Where Everyday AI Use Goes Wrong at Work
Last updated:
The mistakes are rarely dramatic
When AI goes wrong in an ordinary business, it rarely makes headlines. A quote goes out with a figure the model made up. A client's contract is pasted into a free chatbot on a personal account. A support reply promises a refund policy that does not exist. A junior analyst submits a report with three references to research papers that were never written.
Each incident is small. Together they erode customer trust, create data protection exposure and, occasionally, produce a genuinely expensive mistake. The good news is that most of them follow a handful of patterns, and the patterns have simple fixes.
Mistake one: confidential data in the wrong tool
This is the most common and the least visible. Someone wants help with a task, the approved tool is clunky or unknown to them, and they paste client names, contracts, salaries or health information into whatever free assistant is open in their browser.
Terms vary, and some consumer tools may use conversations to improve their models unless settings are changed. Even where they do not, you have moved personal data to a processor with no contract, which is a data protection problem in itself under UK and EU rules.
- Provide an approved business tool that is at least as easy to use as the free one
- Say plainly what must never go into any unapproved tool
- Make it easy to ask 'is this okay to paste?' without embarrassment
Banning AI outright tends to push usage underground rather than stop it. Our piece on shadow AI at work covers that dynamic in detail.
Mistake two: trusting facts it made up
Language models produce fluent, plausible text whether or not it is true. They invent statistics, misremember regulations, fabricate citations and get arithmetic wrong, all in the same confident tone as their correct answers.
| Output type | Risk of invention | Rule |
|---|---|---|
| Figures and calculations | High | Compute in a spreadsheet or system, never in the chat |
| Legal or regulatory claims | High | Check the primary source or ask a professional |
| Citations and references | High | Open every link; confirm every source exists |
| Facts about your own business | High unless provided | Only trust facts you gave it |
| Summaries of a document you supplied | Lower | Check references for key points |
| Rewording your own text | Low | Read it for meaning drift |
The dangerous AI answer is not the wrong one. It is the wrong one that looks exactly like the right one.
Mistake three: output sent without a human reading it
The time saving tempts people to skip the read-through. Customer emails with the wrong name, social posts with a claim you cannot support, proposals promising outcomes nobody agreed to. None of these would pass a two-minute read.
The rule is simple and worth writing down: anything a customer, supplier, regulator or the public will see is read in full by a named person before it goes.
Mistake four: quiet over-reliance
Some of the costs are slower. A junior who always asks AI to draft never learns to structure an argument. A team that always asks for a summary stops reading the source documents, and loses the instinct for when something does not add up. Nobody notices until the tool is unavailable or wrong about something important.
- Have juniors write first and use AI to critique, at least while they are learning
- Periodically read the full source rather than the summary, especially for important decisions
- Keep the skills the business depends on inside people, not only inside prompts
- Watch for the phrase 'the AI said' used to end a discussion
Mistake five: nobody accountable
When an AI-assisted piece of work goes wrong, the question 'whose is this?' needs a clear answer. The person who sent it is accountable for it, exactly as if they had written it themselves. The tool is not a colleague who shares the blame.
Accountability also applies to the tools themselves. Someone should own the decision about which AI tools are approved, what they are connected to and what data goes into them. In many small businesses nobody does, and every new subscription arrives through someone's expense claim. Under the EU AI Act, businesses using AI also have AI literacy obligations for their staff, which is one more reason for someone to own this.
A one-page set of rules that prevents most of it
- Use only these approved AI tools for work: [list].
- Never put these into any AI tool not on that list: client personal data, contracts, financial account details, health or HR information.
- Anything external is read in full by a named person before it is sent or published.
- Numbers come from systems and spreadsheets, not from AI chat.
- Check every fact, legal claim and reference you pass on.
- You are responsible for anything you send, however it was drafted.
- If you are not sure, ask [name]. Asking is always the right call.
That fits on a page and covers most real-world incidents. For a fuller version, see writing an AI policy for your business.
At SpiderHunts, when we help a business bring AI into daily work, we set these rules up before we build anything, and we design integrations so that the safe path is also the easy path: approved tools connected to the right data, drafts that require approval, and numbers pulled from systems rather than generated. That approach runs through all our AI integration projects. If you want the positive side of the same picture, our post on AI habits that save a team time is the companion to this one.
Frequently asked questions
What are the biggest risks of using AI at work?
Is it against GDPR to paste customer data into ChatGPT?
Should we ban AI tools at work?
Who is responsible when AI makes a mistake at work?
How do I check if AI-generated information is accurate?
Worried about how your team is using AI?
Tell us which tools people are using and what they use them for. We will point out the real risks, and the ones that are not worth losing sleep over.