I want to admit something before I ask you to agree with me about anything.
Some months ago I used a work AI assistant to draft a message I was dreading — the kind about a colleague, where you are trying to be fair and also trying very hard not to say the true thing. And because these tools are conversational, and because it was late, I did what I suspect a great many of you have done: I asked it, in the same thread, whether I was being unreasonable. I typed a sentence about a real person that I would not have said out loud in a meeting room. Then I closed the tab and thought about it exactly never again.
Weeks later, reading vendor documentation for an unrelated reason, I learned where that conversation went. Not deleted. Not anonymized into some statistical haze. Sitting in a mailbox, indexed, retained under a policy somebody in my organization had chosen, retrievable by a person with the right role assignment and a reason.
Here is the part that still bothers me. I read this stuff professionally, and I did not know — not because anyone hid it. The documentation is public, thorough, and frankly rather good. I did not know because nothing in the moment of typing told me, and nothing since has let me go and look.
First, what is actually in the log
Let's establish the factual floor, because the argument only matters if the machinery is real. It is.
Microsoft's compliance guidance for its own AI assistant is not coy: like other activities, it says, prompts and responses are captured in the unified audit log. The substance goes somewhere too — those prompts and responses sit in the user's own mailbox, so an organization can open a case and search them the way it would search email, and retention policies can retain or delete the material on a schedule the employer sets.
To be fair, that is not the same as every manager reading your chat over coffee. Displaying the actual prompt and response text requires a specific role assignment, and the documentation says so plainly. This is a governed capability, built for legal holds, security investigations and regulatory compliance. I am not describing a conspiracy. I am describing a filing cabinet.
But a filing cabinet with your unguarded thinking in it is a new kind of object, and the law is already reaching for it. Morrison Foerster's guidance for workplace disputes now itemizes what discovery asks for, and the list includes AI-generated performance reviews or disciplinary drafts relating to a plaintiff, alongside prompts, outputs and AI-assistant meeting transcripts. In February, a federal judge in Manhattan held that a defendant's chatbot conversations were not privileged, reasoning that the AI tool is not a licensed attorney. Fisher Phillips notes that a split appears to be emerging — another court that month protected a plaintiff's chats as work product. So this is unsettled, not settled. Which is precisely when it is worth writing a rule.
Meanwhile, workers have drawn their own conclusions. In Slack's Workforce Index — 17,372 desk workers across fifteen countries, fielded in August 2024 — nearly half, 48 percent, said they would be uncomfortable admitting to their manager that they had used AI for at least one common workplace task. A PagerDuty survey of 1,250 office professionals released in June 2026 found two-thirds had used AI tools at work even though they believed doing so was not permitted under company policy.
Read those together and you have the actual state of the American workplace: people using a tool they are unsure they are allowed to use, in a way they would rather their boss not know about, on a system that writes all of it down.
What the law asks of your employer, in full
Now the part that surprised me — and the reason I am writing this instead of something else.
Connecticut requires that each employer who engages in any type of electronic monitoring shall give prior written notice to all affected employees, informing them of the types of monitoring which may occur. Good. Then the very next sentence says a conspicuous posting shall constitute that prior written notice. A sign on the wall is the notice. And the state's courts have held there is no private cause of action — enforcement runs through the Labor Commissioner, with a maximum penalty starting at five hundred dollars.
That is the general shape of American workplace-monitoring law: tell them once, somewhere, and you are done.
And then there is Delaware, which is where I stopped reading and started writing. Its statute says an employer may not monitor an employee's email or internet usage unless the employer does one of two things. Option two is the familiar one: a one-time notice, acknowledged. Option one is this — an electronic notice of such monitoring or intercepting policies or activities to the employee at least once during each day the employee accesses the employer-provided email or internet access services.
Read that again, because I had to. Daily notice. Every day you log on, the employer tells you again. That idea — the one I was preparing to argue for as though it were novel — has been sitting in an American statute book since the amendment that put it there was approved on July 9, 2002, and the section has not been touched since.
It was simply made optional. The legislature wrote both doors and let the employer pick. I have no survey telling me which door Delaware employers chose, and I am not going to pretend otherwise — the point is structural. When you offer a meaningful notice and a trivial one at the same price, you have not created a right. You have created a preference. The penalty for skipping both, incidentally, is one hundred dollars per violation.
On the second half — your right to see what was collected — the American map is nearly blank. California is the exception, and only recently: employee personal information stopped being exempt from the state's privacy law as of January 1, 2023, giving workers there the right to know what their employer collects about them. Its newer automated-decision rules go further: beginning April 1, 2027, businesses using such systems for significant decisions — a category that expressly includes decisions affecting employment — must give a pre-use notice and honor a request to access information about that use.
Real progress, and still not the thing, because a request is not a window. The state's own guidance says businesses must respond within 45 calendar days, extendable by another 45. Ninety days, at the outside, to be told about a conversation you had in four minutes — by which time the decision it informed has been made, and you were not in the room for it.
The two sentences I would add
So here is what I want, stated plainly enough to be argued with. Two prongs: the recording light and the mirror.
The recording light. Where an employer logs an employee's use of an AI system, the employee is notified at the start of each session that the session is being logged — not once at onboarding, not on a poster by the elevator. Per use. Every new session.
We already accept this everywhere else. You cannot call your bank without a voice telling you the call may be recorded — not once, when you opened the account, but every single time. Nobody calls this a crushing burden on the banking industry, or argues it should be replaced by a line in the terms of service you signed in 2019.
The mirror. Where the data was generated by the employee's own use, the employee can browse it at the time it becomes available to the employer. Not a form. Not a verification process. Not forty-five days. The same screen your employer sees, when they can see it.
That second prong does the real work, and it is the one that will be resisted, so let me be precise about its limit: it covers what your use generated. Your prompts, your outputs, the record of your sessions. Not the security team's investigation file about you, not your manager's notes, not anyone else's data.
The strongest case against what I just proposed
I would rather make this argument against myself than have it made for me.
The best objection is that per-session notice is a cookie banner, and cookie banners failed. This is not a cheap shot; it is supported. When researchers scraped the consent pop-ups on the most popular UK websites for a study presented at CHI 2020, they found dark patterns and implied consent were ubiquitous, and that only 11.8% met the minimal requirements the authors derived from European law. Different setting, different mechanism. But the lesson travels: show a person the same banner four hundred times and you have taught them where the dismiss button is, not what the policy says.
The second objection is sharper still. The Information Technology and Innovation Foundation argues that policymakers should regulate what employers do with workplace data, not which device collects it, criticizing the current congressional bills for regulating workplace technologies based on how much data they collect rather than how employers use it. That is a genuinely good critique: notice is cheap, and does nothing about the underlying use.
And from the free-market side, Adam Thierer and Logan Kolas of the R Street Institute counted more than 1,500 bills with an artificial intelligence nexus sitting in the states, warning the spread would worsen the patchwork of confusing and costly mandates already mounting. If you run a company in thirty states, that is not ideology. It is Tuesday.
Here is my answer, and it is why I want both prongs rather than the first alone. Every one of those objections is an objection to notice by itself — a banner nobody reads, changing nothing. The mirror is what converts the notice from theater into a fact you can check. A recording light with no way to see the recording is exactly the cookie banner they describe; a recording light attached to a window is a different instrument. And the patchwork argument, note, is an argument for doing this federally rather than in thirty state legislatures.
Ontario ran the first half of this experiment and wrote the ceiling into the statute
If you want to know what notice-without-access delivers, you do not need a thought experiment. You need a plane ticket to Toronto.
Ontario did the hard political thing. As of October 11, 2022, all employers in Ontario with 25 or more employees must have a written policy disclosing whether and how they electronically monitor their employees. Compulsory, province-wide, no opt-out door. Next to a Connecticut poster, it is a serious law.
Now read what the province's own guidance says the law does not do. The requirements, it states flatly, do not establish a right for employees not to be electronically monitored by their employer. And then the sentence that should be printed on the wall of every legislature drafting one of these: the employer must state in its policy the purposes for which it may use the information — however, the guidance continues, the law does not limit the employer's use of the information to the stated purposes.
You must be told why. You cannot hold them to it. That is transparency operating exactly as designed, and it is why I do not think the first prong is worth passing alone.
Europe went ex ante rather than per-use: under the EU AI Act, before putting a high-risk system into service at the workplace, employers shall inform workers' representatives and the affected workers that they will be subject to it. Better than nothing — still a single announcement before the thing switches on, not a light that stays lit.
Just imagine the next three years
Everything above assumes the log is a transcript. It is about to stop being one.
Picture your assistant three years from now. It does not wait for prompts; it drafts your replies overnight, reorders your task list, joins the meeting you skipped, and asks you to approve fourteen small things in the morning. Every one of those is an event with a timestamp, an input, an outcome, and — this is the part people miss — a record of what you approved and what you overrode.
At that point your employer is not holding a chat history. They are holding a behavioral model: your working hours, your hesitations, which suggestions you accept and which you quietly reject, how your judgment drifts on a Friday afternoon. Nobody builds that model on purpose. It assembles itself out of ordinary compliance logging, the way a river assembles a canyon.
And you still will not have seen it. The first time you learn what the record says about your judgment is the meeting where somebody has already read it. Close that asymmetry while it is cheap — the mirror costs almost nothing to build today, and becomes politically impossible the moment the model is valuable.
What the people who study this say
The scholarship got here before the legislatures did. Ifeoma Ajunwa — the Asa Griggs Candler Professor of Law at Emory and founding director of its AI and the Future of Work program — argued with Kate Crawford and Jason Schultz in the California Law Review that surveillance capacity had outrun its constraints, leaving the law as the last meaningful avenue to delineate boundaries for worker surveillance. Her book-length version of the argument, from Cambridge University Press, is blunter still: big data and AI are used to surveil workers and shift risk.
The American Civil Liberties Union frames the same gap for a general reader: many of the basic rights we take for granted are not protected when we go to work. Its standard is proportionality rather than prohibition — employers have a legitimate interest in monitoring work, it says, but surveillance often goes well beyond legitimate management concerns.
And then the detail that decided this piece for me. Both of my prongs already exist in American workplaces — bargained rather than legislated. The UC Berkeley Labor Center's inventory of union contract language records that while some provisions require written or annual notice, others require real-time disclosures through signage or system alerts. On access, the same inventory finds contracts giving employees the right to access the types, format, and location of all records maintained under their personal identifier — and, in one professional sports agreement, full access to all data collected from wearables.
So this is not a utopian ask. It is a benefit some workers have already negotiated at the bargaining table, and that everyone without a bargaining table has no mechanism to obtain. ITIF and R Street are right that the mechanism matters and the patchwork is real. Both are arguments about how to write it. Neither is an argument that you should not be able to see your own words.
What does this mean for you?
Concretely, before any of this is law:
Assume the work assistant is a filing cabinet, not a diary. Not because your employer is malicious, but because the retention policy is set by someone whose job is legal risk. If you would not put it in an email, do not type it into a prompt.
Ask your employer two questions in writing. Is my AI usage logged, and what is the retention period? Vague answers are themselves information, and a written question creates a record on your side of the ledger.
Read your monitoring policy, especially in Connecticut, Delaware or Ontario. You may have a posted notice you have never read — and in Ontario you are entitled to the written policy itself.
If you work in California, use the right you already have. The request-to-know is free and it covers your employer. Forty-five days is slow; it is not never.
If you are in a bargaining unit, this is contract language, not a wish. Real-time disclosure and data-access clauses exist today. Someone has already written the words.
The lesson, as I see it
I went looking for an argument that per-use notification would be a bold new idea, and found it half-written in a Delaware statute older than the smartphone. That is a more useful story than the one I expected.
The instinct to tell people they are being recorded is not a modern anxiety we have to talk ourselves into. It is old, ordinary, and already encoded in how we handle telephones, in what unions bargain for, and in one state's employment code since 2002. What we have never done is make the better version mandatory and pair it with the only thing that keeps a notice honest — the ability to go and look.
Delaware wrote one of those two sentences and made it optional. Ontario wrote a stronger version and told employees, in the guidance, exactly how little it buys them. California is closest, and asks you to file a request and wait a quarter of a year.
Nobody has yet written both sentences together, federally, so that they reach the person typing an unguarded thought into a work assistant at eleven at night. That is a small law; it would fit on two pages. My vote? Write it now, while the log is still just a transcript — because the version of this fight we have in 2030, when the record is a model of your judgment rather than a list of your questions, is one we will lose.
The HAIA Foundation argues that the people a system watches should be able to watch it back. If you have ever typed something into a work tool you would not say out loud — and you have — this Substack is written for you.






We have to start to think differently about workers' inputs vs their outputs. You exchange money (e.g. a salary) in return for outputs. If you want to capture inputs, those inputs are a means to an end, not part of the obvious bargain, and the collection thereof needs to be transparent and accessible to the person whose inputs were recorded.