AI assistants are getting hands. Until recently, tools like ChatGPT and Claude lived in a chat window. You asked a question. They answered. Nothing on your computer changed unless you copied something out. That has shifted.
The newest AI tools can now click, type, open apps, read your files, send emails, and browse the web on your behalf. Claude calls its version "Cowork". OpenAI builds it into ChatGPT's agent mode, which absorbed its earlier "Operator". Microsoft has Copilot agents. They are useful. They are also a bigger deal than most people realise.
If you are a small business owner, a community organisation, a council communications officer, or anyone running content for an organisation that handles other people's information, this matters. This is the safety companion to how to start using AI in your business. Read that one for the how; read this one before you give AI the keys.
What "computer use" actually means
When an AI uses your computer, it does what you do. It takes screenshots. It moves the mouse. It types into fields. It clicks buttons. It opens browser tabs. It can read whatever is on your screen.
This is powerful. It can save hours of admin, content reformatting, file organising, and routine work. It also means the AI sees everything that is on your screen while it works. That includes anything sitting in a tab, a folder, or an open window.
The risks in plain language
There are three risks worth knowing about. None of them are reasons to avoid AI. They are reasons to use it like a thoughtful adult.
1. The AI can be tricked. If the AI reads a website, a document, or an email that contains hidden instructions, it can be talked into doing something you did not ask for. This is called prompt injection. It is the most common attack on AI agents.
2. The AI does what you grant it. If you give an AI access to your whole computer, your email, your client folders, your accounting software, and your social accounts, it can act on all of them. That is a lot of power for one tool.
3. You are still responsible. Whatever the AI sends, posts, edits, deletes, or pays for on your behalf is your problem to clean up. It is not the AI's signature on the email. It is yours. Worth sitting with that for a moment.
What the better tools already build in
Here is the reassuring part the fear skips over: the serious tools are built with these risks in mind. Claude's own guidance, Use Claude Cowork safely, is worth a read for how it thinks about this. Its assistant does its work in an isolated, temporary space kept separate from your own computer, and it draws a clear line between "read" actions (looking at things) and "write" actions (changing or sending things), keeping a human in the loop on anything high-stakes.
Microsoft draws similar lines, and here one detail trips people up: there are two different Copilots. The free personal "Microsoft Copilot", and the paid "Microsoft 365 Copilot" that businesses use. The business one keeps your prompts and data inside your own organisation and, per Microsoft's own documentation, does not use them to train the underlying models. None of that removes your judgement. It just means the guardrails are real, and worth turning on.
My practical safety checklist
I use AI tools every day in my business. Here is how I keep it sensible, at a glance first, then in detail.
Create a dedicated working folder. Do not point AI tools at your entire Documents folder. Make a separate folder for AI work. Keep client contracts, financial records, and personal documents out of it.
Back things up before you let AI edit them. Cloud storage with version history is fine. So is a manual copy in a safe folder. If the AI gets it wrong, you want to be able to roll back without crying.
Watch the work, especially at the start. Treat a new AI assistant like a new staff member. You would not give a brand new contractor your bank login on day one. Same thing here. Start small. Build trust. Watch what it does.
Avoid sensitive apps. Banking, MyGov, healthcare portals, anything to do with personal client records. Keep AI agents out of those. They are not the place to experiment.
Be careful with "act without asking" or autopilot modes. Most AI tools have a setting that lets them run without pausing for approval. It is faster. It is also riskier. Only use it when you are sitting at the desk and watching, and only for tasks that are genuinely low stakes.
Be cautious with scheduled tasks. Some AI tools can run on a schedule, doing things while you sleep. Lovely in theory. In practice, start with simple, harmless tasks like summarising your inbox. Do not schedule anything that sends emails, posts content, or moves money without you reading it first.
Limit what websites your AI can visit. Trusted sites only. Your content system, your customer records, your reference docs. A wide-open browser is where prompt injection attacks live.
Treat unknown plugins and integrations like unknown software. Every new connector or extension expands what the AI can touch. Stick to verified ones from official directories. If you do not recognise the developer, do not install it.
What I actually use AI for
Happily let it help
- Drafting blog posts and social captions
- Summarising long documents
- Helping me write proposals
- Organising and renaming files in dedicated folders
- Reformatting transcripts and notes
- Brainstorming content angles
- Building training resources for clients
Where I do not
- Sending client emails without reading them first
- Touching financial records
- Posting anything publicly without my eyes on it
- Anything involving other people's personal data
- Booking, buying, or paying on my behalf
That line is moveable. It will move as the tools mature and as I get to know them better. But the line exists. Yours should too. If you want the fuller version of what is safe to put in and what is not, it is in my piece on how I actually work with AI.
The honest take
AI is not magic. It is also not dangerous if you treat it sensibly. The thing nobody says out loud is this: the risk is not really the AI. The risk is humans skipping the basics. Backups. Working folders. Reviewing output. Logging out of things you do not need open.
If you have those habits in place, you can use these tools and get genuine value out of them without losing sleep. If you do not, AI is not the problem. The habits are.
If you want the original technical guidance from the team behind Claude, the full safety article is here: Use Claude Cowork safely. I have linked it because I want you to see the actual source, not because you need to read 2,000 words of documentation. The summary above covers what matters for most of us running small organisations.
Final thought
Video, AI, and the tools we use to create content are moving faster than ever. That is exciting. It is also tiring. You do not need to use every tool. You do not need to be first. You just need to use what you choose with care, attention, and a bit of common sense. That has always been the eMotion Video way. Use the tool. Keep your wits about you. Tell better stories.
Want help building AI into your workflow without falling into the traps above?
That is exactly the sort of training we run. Get in touch and we will work out where you actually need it.
Have a chatMore from the blog
Sources
- Anthropic, "Use Claude Cowork safely", Claude Help Center. Source for the isolated working environment and the read-vs-write tool distinction.
- Microsoft, "Data, Privacy, and Security for Microsoft 365 Copilot", Microsoft Learn. Source for Microsoft 365 Copilot keeping your data in your organisation and not training the foundation models on it.