The short answer
AI assistants help most with questions that have a general answer: what a term means, how a technology works, what the usual options are, how to word a policy. They fail most with questions whose answer depends on things they cannot see: your configuration, your licence tier, your vendor's current interface, your compliance obligations and what else will break if you change one setting. A good rule is simple: use AI to understand, use a professional to decide and change. The closer a question gets to live systems, security or personal data, the more a human check is worth.
Where AI genuinely helps
These are the tasks where we would happily tell a client to start with an AI assistant:
- Learning the vocabulary. Explaining conditional access, VLANs, RPO versus RTO, or what an ERP "document type" is.
- Comparing approaches in general terms. Cloud versus on-premise backup, per-user versus per-device licensing, fully managed versus co-managed IT.
- Drafting documents for review. Acceptable-use policies, onboarding checklists, a project brief, an email to staff about a system change.
- Reading and summarising. Turning a long vendor article into the three points you need to discuss.
- Preparing questions before a meeting with a vendor, auditor or IT provider.
- Simple, personal, reversible tasks. A spreadsheet formula, a mail rule on your own inbox, a keyboard shortcut.
In each case, a wrong answer is cheap to spot and cheap to undo.
Where it predictably fails
The failures are not random. They cluster in a few places:
| Failure mode | What it looks like | Why it happens |
|---|---|---|
| Out-of-date instructions | Menus and settings that moved or were renamed | Vendors change interfaces often; training data lags |
| Generic advice | Steps that assume a licence or edition you do not have | It does not know your environment |
| Confident but wrong commands | A script that runs, but against the wrong scope | It cannot see the output or your tenant |
| Missing side effects | A "fix" that disables logging, backups or a security control | It optimises for the symptom you described |
| Invented detail | A setting, parameter or policy name that does not exist | Plausible text is not the same as verified fact |
| No local context | Advice written for another country's data protection law, or that assumes stable power and fast links | General training, not your obligations or your infrastructure |
The NIST AI Risk Management Framework lists validity and reliability among the characteristics of trustworthy AI systems, which is a polite way of saying that outputs must be checked rather than assumed (NIST). Verify anything important against the vendor's own documentation before you act on it.
How to ask better questions
If you are going to use an assistant, you can make its answers much more useful and much safer:
- Give context without secrets. Say "Microsoft 365 Business Premium, about 40 users, hybrid workers" rather than pasting your tenant configuration.
- Ask for options and trade-offs, not a single command. "What are three ways to do this, and what could each break?"
- Ask what it does not know. "What would you need to confirm about my setup before recommending this?" The answer is often the most valuable part.
- Ask for the official source, then read the vendor's own documentation before acting.
- Remove personal data. Under the Nigeria Data Protection Act 2023 (NDPA), pasting customer or staff details into a public AI tool is a disclosure of personal data to a third party, often outside Nigeria. Use anonymised or de-identified information in prompts wherever possible (NDPC).
- Never paste credentials, API keys, licence keys or full log files containing user data.
A traffic-light guide
Green: fine to rely on AI, with a quick sense check
- Explaining a concept or term
- Drafting text a person will review
- Personal productivity tasks you can undo
Amber: use AI to prepare, then confirm with the vendor's documentation or an IT professional
- Choosing between products or licence plans
- Planning a change to a shared system
- Interpreting an error message on a business system
Red: do not act on AI output alone
- Changes to firewalls, identity, email authentication or security policies
- Anything touching backups, retention or deletion
- Scripts that run across all users, mailboxes or records
- Decisions about data protection, breach reporting or regulatory obligations
Rather talk it through? If you have an AI answer that falls in the amber or red zone, we can check it against your actual systems before anyone runs it. Talk to a Promatics specialist
What usually goes wrong in practice
The most common problem is not that the AI was badly wrong. It is that a reasonable answer was applied by someone who could not tell when it did not fit. A few patterns we see:
- The fix works, the side effect is invisible. Turning off a protection to stop a nuisance prompt, for example, solves the complaint and quietly weakens security.
- Half-applied changes. Step four fails, nobody knows how to roll back steps one to three, and the system is left in a state no document describes.
- No record. Six months later, nobody knows why a setting was changed or by whom, which slows down every future fix.
- A change made during a power cut or on a poor link. A long script interrupted halfway by an outage can leave a system in an inconsistent state. Plan risky changes for when power and connectivity are stable, and have a rollback ready.
When to bring in help
AI plus common sense is enough for learning and low-risk, reversible tasks. Bring in a professional when the change affects more than one person, involves security or personal data, cannot easily be undone, or when you need someone to plan across systems rather than answer one question at a time.
That planning role is what IT consulting is for: someone who knows your environment, weighs the trade-offs with you, and is accountable for the recommendation.
Sources and further reading
Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.
- AI Risk Management Framework, National Institute of Standards and Technology
- Nigeria Data Protection Commission (NDPA and GAID 2025), Nigeria Data Protection Commission
This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.