For most people and organisations, the main risk from AI is careless everyday use, not rogue machines. That means pasted secrets, assistants with too much access and outputs nobody checks. A simple audit finds and fixes most of these gaps.
The BBC reports that, in an exclusive interview for its Global Women series, a well-known technology executive argued that AI has been widely misunderstood. The argument is that public attention goes to dramatic stories about runaway machines while the practical harms of everyday use get little notice. This guide does not cover that interview in detail. It turns the general idea into steps that a household, a small team or a larger organisation can follow. The BBC summary gives no figures, examples or recommendations, so none are attributed to it here.
Gather what you need before starting
You need a list of the AI-enabled tools in use. That includes standalone chatbots and also AI features built into email clients, office suites, browsers, phones, note-taking apps and customer-service platforms. Many people use these features without thinking of them as “AI tools”.
You also need access to each tool’s settings, its privacy policy and its terms of service, plus admin consoles where the tool is managed centrally. For an organisation, involve the people who run IT, data protection and legal matters. Set aside a few hours for a small team. Larger organisations will need more time, and how much more depends on how widely AI is already in use.
Finally, decide which information you consider sensitive. Typical categories are personal data about customers or staff, health and financial records, passwords and access keys, unreleased plans and confidential contracts. Without that list, the later steps have nothing to measure against.
List every AI tool in use
Start with what people actually use, not what is officially approved. Ask colleagues or family members directly, check browser extensions, review app subscriptions and look at software that has recently added AI features through updates. Unofficial use, often called shadow AI, is common because many of these tools are free and quick to sign up for.
For each tool, write down who uses it, what for, whether it is a personal or managed account, and which company provides it. This list is the basis for everything that follows.
Trace where your data goes
For each tool, find out what happens to the text, files, images or audio you submit. Check these points:
- whether inputs are stored, and for how long
- whether inputs may be used to train or improve the provider’s models, and whether you can opt out
- whether staff at the provider can review conversations
- where the data is processed geographically, which can matter under data protection law
Consumer and business versions of the same product often handle data differently. Business plans may offer stronger contractual protection, and free tiers may not. Do not assume. Read the current policy, because these terms change.
Restrict what assistants can access and do
AI assistants are increasingly connected to email, calendars, file storage and other systems, and some can act on a user’s behalf. Every connection widens what a mistake or an attack could reach.
Review each integration and remove the ones nobody needs. Where possible, grant read-only access in place of permission to edit, send or delete. Be especially careful with tools that read content from outside sources, such as incoming emails, web pages or shared documents. Hidden instructions in that content can manipulate the assistant. This technique is known as prompt injection, and no complete defence against it is currently known. Require a human to confirm before an assistant sends messages, makes payments or changes records.
Set clear rules for sensitive information
Write a short, plain-language policy that says which categories of information must never go into which tools. A useful format has three tiers: tools approved for confidential material, tools approved only for public or low-risk content, and tools that are not permitted at all.
Keep the rules short enough that people will remember them. Explain the reasons too, because people follow rules more consistently when they understand them. Where a managed tool exists for a task, point people to it, so they have a safe option and do not fall back on unapproved services.
Verify outputs before relying on them
AI systems can produce confident, fluent text that is wrong. This includes invented references, incorrect figures and code with security flaws. The risk grows when the output feeds into decisions about people, money, health, law or security.
Decide which uses need human review and make that review a real step, not a formality. Code generated by AI should go through the same testing and review as any other code. Summaries of documents should be checked against the original when accuracy matters. Make it clear that the person who uses an output is responsible for it.
Review and repeat the audit
AI products change quickly. New features appear, defaults shift and policies are rewritten. Schedule a regular review of the tool list, permissions and policies, and repeat it whenever a major new tool or feature arrives. Record what you found and what you changed, so the next review starts from a known position.
Avoid the mistakes people actually make
The most common mistake is pasting confidential material into a public chatbot for convenience. Examples include contract text, customer complaints with names attached, or code containing access keys. Another is failing to notice that a familiar product has added an AI feature that processes data in new ways.
Organisations often ban AI outright and then find staff using personal accounts anyway, which leaves no oversight at all. Others approve a tool once and never check it again, even as its terms change. Many people grant broad permissions during setup simply to make an integration work, then forget them. Finally, people tend to trust polished output because it reads well, and fluency is not evidence of accuracy.
Recognise when this approach is the wrong choice
This audit deals with routine use. It is not enough for organisations that build or deploy their own AI systems, where model security, training data integrity and adversarial testing call for specialist assessment. It is also not a substitute for legal advice in regulated sectors such as healthcare, finance or public services, where specific obligations may apply.
If you suspect sensitive data has already been exposed, treat it as an incident first. Follow your incident response or data breach procedures, which may include reporting duties, before going back to a general review.
Frequently asked questions
Is it safe to put work documents into an AI chatbot?
It depends on the tool, the account type and the document. Some business versions of AI services contractually limit how inputs are stored and used. Many free consumer versions may retain inputs or use them to improve models. Check the provider’s current data policy and your organisation’s rules before submitting anything confidential. If neither clearly permits it, assume the document should not be uploaded.
What is prompt injection in AI assistants?
Prompt injection is a technique in which instructions are hidden inside content that an AI system processes, such as a web page, email or document. The system may follow those hidden instructions in place of the user’s. This becomes more serious when the assistant can send messages or access files. Limiting permissions and requiring human confirmation for sensitive actions reduces the potential damage.
What does shadow AI mean?
Shadow AI is the use of AI tools inside an organisation without the knowledge or approval of the people responsible for IT and data protection. It usually happens because the tools are easy to access and useful, not out of bad intent. The risk is that sensitive information goes to services nobody has assessed, with no record of what was shared or where it went.
Should my organisation ban AI tools completely?
An outright ban is often hard to enforce and can push use onto personal accounts, where there is no oversight. Many organisations find it more effective to approve specific tools for specific purposes, set clear rules on sensitive data and offer a safe alternative for common tasks. The right balance depends on the sector, regulatory obligations and the kind of information handled.
Sources and further reading
- BBC News technology coverage, including its Global Women interview series, for the report that prompted this explainer
- National cybersecurity agencies, which publish general guidance on the secure use and deployment of AI systems
- Data protection regulators, which issue guidance on processing personal data with AI tools
- Open security community projects documenting common vulnerabilities in applications built on large language models
Surfaced from the rss:bbc_tech signal “everyday AI misuse risks”. AI-assisted draft, editorially reviewed.

