top of page

When an AI Whistleblower Goes to the Attorney General — Wix Copy

Writer: Todd B. Nurick
Todd B. Nurick
8 minutes ago
9 min read

AI whistleblower complaint involving internal investigation, corporate compliance, and government reporting.
AI whistleblower complaint involving internal investigation, corporate compliance, and government reporting

An employee raises a concern about an artificial intelligence system. Maybe the concern involves cybersecurity, privacy, discrimination, unsafe model behavior, misleading disclosures, or pressure to deploy a system before known risks are resolved.


Management may see a technical disagreement. The employee may see unlawful or dangerous conduct. A regulator may see the beginning of an investigation.


That gap became more important on September 17, 2026, when the New York Attorney General's Office issued an industry alert encouraging workers with information about potentially unsafe or unlawful AI development to submit confidential whistleblower complaints through the Office's secure portal. The alert expressly refers to cybersecurity, economic, and other safety risks associated with emerging AI technology. New York Attorney General industry alert, Sept. 17, 2026.


For businesses, the message is broader than New York and broader than AI developers. An AI whistleblower complaint can quickly become an employment, regulatory, privacy, cybersecurity, consumer-protection, securities, contract, or litigation issue. The technology may be new. Many of the legal obligations are not.


This also fits a broader enforcement trend in which regulators increasingly rely on information from insiders. I discussed that development in DOJ Fraud Enforcement Is Expanding: What Businesses Should Do Now.


The practical question for General Counsel is therefore not whether the employee is "right" during the first conversation. It is whether the company has a process capable of finding out what happened without creating a second problem through retaliation, poor preservation, privilege mistakes, or an investigation that appears designed to discredit the person who reported the concern.

New York Has Put AI Whistleblower Complaints Directly on the Regulatory Radar

The Attorney General's September 17 alert encourages workers with information about companies developing AI technology to report potential violations of law through a secure whistleblower portal. The Office states that complaints may be made anonymously and confidentially. The alert is available here.


The alert also points toward New York's Responsible AI Safety and Education Act, or RAISE Act. The statute takes effect January 1, 2027 and applies to covered frontier AI developers, including additional requirements for certain large frontier developers involving safety frameworks, catastrophic-risk assessment, cybersecurity, internal governance, and critical-safety-incident reporting. New York General Business Law Article 44-B.


The RAISE Act does not regulate every company that uses AI. Its scope is directed at covered frontier-model developers. It is nevertheless important context for the Attorney General's alert because the Act gives the Attorney General civil-enforcement authority for specified violations after the law becomes effective. New York General Business Law § 1427.


Companies should also avoid a common mistake: assuming that conduct involving AI is legally unregulated until an AI-specific statute applies. Existing employment, privacy, cybersecurity, discrimination, consumer-protection, securities, contract, safety, and other laws may already govern the underlying conduct.

An AI Whistleblower Complaint Creates Two Problems to Manage Separately

Once an employee raises a serious concern, management should separate two questions.


First: Is the underlying allegation true?


Second: Is the employee being treated differently because the concern was raised?


Those are separate risk tracks. A company can ultimately conclude that the underlying allegation is unsubstantiated and still create exposure if managers retaliate against the employee for making a protected report. Conversely, treating every complaint as automatically protected does not mean that ordinary performance, conduct, or disciplinary issues disappear. The analysis is fact-specific and should be documented carefully.

New York's Whistleblower Law Is Broad, but It Has Conditions

New York Labor Law § 740 generally prohibits retaliatory action against an employee who discloses or threatens to disclose to a supervisor or public body an employer activity, policy, or practice that the employee reasonably believes violates a law, rule, or regulation, or poses a substantial and specific danger to public health or safety. It also protects certain participation in public investigations and certain objections or refusals to participate. New York Labor Law § 740.


For disclosures to a public body, the statute generally requires a good-faith effort to notify the employer and give the employer a reasonable opportunity to correct the issue. The statute contains exceptions, including circumstances involving imminent and serious public danger, possible destruction or concealment of evidence, potential harm, or a reasonable belief that the supervisor already knows of the conduct and will not correct it. See N.Y. Labor Law § 740(3).


That makes the internal reporting process especially important. A company that gives employees a credible way to raise concerns, investigates them seriously, and documents corrective action is in a materially different position from a company whose reporting process exists only on paper.

Pennsylvania Requires a Different Analysis

Pennsylvania should not simply be treated as if it has the same private-sector whistleblower statute as New York.


The Pennsylvania Whistleblower Law protects employees in covered settings involving public bodies and certain employers receiving public money to perform work or provide services relating to a public body. It prohibits specified retaliation for good-faith reports of wrongdoing or waste and for certain participation in investigations. Pennsylvania Whistleblower Law, Act 169 of 1986.


That statute is not a general private-sector whistleblower law covering every Pennsylvania employer. Depending on the facts, however, other federal or state anti-retaliation provisions, contractual protections, employment laws, securities laws, safety laws, or protected concerted-activity principles may apply. The underlying subject of the employee's complaint therefore matters.

Do Not Investigate the Whistleblower Instead of the Allegation

One of the fastest ways to make a difficult situation worse is to shift the company's attention from the allegation to the person who raised it.


Management will naturally want to know whether the employee is credible, whether there is a performance history, whether the employee has a personal dispute with a supervisor, and whether the complaint is exaggerated. Those facts may ultimately matter. They should not become the opening premise of the investigation.


The first task is to define the allegation neutrally. What conduct is being reported? What system, model, product, deployment, disclosure, or decision is involved? Which people knew what, and when? What records can confirm or contradict the allegation?


An investigation structured around those questions is more likely to produce useful facts and is easier to defend later if a regulator, court, board, auditor, or outside counsel reviews the company's response.

Preserve the AI Evidence Before It Changes

AI investigations can present preservation issues that are less obvious than preserving ordinary email.


Depending on the allegation, relevant evidence may include model versions, system prompts, logs, safety evaluations, red-team results, incident reports, internal chat messages, approval records, testing data, vendor communications, deployment decisions, access records, configuration changes, training or fine-tuning documentation, and records showing who approved a particular release or use.


If litigation or a government investigation is reasonably anticipated, counsel should assess preservation obligations promptly. Routine deletion, system updates, model replacement, overwritten logs, or automated retention settings can eliminate information that later becomes central to determining what occurred.


This is also where a properly scoped internal investigation and risk review can be valuable. The company should identify what must be preserved before the underlying technology or its records change.

Privilege Does Not Happen Automatically

Businesses often assume that putting a lawyer in the room makes an internal investigation privileged. That is too simple.


The attorney-client privilege generally protects confidential communications made for the purpose of obtaining or providing legal advice. In the corporate context, the Supreme Court's decision in Upjohn Co. v. United States rejected a narrow "control group" approach and recognized that communications with employees can be privileged when the requirements for the privilege are satisfied. Upjohn Co. v. United States, 449 U.S. 383 (1981).


That does not mean every factual investigation, email copying a lawyer, interview note, or internal report is automatically protected from disclosure.


At the outset, counsel should define the legal purpose and scope of the investigation, determine who is directing it, control dissemination of sensitive communications, and consider whether outside counsel or specialized investigators should be retained when independence, credibility, technical expertise, or management conflicts are concerns.


Employees interviewed by company counsel should also understand whom the lawyer represents. An appropriate Upjohn warning generally makes clear that counsel represents the company, that the privilege belongs to the company, and that the company may decide whether to disclose information learned during the interview.

Be Careful Using AI to Investigate an AI Complaint

There is an additional issue that did not exist in many traditional investigations: the investigation team may itself be tempted to use generative AI to summarize interviews, analyze documents, search communications, or draft investigative materials.


That can create confidentiality, privilege, data-security, reliability, and recordkeeping concerns. Sensitive investigation material should not be placed into an unapproved public AI system merely because the tool is convenient.


If AI tools are used in an investigation, the company should understand the vendor's data-use practices, security, retention, access controls, and whether submitted information is used for model training. Human investigators should remain responsible for credibility judgments, factual conclusions, and recommendations.

Confidentiality Agreements Are Not a Wall Around Government Reporting

Companies have legitimate reasons to protect trade secrets, confidential business information, model architecture, cybersecurity controls, and other proprietary information. But confidentiality provisions must be drafted and applied with whistleblower rights in mind.


For example, SEC Rule 21F-17(a) prohibits actions that impede an individual from communicating directly with SEC staff about a possible securities-law violation, including enforcing or threatening to enforce a confidentiality agreement against such communications. SEC Whistleblower Protections and Rule 21F-17.


Not every AI complaint involves securities law, and Rule 21F-17 is not a universal whistleblower statute. The broader drafting lesson remains useful: employment agreements, NDAs, severance agreements, policies, and investigation instructions should not be written or administered as though legitimate confidentiality interests automatically prohibit protected communications with government authorities.

What General Counsel Should Do When an AI Whistleblower Complaint Arrives

A workable response should be disciplined without becoming bureaucratic.

  1. Triage the allegation immediately. Identify the conduct alleged, the potentially affected people or customers, the systems involved, and any immediate safety, cybersecurity, legal, or disclosure risk.

  2. Separate the investigation from employment decisions. Managers evaluating the employee's performance should not casually mix those decisions with the investigative process. Document legitimate employment decisions carefully.

  3. Preserve relevant evidence. Consider ordinary business records and AI-specific records such as logs, model versions, testing, safety reports, prompts, access records, deployment decisions, and vendor data.

  4. Determine who should lead the investigation. In-house counsel may be appropriate for some matters. Outside counsel or an independent investigator may be preferable when senior management is implicated, the issue is highly sensitive, independence is important, or regulator scrutiny is likely.

  5. Define privilege expectations accurately. Structure the investigation for its legal purpose where appropriate, control distribution, and give proper Upjohn warnings during employee interviews.

  6. Assess retaliation risk separately. Determine whether the employee's conduct may be protected under applicable whistleblower, employment, securities, safety, labor, or other laws.

  7. Review confidentiality language. Make sure NDAs, severance agreements, employee policies, and investigation instructions contain appropriate regulatory and whistleblower carve-outs where required.

  8. Decide whether escalation is necessary. Material safety, regulatory, financial, disclosure, or management-integrity issues may require escalation to senior leadership, the board, a board committee, insurers, auditors, or outside specialists.

  9. Document the company's response. A regulator examining the issue later may care not only about the original allegation, but also about what the company did after receiving it.

AI Whistleblower Complaints Are Also an AI Governance Test

A company can have an AI policy, an AI committee, a model inventory, and a sophisticated vendor-review process and still fail the governance test that becomes most visible after an employee raises a serious concern.


The real test is whether people know where to report a problem, whether someone independent evaluates it, whether evidence is preserved, whether management receives bad news without punishing the messenger, and whether legal, technical, compliance, and business teams can reach a defensible conclusion.


The New York Attorney General's alert gives employees another visible external reporting channel. Businesses should assume that an internal AI concern may eventually be reviewed outside the company and build their internal response accordingly.


For companies without a full-time in-house legal department, an experienced Fractional General Counsel/Outside General Counsel can help coordinate the legal, employment, investigative, governance, vendor, and regulatory issues before separate problems begin moving in different directions.

About Todd B. Nurick

Todd B. Nurick is a Pennsylvania and New York business attorney with approximately 30 years of experience advising businesses on contracts, transactions, corporate governance, investigations, compliance, employment-related business issues, risk management, and disputes. Through the Law Office of Todd B. Nurick, he also serves businesses as Fractional General Counsel/Outside General Counsel, providing experienced legal oversight without requiring a full-time in-house legal department.

Sources

Office of the New York Attorney General, Industry Alert: Attorney General James Urges Workers With Knowledge of Unsafe AI Development to File Whistleblower Complaints, Sept. 17, 2026. New York Attorney General source

New York Labor Law § 740, Retaliatory Action by Employers; Prohibition. New York statutory source

New York General Business Law Article 44-B, Responsible AI Safety and Education (RAISE) Act. New York statutory source

New York General Business Law § 1427, RAISE Act Enforcement. New York statutory source

Pennsylvania Whistleblower Law, Act of Dec. 12, 1986, P.L. 1559, No. 169. Pennsylvania statutory source

Upjohn Co. v. United States, 449 U.S. 383 (1981). U.S. Reports / GovInfo source

U.S. Securities and Exchange Commission, Whistleblower Protections and Rule 21F-17. SEC source

National Labor Relations Board, Concerted Activity. NLRB source

This article is for general informational purposes only and does not constitute legal advice or create an attorney-client relationship. Whistleblower, retaliation, employment, AI, privilege, and regulatory issues are highly fact-specific, and businesses should obtain legal advice concerning their particular circumstances.

bottom of page