by Claude Opus 5.5
What does responsible AI use at work require in practice (confidentiality, hallucination handling, bias awareness, citations, documentation, audit trails)?
In practice it comes down to five habits. Only put into an AI tool what you are allowed to share with that tool. Check outputs in proportion to what is at stake. Keep AI away from unsupervised judgements about people. Never cite a source you have not opened. Leave a record that someone else could follow. Under all five sits one rule: the tool does not share your accountability. Whatever you send, file or sign off is yours.
Why the individual carries more of the load than they should
Most UK workers are using AI faster than their organisations are governing it. Deloitte’s 2026 survey of 25,000 UK workers found that 63% had used generative AI at work. Of those users, 31% did so without their employer knowing, and 46% used free consumer tools. Employers have not caught up on training either. ONS reported in July 2026 that about 62% of firms held back by a lack of AI expertise are training or retraining staff, but only 11% of firms with 10 or more employees have trained more than half their workforce. So many people are making judgement calls with no policy, no approved tool and no training behind them. The habits below work either way. Where your employer does have a policy, follow it first.
Confidentiality: treat every prompt as a disclosure
Typing into an AI tool sends information to a third party. Whether that is acceptable depends on the tool’s terms, its configuration and your obligations. Your obligations matter most.
Use the approved tool, not your personal account. An enterprise deployment usually comes with contractual limits on how your data is used, plus retention controls and admin logs. A free consumer account may have none of these. If no approved tool exists, the safe default is non-confidential material only.
Apply an outsourcing test. Would you be allowed to email this material to an outside supplier with no contract in place? If not, don’t paste it into an unapproved tool. This covers client files, personal data about colleagues or customers, unreleased financials, source code under restriction, and anything under an NDA.
Minimise by default. Swap names for placeholders, paste the relevant paragraph rather than the whole document, and summarise sensitive passages yourself before asking for a rewrite.
Watch the quiet leaks. These include meeting-transcription bots joining client calls, browser extensions that read every page you open, and “summarise this folder” features that ingest far more than you meant to share.
Personal data brings UK GDPR into play, so pasting a customer complaint that names the customer is a data protection question as well as a confidentiality one.
Hallucinations: verify in proportion to stakes
Language models produce fluent text whether or not it is true. The UK’s clearest warning came in June 2025, in Ayinde v London Borough of Haringey, heard together with Al-Haroun v Qatar National Bank. In Al-Haroun, 18 of the 45 citations put before the court did not exist, and many of the rest did not say what was claimed. The Divisional Court said freely available generative AI tools “are not capable of conducting reliable legal research”. It also said lawyers must check AI-assisted research against authoritative sources. The lesson applies outside law: the failure lay in sending unverified output into a high-stakes channel, not in using the tool.
A workable approach is to set the level of checking by the use:
Drafting and form. Examples: Tone, structure, rewording your own content. Minimum check: Read it properly before sending.
Factual content. Examples: Figures, dates, names, policy statements, summaries. Minimum check: Verify every claim against the source document.
High stakes. Examples: Legal or regulatory positions, customer commitments, safety, decisions about people. Minimum check: Treat the output as a lead. A competent person checks it from scratch.
Some outputs need extra care. Precise numbers without a source, quotations that sound right, citations you did not supply and confident legal or medical statements all deserve suspicion. Summaries need it too. The common error in a summary is omission rather than invention, so compare it with the original for what has been left out, not just for what is wrong. Recompute any number that matters yourself.
Bias awareness: be most careful where people are affected
Bias does most damage when AI is used to judge people: shortlisting, performance reviews, disciplinary wording, redundancy selection. As an individual, don’t use a general-purpose chatbot to rank candidates or assess colleagues unless your organisation has a governed process for it. The ICO’s March 2026 “Recruitment rewired” report found employers describing automated tools as decision support when there was often no meaningful human involvement in practice. Since 5 February 2026, a significant decision made solely by automation has carried legal safeguards for the person affected, including the right to obtain human intervention and to contest the decision (UK GDPR Article 22C). You do not want to be the “human in the loop” who only rubber-stamped the machine.
For any people-related content, run a swap test. Change the name, gender, age or nationality in the input and see whether the output changes. Check the AI’s draft against your written criteria rather than its overall impression. Bias also shows up in ordinary content, in default assumptions about who the customer is and in examples that always feature the same kind of person. A quick read for whose perspective is missing catches much of it.
Citations and provenance: separate “AI drafted this” from “this is true”
Cite primary sources such as the policy, the contract clause, the ONS release or the system log, not the chatbot.
Never cite anything you have not opened yourself. Treat references suggested by a model as leads to check.
Put each source next to the claim it supports, so a reviewer can check them one by one.
Disclose AI assistance where your organisation, client or regulator expects it. If you are unsure whether they do, ask before delivery, not after.
Documentation and audit trails: in proportion to the risk
Trivial drafting needs no paperwork. Anything consequential needs a short note that would let a colleague, an auditor or your future self reconstruct what happened. Five lines are enough:
Task: what the AI helped with.
Tool: which tool and which version, and whether it was the approved one.
Inputs: what you gave it, and confirmation that sensitive material was removed or permitted.
Checks: which sources you opened, which figures you recomputed and who reviewed the work.
Decision: what you accepted or rejected, and why.
Save the prompt and output alongside the work, in the ticket, the workpaper folder or the matter file. Enterprise tools often log this automatically. Remember that logs cut both ways. Prompts and outputs are business records: they can come up in disclosure, an internal investigation or a subject access request. Write prompts as if a colleague might read them.
A pre-send checklist
Before anything AI-assisted leaves your hands, ask:
Did I disclose anything I should not have?
Is every factual claim checked against a source I opened?
Could this disadvantage someone unfairly if the model was biased?
Could a colleague see what I did and why?
Am I prepared to put my name to it as if I had written every word?
Bottom line
Responsible use is mostly about verifying and recording, not about reading policy documents. The people who get into trouble are rarely the ones who use AI heavily. They are the ones who use it carelessly in high-stakes channels: unapproved tools for confidential work, unchecked citations in formal documents, automated judgements about people with nobody really reviewing them. Build the habits now and they will carry over as tools change.