Skip to main content

RAIUC blog

10 Questions Every Organisation Should Ask Before Using AI

· Stephen Whitelaw · 7 min read

AI is becoming part of everyday business faster than many organisations expected. It can help teams work more efficiently, analyse information, draft content, support customer service and improve decision-making. Used well, it can save time and create real operational value. But adopting AI is not simply a matter of choosing a tool and giving employees access to it.

AI is becoming part of everyday business faster than many organisations expected.

It can help teams work more efficiently, analyse information, draft content, support customer service and improve decision-making. Used well, it can save time and create real operational value.

But adopting AI is not simply a matter of choosing a tool and giving employees access to it.

The bigger questions are about governance, responsibility, data, accuracy and risk. What is the AI being used for? What information is being entered into it? Who checks the output? And who is accountable if something goes wrong?

Those questions matter whether you are a small business experimenting with generative AI or a larger organisation introducing AI across multiple departments.

Before approving or expanding the use of AI, every organisation should be able to answer the following ten questions.

1. What are we actually using AI for?

Start with the business purpose.

What problem are you trying to solve, and why is AI the right tool for the job?

An organisation might use AI to draft documents, summarise information, analyse data, answer customer enquiries, support recruitment, create marketing material or assist employees with research and decision-making.

Each of those uses comes with different benefits and different risks.

Defining the purpose at the outset makes it easier to decide whether the use is appropriate, what safeguards are needed and how success should be measured.

AI should not be adopted simply because it is available or because competitors are using it. There should be a clear reason for introducing it.

2. What information are we putting into AI systems?

This is one of the most important questions an organisation can ask.

Employees may enter customer records, internal documents, employee information, financial data or commercially sensitive material into an AI system without fully understanding what happens to that information afterwards.

In many cases, the risk does not come from deliberate misuse. It comes from convenience.

An employee may copy and paste a document into an AI tool to summarise it, rewrite it or extract key points without considering whether the information should have been entered into that system in the first place.

Organisations therefore need clear rules covering what information can and cannot be submitted to AI tools.

Those rules are especially important where personal data, confidential information, intellectual property or other sensitive material is involved.

3. Where does our data go?

Knowing what employees are entering into an AI system is only part of the picture.

Organisations also need to understand how the provider handles that information.

Important questions include whether data is stored, how long it is retained, where it is processed, who may have access to it and whether it can be used to improve or train the provider's systems.

Organisations should also understand what administrative controls are available.

Can data retention be limited? Can certain features be switched off? Are business and enterprise accounts treated differently from consumer accounts? Can administrators control how staff use the service?

These questions should form part of the assessment before any AI platform is approved for organisational use.

4. Who checks the AI's work?

AI systems are capable of producing polished, confident and persuasive answers.

That does not mean those answers are always correct.

AI-generated content can contain factual errors, missing context, incorrect assumptions or fabricated information. In some cases, those mistakes can be difficult to spot because the output appears entirely plausible.

Human oversight is therefore essential.

Organisations should decide who is responsible for reviewing AI-generated work and when additional verification is required.

The level of checking should reflect the level of risk.

An AI suggestion for improving the wording of an internal email does not require the same level of scrutiny as AI-generated information relating to legal advice, financial decisions, recruitment, healthcare or workplace safety.

5. How do we know the information is accurate?

One of the easiest mistakes to make with AI is to confuse confidence with accuracy.

AI systems can present incorrect information in a highly convincing way.

Where accuracy matters, organisations should have a clear process for verifying the output.

That might involve checking the original source material, consulting reputable external sources, confirming calculations, reviewing cited references or asking someone with the relevant expertise to assess the result.

The key principle is straightforward: AI-generated information should be verified according to the consequences of getting it wrong.

The more important the decision, the stronger the checking process should be.

6. Will people know when AI has been used?

Not every use of AI needs to be announced.

But there are situations where transparency is important.

If AI has played a significant role in communicating with a customer, assessing an individual, producing professional advice or influencing a decision, an organisation should consider whether the person affected ought to know.

Context matters.

Using AI to correct grammar in a routine email is very different from using AI to draft a response to a formal complaint or help evaluate a job applicant.

A useful test is to ask whether disclosure would help someone understand how an important communication, recommendation or decision was produced.

If the answer is yes, transparency deserves serious consideration.

7. Who is accountable if something goes wrong?

AI may assist with work, but responsibility still rests with people and organisations.

That principle should be clear from the start.

An organisation should know who owns the AI system, who is responsible for approving its use, who checks the output and who takes responsibility for decisions influenced by it.

"The AI made the decision" is not a meaningful accountability framework.

This becomes particularly important where several teams, external suppliers and automated systems are involved.

Without clear ownership, responsibility can quickly become fragmented.

Good AI governance should make accountability easier to identify, not harder.

8. What could go wrong?

Before introducing any AI tool, organisations should spend time thinking about failure, not just benefits.

Potential risks may include inaccurate information, privacy breaches, disclosure of confidential material, discrimination or bias, copyright issues, cybersecurity concerns, inappropriate automation, poor decision-making or reputational damage.

The risks will vary depending on how the technology is being used.

A tool used for brainstorming marketing ideas presents a very different risk profile from one used to support employment decisions or analyse sensitive customer information.

The objective is not to eliminate every possible risk.

It is to identify the significant ones early enough to put proportionate safeguards in place.

9. Do our employees know how to use AI responsibly?

Buying an AI tool is easy.

Making sure people use it responsibly is more difficult.

A policy can provide a useful framework, but employees also need practical guidance that reflects the situations they encounter in their day-to-day work.

They should know which tools they are permitted to use, what information they must not enter, when AI-generated work requires checking and when they should seek additional advice.

They should also understand the limitations of the technology.

AI can make mistakes. It can misunderstand context. It can produce biased or incomplete output. And it can sound convincing while doing all three.

Responsible AI use therefore depends on more than technology and written policies. It depends on employee judgement, training and organisational culture.

10. Are we reviewing our use of AI?

Approving an AI system should not be the end of the process.

AI tools change. Providers update their terms. New features are introduced. Data handling practices can evolve. Employees may also begin using systems in ways that were never originally anticipated.

Organisations should therefore review their use of AI on a regular basis.

That could include maintaining a register of approved AI tools, reviewing incidents and near misses, reassessing higher-risk uses, monitoring changes to provider terms and updating employee guidance where necessary.

Regular review helps organisations identify problems before they become embedded in everyday working practices.

Responsible AI Starts With the Right Questions

Responsible AI does not mean avoiding AI.

It means using the technology deliberately, understanding where its limitations lie and maintaining appropriate human oversight and accountability.

Before introducing a new AI system, an organisation should be able to explain:

  • what the technology is being used for;
  • what information it will handle;
  • where that information goes;
  • how the output will be checked;
  • what the main risks are; and
  • who remains accountable for its use.

If those questions cannot be answered clearly, the organisation may not yet be ready to approve the system.

At the Responsible AI Use Campaign, we encourage organisations and professionals to think about these issues before problems arise rather than after the damage has been done.

Good AI governance does not always need to begin with a complicated framework.

Often, it begins with something much simpler: asking the right questions before the technology becomes part of everyday work.

 

Comments

No comments yet.

Leave a comment

Your email address will not be shown. Comments appear only after review.

Read our Privacy Policy for how we handle your details.

Please click here to read next blog postWhat Does Responsible AI Actually Mean in Everyday Business?