Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
AI Integration

Where Everyday AI Use Goes Wrong at Work

Last updated:

The mistakes are rarely dramatic

When AI goes wrong in an ordinary business, it rarely makes headlines. A quote goes out with a figure the model made up. A client's contract is pasted into a free chatbot on a personal account. A support reply promises a refund policy that does not exist. A junior analyst submits a report with three references to research papers that were never written.

Each incident is small. Together they erode customer trust, create data protection exposure and, occasionally, produce a genuinely expensive mistake. The good news is that most of them follow a handful of patterns, and the patterns have simple fixes.

Mistake one: confidential data in the wrong tool

This is the most common and the least visible. Someone wants help with a task, the approved tool is clunky or unknown to them, and they paste client names, contracts, salaries or health information into whatever free assistant is open in their browser.

Terms vary, and some consumer tools may use conversations to improve their models unless settings are changed. Even where they do not, you have moved personal data to a processor with no contract, which is a data protection problem in itself under UK and EU rules.

  • Provide an approved business tool that is at least as easy to use as the free one
  • Say plainly what must never go into any unapproved tool
  • Make it easy to ask 'is this okay to paste?' without embarrassment

Banning AI outright tends to push usage underground rather than stop it. Our piece on shadow AI at work covers that dynamic in detail.

Mistake two: trusting facts it made up

Language models produce fluent, plausible text whether or not it is true. They invent statistics, misremember regulations, fabricate citations and get arithmetic wrong, all in the same confident tone as their correct answers.

Output typeRisk of inventionRule
Figures and calculationsHighCompute in a spreadsheet or system, never in the chat
Legal or regulatory claimsHighCheck the primary source or ask a professional
Citations and referencesHighOpen every link; confirm every source exists
Facts about your own businessHigh unless providedOnly trust facts you gave it
Summaries of a document you suppliedLowerCheck references for key points
Rewording your own textLowRead it for meaning drift
The dangerous AI answer is not the wrong one. It is the wrong one that looks exactly like the right one.

Mistake three: output sent without a human reading it

The time saving tempts people to skip the read-through. Customer emails with the wrong name, social posts with a claim you cannot support, proposals promising outcomes nobody agreed to. None of these would pass a two-minute read.

The rule is simple and worth writing down: anything a customer, supplier, regulator or the public will see is read in full by a named person before it goes.

Mistake four: quiet over-reliance

Some of the costs are slower. A junior who always asks AI to draft never learns to structure an argument. A team that always asks for a summary stops reading the source documents, and loses the instinct for when something does not add up. Nobody notices until the tool is unavailable or wrong about something important.

  • Have juniors write first and use AI to critique, at least while they are learning
  • Periodically read the full source rather than the summary, especially for important decisions
  • Keep the skills the business depends on inside people, not only inside prompts
  • Watch for the phrase 'the AI said' used to end a discussion

Mistake five: nobody accountable

When an AI-assisted piece of work goes wrong, the question 'whose is this?' needs a clear answer. The person who sent it is accountable for it, exactly as if they had written it themselves. The tool is not a colleague who shares the blame.

Accountability also applies to the tools themselves. Someone should own the decision about which AI tools are approved, what they are connected to and what data goes into them. In many small businesses nobody does, and every new subscription arrives through someone's expense claim. Under the EU AI Act, businesses using AI also have AI literacy obligations for their staff, which is one more reason for someone to own this.

A one-page set of rules that prevents most of it

  1. Use only these approved AI tools for work: [list].
  2. Never put these into any AI tool not on that list: client personal data, contracts, financial account details, health or HR information.
  3. Anything external is read in full by a named person before it is sent or published.
  4. Numbers come from systems and spreadsheets, not from AI chat.
  5. Check every fact, legal claim and reference you pass on.
  6. You are responsible for anything you send, however it was drafted.
  7. If you are not sure, ask [name]. Asking is always the right call.

That fits on a page and covers most real-world incidents. For a fuller version, see writing an AI policy for your business.

At SpiderHunts, when we help a business bring AI into daily work, we set these rules up before we build anything, and we design integrations so that the safe path is also the easy path: approved tools connected to the right data, drafts that require approval, and numbers pulled from systems rather than generated. That approach runs through all our AI integration projects. If you want the positive side of the same picture, our post on AI habits that save a team time is the companion to this one.

Frequently asked questions

What are the biggest risks of using AI at work?

Confidential or personal data going into unapproved tools, invented facts and figures being passed on, and AI output reaching customers without human review. Over time, over-reliance and unclear accountability also cause problems.

Is it against GDPR to paste customer data into ChatGPT?

It can be. Putting personal data into a tool without an appropriate data processing agreement, a lawful basis and suitable safeguards may breach UK or EU GDPR. Business plans with proper terms reduce that risk, but you still need to consider what data is necessary.

Should we ban AI tools at work?

Outright bans usually push usage onto personal accounts where you have no visibility. Providing an approved tool with clear rules on data and review tends to be safer.

Who is responsible when AI makes a mistake at work?

The person who used the output and the business that employs them, just as with any other work. Using AI does not transfer responsibility to the tool or its vendor.

How do I check if AI-generated information is accurate?

Verify figures in your own systems, open every reference to confirm it exists, check legal or regulatory claims against primary sources, and ask for page references when summarising documents you provided.

Keep reading

Worried about how your team is using AI?

Tell us which tools people are using and what they use them for. We will point out the real risks, and the ones that are not worth losing sleep over.

Book a free 30-minute call Get a project estimate WhatsApp us

Related services

What we build for problems like this one

AI IntegrationEnterprise AIAI Agents