Risks of using AI at work
The "Risks of using AI at work" template assesses how employees perceive and experience the downsides of using AI tools for work tasks. It combines perceived likelihood of specific risks with real incidents people have already faced, the data they refuse to share, and the safeguards they apply. Use it to build a realistic risk picture and prioritize the controls that matter.
What the “Risks of using AI at work” survey measures
The survey captures AI usage frequency, whether respondents have already hit a risk or issue, and which concrete situations they encountered — factual errors, wrong decisions driven by AI output, accidental sharing of internal data, hard-to-verify results, copyright/licensing exposure, inappropriate wording, or uncertainty about whether AI use was even allowed. A perceived-risk slider and a likelihood matrix rate threats such as confidential data leakage, sharing personal data, work-affecting errors, misread context, copyright violations, non-compliance and reputational risk. It also maps the data people deliberately keep out of prompts (customer and employee personal data, passwords/tokens, restricted files, financial metrics, contracts, internal code, plans and strategies), the risk-reduction actions they take (anonymize, use approved tools, verify facts, ask for rationale, avoid high-stakes tasks), and which measures would help most.
Who the “Risks of using AI at work” template is for
It fits security, risk, compliance and data-protection teams building an AI risk register, IT leaders defining approved tools and controls, and managers deciding where AI is safe to use. Organizations preparing an AI governance framework, or investigating incidents after early adoption, get evidence on both perceived and experienced risk in one survey.
How to adapt the template to your needs
Align the risk and data lists with your threat model — add sector-specific concerns (regulated data, trade secrets) or remove code-related items for non-technical teams. Add branching so people who report a real incident get a follow-up open question describing what happened, and route non-users straight past the safeguards block. You can turn the likelihood matrix into your own risk taxonomy, adjust the controls list to what you can technically enforce, or add a severity question alongside likelihood.
Questions and answer options
Answer options:
— Daily
— Several times a week
— About once a week
— Less often
— I do not use AI
Answer options:
— The output contained factual errors or made-up data
— The AI result led to an incorrect decision/action
— The prompt accidentally included internal data that should not have been shared
— It was difficult to verify the correctness of the output
— The AI used materials that could create copyright/licensing risk
— The output contained wording that was inappropriate for a work context
— It was unclear whether using AI for this task was allowed
Answer options:
— Leakage of confidential information
— Sharing personal data with AI
— Errors/inaccuracies that affect work outcomes
— Misinterpretation of context or requirements
— Copyright/licensing violations when using outputs
— Non-compliance with internal rules/regulatory requirements
— Reputational risk due to inappropriate wording
Answer options:
— Customers’ personal data
— Employees’ personal data
— Passwords, tokens, access keys
— Internal documents and files with restricted access
— Financial data and metrics not intended for distribution
— Information about customers/contracts/terms
— Code or code snippets from internal repositories
— Plans, strategies, non-public decisions
Answer options:
— Remove/anonymize sensitive data before prompting
— Use only company-approved tools/accounts
— Verify key facts, numbers, and links before using the output
— Ask the AI to show steps/rationale for the result
— Compare the output with internal sources/documents
— Do not use AI for high-criticality tasks
— Save results only in approved locations
— Confirm AI use with a manager/security team when unsure
Answer options:
— Short “do’s and don’ts” rules with examples
— Built-in prompts and warnings while entering a request
— A list of approved tools and use cases
— Prompt templates for safe common tasks
— A quick consultation channel (chat/form) for borderline cases
— Regular short training (10–15 minutes)
— Technical controls (data masking, blocking sensitive pastes)