AI Cert Prep
Type to search documentation.

AI Foundations

D7 · Responsible and Safe Use

Data sensitivity classes, PII and confidentiality, disclosure, bias, human review gates, workplace policy and educator/student integrity when using ChatGPT.

This domain is worth 10% of the mock – roughly 6 of 60 items, the lightest weighting, but it carries outsized real-world consequence: a single mistake here can breach confidentiality, expose personal data, or mislead an audience. It tests judgment about what you may put into ChatGPT, what you must check before acting on its output, and how to be honest about its use – especially in a workplace and in education.

What you need to know

Responsible use starts with data sensitivity: classify information before you paste it, and keep confidential, personal or regulated data out of tools and settings that are not sanctioned for it. Bias can appear in outputs and must be mitigated by neutral prompting, representative examples and human review. High-stakes, irreversible, regulated or external outputs require a human review gate. Disclosure – being transparent that AI was used, where honesty requires it – matters, and in education, academic integrity rules govern what students and educators may do. Organisational AI-use policy takes precedence over personal convenience.

Learning objectives

By the end of this page you should be able to:

  1. Classify information by sensitivity and decide what may go into ChatGPT.
  2. Protect PII and confidential data and choose sanctioned tools/settings.
  3. Recognise and mitigate bias in outputs.
  4. Apply human review gates to high-stakes work.
  5. Judge when disclosure of AI use is appropriate.
  6. Apply workplace policy and educator/student integrity norms.

7.1 Data sensitivity classes

Before pasting anything, classify it. A simple four-class scheme covers most workplaces.

ClassExamplesRule of thumb
PublicPublished marketing, public docsSafe to use
InternalNon-sensitive internal notes, general plansUsually fine in sanctioned tools; check policy
ConfidentialUnreleased strategy, contracts, source code, financialsOnly in sanctioned/enterprise settings with appropriate controls
Restricted / regulatedPII, health data, payment data, protected characteristicsAvoid unless explicitly sanctioned; often prohibited
text
before pasting: what class is this?
public ──────────► fine
internal ────────► check policy; use sanctioned tools
confidential ────► sanctioned/enterprise settings only
restricted/PII ──► do not paste unless explicitly permitted

Enterprise settings help: OpenAI states that business data is not used to train models by default on Enterprise, with controls like SSO, RBAC and data residency. But the setting only helps if you use the sanctioned workspace — pasting confidential data into a personal free account is the classic error.

Assessment signal

“An employee pastes X into ChatGPT” items turn on the data class and whether the tool is sanctioned. Confidential or personal data into an unsanctioned/personal account is wrong regardless of how helpful the result would be.

7.2 PII and confidentiality

Personally identifiable information (names tied to data, contact details, IDs, health or payment data) and confidential business information deserve special care.

SituationWrong moveRight move
Summarise customer records with names/emailsPaste raw PII into a personal accountRemove/anonymise PII, or use a sanctioned enterprise workspace per policy
Draft from an unreleased contractUpload it to a free personal accountUse the sanctioned workspace; check confidentiality rules
Analyse a spreadsheet with salariesPaste it anywhere convenientConfirm policy; de-identify where possible
Share a customer’s health detailInclude it to ‘give context’Strip it; it is regulated data

The safe default: minimise — include only the data the task genuinely needs, and de-identify when the specifics are not required.

7.3 Bias and fairness

Outputs can carry bias: skewed framing, unrepresentative examples, stereotyped assumptions, or asymmetric treatment of people or options.

Bias typeExampleMitigation
Framing biasPros for one option, cons for anotherAsk for symmetric, criteria-based comparison
Demographic biasPersonas default to one gender/cultureSpecify diverse, representative attributes; review
Confirmation bias (yours)“Explain why plan A wins”Prompt neutrally against shared criteria
StereotypingRole assumptions by groupReview and correct before use

Bias mitigation is shared: neutral prompting reduces it, representative inputs help, and human review catches what remains — especially for anything touching people or protected characteristics.

7.4 Human review gates

Certain outputs must pass a human before they are acted on — the same gate introduced in Domain 6, viewed through a responsibility lens.

Mandatory review when the output is irreversible, regulated (legal, medical, financial, HR/hiring), external-facing, touches personal data or protected characteristics, is required by policy, or is novel/high-uncertainty. For hiring, medical, legal or financial-advice content, a qualified human — not the model — makes the decision; the model drafts, the human owns.

Assessment signal

Options that let the model decide a regulated matter (hiring, diagnosis, legal/financial advice) are wrong. Correct options keep a qualified human in the loop and accountable.

7.5 Disclosure and honesty

Disclosure is being transparent that AI assisted, where honesty or policy requires it. It is context-dependent, not absolute.

ContextDisclosure expectation
Academic submissionFollow the institution’s rules; often required or restricted
Published journalism/researchDisclose per the outlet’s/field’s norms
Passing AI text off as solely your expert workMisleading; disclose or attribute appropriately
A personal rough draft you will rewriteUsually no disclosure needed

The principle: do not create a false impression of authorship, expertise or effort. When in doubt in a professional or academic setting, disclose and follow the applicable policy.

7.6 Workplace policy and educator/student integrity

Workplace AI-use policy takes precedence over personal convenience. If policy names sanctioned tools, prohibited data classes, or required review steps, follow them even when an unsanctioned shortcut would be faster.

Use ChatGPT to plan lessons, build activities, draft rubrics and communications — with educator judgment reviewing everything for accuracy and appropriateness. Model responsible use and be transparent with students and colleagues per school policy.

text
before acting on AI help at work or school:
1. What does the policy say? ── follow it
2. What data class is involved? ── protect it
3. Does honesty require disclosure? ── disclose
4. Does a human need to own the decision? ── route the gate

Decision framework

Use the CLEAR responsible-use check before you paste sensitive data or act on an output: Classify the data, Limit to what’s needed, Evaluate for bias, Authorise via policy/sanctioned tools, Review by a human where stakes require.

StepQuestionIf it fails
ClassifyWhat sensitivity class is this input?Restricted/PII → do not paste unless sanctioned
LimitAm I including only what the task needs?Strip/anonymise the rest
EvaluateCould the output be biased or unfair?Neutral prompt; representative inputs; review
AuthoriseIs the tool/setting sanctioned by policy?Move to the sanctioned workspace
ReviewIs this irreversible/regulated/external/PII?Route to a human gate; disclose if honesty requires

The value: it turns “is this okay to do with AI?” into five quick, answerable checks that catch the common breaches before they happen.

Common mistakes

MistakeWhy it happensWhat to do instead
Pasting confidential data into a personal accountIt’s fasterUse the sanctioned workspace; check policy first
Including PII ‘for context’It seems helpfulMinimise and de-identify; include only what’s needed
Letting the model decide a hiring/medical/legal matterIt sounds confidentKeep a qualified human accountable for the decision
Ignoring bias because the output reads neutralFluency masks skewPrompt neutrally; use representative inputs; review
Passing AI work off as solely your ownConvenience/pressureDisclose per policy; don’t misrepresent authorship
Treating workplace policy as optionalA shortcut is fasterPolicy takes precedence over convenience
Students submitting AI text where prohibitedDeadline pressureUse AI to learn within integrity rules; follow the syllabus
Assuming ‘internal use’ removes obligationsThe label reassuresSensitivity and stakes follow the data and its use

Scenario challenge

Scenario. Marco, a recruiter, wants to speed up screening. He pastes 40 candidate CVs — full names, addresses, and one candidate’s disclosed disability — into his personal free ChatGPT account and asks it to “rank the candidates and tell me who to reject.” His company has an enterprise ChatGPT workspace and an AI-use policy that prohibits candidate PII in personal accounts and requires human decisions in hiring. The output confidently ranks everyone and recommends rejections.

Expert reasoning trace.

  1. Classify the data. The CVs contain PII and a protected characteristic (disability) — restricted/regulated data. Pasting them into a personal account breaches both the data class rule and the company policy naming the sanctioned enterprise workspace.
  2. Limit. He included far more than needed and highly sensitive specifics; the disability detail in particular should never have been included and risks discriminatory handling.
  3. Evaluate for bias. An AI ranking that “recommends rejections” can encode bias, and doing so on data including a protected characteristic is exactly where unfair, and potentially unlawful, outcomes arise.
  4. Authorise. Even the summarising help must happen in the sanctioned workspace under policy, not a personal account.
  5. Review / decision ownership. Hiring is regulated and consequential: the model may assist (e.g., neutral summaries of stated qualifications), but a qualified human must make and own the decision — the model cannot “decide who to reject.”

Exam-correct outcome: stop; do not paste candidate PII into a personal account; move any assistance to the sanctioned enterprise workspace under policy; remove protected-characteristic and unnecessary data; use AI only for neutral, criteria-based support; and keep the hiring decision with an accountable human — with bias review before any adverse action.

Assessment traps

TrapWhy it is temptingThe discriminator
“It’s just internal, so any tool is fine”The label reassuresSensitivity follows the data class, not the label; use sanctioned tools
“Include the personal detail for better context”More context feels helpfulMinimise; PII/protected data should be stripped unless required
“Let the AI decide the hiring shortlist”It ranks confidentlyRegulated decisions need an accountable human
“The output reads neutral, so no bias”Fluency hides skewBias can be subtle; prompt neutrally and review
“No need to disclose AI use anywhere”SimplerDisclosure is context-dependent; academic/professional norms may require it
“Policy is a guideline, speed matters more”DeadlinesPolicy takes precedence over convenience
“Students can submit AI text freely”It’s allowed for learningOnly within integrity rules; submitting as your own may be misconduct

Practice questions

Q1 · An employee wants to summarise a spreadsheet containing customer names and emails. What is the MOST responsible approach? (Select one)

A. Paste it into a personal free account for speed. B. Remove or anonymise the PII, or use the sanctioned enterprise workspace per policy. C. Include everything for better context. D. Post it in a public forum for help.

Answer: B. PII should be minimised/anonymised and only handled in sanctioned settings per policy. A uses an unsanctioned account. C over-shares regulated data. D exposes it publicly.

Q2 · Which data class should generally NOT be pasted into ChatGPT unless explicitly sanctioned? (Select one)

A. Published marketing copy. B. A general, non-sensitive internal note. C. Personal health data and other regulated PII. D. A public blog post.

Answer: C. Regulated PII such as health data is restricted and needs explicit authorisation. A, B and D are public or low-sensitivity and generally acceptable per policy.

Q3 · A hiring manager wants ChatGPT to 'decide who to reject'. What is the correct posture? (Select one)

A. Let the model decide to remove human bias. B. Use AI only for neutral support; a qualified human must make and own the hiring decision. C. Accept the model’s ranking as final. D. Ask the model twice and average.

Answer: B. Hiring is regulated and consequential, so a human owns the decision while AI may assist neutrally. A, C and D hand a regulated decision to the model.

Q4 · A vendor comparison lists many pros for Option A and mostly cons for Option B. What is the issue and fix? (Select one)

A. Hallucination; ask for citations. B. Framing bias; request a symmetric, criteria-based comparison and review it. C. Context overflow; shorten it. D. Non-determinism; regenerate.

Answer: B. Asymmetric treatment is framing bias; a neutral, symmetric structure plus review mitigates it. A, C and D address unrelated issues.

Q5 · When is disclosure of AI use MOST clearly expected? (Select one)

A. A personal rough draft you will rewrite entirely. B. An academic submission where the institution’s rules require it. C. A private brainstorm for yourself. D. Reformatting your own paragraph.

Answer: B. Academic settings often require disclosure per policy. A, C and D are private/low-stakes where disclosure is generally not expected.

Q6 · A company policy names an enterprise workspace as the only sanctioned tool for confidential data, but a personal account is faster. What should an employee do? (Select one)

A. Use the personal account to save time. B. Follow policy and use the sanctioned enterprise workspace. C. Ask ChatGPT which is fine. D. Split the data across both.

Answer: B. Workplace AI-use policy takes precedence over convenience. A and D breach policy. C misplaces the decision onto the model.

Q7 · Which TWO practices protect sensitive data when using ChatGPT? (Select two)

A. Include only the data the task genuinely needs. B. Use the sanctioned workspace/settings per policy. C. Paste full records for maximum context. D. Use a personal account for confidential work. E. Share the data in a public channel for help.

Answer: A and B. Data minimisation and using sanctioned settings are core protections. C over-shares. D and E expose confidential data inappropriately.

Q8 · A student wants to use ChatGPT for an assignment. What is the responsible approach? (Select one)

A. Submit AI-written work as their own regardless of rules. B. Use it to study and get feedback within the institution’s academic-integrity rules, disclosing where required. C. Never use AI for anything academic. D. Assume all uses are permitted.

Answer: B. Using AI to learn within integrity rules is generally acceptable; submitting AI text as one’s own where prohibited is misconduct. A is misconduct. C is overly restrictive. D ignores the rules.

Q9 · An educator uses ChatGPT to draft a quiz. What responsible-use step is essential before using it with students? (Select one)

A. None; the model is authoritative. B. Educator review for accuracy and appropriateness, applying professional judgment. C. Publish it unreviewed to save time. D. Let students grade each other’s AI answers.

Answer: B. Educators must review AI output for accuracy and appropriateness before classroom use. A over-trusts the model. C skips review. D is unrelated to the review obligation.

Q10 · An output personas 'the engineer' as male and 'the nurse' as female by default. What is this and the fix? (Select one)

A. Hallucination; add citations. B. Demographic/stereotype bias; specify diverse, representative attributes and review before use. C. Inconsistency; recompute. D. A context issue; shorten the prompt.

Answer: B. Default stereotyped attributes are demographic bias; specifying representative attributes and reviewing mitigates it. A, C and D address unrelated problems.

Q11 · Which TWO outputs require a mandatory human review gate before acting? (Select two)

A. A medical-advice draft for a patient. B. A financial recommendation to a client. C. A personal to-do list. D. A rough brainstorm you will rewrite. E. Reformatting your own notes.

Answer: A and B. Medical and financial advice are regulated, high-stakes outputs needing human sign-off. C, D and E are low-stakes and reversible.

Q12 · A colleague argues 'if it's for internal use, we don't need to worry about data sensitivity'. What is the MOST accurate response? (Select one)

A. Correct; internal use removes all obligations. B. Sensitivity follows the data class and its downstream use, not the ‘internal’ label; confidential and personal data still need protection. C. Only external use matters. D. Data sensitivity only applies to published content.

Answer: B. Obligations follow the data’s class and use, not the internal label. A, C and D all wrongly treat ‘internal’ as an exemption.

Key takeaways

  • Classify data before pasting; keep confidential and regulated/PII data out of unsanctioned tools.
  • Minimise and de-identify — include only what the task needs.
  • Mitigate bias with neutral prompting, representative inputs and human review.
  • Irreversible, regulated, external or personal-data outputs require a human review gate; a qualified human owns regulated decisions.
  • Disclose AI use where honesty or policy requires; do not misrepresent authorship.
  • Workplace policy takes precedence over convenience; sensitivity follows the data and its use, not the ‘internal’ label.
  • In education, use AI to learn within academic-integrity rules; educators review everything with professional judgment.

Last updated Sep 18, 2026