Insight / signal

The next AI risk is the context you connect

AI gets useful when it knows the context.

AI gets useful when it knows the context.

That is also when it starts becoming risky.

OpenAI has rolled Health into ChatGPT for US users. People can connect Apple Health and supported medical records, then let ChatGPT use that information to compare lab results, spot changes since an appointment, consider medications, look at sleep and activity, and help prepare questions for a doctor.

There are sensible controls in the announcement. OpenAI says connected health data is not used to train foundation models or target ads. ChatGPT asks by default before using health information. Users can approve once or grant ongoing access. There are notes about encryption, deletion after disconnecting, memory controls, confirmation before sensitive sharing, physician-built evals and the usual warning that ChatGPT can still make mistakes and does not replace a qualified medical professional.

Fine. Good. Necessary.

But the interesting part is not really healthcare. That is just the loudest version because the stakes are obvious.

The real story is this: AI is moving from generic answers to permissioned context.

A generic chatbot can tell you what a blood marker might mean. A context-rich assistant can look at your previous results, medications, recent activity, allergies, appointments and goals, then answer as if it understands your situation.

That is much more useful.

It is also much easier to trust too much.

The same thing is about to happen in business. Replace health records with CRM notes, campaign results, pricing history, support tickets, sales calls, meeting transcripts, customer complaints, legal docs, project plans and financial dashboards.

Everyone says they want an AI that understands the business. That sounds obvious until you ask the awkward questions.

Which records can it see? Which ones are stale? Can it use old client notes in a new proposal? Can it mention margin in a sales email? Can it summarise a support complaint into a public case study? Can it remember something from a private leadership chat and use it three weeks later in a client-facing answer? Can it send anything anywhere? And when it gets the answer wrong because the source data was messy, who owns that?

This is where most AI projects get too casual.

Teams talk about prompts and models because those are visible. They argue about whether one model is smarter than another. They run demos. They ask it to write a campaign plan, summarise a call, draft a blog post, build a report.

Useful enough. But not the hard part.

The hard part starts when the AI is connected to the business brain.

OpenAI’s Health rollout exposes the pattern neatly. The valuable thing is not just the model. It is the connected record layer, the permission prompt, the memory boundary, the data freshness warning, the action confirmation and the professional escalation line.

In plain English: what can the assistant see, when can it use it, what does it remember, what can it share, and when must it hand back to a human?

That is not a prompt-engineering problem. It is an operating-system problem.

Anthropic’s Economic Index connector points in the same direction from a different angle. Claude can now answer questions using Anthropic’s own Economic Index data, and Anthropic says the answers should point back to the source data and its limitations. That last bit matters. A grounded answer is only useful if you can see what it is grounded in.

Otherwise you are just getting a more confident guess with a spreadsheet smell.

The same lesson came through in this week’s Marketing School capture. The hosts were comparing models on real marketing jobs. The useful takeaway was not that one model is permanently better. It was that the test unit should be the actual job: completion, elapsed time, intervention load, accepted output and cost. A model that needs three hours of babysitting may be clever, but it is not the best worker for that job.

Context needs the same kind of test.

Do not ask, “Can the AI use our CRM?”

Ask: did it use the right record? Did it ignore stale fields? Did it cite or expose the source where needed? Did it ask before using sensitive information? Did it avoid carrying private context into the wrong conversation? Did it escalate when the decision was too risky? Did a human accept the output? Could we roll back the action if it went wrong?

Less glamorous. Much more useful.

This is why I keep coming back to the idea that AI deployment is the product. The thing clients should pay for is not “we use the newest model.” The thing worth paying for is the controlled layer around the model.

Source mapping. Permission rules. Freshness checks. Context boundaries. Memory policy. Tool gates. Logs. Evaluation. Escalation. Rollback. Named ownership.

You can make that sound boring if you want. I would rather have boring than a sales assistant casually using last year’s pricing, a support bot leaking internal notes, or a campaign agent turning one angry customer ticket into a fake market insight.

The next wave of business AI will not fail because the models cannot write fluent sentences. They can. Painfully fluent, sometimes.

It will fail because the system around the model does not know which context is allowed, current, safe or decision-grade.

That is the piece business owners need to get their heads around now.

If you connect AI to your company knowledge, you are not just giving it better inputs. You are creating a context layer that can influence decisions.

So treat it like infrastructure.

Start narrow. Connect one workflow, not the whole company. Use a known source set. Label sensitive fields. Decide what the AI can see, what it can quote, what it can remember and what it can never send. Test it on real jobs. Count the interventions. Keep a human on the decisions that matter.

Then widen it when the receipts are clean.

The future is not just better prompts. It is not even just better models.

It is better context, with better controls.

And if that sounds less exciting than “AI will run your business,” good. That line is usually where the bodies start piling up.


Pull quotes

  • AI gets useful when it knows the context. That is also when it starts becoming risky.
  • A generic chatbot is annoying when it is wrong. A context-rich assistant can be expensive.
  • Everyone wants an AI that understands the business. Fewer people have thought through what the AI is allowed to remember, use or share.
  • The next AI failure will not come from a bad prompt. It will come from a good answer based on stale, sensitive or wrongly-permissioned context.
  • If you connect AI to your company knowledge, you are not just giving it better inputs. You are creating a context layer that can influence decisions.

Short LinkedIn / X version

AI gets useful when it knows the context.

That is also when it starts becoming risky.

OpenAI rolling Health into ChatGPT is the obvious example: medical records, Apple Health, lab results, medication history, sleep, activity, appointment notes.

But this is not just a health story.

The same pattern is coming to business AI.

Your assistant will want access to CRM notes, support tickets, campaign data, pricing history, call transcripts and internal docs.

That context makes the system useful.

It also raises the real questions: what can it see, what is stale, what can it remember, what can it share, when does it need approval, and who owns the decision when the answer changes what happens next.

This is why I do not buy the “just add AI” pitch.

The valuable work is the operating layer around the model: permissions, source freshness, memory boundaries, action gates, logs, evals and human judgement.

A generic chatbot is annoying when it is wrong.

A context-rich assistant can be expensive.

Notes and caveats

  • OpenAI’s Health rollout is currently for logged-in US users aged 18+ on web and iOS. Do not imply UK availability unless separately verified.
  • OpenAI says connected health data and conversations using it are not used to train foundation models or target ads. This piece reports that as OpenAI’s claim, not as independently audited proof.
  • A lawsuit reported by TechCrunch and SiliconANGLE sought to block the launch. Treat the allegations as allegations unless court filings are used directly.
  • This piece avoids offering medical advice. Health in ChatGPT is used here as a context/governance example, not a judgement on whether people should use it.
  • The Marketing School model comparison is a small host-run operator test, not a universal benchmark. Used only to support the evaluation-design point.
  • The Anthropic Economic Index reflects Claude usage patterns, not the whole labour market. That limitation is part of the point.
  • This piece overlaps with recent themes: AI deployment as the product, maintenance loops, object-scoped agents. The fresh angle here is context itself as the thing that needs permissions, freshness and ownership, not just the model or the agent wrapper around it.