AI for Absolute Beginners: What It Is and How to Use It Safely

Updated September 15, 2026. Every figure below was checked against the sources at the end of this article on that date.
Type a question into a chatbot and something very specific happens: your text leaves your device, arrives at a company's servers, gets converted into numbers, and a statistical model produces the most plausible continuation of that text. Plausible is not the same as true, and "leaves your device" is not the same as "stays private". Almost everything a beginner needs to know about using these tools safely follows from those two sentences.
You are not alone, and the numbers are worth knowing
The Pew Research Center surveyed 5,119 U.S. adults between February 17 and 23, 2026, drawn from its American Trends Panel. It found that 49% of U.S. adults had used an AI chatbot, up from 33% in its 2024 measurement, and that 44% had specifically used ChatGPT, compared with 18% in 2023. The same survey found 71% of U.S. adults expect increased AI use to make personal information less secure, and 63% say AI is advancing too quickly.
Most people using these tools are simultaneously worried about them, and that worry is well founded rather than superstitious. The rest of this article turns vague unease into specific, checkable habits.
What is actually happening when you type
A general-purpose chatbot is a text predictor wrapped in a product. It has no database of verified facts to look things up in, and no internal flag separating "I know this" from "this pattern of words usually follows that one". When it is wrong, it is wrong in exactly the same confident register as when it is right.
NIST, the U.S. National Institute of Standards and Technology, gave this failure mode a name in its Generative AI Profile (NIST AI 600-1, published July 2024). It calls it confabulation, and defines it as the "production of confidently stated but erroneous or false content ... by which users may be misled or deceived". The word choice is deliberate: "hallucination" suggests a rare glitch, while confabulation describes a system doing its normal job on a question it cannot actually answer.
The second thing happening is that your words are now somebody else's data. The UK's National Cyber Security Centre put it bluntly in guidance published on March 14, 2023: a query to a public LLM "will be visible to the organisation providing the LLM", and "those queries are stored and will almost certainly be used for developing the LLM service or model at some point". The NCSC's advice is to not include sensitive information in queries to public LLMs, and not to submit queries that "would lead to issues were they made public".
The third thing, which beginners almost never hear about, is that a chatbot connected to the web or to your files can be attacked through the content it reads. NIST AI 600-1 distinguishes direct prompt injection, where an attacker types malicious instructions into the system, from indirect prompt injection, where instructions are hidden in a document or web page the model retrieves, potentially causing it to leak data or take actions you did not ask for. In a blog post dated December 8, 2025, the NCSC argued that unlike SQL injection, "there's a good chance prompt injection will never be properly mitigated", and that "the best we can hope for is reducing the likelihood or impact of attacks". That is a regulator's cyber security agency saying the class of bug is structural, not temporary.
What it can and cannot do, task by task
Reliability is a property of the tool plus the task plus whether you supplied the source material. The table below maps common beginner tasks to the named failure mode that applies and the verification step that catches it.
| Task | How reliable | Named failure mode | Verification step |
|---|---|---|---|
| Rewriting or shortening text you paste in | High. The source is in front of it. | Confabulation (NIST AI 600-1) in the form of added detail not present in your text | Read the output against your original and delete any fact you did not supply |
| Explaining a concept you can already partly check | Moderate to high for mainstream topics | NCSC: answers that are "convincing-sounding" but "only partially correct, particularly as the topic gets more niche" | Ask the same question twice in different words; divergence signals the model is filling gaps |
| Recalling specific facts, dates, statistics or citations from memory | Low. This is the weakest use. | Confabulation on open-domain recall | Open the cited source yourself. If the URL does not resolve to the claim, discard the claim, not just the link |
| Summarising a document, PDF or web page you give it | Good, but not zero-error | Unfaithful summarisation; also indirect prompt injection if the file came from a stranger | Spot-check three specific claims against the document; never let it summarise an untrusted file in a session that can also send mail or access other files |
| Drafting code or spreadsheet formulas | Useful draft, unreliable as final | Confabulated functions, libraries or arguments that do not exist | Run it on sample data with a known correct answer before running it on real data |
| Medical, legal, financial or immigration decisions | Not reliable as a decision source | Confabulation plus data privacy risk, which NIST defines as impacts from "leakage and unauthorized use, disclosure, or de-anonymization" of health, location or other sensitive data | Use it only to generate questions to ask a qualified human, never to generate the answer |
| Emotional support or companionship | Actively contested | Under FTC 6(b) inquiry opened September 11, 2025 into how such products "use or share personal information obtained through users' conversations" | Assume the transcript is retained; do not disclose anything you would not put in an email to a company |
Where the primary sources genuinely disagree
Beginners are usually handed a single confident number. In fact credible organisations measuring adoption and error rates get very different results, almost always because they measured different things.
| Question | Source A | Source B | Why they differ |
|---|---|---|---|
| How many people use AI? | Pew Research Center: 49% of U.S. adults have used an AI chatbot. US only, surveyed February 17-23, 2026, n=5,119. | Stanford HAI AI Index 2026, reporting the University of Melbourne and KPMG global survey: 58% of employees used AI on a semiregular or regular basis. 47 countries, fieldwork 2025, n=48,340 employees. | Different populations (all adults vs employees), different geography, and a broader definition of "AI" than "chatbot". Neither is wrong; they answer different questions. |
| How often does a model make things up? | AI Index 2026, HHEM leaderboard: hallucination rates of 1.8% to 5.4% across the top 15 models evaluated in 2026. | AI Index 2026, AA-Omniscience: "Across 26 models, hallucination rates range from 22% to 94%" in 2026. | HHEM measures faithfulness to a source document the model was given; AA-Omniscience measures open-domain recall with no source. Supplying the source text changes the error rate by an order of magnitude. |
| What do the rules require of the tool you are using? | European Union, AI Act: binding law. Four tiers - unacceptable risk (banned), high risk, transparency risk, and minimal or no risk. Entered into force August 1, 2024; generally applicable from August 2, 2026. | United States, NIST AI Risk Management Framework 1.0, published January 26, 2023: explicitly "intended for voluntary use". Four functions - Govern, Map, Measure, Manage - and seven trustworthiness characteristics. | These are different instruments, not competing verdicts. The EU legislated obligations by risk tier; the US published a voluntary framework and enforces case by case through existing consumer protection law. |
One EU rule is directly visible to you as a user. Under the AI Act's transparency rules, which the European Commission states came into effect in August 2026, people "should be made aware that they are interacting with a machine", and providers of generative AI must ensure AI-generated content is identifiable, with deepfakes and AI-written text published to inform the public on matters of public interest labelled clearly and visibly. Other deadlines are still ahead: the Commission lists high-risk use cases in sensitive areas from December 2, 2027, and high-risk systems embedded in regulated products from August 2, 2028.
The NIST framework's seven trustworthiness characteristics are worth reading once even as a non-specialist, because they are a better checklist than most consumer advice: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed.
The checklist to run before you paste anything
These are testable, not aspirational. If you cannot answer one of them, stop before you press enter.
- The front-page test. The NCSC's own standard: would this query cause a problem if it were published? If yes, do not send it. This covers most real mistakes on its own.
- Strip identifiers first. Replace names, addresses, account numbers, dates of birth, employer names and case references with placeholders like [NAME] before pasting. The model almost never needs them to do the task.
- Check the training toggle. OpenAI's Data Controls documentation describes a setting, "Improve the model for everyone", that you can turn off in Settings, and it applies to your entire account. Find the equivalent in whatever tool you use before your first real task, not after.
- Know the retention rule for the mode you are in. OpenAI documents that Temporary Chats "are deleted from our systems after 30 days" and are not used to train models. Deleted is not instant, and rules differ per product.
- Ask whether the task needs recall or comprehension. If the answer requires the model to remember a fact, paste the source in instead. See the HHEM versus AA-Omniscience gap above.
- Never mix untrusted input with capability. If you are asking it to read a document from a stranger, do that in a session that has no access to your email, files or payment tools. This is the direct defence against indirect prompt injection.
- Open every citation. A plausible-looking URL is the easiest thing in the world for a text predictor to generate.
- Check employer and school policy before work data. Personal opt-outs do not make an organisation's data lawful to paste.
Once those are habits rather than decisions, the next step is structure: fixed prompts, fixed checks, and a repeatable process. That is covered in Part 2: Build a reliable AI workflow, and the specific prompt patterns and low-risk automation ideas are in Part 3: Practical prompts and safe automation ideas.
The trade-offs nobody puts in the onboarding screen
Convenience against privacy. The features that make these tools feel magical - memory across sessions, connections to your mail and calendar, file uploads - are exactly the features that widen the data surface and create the conditions for indirect prompt injection. Every capability you connect is a capability an attacker can reach through a poisoned document.
Free against paid. Free tiers often have the weakest retention controls, while paid and business tiers carry contractual commitments consumer tiers do not. Read the specific tier's terms, not the company's general privacy page.
Speed against verification cost. This is the trade-off people get wrong most often. A chatbot can produce an answer in four seconds that takes eleven minutes to check properly. If you will not spend the eleven minutes, you have not saved time, you have transferred risk to whoever reads the output. The asymmetry decides it: the cheaper mistake is over-checking something that turned out to be right. The expensive mistake is publishing, filing or acting on a confabulation. The AI Incident Database recorded 362 incidents in 2025, up from 233 in 2024, as reported in the Stanford HAI AI Index 2026, and the annual count stayed under 100 until 2022.
My own judgement, clearly labelled as such
If I were starting from zero today, here is exactly what I would do and what I would refuse to do. I would pick one tool and stay on it for a month rather than sampling five, because the only way to calibrate is to be wrong with the same system repeatedly and learn its tells. On day one, before any real task, I would turn off training on my conversations and read the retention policy for the specific tier I am on. I would then use it for exactly three categories: rewriting text I wrote, summarising documents I supplied, and generating questions to ask a human expert. I would refuse, without exception, to paste client data, health details, another person's identifying information, or anything covered by a confidentiality agreement, on the NCSC's reasoning that the query is stored and visible to the provider regardless of what I believe about the company. I would refuse to let a chatbot be the last thing that checks my work before it goes out. And I would refuse to connect it to my email for at least the first six months, because the NCSC's assessment that prompt injection may never be properly mitigated is not a warning I am equipped to engineer around as an individual user. The upside of connected agents is real; it is also the part of this field where the safety story is weakest, and beginners should not be the ones absorbing that risk.
The counter-argument deserves a hearing: people who connect everything do get more done, and a blanket refusal costs real productivity. That cost is worth paying while you are still learning what a confident wrong answer looks like.
This article is general information, not legal advice. AI rules differ by jurisdiction and are changing: the obligations described here are those of the European Union under the AI Act, which entered into force on August 1, 2024 and became generally applicable on August 2, 2026, and the voluntary United States framework published by NIST on January 26, 2023. Check the current position for your own country before relying on any of it.
Tip: Verifying AI output means reading a source document next to a chat window for longer than you planned, so the ergonomics of your desk matter more than they sound - a laptop stand and a pair of bluetooth earbuds make long checking sessions considerably less painful. (These are Amazon Associate links - we may earn a small commission on qualifying purchases.)
Sources
- Pew Research Center - Americans and AI 2026: Chatbots, Smart Devices and Views on Impact
- NIST - Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)
- NIST - AI Risk Management Framework
- NIST AI Resource Center - Characteristics of Trustworthy AI Systems
- European Commission - AI Act: Regulatory framework for AI
- UK National Cyber Security Centre - ChatGPT and large language models: what's the risk?
- UK National Cyber Security Centre - Prompt injection is not SQL injection (it may be worse)
- Federal Trade Commission - FTC Launches Inquiry into AI Chatbots Acting as Companions
- Stanford HAI - AI Index Report 2026, Chapter 3: Responsible AI
- Stanford HAI - AI Index Report 2026, Chapter 9: Public Opinion
- OpenAI Help Center - Data Controls FAQ
Comments
Post a Comment