
Is AI Your Newest Coworker? Onboard it Like One.
Practical, No-Panic Advice for Using AI Safely at Work
Guest Blog by Conan Sandberg, Sr. Director of Cybersecurity at Platform Science
Summary: AI tools are increasingly part of daily tasks and work, even in the commercial trucking industry. By proactively managing the use of AI within your fleet from the start, you can properly “onboard” your AI “coworker” for optimal safety, security, and efficiency.
Think about the last new hire at your company. They got a laptop, a badge, an account with the right access at the right times , a walkthrough of the rules, and someone to check in on them for the first few weeks.
Now think about the AI tools your team started using this year. Chances are nobody got that treatment. One person signed up for a chatbot with their work email. Someone else connected an AI assistant to their inbox. A developer plugged an AI coding tool into the repo. A manager pasted a customer contract into a free tool to “just summarize it real quick.”
None of those people were being reckless. They were trying to do their jobs faster, which is exactly what AI is good at. But AI is now the fastest-growing coworker in almost every company, and most of us skipped its onboarding.
The three AI risks that actually keep me up at night (as a cybersecurity professional).
There is a lot of noise about AI. Here is what I see matters most in practice.
1. Data walking out the door, one paste at a time.
When someone drops customer data, source code, pricing, or an employee's personal information into an unapproved AI tool, that data may be stored, logged, or used to train a model you don't control. It is rarely malicious. It is almost always convenient.
2. AI helping the other side.
Attackers use AI too. Phishing emails used to be easy to spot: bad grammar, odd greetings. Now they are polished, personalized, and written in perfect English, Spanish, or anything else. Voice cloning means the “CFO” calling you on the phone and asking for an urgent wire transfer might not be the CFO. Deepfake video calls have already cost companies real money.
3. AI agents with too many keys.
The newest wave of AI doesn’t just answer questions. It takes actions: sends emails, updates tickets, moves files, writes and runs code. That is powerful. It also means an agent with broad access — or one tricked by a malicious instruction hidden in a document or web page known as “prompt injection” — can do real damage quickly.
How to Onboard Your AI ‘Coworker’
The good news: you don't need a brand-new security program to onboard your AI “coworker.” You just need to apply the habits you already use for people.
1. Give it an approved “desk.”
Pick a short list of sanctioned AI tools with business or enterprise terms: data not used for training, retention you can control, single sign-on, etc. Then tell people what these options are. Banning AI outright rarely works; people just use it on their phones. Giving them a good, safe option works much better.
2. Write the one-page rulebook.
Skip the 40-page policy nobody reads. A single page covers it: what tools are approved, what data never goes in (customer personally identifiable information (PII), credentials, secrets, regulated data), and whom to ask when unsure. Put it where people actually look.
3. Least privilege, again.
When you connect AI to email, files, or code, give it the narrowest access needed to do the job. Choose read-only before read-write. One mailbox before all mailboxes. Require a human to approve anything that sends, deletes, pays, or publishes.
Add a "call-back" rule for money and access. Verify any request to move money, change bank details, reset MFA, or grant access through a second, known channel. A phone number from your directory, not the one in the email. This one habit defeats a huge share of AI-powered fraud.
4. Update your phishing training.
Retire the "look for typos" advice. Teach people to watch for urgency, secrecy, and unusual requests, regardless of the grammar. Run a drill that includes a voice message.
5. Keep humans on the hook for output.
AI makes mistakes confidently. The code it writes still needs review and security scanning. Summaries still need a sanity check before they go to a customer. “The AI said so” is not an acceptable root cause.
6. Ask your vendors about AI, too.
Many software providers are quietly adding AI features. Ask which features use your data, where they process it, and whether you can opt out.
Curiosity Beats Fear
The companies that will get hurt by AI are not the ones that use it. They are the ones that use it invisibly, with no guardrails and no conversation. So have the conversation. Ask your teams which AI tools they love and why. You'll learn where the real productivity is, and you'll find the risky workarounds before an attacker does.
Treat AI like the talented, slightly overeager new hire it is: welcome it, set expectations, and check its work.
Your AI Onboarding Checklist
- Publish a short list of approved AI tools.
- Share a one-page “what never goes into AI” guide.
- Require call-back verification for payment and access changes.
- Review what your AI integrations can access, and trim it.
- Refresh phishing training to include AI-written and voice-based scams.
Related Reading: AI in Commercial Trucking
The Platform Science Approach to Cybersecurity
Cybersecurity and AI use in trucking are increasingly on the minds of drivers and carriers. As a premier technology provider to the trucking industry, Platform Science prioritizes transparency in our cybersecurity protocols and enterprise-grade infrastructure.
That is why we offer the Platform Science Trust Portal, a centralized resource where customers can perform their own due diligence. It provides a clear window into our security controls, privacy practices, and our unwavering commitment to compliance. We back this up with industry-leading certifications, including SOC 2 Type II and ISO 27001, proving that our security program meets the highest global standards.
At Platform Science, security is never an add-on. We build protection directly into our hardened infrastructure, featuring end-to-end encryption for data at rest and in transit, and 24/7 incident monitoring to catch threats before they become problems.
Visit the Platform Science Trust Portal today to learn more, or contact us to schedule a demo of our telematics and fleet management solutions.



