Learn through a use case whose output can be checked
In 2023, generative AI made rapid first drafts, summaries and suggested wording widely visible. Speed does not establish accuracy or suitability. A fluent answer can mix correct information, plausible inference and an invented fact. The first leadership question is therefore where errors can be detected before causing consequences, and whether verification costs less time than the assistance saves.
This retrospective was written in 2026. It separates references available in 2023 from later official guidance cited as current context. All examples and measurements are fictional teaching material, not CYTIZEN engagements. The proposed scope is drafting assistance without automatic action or delegation of individual decisions to a model. This boundary allows teams to observe benefits, errors and checking effort before changing more of the process.
A first trial: draft from an authorised corpus
Imagine a fictional help desk answering questions about non-sensitive internal procedures. Staff use a small set of approved documents. They request a draft, check references and edit before sending. The corpus excludes customer files, employee records and commercial secrets. Test questions are fabricated or anonymised using an approved method. Compare assisted preparation with ordinary preparation on cases of similar complexity.
Choosing the corpus is a business decision. Give each document an owner, validity date and permitted scope. Indexing an obsolete procedure does not make it reliable. Resolve contradictions before testing or treat them as a reason to abstain. If documents specify conflicting deadlines, ask for verification rather than inventing a compromise. Retrieval must preserve access rights: it must not expose a document that the requesting employee cannot otherwise access.
An explicit use agreement
| Element | Completed fictional rule | Owner |
|---|---|---|
| Input | Teaching questions and approved non-sensitive procedures; no personal data or secrets | Business and security |
| Output | Short draft, document references, visible uncertainty, no new commitments | Human reviewer |
| Corpus | 24 valid documents; obsolete versions removed; access restricted | Document owner |
| Forbidden action | Automatic sending or autonomous procedure updates | Tool owner |
| Immediate stop | Secret exposure, accepted nonexistent reference or bypassed access restriction | Trial lead and security |
| Continue | Positive net benefit and critical errors caught before use | Business decision maker |
Technical availability does not confer permission to use every data category. Examine supplier terms covering inputs, retention, access, relevant processing location, subcontractors and deletion. Security and data protection specialists assess the risks within their responsibility. A skilled prompt writer should not become the sole interpreter of contractual conditions.
The prompt defines the task, not truth
A useful prompt identifies the task, authorised documents, output format and behaviour when information is absent. For example, request a draft supported by supplied procedures, document identifiers, no invented deadline and an explicit warning about contradictions. This clarifies expectations but cannot guarantee compliance. Asking a model to answer only when certain does not provide a reliable certainty measure or replace external verification.
Separate governing instructions from retrieved content. Documents or user text can contain malicious or misleading directions. The system should not promote those directions into authority. Early trials should avoid tools able to send messages, modify files or initiate transactions. Still include test documents asking the model to ignore rules. The aim is to observe and limit failure, rather than assume an elegant prompt eliminates this risk.
Check output on three levels
First check facts: do names, figures, deadlines and references exist in the corpus? Then check meaning: does the summary preserve exceptions and conditions? Finally check use: can this text be sent to this recipient without disclosing information or creating a new promise? Grammatically excellent output can fail all three tests. Reviewers need enough subject knowledge to recognise persuasive inaccuracies.
Here, hallucination means unsupported content presented as established. It can be an invented reference or a decisive exception absent from the procedure. Displaying a citation is insufficient: open the source and verify that it supports the claim. A corpus provides context and may reduce errors, but does not guarantee their disappearance. Abstention or escalation is an acceptable output when the documents do not answer the question.
Measure net benefit, not generation speed
Prepare an evaluation set containing ordinary questions, exceptions, contradictory sources and unanswerable requests. Keep some cases separate from prompt improvement. Otherwise, strong results may reflect tuning to familiar examples rather than handling new work. Reviewers use the same criteria: factual correctness, reference quality, confidentiality, preserved conditions and effort required to obtain usable output.
Net time saved equals ordinary preparation time minus assisted request writing, reading, checking and correction. In a fictional example, an ordinary response takes twelve minutes; assisted work needs two minutes for the request, four for verification and three for correction. The net gain is three minutes, not ten. A serious error still counts against quality even when a reviewer fixes it before sending.
The directly usable output rate is drafts requiring no substantive correction divided by evaluated drafts. Critical errors include potentially incorrect action, secret disclosure and unauthorised commitments. Track justified abstention separately; reducing it indiscriminately encourages invented answers. No average quality score compensates for a data leak. Define stop conditions before trials, even if users find the tool appealing.
Organise learning without implied expansion
The business owner controls scope and continuation. The document owner fixes source material. The technical owner records model version, relevant settings and corpus configuration. Reviewers log problematic output without sensitive content. Significant model, instruction or document changes trigger targeted rechecking. A successful trial on general procedures does not authorise personal complaints or regulated advice.
Stop if forbidden information enters the service, access rights are bypassed or checks cease. Correct localised errors where the verification burden can be reduced. Abandon a use case if expert checking consistently takes longer than manual preparation. That result identifies an unsuitable task under current conditions. Learning should lead to a decision rather than a collection of attractive demonstrations.
Consequences determine the boundary
Sales drafts must preserve prices, commitments and exclusions. Industrial summaries are not safety instructions or maintenance authorisations. Healthcare drafting support is not diagnosis, and patient information requires separate assessment. In public administration, accessible wording does not replace applicable rules or individual examination. The consequence of the output determines necessary control.
Train staff to identify an incorrect draft, a misleading reference and an unanswered question, then practise escalation. Prompt training alone overlooks data selection and responsibility for output. Being able to reject a draft matters as much as producing it quickly.
2023 references and later context
Official sources checked in October 2026. Evaluation methods, tables and figures are teaching proposals specific to this article.
- NIST, AI Risk Management Framework 1.0, 26 January 2023: a voluntary framework available in the period examined.
- CNIL, Artificial intelligence action plan, May 2023: contemporary context for data protection questions and support.
- CNIL, Initial guidance on deploying generative AI, 2024: later guidance consulted in 2026, explicitly distinct from the 2023 context.