
The damage caused by staying silent about AI mistakes can be huge, warns Mercator Digital’s CTO Alastair Williamson-Pound, who says only a solid Data & AI Usage Policy will give staff the clarity and confidence to speak up when something does go wrong
It’s well known now – having been widely documented in the media – that AI is making a lot of employees feel uneasy with how they work, whether that’s being judged for using it in the first place, or fearing they’ll be blamed if they use it incorrectly.
With that in mind, the findings in the UK Government’s recent AI Skills for Life and Work: General Public Survey perhaps come as no surprise.
It found that, although a decent proportion of people are using AI tools in the workplace (three in four have used AI in the last month), only 21% of those people actually feel confident doing so, while even more (25%) admit to feeling unconfident.
Interestingly, the same piece of research also shows that the skills felt to be most important for using AI in the workplace revolved around the risks of AI, specifically understanding risks and threats, keeping information safe and private, and judging the accuracy of information from AI. And those already confident with AI? They were found to be even more likely to see these risk-related skills as important.
But understanding or being aware of AI risk isn’t the same as feeling able to act on that understanding. Because – confidence and risk awareness aside – the real danger is not necessarily making a mistake with AI, but making one and being too nervous to admit it.
The consequences of not owning up to a mistake
When employees with access to sensitive commercial data, HR records or confidential client files hit “allow, allow, allow” to get their work done, in doing so, they hand AI tools far more power than anyone intended.
Copying client data, for example, directly into AI can mean that information is stored in the system’s memory, to be drawn on later in unpredictable ways. Over time, this can lead to cross-contamination: names, addresses or phone numbers from one client appearing in content for another, or personal and business contexts bleeding into each other.
With a standard LLM, the risk often starts with something as simple as copying and pasting, and the knowledge that the more information you give it, the more context it has to work with. You might give it a client letter, a spreadsheet or a chunk of information and ask it to do something with it, but you don’t necessarily know what happens to that information afterwards, where it’s stored or how it might influence what the tool generates next.
Agentic AI takes that a step further because you’re not necessarily giving it the information yourself. You’re giving it permission to go and find it, with minimal human involvement per step. Connect it to your email, your calendar, your shared drives or your business applications, and suddenly the AI can access a huge amount of information and take autonomous actions on your behalf. These tools carry significantly higher risk because their actions can be difficult or impossible to reverse, which is where you really need to stop and think about what you’re allowing it to do.
The danger here is that people can get carried away with the convenience. They see a button that says allow and they click it. Then there’s another one, and they click that too. Before you know it, the tool has access to things you never intended it to have. And if something goes wrong, it’s unlikely to be because someone has deliberately done something they shouldn’t. More often, it’ll be an innocent mistake, followed by someone being too nervous to admit it.
That’s exactly when you need people to speak up. The business can then work out what’s happened, assess the damage and stop it from getting any worse. By not saying anything, employees can not only often make the situation much worse, but there’s also the risk someone else might make the same mistake. This is why a problem that could have been dealt early on, becomes something much bigger.
What makes a good policy?
Bear in mind that according to the UK Government, 84% of people in work have not undertaken any AI-related training in the past 12 months, so a good Data & AI Usage Policy should start by providing employees with a solid understanding of exactly what AI is, how it works and the different types of tools available. The difference between LLMs and agentic AI, for example, is important because the risks and level of access are different.
Next it should cover which tools they should and shouldn’t use and how to handle company and/or client data. This must include clear boundaries on usage and access, particularly for AI tools that have been granted permission to read emails, scan calendars or make autonomous decisions, and details such as how to anonymise information first rather than copying client data directly into AI.
But as well as the above, it should also do much more in terms of explaining the dangers of improper AI use, including the ramifications. Employees should understand that client information can be stored in memory, for example, and the possibility of cross-contamination. It should also explain the risks of using work devices, accounts or licences for personal AI projects – how personal and professional activity can become mixed when AI has memory enabled.
Finally, it should include a clear process for what to do when something goes wrong; who employees tell and what exact steps they should follow. People need to feel confident enough to put their hands up and say, “I’ve made a mistake,” especially given the mistake itself may be innocent, so make it clear that non‑disclosure is a bigger offence so that small AI mistakes don’t turn into large, avoidable crises.
All of this should be drafted in real layman’s terms, so that there’s no chance of misinterpretation, and everyone should receive basic AI training on its content to bring the workforce up to speed. AI is moving so quickly that every six months is almost a different world, so training and guidance ideally need to be revisited as often as new models and tools emerge.
Think of a solid Data & AI Usage Policy as a PR crisis communications plan that handles AI-related issues. The bottom line is, if the policy can make safe use instinctive and admitting a mistake feel safer than hiding it, then it’s doing its job.


