is often the person whose decision is being questioned. It is handled informally. Three months later a performance conversation happens that would have happened anyway, and now the company has to prove that in front of someone skeptical.

The asymmetry here is worth stating plainly: the underlying concern may cost nothing to address. The retaliation claim is the part with damages, fee-shifting and a public record.

Four Legal Routes, Only One of Which Is New

Companies tend to ask whether an AI whistleblower law applies to them, conclude it does not, and stop. That is the narrow version of the question. An employee report about an AI system can find protection through several doors.

  • AI-specific provisions. Newer frameworks aimed at frontier model developers include protections for employees who report serious safety risk, sometimes with an obligation to maintain an internal reporting channel. These are threshold-based and reach relatively few companies directly — but they set an expectation that spreads.
  • Securities and disclosure law. Where the concern touches what investors were told — capability claims, revenue attributed to an AI product, risk factors omitted — established whistleblower protections and award programs apply, and they apply to private companies' communications with investors more often than people assume.
  • Consumer protection and civil rights. A report that a product's marketing overstates what the system does, or that an automated decision system produces disparate outcomes, sits squarely inside statutes that have protected complainants for decades.
  • General employment protections. Many jurisdictions protect employees who report a reasonable belief of unlawful conduct, full stop, without needing a subject-matter-specific statute at all.

Open your standard employment agreement, your NDA template and your severance form and search for the word "government." If none of the three preserves the right to report to an agency without notifying the company, you have a document problem that exists today, independent of anyone ever raising a concern.

The Agreement Problem

The most common finding in this area is not a retaliation event. It is boilerplate. Confidentiality clauses drafted to protect trade secrets routinely sweep in communications with regulators; severance agreements ask departing employees to affirm they have not filed and will not file complaints; equity documents condition vesting on non-disparagement written broadly enough to cover a safety report.

Provisions of that kind have been treated as violations in their own right, regardless of whether anyone was ever discouraged in a specific case. The remedy is unglamorous and cheap: an explicit carve-out, in every document, stating that nothing in the agreement limits the employee's ability to report possible violations to a government agency or to participate in an investigation, and that no prior notice to the company is required.

There is a second-order benefit. A company whose documents visibly preserve that right is much better positioned to argue that an internal report was handled in good faith, because it never had a structure that pushed the concern outward in the first place.

What to Build Before the First Email

  1. A named channel for AI risk reports. It has to reach someone outside the reporting employee's management chain. If the only escalation path runs through the person who made the decision, employees route around it — usually externally.
  2. Written acknowledgment, every time. A dated message confirming receipt and stating who is reviewing it costs nothing and is the single most useful document in a later dispute.
  3. A record of the disposition. What was examined, what was concluded, what changed. "We looked into it" with no artifact is indistinguishable from having ignored it.
  4. An employment-action hold. Once someone has raised a concern, adverse actions affecting them should require review by someone who knows about the report. This is where well-run companies still lose, because the manager acted without anyone connecting the two facts.
  5. Carve-outs in every template. Employment agreement, NDA, severance, equity documents, contractor agreements. Contractors are routinely forgotten and are frequently the people closest to the system.
  6. Say it out loud in training. A policy nobody has heard of does not change behavior. Stating that AI risk concerns are welcome and protected is also, practically, the cheapest way to hear about problems while they are still cheap to fix.

The Governance Argument Nobody Makes

Everything above reads as legal hygiene, and it is. But there is an operational case that lands better with the people who have to fund it: the employee raising a concern about a model is the cheapest detection system a company has. They found the problem before a customer did, before a regulator did, and before it appeared in a publication. A structure that makes that report easy is an early-warning system disguised as a compliance requirement.

The inverse holds as well. Companies that make internal reporting uncomfortable do not stop receiving reports; they stop receiving them first. The concern still exists, and it surfaces somewhere the company has no ability to shape the response.

Frequently Asked Questions

An employee raised a concern and then their performance genuinely declined. Can we act?

Yes, but the sequence and the documentation determine whether you can defend it. Adverse action after protected activity invites a causation inference, and the way to rebut it is contemporaneous evidence that the performance issue was identified and documented independently. Have someone who knows about the report review the decision before it is taken, and record the basis.

Does it matter that the concern was raised in a Slack message rather than through a formal channel?

Generally no. Protection typically attaches to the substance of the report rather than the format, and courts are unimpressed by arguments that an employee used the wrong form. Treat any substantive risk concern as a report regardless of where it arrived.

We are a small company with no compliance function. What is the minimum?

Two things. Put the regulator carve-out in your templates, which is a one-time drafting change. And name a person outside the engineering management chain — a founder who is not the CTO, an outside counsel, a board member — as the destination for risk concerns, and say so in writing. That is most of the protective value at essentially no cost.

Can we require employees to raise concerns internally before going to a regulator?

You can encourage it; requiring it is where companies get into trouble. A term conditioning anything on internal-first reporting, or requiring notice to the company before contacting an agency, is the kind of provision that has drawn enforcement attention. Build an internal channel good enough that people use it voluntarily.

What about a contractor or a vendor's employee who raises the concern?

Do not assume the analysis changes. Several protective frameworks reach beyond direct employees, and in any event a contractor with a concern about your system who is treated dismissively is a person with the same access to regulators and journalists. The practical answer is to run the same process regardless of employment status.

Is there any downside to inviting AI risk reports?

The fear is that documenting concerns creates discoverable evidence of known problems. That fear is backwards. The concern exists whether or not it is written down, and the discoverable record you want is the one showing the report was received, examined and addressed. The damaging record is the one showing it was raised and nothing happened.

Do Your Public Claims Match What Your Team Knows?

Most AI whistleblower reports start as a gap between what a company says publicly about its system and what the people building it understand to be true. The pages making capability, accuracy and safety claims are the ones that gap shows up in.

See every claim your site makes in one pass. Run a free scan and review each page that states what your AI does.

Is your own site ADA compliant?

Run a free WCAG 2.1 AA scan on any public URL. Real axe-core checks in a real browser — instant report, no signup.

Need it watched instead of checked once? Starter is $29/mo for continuous monitoring, audit trails and PDF/CSV exports.