AI

Everyone says we should use AI, so where do we actually start?

By Paul Meakin6 min read

An open laptop and a takeaway coffee cup on a grey table in a red painted room, with red chairs and a glass block window
Photo: Anna Shvets on Pexels

Why does AI feel so hard to start with?

Because the advice is mostly about tools, and your problem is about work.

Every week brings a new product, a new feature and someone explaining that your competitors are already miles ahead. None of that tells you which job in your business, on which day, would actually get easier. So a subscription gets bought, a few people try it, and before long it is used for rewording emails and not much else.

Start from the other end. Forget the tool for a moment and look for the work.

Where does AI actually help?

A simple test. AI earns its place where people spend real time reading, sorting, summarising or drafting, at volume, on material that does not follow a neat pattern.

That last part matters. If the work follows a fixed rule, such as every invoice from this supplier goes in this folder, you do not need AI. A filter or a short script does it the same way every time, for far less. AI is for the messy middle: the inbox where every email is phrased differently, the pile of documents in a dozen layouts, the notes that need turning into a first draft someone can then fix.

Job Good fit for AI? Why
Sorting incoming emails by what they are about Often Varied wording, high volume, easy for a person to check
Pulling key details out of documents in different layouts Often Reading at volume, with a person reviewing the output
First drafts of routine replies or reports Often Saves the blank page, and a person edits before it goes
Moving data between two systems Rarely A fixed rule or an API connection does it more reliably
Deciding whether to offer someone credit or a job Not on its own A significant decision about a person needs human judgement
Anything nobody checks before it goes out No See below

Notice what is not on the list: a chatbot on your website. Sometimes that is the right answer. Usually the bigger saving is behind the scenes, in work your customers never see.

Why do people get AI wrong?

The first mistake is trusting the output because it reads well. The NCSC's guidance on AI is plain about it: generative AI can get things wrong and present incorrect statements as facts. Fluent is not the same as right. Any process that uses AI needs a step where a person, or a separate check, looks at what came out before anyone acts on it.

The second is pasting in things that should never leave the building. An NCSC blog on large language models explains that a query is visible to the organisation providing the service, and recommends not including sensitive information in queries to public LLMs. It also says the terms of use and privacy policy need to be thoroughly understood before asking sensitive questions. Customer records, staff matters, contracts and anything commercially sensitive fall into that category until you know exactly where the data goes and who can see it. If any of it is personal data, UK GDPR applies too, so check the provider's data processing terms before anything goes in.

The third is assuming nobody is using it yet. The NCSC's recent piece on shadow AI describes it as the use of AI technology that is not captured in an organisation's approved systems and processes. If you have not given your team an approved way to use AI, some of them may well have found their own. The NCSC is not telling people to stop using AI. Its point is that the goal should be to reduce risk rather than assume it can be eliminated, which starts with knowing what people are using and why.

The fourth is pointing AI at a process nobody has written down. It will not fix the process. It will just do the confusion faster.

What about decisions about people?

Be careful here, because the law has specific rules.

The ICO's guidance on automated decision making describes it as using personal information to make a significant decision about someone using solely automated processing, including profiling. It also makes the point that a system does not need to involve complex algorithms or AI to come into scope. If a tool would decide something significant about a customer, an applicant or a member of staff with no meaningful human involvement, read that guidance before you build anything, and take proper data protection advice.

For most small businesses the simpler answer is the right one. Let AI sort, summarise and draft. Let a person decide.

How do you test it without betting the business?

Pick one job from the good fit list. Then run a small, boring trial.

Take a sample of real work, with anything sensitive or personal removed, or with a tool whose data handling you have checked against your UK GDPR obligations. Run it through, and have the person who normally does the job mark every result as right, nearly right or wrong. Keep going until you have enough to see a pattern. If most results need heavy correction, stop. If most are right and the errors are easy to spot, you have found something worth building properly.

Then build the check into the process, not around it. The AI step produces a draft or a suggestion. A person approves it. The system records who approved what. That way the time saving is real and the risk stays visible.

Keep the trial small enough that you can stop it without anyone noticing. The aim is to learn whether this particular job suits AI, not to prove that AI works.

Who needs to understand it?

Not everyone needs to be technical. The NCSC's guidance says managers don't need to be technical experts, but they should know enough about the potential risks from AI to be able to discuss issues with key staff. In a small business, that means the owner should be able to answer three questions: which tools are we using, what data goes into them, and who checks what comes out.

If nobody can answer those, that is the first job, and it does not involve buying anything.

When is AI not the answer?

When a fixed rule would do. Rules are cheaper, faster and predictable, and most admin automation needs nothing more.

When the volume is small. If the task takes ten minutes a week, the setup and checking will cost more than it saves.

When the data is too sensitive for the tools you have, and you cannot yet get assurance about where it goes.

When the decision belongs to a person. Credit, hiring, discipline and complaints about the business all need judgement and accountability that a model cannot carry.

And when the real problem is that nobody agrees how the work should be done. Fix that first. It is usually most of the job anyway.

Where do you start?

Spend a week noting every task where someone reads, sorts, summarises or drafts at volume. Then pick the one that is most tedious and easiest to check.

If you want a straight view of where AI would help in your business and where a plain script would do better, tell us what's stuck and we'll map the quickest fix. We build both, through our AI powered solutions and process automation work. Time to talk yet?

Common questions

Is it safe to paste customer data into a public AI tool?

Not by default. An NCSC blog recommends not including sensitive information in queries to public LLMs, and says the terms of use and privacy policy need to be thoroughly understood before asking sensitive questions. Customer data is usually personal data, so UK GDPR obligations apply as well.

Our staff already use AI tools. Should we ban them?

The NCSC is not recommending that people stop using AI. Its advice on shadow AI is to reduce the risk, which starts with understanding what people use and why, and giving them an approved option.

Can AI make decisions about customers or staff?

Be careful. The ICO's guidance on automated decision making sets specific requirements where a significant decision is made about someone by solely automated processing. Keeping a person in the decision is usually the simpler route.

Do we need a chatbot?

Usually not first. The bigger savings tend to be behind the scenes, in reading, sorting and drafting work your customers never see.

Sources

  1. AI and cyber security: what you need to know, NCSC
  2. ChatGPT and large language models: what's the risk?, NCSC
  3. The hidden risks of shadow AI, NCSC
  4. What is automated decision making about people?, ICO

Paul Meakin, Founder

Twenty years of fixing businesses from the inside, eighteen of them in recruitment from consultant to national operations, before building the automation, web applications and compliance systems Staxxd runs today.

More about Paul

Time to talk yet?

Tell us what's stuck and we'll map the quickest fix. Fifteen minutes, no obligation.

Time to talk yet?