How to use AI at work without creating a problem

Most people are already doing this quietly
In April 2026, Wakefield Research surveyed 1,250 office professionals at companies with revenues above $500m across the UK, US, Australia and Japan on behalf of PagerDuty. Two-thirds, 66%, said they had used AI tools at work despite believing company policy did not permit it. 39% said they would rather use AI without telling anyone at all.
The exposure that creates is not hypothetical. 43% had entered work correspondence into public AI tools, 34% had entered customer data, and 31% had put in financial information or confidential company documents.
If that describes you, you're in the majority rather than in unusual trouble. But the quiet version of this is the risky version, because nobody can help you get it right if nobody knows you're doing it.
Answer two questions before you start
Almost all of the risk sits in two questions, and both have short answers once you ask.
First: which tools am I allowed to use? Most organisations have sanctioned something, and the sanctioned version usually has an enterprise agreement behind it that changes what happens to your data. The free consumer tier of the same product often does not offer the same protections.
Second: what am I allowed to put into it? This is the one people guess at. The answer depends on your organisation's data classifications, and it is worth getting in writing rather than inferring from a policy document written before anyone had tried the tools.
If nobody can tell you, that's useful information too. It means the policy gap is organisational rather than personal, and it's worth raising rather than quietly working around.
Start where being wrong is cheap
The sensible place to begin is work where a mistake costs you five minutes rather than a client. Reformatting notes. Drafting an email you were going to write anyway. Summarising a long document you'll read properly afterwards. Turning a rough set of bullet points into something presentable.
Two things happen when you start here. You build a feel for what the tool is good at, which is genuinely hard to get from reading about it. And you learn its failure modes somewhere they can't hurt you, which is the part that keeps you safe later when the stakes rise.
Avoid the opposite instinct, which is to test it on the hardest thing you do. That's how people conclude AI is useless, or worse, conclude it's brilliant on the basis of an answer they weren't qualified to check.
What shouldn't go in
Unless you know your organisation has an agreement covering it, keep these out of any public AI tool:
- Customer and client data. Names, contact details, account information, anything that identifies someone you have a duty to.
- Personal data about colleagues. Performance notes, health information, grievance material, anything from an HR file.
- Confidential commercial material. Unpublished financials, contracts, pricing, deal documents, anything under an NDA.
- Credentials and access. Passwords, API keys and tokens, which should not be pasted anywhere, AI or otherwise.
- Anything you couldn't defend. A reasonable test: if this appeared in a screenshot in front of your regulator or your biggest client, would it be fine?
Where you genuinely need to work on sensitive material, the answer is a properly configured enterprise tool, not a redacted copy pasted into a consumer one. Ask for it rather than improvising.
How to get an answer worth using
Most disappointing results come from asking a model to work with nothing. It doesn't know your company, your client, your tone or your constraints unless you tell it, and it will confidently fill those gaps with plausible invention.
So give it the real material. Paste in the actual brief, the previous version, the style you want to match, the constraints you're working under. Context does far more for output quality than any prompt phrasing.
Then break the job up. Instead of asking for a finished report, pull the structure first, look at it, fix what's wrong, then draft section by section. Each step is small enough to check, which means errors surface early rather than buried in a finished document.
Ask it where things came from. If it makes a factual claim, ask for the source and then go and look at the source. If it can't produce one, treat the claim as unverified, because that's exactly what it is.
Check it before it leaves you
The single habit that separates people who get value from AI from people who get embarrassed by it is verification, and it's boringly simple. Every fact, figure, name, citation and quote is unverified until you've checked it against the actual source.
This matters more than it sounds, because the failure mode is not obvious nonsense. It's a fluent, well-structured, correctly formatted answer with one wrong number in the middle. Professions have learned this expensively: lawyers in the UK and US have been referred to regulators for filing documents citing cases that never existed.
Calibrate the effort to the stakes. Reformatting your own notes needs a glance. Anything going to a client, a regulator, a board or a decision needs a proper check. Learning where that line sits for your own work is the actual skill.
Make it a habit rather than a novelty
The people who get lasting value don't use AI for everything. They find three or four recurring tasks where it reliably helps, and they build a routine around those, saving the prompts and instructions that worked so they don't start from scratch each time.
That's also what turns individual use into something an organisation benefits from. A saved, shared prompt is an asset that survives the person who wrote it. A clever one-off in someone's chat history isn't.
The durable skills underneath all of this are covered in AI skills every professional needs. If you're deciding which tool to get fluent in, Claude vs ChatGPT for business teams compares the two most likely options, and the free AI proficiency assessment will show you where you currently stand in about five minutes.
Frequently asked questions
Is it safe to use AI at work?
It's safe when two things are settled: you're using a tool your organisation has sanctioned, and you know what data you're allowed to put into it. The risk isn't the technology, it's the combination of an unsanctioned consumer tool and confidential material. Wakefield Research found 34% of office professionals had entered customer data into public AI tools, which is the behaviour worth avoiding.
Should I tell my employer I'm using AI at work?
Yes, and it's more in your interest than theirs. 39% of office professionals told Wakefield Research they would rather use AI without telling anyone, but the hidden version is the risky one: nobody can give you a sanctioned tool, an enterprise agreement or a straight answer about what's allowed if nobody knows you're using it. Disclosure is what gets you the protections.
What should I never put into an AI tool?
Customer and client data, personal data about colleagues, confidential commercial material like unpublished financials or contracts, and credentials such as passwords or API keys. A useful test: if this appeared in a screenshot in front of your regulator or your largest client, would it be fine? If you genuinely need to work on sensitive material, ask for a properly configured enterprise tool.
How do I get better answers from AI?
Give it real context rather than a short instruction. Paste in the actual brief, the previous version and the constraints. Then break the work into steps, checking each one, instead of asking for a finished output in a single go. And ask for sources on any factual claim, then check them. Context and structure improve results far more than prompt phrasing does.
How much should I check AI output?
Scale it to the stakes. Reformatting your own notes needs a glance. Anything going to a client, a regulator, a board or a decision needs every fact, figure, name and citation checked against the original source. The failure mode isn't obvious nonsense, it's a fluent and well-formatted answer with one wrong number in it, which is why fluency is not evidence of accuracy.


