WAJD Learning

Module 2 of 2 · 45 minutes

Five habits for using AI at work

By the end of this module you will be able to

  • Explain why a fluent answer is not evidence of a correct one
  • Decide what may and may not be put into an AI tool
  • Check AI output in proportion to what depends on it
  • Say when and how to tell people that AI was used
  • Recognise unapproved AI use and respond to it

Work through it

1 interactive for this module, built on the WAJD Teach engine. Nothing moves until you ask it to, and every one has a written version if you would rather read it.

Watch: Emma and George talk it through

3 minutes. Captions are on, and the same conversation is written out in full below. The voices are computer generated.

Emma George, the law's one thing. But what should I actually do differently on Monday?

George Five habits. And they don't depend on which country's law you're under. First, know what the tool is doing. A generative tool produces the most plausible next words. It isn't looking facts up unless it's been connected to a source.

Emma Which is why it invents references.

George Yes. It sounds as confident when it's wrong as when it's right. And we make it worse, because people trust automated suggestions more than they deserve. Automation bias. The better the tool, the less we look.

Emma Habit two?

George Think before you paste. What you type goes somewhere. With an approved tool there's a contract saying what the supplier may do with it. With a tool you chose yourself, there isn't.

Emma So what stays out?

George Personal data. Anything confidential to a customer or client. Anything commercially sensitive. Those go only into tools your organisation has approved for that purpose.

Emma If I take the names out?

George Not enough. Job title, location, dates and unusual details can identify someone on their own. My test is this. If you wouldn't email it to a stranger, don't paste it.

Emma Three.

George Check in proportion. An internal first draft needs a read. A figure going to a customer needs verifying against its source. And anything about the law, a medicine, a safety limit or a person needs checking against something authoritative. Every time.

Emma And decisions about people?

George A human makes the decision and can explain it. Who's interviewed, who gets credit, who's disciplined. That's where the EU's high risk category and the UK's automated decision rules both bite.

Emma Four.

George Be open about it. If a customer's talking to an AI system, they should know. If something's been generated or altered in a way that could mislead, say so. And if someone would feel misled to learn later that AI wrote it, tell them now.

Emma Am I still responsible for it?

George Completely. Whatever produced the first draft, it's your work.

Emma And five.

George Speak up. Unapproved use at work, people call it shadow AI, is usually someone trying to get through their workload. If you've shared something you shouldn't have, tell your manager or data protection lead straight away.

Emma Why the hurry?

George A reportable breach has a 72 hour deadline, and it runs from when the organisation becomes aware. Every hour you wait comes off theirs.

Emma And one thing to do today?

George Ask your manager for the list of approved AI tools and what each may be used for. If there isn't a list, that's the first thing to fix.

The written material

Habit one: know what the tool is doing

A generative AI tool produces the most plausible continuation of the words it is given. It does not look facts up unless it has been connected to a source, and it has no sense of whether its answer is true. That is why it sounds equally confident when it is right and when it is wrong, and why it can produce a reference, a figure or a quotation that does not exist.

People also tend to trust an automated suggestion more than it deserves, particularly when busy. This is called automation bias, and it grows as a tool becomes more reliable, because the more often it is right the less closely anyone looks.

Habit two: think before you paste

What you type into a tool goes somewhere. With a tool your organisation has approved, there is a contract that says what the supplier may do with it. With a tool you chose yourself, there is not, and its terms may allow your input to be kept or used.

So the rule is simple. Personal data, anything confidential to a customer or client, and anything commercially sensitive go only into tools your organisation has approved for that purpose. Removing a name does not make information anonymous: job title, location, dates and unusual details can identify a person on their own.

Habit three: check in proportion, and keep a human in the decision

Not everything needs the same checking. A first draft of an internal note needs a read. A figure going to a customer needs verifying against its source. A statement about the law, a medicine, a safety limit or a person needs checking against something authoritative, every time.

Where the output feeds a decision about a person, such as who is interviewed, who is offered credit or who is disciplined, a human must make the decision and be able to explain it. This is where the high risk category of the EU Act and the UK rules on automated decisions both bite.

  • Low stakes, internal, easily corrected: read it
  • Leaves the organisation: verify facts and figures against the source
  • Law, safety, health or money: check against an authoritative source
  • A decision about a person: a human decides and can explain why

Habits four and five: be open about it, and speak up

Habit four is openness. If a customer is talking to an AI system, they should know. If a document, image or recording has been generated or altered by AI in a way that could mislead, say so. And if a colleague or client would feel misled to learn later that AI wrote something, tell them now. You remain responsible for the work whatever produced the first draft.

Habit five is speaking up. Unapproved use of AI tools at work, sometimes called shadow AI, is usually not malice. It is somebody trying to get through their workload. If you have done it with information you should not have shared, tell your manager or data protection lead straight away: a reportable breach has a 72 hour deadline that runs from when the organisation becomes aware. If you see a tool producing unfair or wrong results, say so. A concern raised early is the cheapest control there is.

Knowledge check

The knowledge check and your certificate need a free account, so that your progress and results can be saved as evidence.

Create a free account Sign in

The learning itself stays free and open. You are reading all of it right now without an account.