Course resource

AI Safety Checklist

Run this once when you set up your AI accounts, then re-run the Monthly section on the first of each month. It takes about twenty minutes the first time and five minutes thereafter.

Before you paste anything

Ask these four questions. If any answer worries you, stop and use the "safer alternative" column.

Question If the answer is yes Safer alternative
Would I be uncomfortable if this appeared in a news article? Do not paste it Paraphrase, or replace names with placeholders
Does this contain someone else's personal data? You need their consent, or you need it anonymised Replace names, emails, phone numbers and IDs with [NAME_1], [EMAIL_1]
Is this covered by an NDA, employment contract or client agreement? Check the agreement first Use a company-approved tool, or work from a redacted summary
Would a wrong answer here cost money, health or legal standing? Never act on the output alone Use AI to draft, then have a qualified human verify

Never paste into a free-tier account

The rule is not "free tiers are evil". It is that free tiers usually have the weakest data-retention guarantees, and you rarely control where the data goes next.

Account setup, once per tool

My tools and their retention periods:

Tool Account type Training off? Retention Reviewed on

Verifying output before you use it

AI states wrong things in exactly the same confident tone it states right things. Confidence is not a signal.

A quick test: ask for the answer, then in a fresh conversation ask "what would make this answer wrong?" Disagreement between the two is a useful warning.

Prompt injection

If AI reads something you did not write — a web page, a PDF, an email, a shared document — treat that content as untrusted. Instructions hidden inside it can redirect the AI.

Monthly review

If something goes wrong

  1. Delete the conversation, then delete it from any account-level history.
  2. If personal data was exposed, follow your organisation's incident process. If you are the organisation, write down what happened and when.
  3. If credentials were exposed, rotate them immediately — assume they are public.
  4. Record what happened in one paragraph. Most repeat incidents are the same mistake twice.
Back to dashboard