Skip to main content
Skip to main content
Responsible AI

How to use AI responsibly at work: a practical checklist

Responsible use is mostly a set of habits, and the habits are cheaper than the incident.

Andy Wake, Founder and Managing Director6 min read

Most responsible-AI failures at work are not dramatic. Someone pastes a client's personal data into a public tool. Someone sends output containing a confidently wrong figure. Someone lets an assistant draft a decision about a person and forgets that a person still has to make it. All three are preventable with habits, not technology.

Before you paste anything

  • Would you email this text to a stranger? If not, it does not go into a tool you have not assessed.
  • Does it contain personal data, health data, safeguarding detail, pricing, or anything under NDA? Remove or pseudonymise it.
  • Is the tool approved by your organisation, and do you know whether your input is used for training?

While you are working

  • Ask for the reasoning, not just the answer, on anything you would have to defend.
  • Treat every number, citation, date and legal reference as unverified until you check it at source.
  • Ask the assistant what it is uncertain about. A tool that never expresses uncertainty is not being careful, it is being agreeable.

Before the output leaves your hands

  1. Check the facts you cannot afford to get wrong.
  2. Check for unfair or exclusionary language, especially in anything about people.
  3. Decide whether the recipient should be told AI was used — for decisions about a person, the answer is usually yes.
  4. Record the decision if it affects someone's money, education, employment, health, safety or legal rights.

What UK law actually expects

There is no single UK AI statute. UK GDPR governs personal data, including a right to meaningful information about automated decision-making with legal or similarly significant effects. The Equality Act 2010 applies to discriminatory outcomes regardless of whether a machine produced them. Sector regulators apply their own duties on top. The practical implication: you are already regulated, and the evidence you keep is what proves you complied.

Frequently asked questions

Can I put customer data into an AI tool?
Only into a tool your organisation has assessed and approved for that purpose, with a lawful basis, a retention position and a supplier agreement in place. For anything unassessed, remove or pseudonymise personal data first. If in doubt, ask your data protection lead before pasting, not after.
Do I have to tell people that AI was used?
Where AI materially contributes to a decision about someone, transparency is both a data-protection expectation and simple fairness. For routine drafting where a human reviews and owns the output, disclosure is usually unnecessary — but a stated organisational position is better than case-by-case guessing.
What is the minimum policy a small team needs?
One page: approved tools, prohibited data, decisions that always need a named human, how to report a problem, and who owns the policy. Anything longer tends to go unread, which is worse than a short policy people actually follow.

Sources and further reading

Where to go next

More articles on the insights index.

Try the demo