Home
News
Using AI haphazardly in a company can be costly

Using AI haphazardly in a company can be costly

Artificial intelligence has made its way into companies much faster than internal regulations on how to use it. It’s used to write an email, summarize a document, analyze data, prepare a presentation, generate images, or give a quick review of a contract. It’s all very convenient—at least until someone decides to upload a file containing confidential data to a chatbot, publishes information completely fabricated by the AI, or uses a generated image without even checking what’s in it.

The point isn’t to stop using AI. On the contrary, for many companies, it would now be difficult to imagine going back. The problem is using it as if it were just any search engine or an infallible colleague to whom we can entrust anything. Because a wrong prompt can be corrected in ten seconds. A piece of company data ending up where it shouldn’t, a decision made based on false output, or a gaffe published on the company’s official channels can be much harder to fix.

Paste whatever you have in front of you into AI

It’s probably the most trivial mistake—and precisely for that reason, one of the easiest to make. You receive a long document, you need to summarize it, and the temptation is immediate: copy, paste, “give me a summary.”

It’s a shame that document might contain first and last names, customer data, employee information, financial figures, business strategies, contracts, credentials, or confidential material. At that point, the issue is no longer how good the model is at summarizing, but what information we’ve just provided it with and what safeguards are in place for handling that information.

This issue is particularly sensitive when personal data is involved. The European Data Protection Board notes that the development and use of AI can raise significant data protection issues and that the processing of personal data must continue to comply with the framework established by the GDPR.

In other words, “I’m just feeding it to the AI anyway” is not a company policy. Before even considering which prompt to use, a company should know which tools are authorized, which data can be entered, and which data must not leave the designated systems.

Believing in AI because it responds with confidence

AI has a particular talent: it can state something incorrect with the same ease with which it states something correct. It can invent a source, confuse two regulations, attribute a statement to the wrong person, get a number wrong, or fill in missing information with something that sounds entirely plausible. The result is often so well written that it’s natural to trust it.

In a business setting, however, that “it seems right” can end up in a presentation for a client, a public announcement, an internal report, or—worse yet—become the basis for a decision. The mistake, therefore, isn’t asking the AI for information. It’s skipping the next step: verifying it. The more the output has economic, legal, reputational, or human consequences, the less there should be any concept of direct copy-and-paste.

Make her make decisions that you should support

There is a rather significant difference between asking AI to help us review fifty applications and letting AI decide who deserves an interview. The same applies to employee evaluations, the granting of services, customer analysis, and other processes that can have tangible consequences for people.

And this is precisely where the European AI Act becomes particularly important: the regulation classifies uses of artificial intelligence based on risk and establishes different obligations, in addition to prohibiting certain practices. The penalties for certain violations can be very high; for prohibited practices, fines can reach up to 35 million euros or 7% of annual global revenue, in the cases provided for by the regulation and in accordance with specific rules that also apply to SMEs.

This does not mean that every business use of ChatGPT automatically exposes a company to a fine in the millions. It means something much more concrete: not all uses of AI are the same, and a company needs to know where, how, and why it is using it.

Post without checking what you've created

AI-generated gaffes are probably the most visible part of the problem. Texts containing made-up information, images with absurd details, translations that completely alter the meaning of a sentence, and outputs that retain parts of the original prompt.

As long as it happens in someone’s private chat, it’s just a laugh. When it appears on a company’s official account, it immediately becomes a reputation issue. AI greatly accelerates content production, but speeding up production shouldn’t mean eliminating oversight. In fact, the more content we’re able to produce through automation, the more important it becomes to determine who is responsible for the final review before publication.

So the relevant question isn't "Did a person write this, or did AI?", but "Did someone review what we're putting out on behalf of the company?"

Let everyone choose the AI they want

Another problem arises when AI is used in the company, but no one knows exactly how. One employee uses a chatbot with their personal account, another tries out a free tool they just discovered online, and yet another uploads documents to a platform because it promises to analyze them in a matter of seconds.

As a result, business information can pass through various services without there being a clear understanding of how it is managed. That’s why it’s not enough to simply tell employees, “You can use AI”: approved tools and clear guidelines are needed regarding what can be uploaded, for what purposes, and with what controls. Otherwise, there is a risk of so-called “Shadow AI”—that is, the use of artificial intelligence tools outside of those known to and authorized by the organization.

To think that everything it produces is automatically usable

An image can be generated in thirty seconds, a text in ten, and a few hundred lines of code can appear even faster. But “AI-generated” does not automatically mean “ready for business use.”

Depending on the content and how it is used, issues such as copyright, licenses, personal data, confidential information, and security concerns may arise. Even generated code, for example, may contain vulnerabilities or simply do something different from what we intended. The ease with which we can create output today risks making us forget that verifying it remains necessary.

Don't have any rules because, after all, “we only use it once in a while”

Perhaps this is where nearly all of the previous mistakes converge. If a company does not establish how to use artificial intelligence, the rules are created spontaneously by those who use it. And it is unlikely that fifty people will reach the same conclusions about what is safe to upload, which tool to choose, or when a result should be reviewed.

This doesn't mean writing an endless manual that no one will read. A good policy should, above all, be easy to understand: which tools are permitted, what information should not be included, for which activities human oversight is required, and what to do when you want to use a new AI system.

It's not enough just to know how to write a good prompt

Ultimately, many of these errors stem from the same root cause: we use extremely powerful tools without understanding them well enough. Knowing how to write a good prompt is helpful, but in a business setting, true AI proficiency also involves knowing what not to include, recognizing an unreliable result, understanding when human verification is needed, and being aware of the risks associated with the tool you’re using.

And this is where the AI Act comes into play once again. Article 4 establishes obligations regarding AI literacy: providers and deployers must take measures to ensure that their staff and other individuals using AI systems on their behalf have a sufficient level of competence, taking into account their knowledge, experience, and the context in which these systems are used.

So it’s not simply a matter of teaching employees a few better prompts. Training is needed to ensure that AI is used without turning a tool that’s supposed to save time into a new risk for the company. And given how quickly AI is becoming part of our daily work, continuing to use it “haphazardly” is probably the habit we should break first.

Image by Simone Cerchia

by 

Simone Cerchia
Share this post:

More posts