Safe, responsible and legal use
This is the module that keeps you and your employer out of trouble. Data protection, bias, honesty, and knowing when NOT to use AI.
🎬 Watch the video lesson, then work through the full written module below.
Your goals
- Protect personal and confidential data (UK GDPR).
- Handle bias, accuracy and disclosure responsibly.
- Know when not to use AI, and follow your policy.
Data protection first
Never feed it secrets
Don’t put personal data, client details or confidential information into public AI tools. UK GDPR still applies to anything you paste. Use employer-approved tools for sensitive work.
Which is safe to paste into a public AI tool?
Bias, accuracy and disclosure
AI can be biased and can be wrong — and you are accountable for what you send. Check outputs for fairness and errors. Where it matters — advice, official documents, decisions about people — be honest that AI was involved.
When NOT to use AI
Avoid AI as the decider for legal, financial or medical advice, for final decisions about people (hiring, discipline), and for anything you can’t verify. Always follow your employer’s AI policy.
What counts as personal or confidential data
If in doubt, keep it out. Under UK GDPR, personal data is anything that identifies a living person:
- Names, emails, phone numbers, addresses
- Customer, patient or employee records
- Financial details, ID numbers
- Anything confidential: contracts, unreleased plans, passwords
None of this goes into a public AI tool. Use approved tools, or anonymise/use dummy data to work out the method.
Know your company's AI policy
Before using AI for real work, check:
- Which tools are approved (and which are banned)?
- What data is never allowed in AI tools?
- Do you need to disclose AI use to clients or in documents?
- Is there a human sign-off step for anything important?
No policy yet? Then be conservative and raise it — you're often the person who spots the need.
Write your personal AI-use checklist
Your task (5–10 min)
Make your own 5-line safety rule.
- Write: “Before I use AI I will…” in 5 short lines.
- Include: no personal/confidential data; verify facts; check policy; keep my voice; own the output.
- Pin it near your desk.
- Use it for a week and refine.
- Share it with a colleague.
Screening CVs
A busy HR manager wants AI to score and reject job applicants automatically to save time.
What should they do? Think, then reveal.
Reveal the answer
Stop — high risk.
Auto-rejecting people risks bias and data-protection breaches, and the decision is one a human must own. Check company policy, keep a human in the loop, and don’t feed personal data into public tools.
Redacted vs unredacted — what to paste
❌ Never paste this
“Draft a reply to Priya Sharma (priya@acme.co.uk, account 4471-2093) who is angry her £3,400 refund is late…”
Real name, email and account number in a public tool.
✅ Anonymise first
“Draft a reply to a customer who is angry that a refund is late. Warm, apologetic, offer a clear next step…”
Get the wording, then paste the real details back in yourself.
End-of-module quiz
6 questions. You need 4 to pass. Retake as often as you like.
Question 1
Safe to put into public AI?
Question 2
Who is accountable for AI output you send?
Question 3
A poor use of AI is…
Question 4
UK GDPR applies to data you paste into AI:
Question 5
Your firm has no AI policy yet. You should:
Question 6
A client asks if AI was used in a report containing advice. Best practice is:
Remember this
- Never put personal or confidential data into public AI — UK GDPR applies.
- You’re accountable: check for bias and errors, disclose where it matters.
- Don’t let AI make legal, financial, medical or people decisions; follow policy.
Finish all 8 modules and pass each quiz to earn your AI Skills for Work certificate of completion — shareable on your CV and LinkedIn. CPD accreditation is being arranged.