Common pitfalls
The mistakes almost everyone makes once: taking invented statements, entering confidential material, trusting arithmetic, believing a confident tone.
The seven most common mistakes
| Mistake | How to spot it | What helps |
|---|---|---|
| Invented citation | It looks perfect | Check each against the source |
| Wrong figure | It is plausible | Recalculate or use a tool |
| Confidential material entered | Noticed only later | Settle in advance which tool for what |
| A commitment in a draft | It sounds helpful | Always check drafts containing commitments |
| Outdated statement | No date given | Ask for the state, demand a source |
| False premise adopted | The question contained it | Check the question, not only the answer |
| Agreement instead of scrutiny | It sounds good | Ask explicitly for counter-arguments |
Three habits that avoid most trouble
- Before entering: would I send this to an external party without a contract?
- After the result: which statement in it must be true, and how do I know?
- Before passing it on: has a person read and owned it?
Why the tendency to agree is dangerous
Models are aligned to seem helpful. Raters prefer answers that agree and confirm. That leads a model to adopt the questioner's position even where it is wrong.
Counter-measure in the prompt:
First name the three strongest counter-arguments to my assumption.
Only then give your assessment.
If my assumption contains a false premise, say that first.
Checking without checking everything
At volume, checking everything is unaffordable. Instead:
- 01
Always check the critical fields
Amounts, deadlines, names, identifiers. That list is short and fixed.
- 02
Sample the rest
Ten percent, drawn at random, with a documented error rate.
- 03
Route uncertainty out
Whatever the system itself flags as uncertain always goes for review.
- 04
Track the error rate
If it rises, the sample does not shrink further. Without that number every review rate is guesswork.
Pitfalls with legal consequences
- Confidential material in unchecked tools. A breach of confidentiality or trade secret protection happens on entry, not on output.
- Personal data without a legal basis. A draft is processing too.
- Automated decision without review. Art. 22 GDPR bites even where nobody intended a decision.
- Missing labelling. For published artificially generated content and for dialogue systems.
- Unsupervised agents with write permissions. An error there is not a wrong answer but a wrong action.
Prompt injection in everyday use
As soon as a tool reads external content, such as a web page or a forwarded email, that content can contain an instruction aimed at the system. The protection is easy to state and hard to keep: read content is always data and never an instruction. Recipients, target addresses and amounts are never taken from read content. See Agents in depth.
The error log
FREE ACCOUNT
Error log for the first weeks
A sheet where every error found lands with its cause and its remedy, because after four weeks that is worth more than any guide.
Worksheet2 items