What You’ll Learn


Useful Does Not Automatically Mean Safe

AI can help you explain, organize, brainstorm, summarize, and draft. But every prompt begins with a decision: what information are you willing and authorized to share with that service?

When you type text, upload a file, add an image, or connect another service, the AI may be able to process that information. How it is stored, retained, reviewed, or used depends on the provider, the product, your account type, and your settings.

The safest default

If you are not authorized to share information with an external service, do not enter it into an AI tool.


Start With the Information, Not the Tool

Before opening an AI assistant, place the information into one of three practical categories.

1. Public information

Information already intended for anyone to see, such as a public webpage, published report, or fictional example. This is usually the lowest-risk material to use.

2. Personal or identifying information

Names, addresses, photographs, account numbers, health details, financial information, employment records, private messages, or anything that could identify a person. Remove or replace these details before using AI whenever possible.

3. Confidential or protected information

Non-public workplace material, client information, legal documents, internal investigations, passwords, security details, or regulated records. Do not use this material unless the organization has explicitly approved both the tool and the specific use.

Calling something “anonymous” is not enough if the remaining details could still reveal who or what it is about. Dates, job titles, locations, unusual events, and combinations of facts can identify someone even after their name is removed.


Choose a Tool Based on Risk

A useful tool choice depends on the task and the consequences—not on the brand name.

GENERAL IDEAS Use: a general AI assistant for brainstorming that requires no private context.
PUBLIC DOCUMENT Use: AI to simplify the wording, then return to the original source because it remains authoritative.
INTERNAL WORK Use: only an organization-approved tool and permitted account. Routine workplace information can still be confidential.
HIGH-STAKES DECISION Use: a qualified person or responsible organization for medical, legal, financial, employment, or eligibility decisions. AI should not be the final authority.

Free and workplace versions may differ

A provider may offer different privacy, retention, administrative, and training controls across free, paid, education, and enterprise accounts. Never assume that one version's protections apply to another. Check the version you are actually using.

Before using AI, pause to check four things: the information, the approved tool, the possible consequence of an error, and the person responsible for review.

What to Check Before Using an AI Tool

A privacy setting is not permission

Turning off training or using a temporary conversation may reduce some exposure, but it does not make an unapproved use acceptable. An approved tool is not automatically approved for every kind of information. Workplace policy, consent, legal duties, and professional obligations still apply.


Responsible Use Goes Beyond Privacy

Protecting information is essential, but responsible use also means taking responsibility for what the AI produces.


Try It: Remove, Replace, Then Ask

PRACTICE EXERCISE

Start with this fictional note:

Jordan Lee, client number 48291, missed an appointment on September 8 and asked for help understanding the new online booking instructions.

Before using AI:

  1. Remove the name, client number, and exact appointment date.
  2. Replace them with neutral descriptions such as [CLIENT] and [DATE].
  3. Keep only the information needed for the task.
  4. Ask the AI to explain the fictional booking instructions without inventing missing details.
  5. Compare the answer with the official instructions.

The sanitized version might say:

A client missed an appointment and needs a plain-language explanation of these fictional online booking instructions. Do not invent missing details. List anything that should be checked with the service provider.

The goal is not to hide sensitive details after sharing them. The goal is to avoid sharing details the task never needed.


Quick Knowledge Check

1. Does turning off model training make every use acceptable?

Answer

No. Approval, purpose, consent and other obligations still apply.

2. What is the safest information for practice?

Answer

Fictional, public or properly sanitized information.

3. Who remains accountable for an AI-assisted decision?

Answer

The responsible person or organization—not the AI system.


The Five-Question Privacy Pause

  1. Am I allowed to use this tool for this task?
  2. Can I remove names, identifiers, or confidential details?
  3. What could happen if this information or answer were exposed?
  4. How will I verify the result?
  5. Who remains responsible for the final action or decision?

Remember this

Use the least sensitive information, in an appropriate tool, for a clearly defined purpose—and keep human judgment involved.

PATH COMPLETE

You finished AI Fundamentals

You now have a practical foundation for prompting, verification, privacy and responsible human oversight.

Review the AI Fundamentals path →