AI Has Entered The Chat: Using AI Without Handing Over The Keys
Imagine I told you I’d hired a new assistant.
They’re available 24 hours a day, seven days a week. They never complain about being asked to rewrite something for the sixth time because I don’t think it “sounds like me”. They can take a page of my slightly chaotic notes and turn them into something coherent in seconds. They’re pretty good at Excel, can explain complicated concepts in plain English, brainstorm ideas when my brain has stopped cooperating and have apparently read almost everything on the internet.
Sounds pretty good, right? There’s just one small catch.
Occasionally, they make things up and, somewhat inconveniently, they deliver the completely made-up answer with exactly the same confidence as the completely correct one.
Welcome to AI.
I use AI… quite a lot actually.
The more I use it, the more convinced I am that it can be an incredibly useful tool for small businesses, bookkeepers & accountants, societies, charities, and boards.
I’m equally convinced that we need to apply a healthy dose of common sense when we use it.
Because AI doesn’t need to be scary, but it probably shouldn’t be given unsupervised access to the filing cabinet either.
One of the things I like most about AI is its ability to help get something out of my head and into a usable format.
Anyone who has ever received one of my first drafts will know that my initial thoughts do not necessarily arrive in the order they are eventually required.
I might know exactly what I want to say in a client report, but getting from “I know what this means” to “here is a concise explanation that somebody else can understand” can take time.
AI can help bridge the gap.
I can give it my over-explained analysis and ask it to help turn that into a clear explanation. I can give it a de-identified draft report and ask what questions a client might have after reading it. I can ask it to identify areas that need further explanation, suggest a clearer structure, or help me explain a financial concept without sounding like I swallowed an accounting textbook, and THAT’S useful.
It can also be a fantastic second set of eyes. Instead of asking, “Does this report look good?”, I can ask it:
“What assumptions have I made here?”
“What questions might someone reading this ask?”
“Is there anything in this explanation that could be misunderstood?”
“What other reasons could explain this movement?”
That last one is particularly useful.
If income has dropped 20%, I might already have a pretty good idea why. But asking AI for other possibilities can prompt me to investigate something I hadn’t considered.
It’s not doing my job for me, it’s helping me think about my job differently.
But would you let the new employee send the report?
Here’s where the analogy becomes important.
If I hired a brand-new employee tomorrow, I might absolutely ask them to help prepare a report.
Would I let them send it straight to a client without looking at it?
No.
Would I assume every calculation they had made was correct?
Also no.
Would I allow them to make a recommendation to a client on my behalf without checking the information they had based it on?
Definitely not.
And would I hand them the keys to the filing cabinet on their first day and say, “Here you go, this contains all of my clients’ financial information, payroll details and other confidential stuff. Have at it”?
Absolutely not.
They’d get access to the information they actually needed to do the job I’d asked them to do, and no more.
So why would I treat AI any differently?
One of AI’s greatest strengths is also one of its greatest weaknesses: it can make almost anything sound convincing.
Bad information doesn’t necessarily arrive with a flashing red banner saying
It can arrive beautifully formatted, logically explained and written with such confidence that you start questioning whether perhaps you’re the one who has it wrong.
I’ve had AI give me legislation that doesn’t exist, confidently explain rules that don’t apply in New Zealand and provide very convincing answers that fall apart the moment you check the source.
That doesn’t make AI useless. It makes checking important. If I’m dealing with tax, I want to know what IRD says. When I’m dealing with employment law, I want to know what the legislation or relevant government guidance says, and when I’m preparing financial information, I want to be able to trace the numbers back to the accounting system and understand why they are there.
AI can help me get to the answer. It cannot be the reason I believe the answer.
About that filing cabinet. . .
This is probably the part of AI use that concerns me most in a business environment.
Confidentiality.
We already understand this concept everywhere else.
I wouldn’t wander into a café, spread a client’s payroll report across the table and start loudly discussing everyone’s salaries.
I wouldn’t forward confidential Board papers to a random person because they offered to proofread them.
I wouldn’t give a new contractor access to every client file I have because they only needed one figure.
Yet it can be surprisingly easy to forget those same principles when the thing we’re sharing information with is a tab on a computer screen.
Before putting information into any AI system, we need to stop and think about what we are actually giving it.
Does it contain names? Employee information? Payroll details? Customer information? Commercially sensitive figures? Board discussions? Personal information? Information that we have a professional or legal responsibility to protect?
And, perhaps most importantly: does the AI actually need that information to do what I’m asking it to do?
Quite often, the answer is no.
AI doesn't need to know that Bob Smith earns $87,500 and works for ABC Plumbing Limited if what I'm asking is how to explain a particular payroll calculation.
Bob can become Employee A.
ABC Plumbing can become Company XYZ Ltd.
Sometimes the numbers themselves can be changed while still giving me what I need to ensure my calculations are correct.
Removing identifying information doesn't solve every privacy or confidentiality issue, and businesses still need to understand the tools they're using and the terms that apply to them, but it's a pretty sensible place to start. The same rule we apply elsewhere should apply here too. Only give someone the information they actually need. Even when that “someone” is AI.
Maybe we need some rules…
And no, I don't mean a 47-page AI policy that everybody signs and nobody reads.
For a lot of small businesses, charities and boards, some fairly simple guidelines would be a good start.
Which AI tools are we comfortable using, and what information should never be entered into them?
When should information be de-identified and what work needs to be checked by a human?
Can AI be used to draft reports, policies or communications and what sources should be checked before relying on an answer?
Who remains responsible for the final output?
None of these questions require you to understand how a large language model works. They require you to understand your own responsibilities. Because without those conversations, everyone is left to make up their own rules. One person might be happily using AI to tidy up the wording of a completely de-identified report, while someone else is copying and pasting an entire confidential document into it without giving it a second thought.
And what happens when we're not sure? Is the expectation simply that we stop and ask before we put something into an AI tool?
I don’t believe the answer needs to be “don't use AI”, it needs to be “this is how we use AI here.”
That might be as simple as agreeing that confidential or personally identifiable information doesn't go into public AI tools, AI-generated information is checked before it's relied upon, authoritative sources are used where accuracy matters, and a human being always remains responsible for whatever eventually leaves the building.
It also means accepting that those rules might change. The technology is developing quickly, the tools are changing and our understanding of the risks and opportunities is changing along with them. What makes sense today might need another look in six months.
Don't be scared of it. Just don't switch your brain off.
As I said, I don't think avoiding AI altogether is the answer. Used well, it can save time, improve communication, challenge our thinking and help make information more accessible. For small businesses in particular, that can be incredibly valuable.
It gives us access to tools and capabilities that, not very long ago, would have required significantly more time, money or people.
That's exciting.
But using AI well isn't about asking it to do everything. It's about knowing what to ask it to do, knowing what information you're comfortable giving it, when to check the source, recognising when something doesn't quite look right and it's remembering that, at the end of the day, if my name is on the report, I'm responsible for what's in it.
So yes, AI has joined the team.
I'll happily let it organise my thoughts, challenge my assumptions, proofread my reports and explain something to me three different ways until one finally makes sense.
I'll even invite it into the meeting. I'm just not giving it the keys to the filing cabinet, because while the technology might be new, common sense isn't.

