What to be careful about
In one line: four things actually go wrong. None of them is the robot uprising, and all four are manageable once you know they are there.
1. It makes things up, fluently
The failure people know by name — hallucination — and the thing to understand is that it does not feel different from the inside. It is guessing the next plausible thing, and an invented citation is exactly as plausible as a real one.
Where it bites hardest: names, dates, numbers, quotations, references, case law, prices, versions, anything with a URL. Precise-looking facts are the most dangerous, because the precision reads as confidence.
What to do. Ask yourself: would I notice if this were wrong? If no, check it. If it gave you a link, open the link. If it cited something, look it up. Use a tool that searches when the answer could have changed since it was trained.
2. Your text goes to somebody else's computer
Unless you are running a model locally, everything you paste is sent to a company, over the internet, and usually kept for some period.
What that means in practice: do not paste client material, medical or financial details, credentials, or anything under an NDA into a hosted model without knowing that vendor's terms. Business tiers usually promise not to train on your data; free tiers often do not.
This is what "local first" is for. AIOS keeps your notes on this machine and shows LOCAL in the top bar until you turn sync on. Your Private notes never leave, even then, and no setting can change that.
3. It agrees with you too easily
Push back on a correct answer and it will often fold. Ask a leading question and it will often go along. It is trained to be helpful, and agreeing feels helpful.
What to do. Ask for the case against. "What is wrong with this plan?" gets you further than "is this a good plan?". If it changes its answer the moment you frown at it, that tells you it was not confident to begin with.
4. Cost creeps
You pay per unit of text in and out. It is small each time and it adds up — especially with large models, long documents, and tools that quietly re-send the whole conversation on every message.
What to do. Use the small model for small jobs. Do not paste an entire document when a section will do. Watch the first month's bill.
AIOS shows you exactly what it would send before it sends it, and handles most of what you type without calling a model at all.
The one that is not on this list
It is not going to develop intentions. It has no goals, wants nothing, and stops existing between your messages. The realistic risks are the four above — being confidently wrong, sending data somewhere, being agreed with, and the bill.
Try this
Ask AIOS something in your own field, deliberately including one small false premise. See whether it corrects you or goes along with it. That tells you more about how to work with these tools than any amount of reading.
If you want to go further
---
Next: Running AI on your own machine · All lessons