The analogy

A trial assistant, talented and lightning-fast, hands you documents that are perfect in form. You wouldn't entrust them with the safe on day one, you wouldn't sign off on their numbers without looking at them, you wouldn't send out a letter of theirs without rereading it. AI is that assistant: very high productivity, reliability still to be verified. Trust is built on checks, not granted sight unseen.

The point is not whether to use it — you already do — but with what process. Without a process, every output is a gamble. With a process, it becomes repeatable, defensible work.

How it really works

The three risks that matter at work

The first is confidentiality: what you paste into the tool can end up outside your control, and on some services the data you enter is used to improve the model unless you opt out, the explicit deactivation. Client data, contracts, proprietary code, personal information: this does not go into a tool whose handling you don't control.

The second is accuracy: AI produces false statements with the same tone as true ones. Publishing them makes you responsible for the error.

The third is originality: the output may resemble an existing work too closely, and the infringement becomes yours when you publish.

The process that closes them

You don't need different rules for every case. You need a fixed filter, to apply before entering and before publishing.

Before entering: is the data confidential? If so, it doesn't go in, or it goes in anonymized (names and numbers replaced with placeholders).

Before publishing: are the facts verified against real sources? Is the text original? On sensitive topics, do I have a professional's oversight?

The difference between internal use and published content

A draft that stays between you and yourself tolerates more risk: you'll review it anyway. Content that goes out — to a client, online, in an official document — requires all the checks, because that is where responsibility takes shape. Calibrate the verification effort to where the output will end up, not to how good it seems to you.

What you can do in practice

  1. Turn off training on your data. In the tool's settings look for the option on data controls or use for training and turn it off; use temporary chats for sensitive content. For work with third-party data, consider a business version that contractually guarantees no reuse.
  2. Anonymize before pasting. Replace names, figures, and identifying details with placeholders. The operational syntax to ask for help with the analysis without exposing the real data:
Analyze this text in which I have replaced the sensitive data with placeholders
like [CLIENT], [AMOUNT], [DATE]. Keep the placeholders in your answer,
don't ask me for the real values.
  1. Verify the facts with external sources. Ask the AI for the sources, then open them. For numbers and quotations, confirm against an independent primary source.
  2. Check originality. Distinctive phrases searched in quotation marks for texts; reverse image search for images.
  3. Keep human judgment where it weighs. On contracts, health, finance, delicate communications, the output is working material for a professional, not the decision.
  4. Keep a log. Which tool, for which stage, with which verification. If one day you have to answer for the work, the log is your defense.

When it does NOT work (and how to fix it)

If you've already pasted confidential data

You can't "withdraw" it from the model, but you can limit the damage: delete the conversation, check in the settings that training was turned off, and if the data belonged to a client or was personal in nature, consider the notification obligations set by your organization. From now on, anonymize first.

If you've published a fact that turned out to be false

Correct it immediately and visibly, not silently. A prompt correction limits the reputational and legal damage; a hidden error makes it worse. Add source-checking to the process so you don't repeat it.

If your sector forbids or limits AI

Healthcare, legal, public administration, and finance often have strict internal rules. Check your organization's policy before using any tool: the internal rule beats convenience, and breaking it is a risk in itself.

A tip from someone who really uses it

Write your filter on a sticky note next to the screen: "Confidential? Verified? Original?". Three questions, ten seconds. Risk at work doesn't come from using AI, it comes from skipping the check because you're in a hurry. The note is the brake that haste tends to remove.

Frequently asked questions

Can I use AI for documents that contain client data?

Only if you've turned off data reuse or you use a business version with contractual guarantees, and better still if you anonymize first. Without these conditions, you are exposing third-party data: it's the most serious risk and the one that triggers legal obligations.

Do I have to tell the client I used AI?

It depends on the contract and the expectations. Transparency never harms; hiding it and being caught does. For content distributed in Europe, in many cases the declaration is due.

Can a company really get into trouble over a text written by AI?

Yes, and not for "having used AI", but for having published the wrong output: a false figure spread, content that copies someone else's work, confidential data exposed. Responsibility falls on the organization, not on the tool. This is exactly why the control process matters more than the tool you choose.