Most people don't need a 40-page AI policy to use ChatGPT, Claude, or Copilot responsibly — they need two rules they can actually remember. Keep sensitive information out, and own everything that comes back. Everything else is detail. Use this to teach a team in ten minutes, or run present mode to put each rule on the screen.
They map to the only two ways an AI tool gets a professional into trouble: something sensitive goes in, or something wrong comes out and you ship it with your name on it. Guard both ends and you've handled the vast majority of the real risk.
Treat the prompt box like a public space. No personal data, no credentials, no confidential business information. If you'd hesitate to post it publicly, don't paste it.
The model is a fast, confident assistant — not a source of truth. Whatever you ship is yours, not the tool's. So review the hell out of it before your name goes on it.
What you type into a public AI tool can be stored on someone else's servers, retained, reviewed by humans for quality, used to improve future models, or exposed in a breach. You lose control of it the moment you hit enter — so the safe move is simple: don't put sensitive things in there in the first place.
Three buckets cover almost everything. When in doubt, assume it belongs in one of them.
Anything that identifies a real person: names tied to details, emails, phone numbers, home addresses, dates of birth, national / tax / ID numbers, health information, and financial account details — about customers, employees, or yourself.
Passwords, API keys, access tokens, private keys, security questions, one-time codes, and internal connection strings or config. Pasting these doesn't just risk a leak — it can hand someone the keys.
Unreleased financials, M&A plans, legal matters, trade secrets, proprietary source code, client deliverables under NDA, and anything marked internal or restricted.
The mental model: would I write this on a postcard? A postcard can be read by anyone who handles it on the way to its destination. If a sentence would make you uncomfortable on a postcard, it doesn't go in the prompt.
You rarely need the real, specific details to get a useful answer. Redact before you prompt: swap the sensitive specifics for placeholders or dummy values, get your draft, then put the real details back in yourself, offline.
An AI tool produces text that sounds authoritative whether or not it's correct. It can invent facts, fabricate quotes and citations, get numbers wrong, miss your context, and reflect bias — all in fluent, confident prose. The moment you use what it gives you, that work becomes yours. The accountability never transfers to the tool.
Not to a client, a regulator, a court, an auditor, or your boss. If it goes out under your name or your company's, you are answerable for every word — the brilliant lines and the confidently wrong ones alike. Think of the model as a sharp but unreliable intern: useful for a first pass, never to be trusted unchecked on anything that matters.
Match the scrutiny to the stakes. A throwaway brainstorm needs a glance. A client deliverable, a published number, a legal or medical claim, or anything irreversible needs you to verify it line by line against a source you trust.
Reviewing AI output isn't a quick proofread. You're checking whether it's true, whether it fits your situation, and whether you could defend it yourself if challenged.
Two questions, one for each rule. Ask them every time and the rules become a habit instead of a poster on the wall.
"Is there anything in here I wouldn't want made public?"
If yes — a name, an account, a secret, something confidential — take it out, swap in a placeholder, or move to an approved tool before you send.
"Can I stand behind whatever comes back?"
If your name is going on it, plan to check it properly — facts, numbers, fit — and don't ship anything you couldn't defend yourself.
Run present mode and put one rule on the screen at a time. Let the room react before you explain it.
Ask the group for a real example of each — a time something sensitive almost went in, or wrong output almost went out.
Close by having everyone commit the two gut-check questions to memory. That's the whole policy, made portable.
Rules on a slide change behaviour for about a week. Making safe, confident AI use stick — across a team that's nervous, sceptical, or over-eager — takes hands-on training, the right approved tools, and a policy people actually understand. That's what our facilitated AI sessions are built to do.
Talk to us about AI training