AI tools can save you hours each week. They can also expose you to legal liability, embarrass you professionally, or breach your employer's policies if you use them without thinking.
Most professionals who run into trouble with AI at work do not do so deliberately. They simply do not know where the lines are. This guide is a practical rundown of the real risks — and what habits to build to avoid them.
The risks are real, not theoretical
Before the practical rules, it is worth being clear about why this matters.
In 2023, a lawyer submitted a court brief containing fabricated case citations generated by ChatGPT. He did not check them. The judge sanctioned him. In 2023, Samsung employees pasted proprietary source code into ChatGPT — it became part of OpenAI's training data. The company subsequently banned all use of external AI tools.
These are not edge cases. They are the predictable result of professionals using powerful tools without understanding the risks.
In 2023, a lawyer submitted a court brief containing fabricated case citations generated by ChatGPT — he did not check them and was sanctioned by the judge. In the same year, Samsung employees pasted proprietary source code into ChatGPT, which then became part of OpenAI's training data. These are not edge cases; they are the predictable outcome of using powerful tools without understanding the risks.
Risk 1: Putting confidential data into consumer AI tools
The most common and serious risk.
When you paste client data, internal financial figures, employee information, or commercially sensitive strategy documents into ChatGPT, Claude, or any consumer AI product, you are sending that data to a third-party server. Depending on the product's terms and your organization's agreements, that data may be used to train future models, stored in ways you cannot control, or accessible to the provider in ways you have not explicitly consented to.
The rule: Never input personally identifiable information (PII), client details, confidential financial data, legally sensitive material, or trade secrets into a consumer AI tool without first checking whether your organization has an enterprise agreement with that provider — and whether that agreement includes appropriate data processing terms.
If you are unsure, assume it is not safe and act accordingly.
Risk 2: Copyright and ownership of AI outputs
AI-generated outputs occupy contested legal territory in most jurisdictions. Several key points are still being determined by courts and regulators.
What is fairly clear: in most countries, content generated entirely by an AI without meaningful human creative input does not attract copyright protection in the same way human-authored content does. This matters if you are using AI to generate content that your organization plans to commercialise or defend legally.
What is less clear: the copyright status of AI-generated content that incorporates patterns from copyrighted training data. Ongoing litigation in the US and UK is addressing this directly.
The rule: Do not assume AI-generated content is entirely free from IP concerns, particularly for high-value commercial use. For anything significant, get a legal opinion.
Risk 3: Hallucination in professional documents
LLMs generate plausible text — not verified facts. This is a fundamental characteristic of how they work, not a bug being fixed in the next update.
When you use AI to draft a proposal, prepare a report, or create a client-facing document, the output may contain invented statistics, misattributed quotes, inaccurate dates, or fabricated references. The text will look confident and well-formatted. It will be wrong in ways that are not obvious unless you check.
The rule: Never publish, submit, or send AI-assisted work in a professional context without reviewing every factual claim independently. This is especially critical in legal documents, financial reports, medical information, and any client-facing output where accuracy is a professional obligation.
Risk 4: Regulatory and industry-specific requirements
Some industries have explicit rules about AI disclosure and use. Financial advisers in regulated markets may have obligations under suitability rules. Lawyers have professional duties of competence and candour. Healthcare professionals face strict data protection requirements. Journalists at publications with editorial standards have disclosure obligations.
The rule: Know your sector's regulatory requirements before using AI in professional outputs. If your profession has a regulator, it is worth checking whether they have issued guidance on AI use — most have, or are in the process of doing so.
Use enterprise-approved AI tools wherever your organization has them. Microsoft Copilot integrated into your organization's M365 tenancy, for example, operates under your organization's data agreements — not a consumer privacy policy. This changes the risk profile significantly compared to pasting the same content into a consumer chat interface.
Building good habits
The practical habits that protect you:
Check your company's AI policy first. Many organizations now have one. If yours does not, ask your manager or legal/compliance team for guidance before using AI for work tasks. Using AI in the absence of clear policy is a reasonable professional decision — but using it carelessly in the absence of policy is not.
Use approved enterprise tools where available. Microsoft Copilot integrated into your organization's M365 tenancy, for example, operates under your organization's data agreements — not a consumer privacy policy. This changes the risk profile significantly.
Keep a human in the loop for all consequential outputs. AI should be a drafting assistant, not a decision-maker. You are responsible for every word that goes out under your name.
Disclose when your context requires it. Some clients, some publications, and some professional relationships require or expect disclosure of AI use. When in doubt, disclose.
Professional liability for AI-assisted outputs sits with the professional, not the model. If AI-generated content in a legal document, financial report, or client deliverable turns out to be wrong, the responsibility is yours. Keeping a human in the loop for every consequential output is not optional caution — it is the minimum standard for professional use.
What to do when there is no AI policy
If your organization has not yet established an AI policy, you are in a position many professionals find themselves in. The absence of a policy is not permission to do anything — it is a gap that creates risk.
The sensible approach: apply the most conservative reasonable interpretation of your existing data privacy, confidentiality, and professional conduct obligations. Treat AI-generated content with the same scrutiny you would apply to work from an unsupervised junior employee. Advocate internally for a clear policy — teams that operate without one are accumulating risk that will eventually materialise.
AI tools are genuinely useful. The professionals who benefit most from them are those who understand the constraints — and work confidently within them.
