A practical guide for staying sane, asking better questions, and not letting every shiny AI announcement turn into your organisation’s next avoidable mistake.

Every week, artificial intelligence appears to arrive wearing a different costume.

One week, it is the future of productivity. The next, it is the end of work. Then it is a therapist, a teacher, a personal assistant, a search engine, a project manager, a creative partner, a research analyst, a compliance risk, a boardroom obsession, and a small glowing button that someone has added to software you were already barely managing to use.

It is a lot.

And the strange thing is that the excitement is not entirely invented. This is not one of those technology conversations where nothing real is happening underneath the noise. Something real is happening. AI systems are becoming more capable, more widely available, and more deeply integrated into the tools people use every day. Stanford’s 2025 AI Index reports that 78% of organisations used AI in 2024, up from 55% the year before, while generative AI investment and business adoption continued to accelerate.

So the issue is not that everyone is excited about nothing.

The issue is that excitement is often moving faster than judgement.

If AI were only hype, the sensible response would be to ignore it. If AI were only danger, the sensible response would be to reject it. But AI is neither a miracle nor a monster. It is a powerful set of technologies entering organisations, classrooms, public services, creative work, youth spaces, health-adjacent settings, administrative systems, and daily life at a speed many institutions are still learning how to govern.

This is where the real difficulty begins.

Most organisations are not struggling only with whether AI is impressive. They are struggling with how to use it responsibly. McKinsey’s 2025 global survey captures this tension clearly: nearly nine out of ten respondents said their organisations regularly use AI, but most organisations had not yet embedded it deeply enough into workflows and processes to realise material enterprise-level benefits. The same survey found that 51% of respondents from organisations using AI had seen at least one negative consequence, with inaccuracy the most commonly reported issue.

That is a very useful finding to sit with for a moment.

It reminds us that adoption is not the same as readiness. An organisation can be using AI and still not understand where it fits. A team can run pilots and still lack a risk plan. A project can have a beautiful demo and still be unprepared for real users. A tool can sound helpful and still be unsafe in the wrong context. A platform can include a “human in the loop” and still fail to define who that human is, what authority they have, or what happens when they disagree with the system.

This guide is written for the people standing in that uncomfortable middle space.

Not the prophets who believe everything will be transformed by Tuesday. Not the panic goblins who want to unplug the fridge just in case. Not the productivity wizards who saved six hours with AI and spent nine hours configuring the workflow.

This is for the people trying to remain useful, sane, responsible, and awake while everyone around them is either accelerating, panicking, branding, demoing, or asking whether “we should have an AI strategy” in a tone usually reserved for missing passports at the airport.

The answer is neither to worship AI, nor to fear it. The answer is to ask better questions before the shiny thing becomes an expensive mistake, a safety problem, or another system people are expected to trust without understanding.

Welcome to AI Hype Season

AI Hype Season is not really a season anymore.

It used to be possible to imagine hype as something that arrived in waves. A big launch. A dramatic announcement. A new model. A round of breathless predictions. Then a brief pause in which everyone could drink water, update their passwords, and quietly admit that the demo did not quite work on their actual documents.

Now the season is permanent.

Every week brings a new promise. AI will transform education, replace search, personalise learning, run customer support, detect emotion, manage workflows, summarise meetings, write reports, generate images, produce code, analyse data, advise leaders, design policy, help doctors, support teachers, coach employees, and maybe, if prompted politely, remember where you saved that PDF from March.

Some of this is genuinely useful. Some of it is premature. Some of it is dangerous. Some of it is just a spreadsheet wearing a cape.

The problem is not excitement. Excitement is fine. Curiosity is good. Experimentation is important. Many people are finding real value in AI tools, especially when they use them carefully, narrowly, and with a clear understanding of what the tool is doing and what it is not doing.

The problem begins when excitement becomes governance.

When the fact that something is impressive becomes proof that it is ready. When a beautiful demo replaces a risk plan. When a launch date becomes more important than a safety review. When “AI-powered” becomes a substitute for explaining the actual problem being solved. When “we need to keep up” becomes the entire strategy.

That is when hype stops being harmless noise and starts becoming an organisational risk.

The Three Species of AI Hype

To survive AI Hype Season, it helps to recognise the creatures moving through the landscape.

The first is the Prophet. The Prophet announces that everything will be transformed by Tuesday. Education, work, government, medicine, creativity, logistics, parenting, procurement, agriculture, civic participation, and possibly the emotional life of your houseplants will all be radically reinvented before the next quarterly review.

The Prophet is not always wrong. Sometimes they see genuine patterns early. The problem is that they often confuse direction with inevitability, possibility with readiness, and demonstration with deployment. “Everything is changing” may be true. It is not, by itself, a plan.

The second species is the Panic Goblin. The Panic Goblin believes nothing is safe, everything is already lost, and the only responsible action is to unplug the fridge, move to a cabin, and communicate exclusively through potatoes.

The Panic Goblin is also not always wrong. There are real risks. AI systems can produce misinformation, amplify bias, expose private data, deepen surveillance, create dependency, distort labour markets, and encourage people to trust systems they do not understand. Stanford’s AI Index notes that AI-related incidents are rising sharply and that standardised responsible-AI evaluations remain rare among major industrial model developers.

But panic does not produce good governance either. Fear can identify danger, but it cannot design a responsible workflow. It cannot build a data protection process, test5 outputs, train users or write an escalation protocol. It mostly just runs around the room holding a very small lantern.

The third species is the Productivity Wizard. The Productivity Wizard saved six hours using AI and spent nine hours configuring the workflow. They have a tool for notes, a tool for summaries, a tool for tasks, a tool for prompts, a tool for meetings, a tool for automation, a tool for managing the tools, and a dashboard tracking the emotional journey of the tools.

The Productivity Wizard is often sincere. They may even be helpful. Some workflows really do improve with AI. But there is a point at which productivity culture becomes a second job wearing a very nice interface. If the setup requires three integrations, two paid subscriptions, a permissions review, a training session, a Zapier ritual, and one colleague named Daniel who understands the whole thing but is leaving in August, we may need to pause.

The goal is not to join any of these tribes.

The goal is to remain human enough to ask: what is this actually for, who might it affect, what could go wrong, and who is responsible when it does?

Red Flag 1: They Say “Human in the Loop” but Cannot Tell You Which Human

“Human in the loop” is one of the most comforting phrases in AI governance.

It sounds responsible and balanced. It sounds like somewhere, at the right moment, a wise and properly caffeinated human will step in, review the situation, and prevent the system from doing something foolish.

Unfortunately, in many discussions, “human in the loop” means something closer to: we hope a person appears before anything bad happens.

That is not governance. That is folklore.

Human oversight only means something if it is concrete. Who is the human? What exactly do they review? At what stage do they intervene? Can they override the AI? Are they trained? Are they accountable? Do they have enough time? Do they have the authority to stop the process? What happens if they disagree with the system? What happens if leadership disagrees with the human? What happens if the human is overloaded, absent, underqualified, or treated as decorative?

A human in the loop who cannot stop the system is not oversight. A human in the loop who has no training is not protection. A human in the loop who has three seconds to review an AI decision is not meaningful governance. A human in the loop who is ignored when they raise concerns is not part of the safety system. They are part of the theatre.

This matters especially in education, youth work, mental health, social support, recruitment, public services, and any context involving vulnerable people. In those environments, “there is a human somewhere” is not enough.

The human must be named. The role must be clear. The authority must be real. The escalation route must exist before the crisis.

This is not only a moral preference. It is increasingly part of the regulatory direction. The EU AI Act, for example, treats high-risk AI systems differently from low-risk systems and requires strict safeguards for high-risk uses, including risk-mitigation systems, high-quality datasets, clear information for users, and human oversight.

Not every AI tool will be legally classified as high-risk. But the principle is still useful: the more serious the possible consequences, the less acceptable it becomes to rely on vague assurances. If human oversight is being used to make a system sound safe, then the oversight has to be real enough to carry the weight of that promise.

Otherwise, “human in the loop” becomes a charm we hang around the neck of a system we have not actually made safe.

Red Flag 2: The AI Is “Empathetic” but Has No Duty of Care

Another popular word is “empathetic.”

We hear that AI tools can be supportive, emotionally intelligent, caring, compassionate, therapeutic, or “human-like.”

This is where we need to become very boring very quickly.

A chatbot can produce warm language. That is not the same as care. A chatbot can say, “I’m sorry you’re feeling this way.” That is not the same as understanding distress. A chatbot can mirror emotion. That is not the same as responsibility.

A chatbot can offer calming phrases, reflective questions, or general wellbeing suggestions. Some users may find that helpful in limited contexts. But sounding supportive is not the same as being able to recognise harm, understand vulnerability, manage crisis, protect a young person, assess risk, hold confidentiality, follow safeguarding procedures, or make a professional judgement.

Supportive tone is not support.

This distinction matters because vulnerable users may not experience it as a distinction. A young person in distress, an exhausted parent, a lonely worker, a person in crisis, or someone looking for help may not care whether the system is technically “only informational.” If it sounds caring, they may treat it as care.

That creates responsibility.

UNESCO’s guidance on generative AI in education and research warns that GenAI tools are developing faster than many national regulatory frameworks, leaving data privacy and institutional validation challenges unresolved. It also argues for a human-centred approach that protects ethical, safe, equitable, and meaningful use in education and research.

That matters far beyond schools. It matters wherever AI tools are introduced into environments where people may be learning, seeking support, making decisions, or asking questions from a place of uncertainty.

The question is not, “Can the AI sound caring?”

The question is, “What happens when sounding caring is not enough?”

If an AI tool appears in a support context, it needs clear boundaries. It needs escalation routes. It needs crisis guidance. It needs human oversight that is not imaginary. It needs user-facing explanations that people can actually understand, not legal fog buried in terms and conditions. It needs testing with real users, not only demonstration prompts. It needs a plan for what happens when the AI says the wrong thing at the wrong moment to the wrong person.

Care is not a tone. Care is a responsibility structure.

Red Flag 3: Everyone Is Excited and Nobody Has a Risk Plan

There is a very specific organisational smell that appears around risky innovation.

It smells like enthusiasm, branding, and missing documentation.

The project has a launch plan, a communications plan, a logo. It has a slide deck. It has a demo video. It has a sentence about transformation. It may even have a dramatic name involving words like “next-generation,” “intelligent,” “adaptive,” “agentic,” or “reimagined.”

Then you ask a few simple questions.

Where is the risk plan? Who reviewed data protection? What happens if the tool gives a harmful answer? How can users report a problem? What is the escalation procedure? Who checks for bias? Who tested it with real users? What happens if the tool fails? Who maintains it after the pilot? What would make us pause or stop?

And suddenly the room becomes very interested in the font size on slide 14.

This is a red flag.

Certainly, most project don’t need a 300-page governance document before anyone can test anything. That would also be a problem. Over-bureaucratising innovation can kill useful experimentation.

But if an AI tool is going to interact with people, influence decisions, process data, support learning, shape access, respond to sensitive questions, or operate in a context where harm is possible, then some form of risk planning is not optional. It is basic professional hygiene.

The U.S. National Institute of Standards and Technology describes trustworthy AI in terms of characteristics such as validity and reliability, safety, security and resilience, accountability and transparency, explainability and interpretability, privacy enhancement, and fairness with harmful bias managed. NIST also notes that trustworthiness is tied not only to technical features, but to social and organisational behaviour, datasets, model choices, and the humans who oversee these systems.

That last part is important.

AI risk is not only inside the model. It is also inside the organisation that deploys the model. It is inside the decision to skip testing because the deadline is uncomfortable. It is inside the pressure to launch before safeguards are ready. It is inside the assumption that users will behave exactly like the demo. It is inside the belief that a disclaimer can replace a duty of care.

If the only risk mitigation strategy is “the AI is very advanced,” please step away from the pilot.

Advanced systems can still fail. Beautiful interfaces can still mislead. Powerful models can still hallucinate. Automations can still amplify mistakes. Users can still misunderstand what the tool is for. Organisations can still deploy systems they are not prepared to govern.

A risk plan is not anti-innovation.

A risk plan is what allows innovation to survive contact with reality.

Red Flag 4: The Tool Solves a Problem Nobody Has Properly Named

AI tools often arrive carrying solutions.

This is exciting, except when nobody has clearly named the problem.

The organisation says, “We should use AI for this.”

For what?

“To improve efficiency.”

Which efficiency?

“For users.”

Which users?

“To streamline processes.”

Which processes?

“To enhance engagement.”

What kind of engagement? From whom? Why is engagement low now? Is the problem content, access, trust, timing, language, workload, design, staffing, coordination, unclear instructions, or the fact that the form has seventeen mandatory fields and one of them is “Other, please specify”?

AI can be useful when the problem is understood. It becomes risky when the tool becomes a way to avoid understanding the problem.

Before adopting an AI tool, we need to slow the sentence down. What problem are we solving? Who has this problem? How are they solving it now? What is painful about the current process? What would improve if the tool worked? What could get worse? What happens if the AI is wrong? Who would notice? Who would be harmed?

And then the question many organisations least want to ask:

Would something simpler solve this?

Would a checklist solve it? Would a template solve it? Would a better form solve it? Would an open-source tool solve it? Would better documentation solve it? Would a trained human being with enough time solve it? Would the real solution be to stop doing something unnecessary?

Sometimes AI is genuinely the right tool. Sometimes it is not. Sometimes the problem is not lack of AI. Sometimes the problem is that the organisation has confused complexity with sophistication and now everyone is trying to automate a process that should have been simplified three years ago.

AI should not be used to decorate confusion or to avoid management decisions.

It should absolutely not be used to make a broken process faster at breaking things.

A good AI use case begins with a clear problem, not with a tool looking for somewhere to land.

Red Flag 5: The Demo Is Perfect, but the Real World Is Not

The demo always works.

The Wi-Fi is stable. The user is cooperative. The question is clear. The data is clean. The phone is modern. The language is expected. The room is quiet. The user has slept. Nobody is panicking. Nobody is multitasking. Nobody is confused by the interface. Nobody clicks the wrong thing. Nobody writes the question in a mixture of Portuguese, English, emoji, frustration, and “please help me now.”

Then reality enters the room.

Real users are tired. They are distracted. They use old phones. They have bad Wi-Fi. They skip instructions. They misunderstand buttons. They write in multiple languages. They ask questions the designers did not expect. They use the tool in emotional contexts. They copy answers into places nobody anticipated. They trust things they should question. They ignore warnings that were technically visible but practically invisible.

They are human, which is very inconvenient for demos.

This is why testing matters.

Testing is not failure, embarrassment or a personal attack on the people who built the tool. Testing is where reality enters the room.

A responsible organisation should want to know what breaks before users depend on it. It should want to see confusion early. It should want to hear uncomfortable feedback before a public launch. It should want young people, educators, workers, clients, or community members to say, “This part does not make sense,” while there is still time to change it.

The most dangerous demo is the one that convinces everyone the real world will behave.

It will not.

The real world has cracked screens, overloaded staff, anxious users, language barriers, old devices, unclear contexts, and people doing their best with limited time.

If a tool cannot survive testing, it is not ready for release. If a team cannot survive feedback, it is not ready to govern the tool.

Boring Questions That Save Everyone Later

Now we arrive at the least glamorous part of responsible AI.

The boring questions.

These are not the questions that get applause at conferences or appear in launch videos. They do not sparkle. They do not sound futuristic. But they are the questions that save organisations from avoidable mistakes.

What data does the tool collect? Where is the data stored? Who can access it? Is personal data involved? Are minors or vulnerable users involved? Can users opt out? What does the tool remember? What does it share with third parties?

What happens when it gives a wrong answer? How do users report harm? Is there a human escalation route? Who responds to reports? How quickly?

Who maintains the tool after launch? Who updates the content? Who checks whether the tool is still accurate? Who reviews logs? What are the known limitations? How are those limitations communicated to users?

Has the tool been tested with real users? Has it been tested in different languages? Has it been tested on mobile devices? Has it been tested with unclear, emotional, incomplete, or adversarial prompts?

What does success actually mean? What would count as failure? What would make us pause the tool? What would make us stop using it? Who has the authority to say no?

These questions are not anti-AI. They are pro-responsibility.

They are how we move from enthusiasm to stewardship. They are how we avoid turning users into unpaid beta testers for systems that should have been checked before they reached them. They are how we protect the people who will be affected by the tool, not only the people excited to launch it.

The future may be full of AI.

Fine.

Then the future needs more boring questions, not fewer.

The AI Sanity Checklist

Before adopting, piloting, presenting, funding, launching, or emotionally attaching ourselves to an AI tool, we can use a simple sanity checklist.

1. Purpose. What is the tool for? What is it not for? What problem does it solve? Why is AI needed here?

2. People. Who will use it? Who may be affected by it? Who might be excluded, confused, or harmed? Who is responsible for supporting users?

  1. Data. What data does it collect? Where does that data go? Who can access it? What are the privacy implications?

4. Risk. What could go wrong? How likely is it? How serious would it be? Who would notice? Who would be affected first?

5. Oversight. Who is the human in the loop? What authority do they have? Can they override the system? Can they stop deployment?

6. Escalation. What happens if the tool gives unsafe guidance? What happens if a user reports distress? What happens if personal data is mishandled? What happens if the tool fails?

7. Testing. Has it been tested with real users? Has it been tested across languages, devices, and realistic conditions? Have failures been documented? Have changes been made based on feedback?

8. Accessibility. Can people understand how to use it? Are the instructions clear? Does it work for people with different levels of digital confidence? Does it assume perfect users?

9. Maintenance. Who updates the tool? Who monitors performance? Who reviews risks over time? Who pays for maintenance after the pilot?

10. Exit. How do we stop using it? How do users leave? How do we export or delete data? What happens if the provider changes terms, prices, access, or functionality?

This checklist will not make every AI decision easy.

But it will make vague enthusiasm harder to pass off as readiness.

And that is already progress.

Stay Curious, Stay Boring, Stay Human

AI is not going away. The point is not to pretend it will. The point is also not to surrender every decision to the loudest person in the room with a demo link and a prophecy.

We need a better posture. Curious, but not dazzled. Careful, but not paralysed. Practical, but not obedient to hype. Open to experimentation, but honest about risk. Willing to learn, but unwilling to confuse speed with responsibility.

Because the real choice is not between worship and fear. It is between passive adoption and active judgement.

It is between asking, “How fast can we launch this?” and asking, “What would make this safe enough, useful enough, and accountable enough to deserve people’s trust?”

It is between treating AI as magic and treating it as infrastructure.

And infrastructure needs governance. It needs maintenance. It needs limits. It needs people who are willing to ask boring questions before the exciting mistake becomes expensive, harmful, or impossible to undo.

So no, we do not need to become prophets. We do not need to become doomsday goblins. We do not need to pretend every tool is revolutionary, every risk is apocalyptic, or every workflow needs a chatbot sitting in the corner wearing a tiny productivity hat.

We can do something better.

We can stay curious.

We can stay boring.

We can stay human.

And we can remember that sometimes the most responsible sentence in the room is not “AI will change everything.”

It is:

Before we launch this, can someone show me the risk plan?