The risks of AI — hallucinations, data privacy, and what should never go into a chatbot
Every week this column shows what AI can do for a finance team. This week, the other side of the ledger: how these tools fail, where your data goes when you press send, and the short list of things that should never be pasted into a chat window.
For nine weeks this column has argued that AI belongs in the Jamaican finance office: forecasting cash flow, cleaning a year of receipts, turning spreadsheets into slides, reading 200-page agreements before anybody signs them. Nearly every one of those columns closed with the same two warnings — verify everything, and keep confidential material on a business account.
This week those warnings get the full column, because the tools are spreading through Jamaican businesses faster than the habits that make them safe.
The two risk families from this week’s column: what AI can do to information, and what can
happen to the information you give it. (Branded graphic by PGH Consulting, LLC)
The risks fall into two families. The first concerns what AI does to information: it can invent it, fluently and with total composure. The second concerns what happens to information you give it: it can travel further than you intended. Neither risk is a reason to sit the technology out. Both are reasons to use it with rules, and the rules fit on one page.
Hallucination is not a malfunction
A large language model works by predicting what words plausibly come next, and most of the time plausibility and truth line up. When they do not, the machine does not stop or stumble; it produces something that sounds right, in exactly the tone it uses when it is right. The industry calls these failures hallucinations. In a finance setting they look like this: a total that was never in the spreadsheet, a contract “summary” that includes a clause the contract does not contain, or a Jamaican tax threshold that is two years stale or entirely imagined, delivered with the same calm authority either way.
From source files to a vague prompt to a confident answer — and the two habits that catch
most of it. (Branded graphic by PGH Consulting, LLC)
The newest models hallucinate less than their predecessors, but less is not never, and the failure has an unkind shape: it shows up most where checking is hardest — precise figures, obscure facts, citations and references — and the confidence of the answer tells you nothing about its accuracy. A chatbot is never more dangerous than when it is specific, fluent, and wrong.
The two habits that catch most of it
The first habit is the rule this series repeats every week: AI reads figures, it never generates them. If a number was not in the document, spreadsheet, or statement you gave the tool, it does not belong in anything you send out. The same discipline applies to anything statutory. Tax rates, contribution thresholds, and filing deadlines come from Tax Administration Jamaica, your accountant, or the legislation itself; a chatbot’s recollection of them is a guess wearing a suit.
The second habit is references, familiar from the due diligence column two weeks ago: every answer you intend to act on must point at something you can check — a page, a clause, a cell. That means asking “where in this document does it say what happens if I pay late?” rather than “what usually happens if a business pays late?”. The first question keeps the tool in the job it is excellent at, reading what you supplied. The second invites it to improvise, and it will oblige.
“A chatbot is never more dangerous than when it is specific, fluent, and wrong.”
Where your chats actually go
On the personal tiers of the leading assistants, free and paid alike, your conversations can be used to train future models unless you switch that off yourself. ChatGPT keeps the setting under its data controls, labelled “Improve the model for everyone”; Claude added an equivalent training setting when its consumer policy changed in 2025. Both default to sharing on personal accounts, and opting out is not retroactive — it covers new conversations, not what you have already pasted.
Business plans are a different arrangement: ChatGPT’s Team and Enterprise tiers, Claude for Work, and Microsoft’s commercial Copilot licences do not train on your data under their commercial terms, which is why this series has recommended a business plan since the first column. Check the current position on the vendor’s own pages rather than taking any third-party summary on faith, this column included.
This stops being a matter of personal preference the moment other people’s information is involved. Jamaica’s Data Protection Act places legal obligations on businesses that handle personal data, and a staff member pasting a customer list into a personal chatbot account is handling personal data. The law is not impressed that the tool was helpful.
Six things that never go into a chat window, business plan or not — and the anonymising step
that unlocks the legitimate cases. (Branded graphic by PGH Consulting, LLC)
The never-paste list
Some things do not go into a chat window at all, business plan or not:
1. Customer or staff personal data — names attached to TRNs, addresses, salaries, or medical details.
2. Banking credentials, card numbers, PINs, passwords, or any key that opens an account.
3. Payroll files with names attached — anonymise first if the analysis is genuinely needed.
4. Anything covered by a non-disclosure agreement, unless you have checked what the NDA says about service providers.
5. Unannounced deals, results, or anything price-sensitive.
6. Other people’s documents that you have no permission to share.
Where the work truly needs the data — payroll analysis is a legitimate use — strip the identities first: replace names with staff codes and keep the key in a separate file the AI never sees. Ten minutes of anonymising buys the analysis without the exposure.
Most AI data leaks are a helpful employee with a deadline — a short written policy protects
them and the business. (Branded graphic by PGH Consulting, LLC)
A one-page policy beats a ban
Most AI data leaks are not sabotage; they are a helpful employee with a deadline. Ban the tools outright and that employee keeps using them anyway, on a personal phone, on a personal account, with none of the protections above. The stronger move is a short written policy: which tools and accounts are approved, what never gets pasted (the list above is a starting point), and the standing rule that AI output is a draft until a named person has checked it against a source. Three paragraphs, shared with everyone who touches the tools, revisited every few months as the products change — which, as this year has shown, they do.
What to try this week
1. Open the data controls on every AI account you or your team use, and switch off model training on the personal ones — in ChatGPT the setting is “Improve the model for everyone”; Claude has its equivalent under privacy settings.
2. Run a calibration drill: ask your assistant three questions your own books already answer, and grade the results. The point is to feel how confident wrong sounds.
3. Write the never-paste list for your business, starting from the six categories above, and put it where the team will actually see it.
4. If confidential work is still happening on personal accounts, price a business plan this week and weigh the monthly cost against a single data mistake involving customer information.
5. Make the reference rule policy: no AI answer goes into a decision, an email, or a filing until someone has checked it at the source it cites.
Treat every AI answer as a draft, keep other people’s data out of personal accounts, and be most sceptical exactly when the tool sounds most sure — the signature, as ever, is still yours.
Peta-Gaye Hardy is the founder of PGH Consulting, LLC, where she helps finance and operations teams adopt AI in practical, low-risk ways. She writes the weekly AI in Finance & Business column and is based between Jamaica and the United States. Learn more at www.pghconsultinggroup.com. Follow on Instagram and YouTube @pghconsultinggroup, and connect on LinkedIn at linkedin.com/in/peta-gaye-hardy.
Disclosures: This article is informational and does not constitute investment, tax, legal, or accounting advice. AI tools can produce errors; every figure, clause, or claim they produce should be verified against a source before being shared or acted upon. Product features, data-handling policies, and plan terms are as published by the vendors at the time of writing (August 2026) and are subject to change; readers should confirm current settings on the vendors’ own pages. The author has no commercial relationship with OpenAI, Anthropic, Microsoft, or any product mentioned and was not compensated by them. The examples described are illustrative and do not depict any real business.