Teaching tool

Two rules for using AI at work.

Most people don't need a 40-page AI policy to use ChatGPT, Claude, or Copilot responsibly — they need two rules they can actually remember. Keep sensitive information out, and own everything that comes back. Everything else is detail. Use this to teach a team in ten minutes, or run present mode to put each rule on the screen.

01 — The two rules

If you remember nothing else, remember these.

They map to the only two ways an AI tool gets a professional into trouble: something sensitive goes in, or something wrong comes out and you ship it with your name on it. Guard both ends and you've handled the vast majority of the real risk.

Rule 01 · The input

Don't put in anything sensitive.

Treat the prompt box like a public space. No personal data, no credentials, no confidential business information. If you'd hesitate to post it publicly, don't paste it.

Rule 02 · The output

You own everything it gives back.

The model is a fast, confident assistant — not a source of truth. Whatever you ship is yours, not the tool's. So review the hell out of it before your name goes on it.

Read the detail
02 — Rule one

Keep sensitive information out.

What you type into a public AI tool can be stored on someone else's servers, retained, reviewed by humans for quality, used to improve future models, or exposed in a breach. You lose control of it the moment you hit enter — so the safe move is simple: don't put sensitive things in there in the first place.

A

What counts as "sensitive"

Three buckets cover almost everything. When in doubt, assume it belongs in one of them.

Personal data (PII)

Anything that identifies a real person: names tied to details, emails, phone numbers, home addresses, dates of birth, national / tax / ID numbers, health information, and financial account details — about customers, employees, or yourself.

Credentials & secrets

Passwords, API keys, access tokens, private keys, security questions, one-time codes, and internal connection strings or config. Pasting these doesn't just risk a leak — it can hand someone the keys.

Confidential business information

Unreleased financials, M&A plans, legal matters, trade secrets, proprietary source code, client deliverables under NDA, and anything marked internal or restricted.

The mental model: would I write this on a postcard? A postcard can be read by anyone who handles it on the way to its destination. If a sentence would make you uncomfortable on a postcard, it doesn't go in the prompt.

B

How to use AI without the data

You rarely need the real, specific details to get a useful answer. Redact before you prompt: swap the sensitive specifics for placeholders or dummy values, get your draft, then put the real details back in yourself, offline.

Don't paste this Draft a payment-overdue email to Maria Chen at Acme Corp, account #4471-9920, $48,500 outstanding since March. Her number is +1 415 555 0132.
Paste this instead Draft a payment-overdue email to [CLIENT NAME] at [COMPANY], account [ACCOUNT #], [AMOUNT] outstanding since [MONTH]. Firm but professional tone.
Do
  • Use placeholders and dummy data, then fill in the specifics yourself.
  • For real, sensitive data, use only tools your organisation has approved with a data agreement (e.g. an enterprise plan that excludes your data from training).
  • Ask for the structure, template, or approach rather than handing over the raw record.
  • Check your company's AI policy — it tells you which tools are cleared for what.
Don't
  • Paste customer lists, spreadsheets, or exports "just to summarise them."
  • Drop in a contract, medical note, or HR file to "tidy it up."
  • Share API keys, passwords, or tokens — even to debug a quick error.
  • Assume a free consumer chatbot keeps anything you type private.
03 — Rule two

You own the output.

An AI tool produces text that sounds authoritative whether or not it's correct. It can invent facts, fabricate quotes and citations, get numbers wrong, miss your context, and reflect bias — all in fluent, confident prose. The moment you use what it gives you, that work becomes yours. The accountability never transfers to the tool.

A

"The AI said so" is not a defence

Not to a client, a regulator, a court, an auditor, or your boss. If it goes out under your name or your company's, you are answerable for every word — the brilliant lines and the confidently wrong ones alike. Think of the model as a sharp but unreliable intern: useful for a first pass, never to be trusted unchecked on anything that matters.

Match the scrutiny to the stakes. A throwaway brainstorm needs a glance. A client deliverable, a published number, a legal or medical claim, or anything irreversible needs you to verify it line by line against a source you trust.

B

Review the hell out of it

Reviewing AI output isn't a quick proofread. You're checking whether it's true, whether it fits your situation, and whether you could defend it yourself if challenged.

Do
  • Verify every fact, name, number, quote, and citation against a real source.
  • Treat citations and statistics as guilty until proven real — models invent them.
  • Read for your specific context, not just general correctness.
  • Rewrite enough that you genuinely understand and stand behind it.
  • Use it to draft, structure, and pressure-test your thinking — its real strengths.
Don't
  • Copy-paste straight into a doc, email, or codebase and send it.
  • Trust a confident tone as evidence the content is right.
  • Rely on it for current events or facts past its training cut-off.
  • Let it make a decision you're the one accountable for.
  • Ship anything you couldn't explain or defend in your own words.
04 — Before you hit enter

The five-second gut check.

Two questions, one for each rule. Ask them every time and the rules become a habit instead of a poster on the wall.

Rule 01 — the input

"Is there anything in here I wouldn't want made public?"

If yes — a name, an account, a secret, something confidential — take it out, swap in a placeholder, or move to an approved tool before you send.

Rule 02 — the output

"Can I stand behind whatever comes back?"

If your name is going on it, plan to check it properly — facts, numbers, fit — and don't ship anything you couldn't defend yourself.

Facilitate · 01

Run present mode and put one rule on the screen at a time. Let the room react before you explain it.

Facilitate · 02

Ask the group for a real example of each — a time something sensitive almost went in, or wrong output almost went out.

Facilitate · 03

Close by having everyone commit the two gut-check questions to memory. That's the whole policy, made portable.

05 — Go deeper

Two rules get you safe. A culture keeps you there.

Rules on a slide change behaviour for about a week. Making safe, confident AI use stick — across a team that's nervous, sceptical, or over-eager — takes hands-on training, the right approved tools, and a policy people actually understand. That's what our facilitated AI sessions are built to do.

Talk to us about AI training