[ Use AI Securely ]

[ Chapter 5 · Practical guidelines for safe AI use ]

The golden rules

3 min read

Everything in this course compresses into six rules. They are deliberately few, because rules people remember beat policies people file away. In places they are stricter than the letter of the law; that is intentional. They target the failure patterns behind the incidents you met in Chapter 4.

  1. Use the tools your organisation approved, with your work account. The interface may look identical to the free version; the data protections are not.
  2. Apply the paste test. Would you email this content to an outside company without a contract? If not, strip it or stop.
  3. Verify AI-supplied facts before they travel. Any number, name, date, citation, or legal/medical claim the model produced from its own memory gets checked against an independent source before it reaches a decision, a customer, or a document with your name on it.
  4. Match review to stakes. Low-stakes drafting needs a skim; anything customer-facing, contractual, financial, or about people needs a real review. Judge by the cost of an unnoticed error, not by how confident the output sounds.
  5. Keep humans in charge of decisions about people. AI may inform hiring, evaluation, or customer outcomes; do not let it decide them alone. This course rule is deliberately stricter than the law in places; it is what keeps decisions defensible.
  6. Be transparent when it matters. Do not present AI output as purely your own work where authorship matters, and make sure people know when they are interacting with a machine.

The next three lessons turn the rules into technique: how to prompt without leaking, how to verify efficiently, and what transparency looks like in practice.