
10 golden rules for using AI at work
- Home
- Artificial intelligence and data
- 10 golden rules for using AI at work
Ten rules for using artificial intelligence at work. We wrote them for our own people first, then rewrote them so they would be useful to organisations that are not our customers.
AI at work is not governed by a ban, and not by a subscription either. It is governed by a small number of rules that a person still remembers when they are in a hurry — which is the only moment the rules actually matter.
They are free to use: take them and adapt them to your organisation. No registration, no form to fill in before reading.
1. Use approved tools, not shortcuts
Choose tools your organisation has assessed for purpose, data handling, security and terms of use. A personal or free solution looks like the fast route, but it is not automatically suitable for business data and processes: the terms attached to a personal account are not the terms attached to a corporate one, and nobody has read them on your behalf.
2. A prompt is not a vault
Passwords, API keys, credentials, trade secrets, confidential data: these do not go into an AI system. The question to ask before pasting anything is a simple one — would I send this, in this form, to an external party? If the answer is no, it does not belong in a prompt either.
3. Share what is necessary, not everything that is possible
Keep data to the minimum needed and strip identifiers, unnecessary detail and sensitive information where they are not essential. Input quality does not depend on quantity: a whole document pasted whole almost always produces a worse answer than the three lines that mattered.
4. Special-category data needs a dedicated assessment
Data concerning health, biometrics, opinions, private life or other special categories requires enhanced care. Do not use it in an AI system before checking purpose, permissions, safeguards and the involvement of the appropriate functions. This is not a formality: it is the difference between lawful processing and unlawful processing.
5. AI accelerates. A person reviews.
A plausible output is not always correct, current or suitable for its context. Sources, calculations, citations, tone and operational consequences are checked before a result is used, sent or published. Language models are wrong confidently, and it is the confidence of the tone that makes the error hard to see.
6. Responsibility remains human
The person using an AI output is responsible for the decision, message or action that follows. AI can assist; it cannot become an excuse for delegating judgement, accountability or the relationship with customers and colleagues. “The system wrote it” is not an explanation that holds up in front of a customer, an inspector or a colleague.
7. No algorithm decides alone about people
Recruitment, appraisals, disciplinary action, access to services: these are decisions with significant effects on people, and AI cannot be their sole decision-maker. Meaningful human oversight and a review path are always required. It is also what Article 22 of the GDPR protects: the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects a person, and the right to obtain human intervention where such a decision is allowed.
8. Inform first, then record
If AI transcribes, summarises or supports a meeting, the people involved are informed first, and collection, access and retention are limited to what is necessary. A recording is not an unlimited archive: it is data processing with a purpose, a retention period and a list of who may read it.
9. When content is synthetic, consider how it should be recognisable
For audio, images, video or text that may appear authentic, assess the transparency obligations and the expectations of the people receiving it. In some cases the AI Act requires specific measures; in every case, clarity and editorial review protect trust, which is the slowest thing to rebuild.
10. Reporting an anomaly is part of control
Unexpected outputs, invented sources, exposed data, odd behaviour or plain doubts about a tool should not be ignored, and reporting them is not an embarrassment. Early reporting is what makes correction possible, and an organisation that receives no reports is not an organisation without problems: it is an organisation that cannot see them.
Start with the right questions
Before introducing a new use case, the five questions worth putting in writing:
- Which process do we want to improve, and for whom?
- Which data enters the system, and under which permissions?
- Who checks the output and decides whether to use it?
- How will we measure quality, error, security and value?
- What happens when the system cannot give a reliable answer?
The same questions in extended form, with the matrix linking use, risk, control and evidence, are in the responsible AI white paper.
⚠️ Notice. This is information, not legal advice. Applying the AI Act, the GDPR and other rules requires an assessment of the specific case. The legal framework cited here is current as of 22 August 2026: primary sources and application dates are on Transparency and the AI Act.
