Artificial intelligence is rapidly becoming part of everyday business operations.
Companies are using AI-powered tools to answer customer questions, analyse business data, screen job applicants, generate marketing content, assist employees, automate administrative tasks, and support management decision-making.
For businesses, the potential benefits are significant. AI can improve productivity, reduce repetitive work, accelerate analysis, and create new ways of delivering products and services.
However, the increasing use of AI also creates a new category of legal and compliance risks.
When a company enters information into an AI system, generates content using an AI model, relies on AI to make recommendations, or integrates an external AI service into its business operations, several legal questions may arise.
What happens to personal data submitted to the AI system? Who owns AI-generated content? Can confidential company information be shared with an AI provider? What happens if an AI system produces inaccurate or discriminatory results? Who is responsible when an AI-assisted decision causes financial or reputational harm?
These questions make AI law in Indonesia an increasingly important consideration for businesses adopting artificial intelligence.
For companies, the issue is not necessarily whether AI should be used. The more important question is how AI can be adopted while managing legal, contractual, data, intellectual property, and corporate governance risks.
At Kairos Advocates, we view AI adoption as both a technology and legal governance issue. Companies need to understand not only what AI can do, but also the legal consequences of using it within their business operations.
AI Adoption Is Creating New Legal Risks for Businesses
AI systems can process large amounts of information and generate outputs at remarkable speed. But speed and efficiency do not eliminate legal responsibility.
In many circumstances, the company remains responsible for how technology is deployed.
For example, a business may use an AI chatbot to communicate with customers. If the chatbot provides misleading information, the company may still face customer complaints or commercial consequences.
Similarly, an HR department may use AI to screen job applications. If the system produces discriminatory results, the company may need to address the consequences even if the decision was influenced by an automated tool.
AI therefore should not be treated as an independent legal decision-maker.
It should be incorporated into the company’s existing legal and governance framework.
1. Personal Data Protection and AI
One of the most significant legal risks associated with AI is the handling of personal data.
Companies may enter personal information into AI systems for various purposes, including:
- Customer service;
- Data analysis;
- Marketing;
- Recruitment;
- Employee management;
- Customer profiling; and
- Business intelligence.
This creates important data protection questions.
Before using personal data with an AI system, companies should consider whether they have an appropriate legal basis and whether the processing is consistent with applicable data protection requirements.
Indonesia’s Personal Data Protection Law creates obligations concerning the processing and protection of personal data. Businesses therefore need to consider how AI applications fit within their existing data protection responsibilities.
Important questions include:
- What personal data is being submitted to the AI system?
- Why is the data being processed?
- Who controls the data?
- Who processes the data?
- Where is the data stored?
- Can the AI provider use the information for other purposes?
- How long is the information retained?
- Can the data be deleted?
- Is the data transferred to another jurisdiction?
These questions become particularly important when a company uses third-party AI platforms.
A free or commercially available AI tool may appear harmless from an operational perspective. However, employees may unknowingly upload customer records, employee information, financial data, or other sensitive information into the system.
Companies should therefore establish clear rules regarding what information employees are permitted to submit to AI tools.
2. Confidentiality and Trade Secrets
Data protection is not the only concern.
Businesses also need to protect confidential information and trade secrets.
Consider a company employee who uses an AI platform to summarise an internal document. The document may contain:
- Business strategies;
- Financial information;
- Customer lists;
- Pricing information;
- Product development plans;
- Technical specifications;
- Legal documents; or
- Trade secrets.
If the AI platform processes or stores that information, the company may lose control over where the information goes and how it is handled.
This can create serious confidentiality risks.
The problem may become even more significant when employees use consumer AI applications without understanding their data-handling practices.
Companies should therefore develop internal AI policies that clearly define:
- What information may be submitted to AI systems;
- What information is prohibited;
- Which AI tools are approved;
- Who can use them;
- How outputs must be reviewed; and
- How confidential information should be handled.
Confidentiality obligations should also be considered when negotiating contracts with AI vendors.
3. Intellectual Property and AI-Generated Content
Another emerging issue concerns intellectual property.
Businesses increasingly use AI to generate:
- Articles;
- Advertising copy;
- Images;
- Videos;
- Software code;
- Product descriptions;
- Presentations; and
- Other creative materials.
This creates several legal questions.
Who owns the output?
Can the company commercially use it?
Could the output unintentionally reproduce someone else’s protected work?
What rights does the AI provider claim under its terms of service?
These questions cannot always be answered simply by saying that the company paid for the AI service.
Intellectual property rights depend on the applicable legal framework, contractual arrangements, and the nature of the material involved.
Companies should therefore avoid assuming that every AI-generated output is automatically free from intellectual property risk.
For commercially important materials, businesses should consider appropriate human review and documentation of the creation process.
This is particularly important for brands, advertising campaigns, software, product designs, and other assets that may become valuable corporate property.
4. AI Vendors and Contractual Risks
Many businesses do not develop AI systems themselves.
Instead, they purchase or subscribe to AI services provided by third-party vendors.
This creates another important area of legal risk: contracts.
Before adopting an AI solution, businesses should review the provider’s contractual terms carefully.
Important provisions may include:
- Data ownership;
- Data processing;
- Confidentiality;
- Intellectual property;
- Security obligations;
- Service levels;
- Liability limitations;
- Indemnification;
- Data retention;
- Termination;
- Data deletion; and
- Dispute resolution.
A company should understand what happens to its information when the contract ends.
Can the company retrieve its data?
Will the provider delete it?
Can the provider use customer information to improve its services?
What happens if the AI service becomes unavailable?
Who bears responsibility if a security incident occurs?
These questions are particularly important when AI becomes integrated into critical business processes.
A business should not evaluate an AI vendor solely based on features and price. Legal and contractual risk should also form part of the procurement process.
5. AI in Recruitment and Employment Decisions
Human resources is another area where AI can create significant legal exposure.
Companies may use AI to:
- Screen CVs;
- Rank candidates;
- Analyse applications;
- Evaluate employee performance;
- Predict employee turnover; or
- Assist recruitment decisions.
Although these tools may improve efficiency, automated systems can produce biased or inaccurate results.
For example, an AI recruitment system may disproportionately exclude candidates based on patterns embedded in historical data.
The company cannot necessarily avoid responsibility simply by arguing that “the AI made the decision.”
Businesses should maintain meaningful human oversight over significant employment decisions.
AI should ideally support decision-making rather than replace appropriate managerial and legal judgment.
Companies should also consider whether applicants and employees need to be informed about relevant data processing activities and how personal information is handled.
6. AI and Customer Service
AI-powered customer service has become increasingly common.
Chatbots can answer questions, recommend products, process basic requests, and provide information around the clock.
However, customer-facing AI systems create several potential risks.
An AI chatbot may provide:
- Incorrect product information;
- Inaccurate pricing;
- Misleading statements;
- Incorrect contractual explanations; or
- Advice that the company never intended to provide.
If customers rely on those statements, disputes may arise regarding the company’s responsibility.
Businesses should therefore establish appropriate controls around AI-generated customer communications.
Important measures may include:
- Clearly defining what the AI system is authorised to do;
- Limiting the types of questions it can answer;
- Escalating sensitive matters to human staff;
- Monitoring AI outputs;
- Maintaining records where appropriate; and
- Regularly testing the system.
The more consequential the interaction, the greater the need for human oversight.
7. AI and Corporate Decision-Making
AI is increasingly being used to support management decisions.
Executives may use AI to analyse:
- Market trends;
- Financial information;
- Customer behaviour;
- Business performance;
- Investment opportunities; or
- Operational risks.
AI can provide valuable insights, but management should not automatically treat AI-generated recommendations as objective or correct.
AI systems depend on the quality and context of the data they receive.
A flawed dataset can produce a flawed recommendation.
From a corporate governance perspective, directors and management should continue to exercise appropriate judgment when making significant business decisions.
AI can assist management, but it should not eliminate accountability.
This becomes particularly important when AI recommendations affect major transactions, financial commitments, employees, customers, or shareholders.
8. Liability When AI Produces an Error
One of the most difficult questions surrounding AI is responsibility.
Suppose an AI system generates incorrect information that causes a company to lose money.
Who is responsible?
The answer may depend on several factors, including:
- How the AI system was configured;
- Who provided the underlying data;
- How the output was reviewed;
- What the contract with the AI vendor says;
- Whether employees followed internal policies; and
- Whether the company had appropriate safeguards.
Businesses should not assume that responsibility automatically shifts to the AI provider.
Many AI service agreements contain limitations of liability and disclaimers that can significantly affect the company’s legal position.
This makes contractual review particularly important before integrating AI into important business processes.
9. AI Governance Should Become Part of Corporate Governance
As AI becomes more deeply embedded in business operations, companies should consider developing an internal AI governance framework.
An AI governance framework can define:
- Which AI tools are approved;
- Who is authorised to use them;
- What information may be processed;
- What decisions require human review;
- How AI outputs are monitored;
- How incidents should be reported; and
- Who is responsible for AI-related compliance.
For larger companies, AI governance may also involve cooperation between:
- Management;
- Legal teams;
- IT;
- Compliance;
- Human resources;
- Data protection teams; and
- Information security personnel.
The objective is not necessarily to create excessive bureaucracy.
Instead, the purpose is to ensure that AI adoption remains aligned with the company’s legal obligations and risk appetite.
Practical Checklist Before Your Company Uses AI
Before introducing a new AI tool into business operations, management should consider the following questions:
Data
- What data will the AI system process?
- Does the data contain personal information?
- Is sensitive or confidential information involved?
- Where will the data be stored?
- Can the vendor reuse the data?
Contracts
- Who owns the data?
- Who owns the AI-generated output?
- What liability does the vendor accept?
- What happens after termination?
- Is there an adequate confidentiality obligation?
Intellectual Property
- Can the company commercially use the output?
- Are third-party rights potentially involved?
- Are ownership rights properly documented?
- Does the company’s use of AI comply with applicable licensing terms?
Governance
- Who approves the use of AI?
- Who monitors the system?
- Which decisions require human review?
- What happens if the AI generates an incorrect result?
Risk Management
- What happens if the AI system fails?
- Could its output cause financial or reputational harm?
- Does the company have an incident response procedure?
- Are employees trained on responsible AI use?
These questions can form the foundation of an internal AI risk assessment.
How Kairos Advocates Can Help Businesses Manage AI Legal Risks
AI adoption is no longer solely a technology issue.
As businesses integrate AI into customer service, recruitment, marketing, data analysis, software development, and management processes, legal considerations become increasingly important.
Kairos Advocates can assist companies in navigating the legal aspects of technology adoption and developing a more structured approach to AI-related risk management.
Legal support may include:
- Reviewing AI-related contracts and vendor agreements;
- Assessing data protection and confidentiality risks;
- Reviewing intellectual property considerations;
- Advising on AI governance and corporate policies;
- Identifying potential contractual and liability exposure;
- Reviewing employment and recruitment implications;
- Supporting technology transactions; and
- Advising businesses on legal risk management in digital transformation.
The appropriate approach will depend on how the company uses AI, what data is involved, the industry in which it operates, and the potential consequences of AI-assisted decisions.
Conclusion: AI Innovation Requires Legal Responsibility
Artificial intelligence can provide significant opportunities for businesses, but technological innovation should be accompanied by appropriate legal risk management.
The most important legal issues are not limited to whether AI is technically effective. Companies must also consider personal data protection, confidentiality, intellectual property, vendor contracts, employment practices, liability, and corporate governance.
Businesses should therefore avoid adopting AI solely because a tool is inexpensive, popular, or highly efficient.
Before integrating AI into important business processes, companies should understand what information will be processed, who controls it, what contractual obligations apply, who owns the resulting work, and who remains responsible when something goes wrong.
The legal framework surrounding AI will continue to evolve as technology develops. Businesses that establish responsible governance and risk management practices early will be better positioned to adopt AI while protecting their legal and commercial interests.
Kairos Advocates is committed to helping businesses navigate emerging legal challenges in technology and digital transformation. If your company is adopting AI or planning to integrate AI into its operations, a legal review can help identify potential risks before they become costly disputes or compliance problems.
Contact Kairos Advocates to discuss AI-related legal risks, technology contracts, data protection, intellectual property, and corporate governance for your business.
