The risks of using AI at work fall into five groups, and each has evidence behind it. It gets things wrong in a confident voice. People put information into it that should not leave the organisation. People follow it when it is wrong, and believe they are faster than they are. Skills it takes over fade. And when something goes wrong, nobody is sure who owned the decision. The first two get most of the attention and most of the policy. The other three are harder to see from inside, they grow with time, and they are the ones a leadership team can still get ahead of. Each of the five has a control that can be put in place this quarter.
The answer, in one line
Five, each with evidence: confident errors, company or personal data entered into tools that should not have it, people trusting output they should check, skills fading when the tool does the work, and decisions nobody owns.
1. It is wrong, and it sounds right#
Language models produce fluent text whether or not it is true. Zhou and colleagues found that only about 5 per cent of generated answers carry any marker of uncertainty, and that among confidently expressed answers the error rate averaged 47 per cent in their tests. Specialist tools are better and still not safe to trust unchecked: Magesh and colleagues found three commercial legal research tools hallucinating between 17 and 33 per cent of the time on their queries, in 2024 versions that have since been updated. The public record of consequences is longest in law. Damien Charlotin's database held 2,022 court decisions involving AI-fabricated or misrepresented material as at 6 September 2026, and it counts only cases where a court ruled, not every fake citation filed. In England the Divisional Court said in Ayinde in 2025 that freely available generative tools are not capable of reliable legal research and that the duty to check sits with the professional.
The control is a checking rule per task type, written down, with a named person responsible for the check. More at how often AI is wrong and what an AI hallucination is.
2. Information that should not have left#
In Cisco's 2024 Data Privacy Benchmark, a survey of 2,600 privacy and security professionals across twelve countries, 48 per cent admitted entering non-public company information into generative AI tools and 45 per cent employee information. The best-known case is Samsung, which The Register reported in May 2023 had banned the tools for staff in one of its largest divisions after source code was entered into a public chatbot. Deloitte's 2026 UK survey adds that 31 per cent of workers who use generative AI do so without their employer's knowledge, which means the organisation cannot see where its information has gone.
The control is a data rule people can remember, an approved tool with enterprise terms so there is somewhere legitimate to go, and clarity about what the employer can see. The last is covered at can my employer see what I put into AI.
3. Trusting it when you should not#
Skitka, Mosier and Burdick described the two errors automated aids produce in 1999: missing what the system failed to flag, and following advice that was wrong. Both appear with generative AI. Dell'Acqua and colleagues found that consultants using AI did better on tasks inside the tool's strengths and worse than colleagues with no AI on a task outside them that looked similar. Perception does not correct for this. In METR's 2025 trial, sixteen experienced developers were 19 per cent slower with AI tools and still estimated afterwards that AI had made them about 20 per cent faster. METR has since said the study is not a guide to current tools, and it was small; the gap between felt and measured speed is the part that matters here.
The control is measurement that does not rely on how people feel, and designs that make people form a view before they see the machine's answer. See automation bias and how to measure adoption properly.
4. Skills that fade#
Budzyń and colleagues found that endoscopists' detection rate in unassisted colonoscopies fell from 28.4 to 22.4 per cent after routine exposure to AI assistance. It is one observational study of one procedure, and also the clearest measurement so far of a skill weakening while the tool was doing the work. Older research on skill decay, summarised by Arthur and colleagues, found cognitive and accuracy-based skills fade faster with non-use than physical ones. Executives are noticing: half of the 70 surveyed by BCG in 2026 said they already see deskilling in their organisations. That is perception from a small base, not prevalence.
The risk compounds the first three. A team that can no longer do the work cannot check the machine doing it. The control is a short list, per role, of what people must stay able to do, with time protected to do it. See deskilling and AI-free periods at work.
5. Nobody owns the decision#
In England and Wales an AI system has no legal personality and cannot itself be liable, according to the UK Jurisdiction Taskforce's 2026 legal statement, and professionals can be negligent for careless use of it. Responsibility always comes back to people. Inside many organisations, though, the decision a tool shaped has no named owner: it was drafted by the machine, approved by someone who did not check, and acted on by someone who assumed it had been checked. The EU AI Act's deployer duties for high-risk systems require human oversight to be assigned to people with the competence, training and authority to exercise it. Most uses at work are not high-risk under the Act, and the principle travels well regardless.
The control is a named owner for each class of decision the tool touches, and a named person who can stop it. The legal position is set out at who is responsible when AI gets it wrong.
The order to deal with them in#
Most organisations start with the data rule, and that is right, because it is the risk most likely to cause a reportable incident this year. The mistake is stopping there. The confident error and the misplaced trust are managed by checking rules and better measurement. The fading skill and the missing owner are managed only by decisions leadership has to make in advance: which decisions a machine may make, who can stop each one, what people must remain able to do, and how anyone would know if it went wrong. Those four are Rules Before Tools, and a policy built on them is described at how to write an AI use policy that works.
What this does not show#
It does not rank the five risks by how much harm each causes, because no study measures them side by side. The error figures come from particular tools at particular dates and will change. The data-entry figures are self-reported by privacy professionals in a vendor's survey. The deskilling evidence is strongest in medicine and is an inference elsewhere. The legal position described is England and Wales, in a statement rather than a judgment. And it says nothing about the risks of not using AI, which are real and are covered at whether a professional could be negligent for not using it.
Explainer · SS-2026-415 · Graded against the published rubric · 5 peer-reviewed studies, 2 working papers, 2 compiled reviews and 5 of other kinds
Hirji, R. (2026). What are the risks of using AI at work?. The SuperSkills evidence base, SS-2026-415. https://thesuperskills.com/research/what-are-the-risks-of-using-ai-at-work. Last reviewed 5 October 2026.
An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.
How citations and IDs work