ai-real-world

AI in the Real World Part 2: AI at work — the opportunities, the risks, and what your employer should be telling you

49% of employees use AI tools not approved by their employer. Here is what you should know regardless of whether your organisation has caught up yet.

Robert Shone 4 min read
AI in the Real World Part 2: AI at work — the opportunities, the risks, and what your employer should be telling you

A question worth asking before you read this article: in the past month, have you used an AI tool — ChatGPT, Copilot, Gemini, Claude, or anything similar — to help with something work-related?

If you said yes, you are in the majority. A 2025 survey found that 49% of employees use AI tools not formally approved by their employer. Which means that nearly half the workforce is using AI for work while their employer has not yet thought carefully about the implications, the risks, or what guidance to give.

This article is about what you should know as an employee, regardless of whether your employer has caught up yet.


What AI at work actually looks like

AI at work in 2026 covers a broad range. At the simple end: using ChatGPT to help draft an email, Copilot to summarise a long document, or Grammarly to check your writing. At the more complex end: AI agents that read your email, manage your calendar, prepare briefings, and complete multi-step tasks autonomously while you focus on other things.

Both of these are happening, at every level of organisations, across almost every industry. The legal profession, medicine, finance, marketing, customer service, teaching, coding, accounting — all of them have seen significant AI adoption in the past two years. Most of it has happened faster than the governance frameworks designed to manage it.


The data problem your employer may not have addressed

When you paste a client's contract, a patient's record, a sensitive internal document, or a colleague's personal details into an AI chat tool, that information travels to a server run by the company behind the AI. Depending on the tool and the settings, it may be stored, used for training, or in some cases accessible to company employees for safety review.

The Samsung case from 2023 is the canonical example: engineers pasting proprietary source code into ChatGPT while debugging, inadvertently sharing intellectual property with a third-party company. Samsung subsequently banned unapproved AI tools. But the same thing happens at smaller scale in organisations all the time, with client data, personnel information, legal documents, and financial records.

This is not a reason to never use AI at work. It is a reason to know your organisation's policy, and in the absence of a policy, to apply the same judgment you would to any other external service: if you would not email the document to a stranger, do not paste it into an AI tool.


The opportunity is real

This series has a habit of balancing risk with genuine positive reality, and the positive reality of AI at work is significant.

For repetitive tasks — summarising documents, drafting first versions of standard communications, transcribing meetings, organising information — AI tools are genuinely transformative. They do not replace the judgment, the relationships, or the expertise that makes skilled workers valuable. They free up time that was previously spent on the administrative overhead around that work.

For accessibility: AI tools have made real-time transcription, document accessibility, and communication support available at a quality and scale that was previously expensive and limited. For people with dyslexia, hearing difficulties, or other communication differences, AI tools have materially improved workplace experience.

For learning: being able to ask a question in plain English and receive a clear explanation, at any hour, on any topic related to your work, is genuinely useful in a way that the internet broadly has been but AI specifically does better.


The risks worth understanding

Hallucination in professional contexts. As covered in the original AI series, AI models can be confidently, fluently wrong. In a casual context, this is inconvenient. In a professional context — a legal briefing, a medical reference, a financial calculation, a technical specification — it can be seriously harmful. AI output that is used in professional work needs to be verified by someone who can identify errors, not just checked for spelling.

Bias. AI models trained on historical data inherit historical biases. In recruitment, performance assessment, lending decisions, and other consequential applications, AI tools can perpetuate and systematise discrimination in ways that are difficult to detect because the process looks automated and therefore objective. It is not. Bias baked into training data emerges as biased output.

The agent risk. As covered in Part 3 of the original AI series, AI agents — tools that take actions rather than just responding — introduce a different order of risk. An agent with access to your email, your files, and your calendar can do significant damage if it is compromised, misdirected, or simply makes an error. The permissions granted to agents in workplace settings deserve the same careful thought you would give to hiring someone new and giving them the same access.


What your employer should be telling you

A good workplace AI policy, which you are entitled to ask for if yours does not have one, should cover: which AI tools are approved for use; what categories of data should never be entered into AI tools; who to contact if something goes wrong; and how AI-generated output should be labelled or verified before use.

The EU AI Act, which reached its full compliance deadline on 2 August 2026, places specific obligations on organisations that deploy AI systems in consequential contexts — including obligations around transparency, documentation, and human oversight. UK organisations serving EU customers are subject to it. UK domestic law is developing in parallel.

If your organisation has not had this conversation yet, the questions above are reasonable ones to raise.


What does this mean for me?

Know your organisation's AI policy. If one does not exist, apply cautious defaults: no client data, no personnel information, no sensitive documents.

Verify AI output before using it professionally. Never rely on AI-generated facts, statistics, or legal or medical references without independent verification.

Understand what you are giving access to when you set up any AI agent or automation tool for work purposes. Read the permissions screen, not just the "getting started" guide.

The opportunity is real. Use AI tools for the things they do well — summarising, drafting, organising, explaining — while keeping human judgment at the centre of the things that actually matter.


🧠 The Human Factor

Technology involved Workplace AI tools from major providers (Microsoft Copilot, Google Gemini, OpenAI ChatGPT, Anthropic Claude), AI agents with access to email and calendar systems, and the governance frameworks that have mostly not kept pace with adoption
Root cause AI adoption in workplaces has outpaced the policies, training, and governance frameworks designed to manage it safely — leaving individual employees navigating significant risks without adequate guidance
What was at risk Client data and confidential information, professional accuracy and integrity, discriminatory outcomes in consequential decisions, and IP and regulatory compliance
Prevention Clear organisational AI policies; data hygiene defaults in the absence of policy; human verification of AI output in professional contexts; thoughtful permissions management for AI agents

References and sources

  • Samsung AI data incident (2023) — Bloomberg
  • EU AI Act compliance deadline 2 August 2026 — artificialintelligenceact.eu
  • Metomic: Shadow AI survey 2025
  • Microsoft Copilot data exposure research — Concentric AI (2025)