AI assistants have quietly become part of the working day: drafting emails, answering questions, summarising documents. They are genuinely useful. But a few recent incidents show that the risks aren’t always where people expect. Here are three simple habits worth building into your team’s routine.

1. Treat a shared AI chat like a public web page

In July, hundreds of conversations people had shared from a popular AI assistant turned up in Google search results. They included CVs, financial spreadsheets and patient names. The sharing feature worked as designed: anyone with the link could read the chat, and search engines found the links. The provider has since fixed the indexing, but a share link is still public by design. We suggest checking your AI tool’s settings for any chats you have shared, and removing anything containing client, staff or financial details. If you need to share an AI answer, copy the text rather than the link, or generate a document and distribute that securely.

2. Don’t click links an AI gives you; type or search instead

AI assistants sometimes invent web addresses that look right but don’t exist. Security researchers at Palo Alto Networks asked AI models more than 685,000 questions about real brands. The models made up around 250,000 web addresses that nobody owned. Criminals have noticed: in one case, a made-up address was registered 23 days after researchers spotted it and turned into a fake copy of a real marketplace that collected logins and payment details. Different AI tools tend to invent the same fake addresses, which makes this predictable for attackers. The habit is simple: if an AI gives you a link to log in or pay, type the address yourself or search for the official site.

3. Never paste a command someone else gives you

A growing scam, known as ClickFix, tricks people into fixing a problem themselves. Recently it targeted gamers: helpful-looking forum replies told them to paste a command into their computer to fix a crash. Instead, it quietly installed software that used their computer to mine cryptocurrency for the attacker. The same trick works on business computers. If a website, forum, chat message or pop-up asks you to copy and paste a command, stop and sanity check what you are doing, or call us to check it.

One more thing

None of this means avoiding AI; it means using it with the same care you’d give writing a handcrafted email. If you’d like help setting sensible AI guidelines for your team, reply to this email.