AI Foundations
D7 · Responsible and Safe Use
Data sensitivity classes, PII and confidentiality, disclosure, bias, human review gates, workplace policy and educator/student integrity when using ChatGPT.
This domain is worth 10% of the mock – roughly 6 of 60 items, the lightest weighting, but it carries outsized real-world consequence: a single mistake here can breach confidentiality, expose personal data, or mislead an audience. It tests judgment about what you may put into ChatGPT, what you must check before acting on its output, and how to be honest about its use – especially in a workplace and in education.
What you need to know
Responsible use starts with data sensitivity: classify information before you paste it, and keep confidential, personal or regulated data out of tools and settings that are not sanctioned for it. Bias can appear in outputs and must be mitigated by neutral prompting, representative examples and human review. High-stakes, irreversible, regulated or external outputs require a human review gate. Disclosure – being transparent that AI was used, where honesty requires it – matters, and in education, academic integrity rules govern what students and educators may do. Organisational AI-use policy takes precedence over personal convenience.
Learning objectives
By the end of this page you should be able to:
- Classify information by sensitivity and decide what may go into ChatGPT.
- Protect PII and confidential data and choose sanctioned tools/settings.
- Recognise and mitigate bias in outputs.
- Apply human review gates to high-stakes work.
- Judge when disclosure of AI use is appropriate.
- Apply workplace policy and educator/student integrity norms.
7.1 Data sensitivity classes
Before pasting anything, classify it. A simple four-class scheme covers most workplaces.
| Class | Examples | Rule of thumb |
|---|---|---|
| Public | Published marketing, public docs | Safe to use |
| Internal | Non-sensitive internal notes, general plans | Usually fine in sanctioned tools; check policy |
| Confidential | Unreleased strategy, contracts, source code, financials | Only in sanctioned/enterprise settings with appropriate controls |
| Restricted / regulated | PII, health data, payment data, protected characteristics | Avoid unless explicitly sanctioned; often prohibited |
before pasting: what class is this? public ──────────► fine internal ────────► check policy; use sanctioned tools confidential ────► sanctioned/enterprise settings only restricted/PII ──► do not paste unless explicitly permittedEnterprise settings help: OpenAI states that business data is not used to train models by default on Enterprise, with controls like SSO, RBAC and data residency. But the setting only helps if you use the sanctioned workspace — pasting confidential data into a personal free account is the classic error.
Assessment signal
“An employee pastes X into ChatGPT” items turn on the data class and whether the tool is sanctioned. Confidential or personal data into an unsanctioned/personal account is wrong regardless of how helpful the result would be.
7.2 PII and confidentiality
Personally identifiable information (names tied to data, contact details, IDs, health or payment data) and confidential business information deserve special care.
| Situation | Wrong move | Right move |
|---|---|---|
| Summarise customer records with names/emails | Paste raw PII into a personal account | Remove/anonymise PII, or use a sanctioned enterprise workspace per policy |
| Draft from an unreleased contract | Upload it to a free personal account | Use the sanctioned workspace; check confidentiality rules |
| Analyse a spreadsheet with salaries | Paste it anywhere convenient | Confirm policy; de-identify where possible |
| Share a customer’s health detail | Include it to ‘give context’ | Strip it; it is regulated data |
The safe default: minimise — include only the data the task genuinely needs, and de-identify when the specifics are not required.
7.3 Bias and fairness
Outputs can carry bias: skewed framing, unrepresentative examples, stereotyped assumptions, or asymmetric treatment of people or options.
| Bias type | Example | Mitigation |
|---|---|---|
| Framing bias | Pros for one option, cons for another | Ask for symmetric, criteria-based comparison |
| Demographic bias | Personas default to one gender/culture | Specify diverse, representative attributes; review |
| Confirmation bias (yours) | “Explain why plan A wins” | Prompt neutrally against shared criteria |
| Stereotyping | Role assumptions by group | Review and correct before use |
Bias mitigation is shared: neutral prompting reduces it, representative inputs help, and human review catches what remains — especially for anything touching people or protected characteristics.
7.4 Human review gates
Certain outputs must pass a human before they are acted on — the same gate introduced in Domain 6, viewed through a responsibility lens.
Mandatory review when the output is irreversible, regulated (legal, medical, financial, HR/hiring), external-facing, touches personal data or protected characteristics, is required by policy, or is novel/high-uncertainty. For hiring, medical, legal or financial-advice content, a qualified human — not the model — makes the decision; the model drafts, the human owns.
Assessment signal
Options that let the model decide a regulated matter (hiring, diagnosis, legal/financial advice) are wrong. Correct options keep a qualified human in the loop and accountable.
7.5 Disclosure and honesty
Disclosure is being transparent that AI assisted, where honesty or policy requires it. It is context-dependent, not absolute.
| Context | Disclosure expectation |
|---|---|
| Academic submission | Follow the institution’s rules; often required or restricted |
| Published journalism/research | Disclose per the outlet’s/field’s norms |
| Passing AI text off as solely your expert work | Misleading; disclose or attribute appropriately |
| A personal rough draft you will rewrite | Usually no disclosure needed |
The principle: do not create a false impression of authorship, expertise or effort. When in doubt in a professional or academic setting, disclose and follow the applicable policy.
7.6 Workplace policy and educator/student integrity
Workplace AI-use policy takes precedence over personal convenience. If policy names sanctioned tools, prohibited data classes, or required review steps, follow them even when an unsanctioned shortcut would be faster.
Use ChatGPT to plan lessons, build activities, draft rubrics and communications — with educator judgment reviewing everything for accuracy and appropriateness. Model responsible use and be transparent with students and colleagues per school policy.
Use ChatGPT to study, plan, and improve work within the institution’s academic-integrity rules. Submitting AI-written work as your own where that is prohibited is misconduct; using it to learn, check understanding or get feedback is usually allowed. When unsure, ask and follow the syllabus policy.
before acting on AI help at work or school: 1. What does the policy say? ── follow it 2. What data class is involved? ── protect it 3. Does honesty require disclosure? ── disclose 4. Does a human need to own the decision? ── route the gateDecision framework
Use the CLEAR responsible-use check before you paste sensitive data or act on an output: Classify the data, Limit to what’s needed, Evaluate for bias, Authorise via policy/sanctioned tools, Review by a human where stakes require.
| Step | Question | If it fails |
|---|---|---|
| Classify | What sensitivity class is this input? | Restricted/PII → do not paste unless sanctioned |
| Limit | Am I including only what the task needs? | Strip/anonymise the rest |
| Evaluate | Could the output be biased or unfair? | Neutral prompt; representative inputs; review |
| Authorise | Is the tool/setting sanctioned by policy? | Move to the sanctioned workspace |
| Review | Is this irreversible/regulated/external/PII? | Route to a human gate; disclose if honesty requires |
The value: it turns “is this okay to do with AI?” into five quick, answerable checks that catch the common breaches before they happen.
Common mistakes
| Mistake | Why it happens | What to do instead |
|---|---|---|
| Pasting confidential data into a personal account | It’s faster | Use the sanctioned workspace; check policy first |
| Including PII ‘for context’ | It seems helpful | Minimise and de-identify; include only what’s needed |
| Letting the model decide a hiring/medical/legal matter | It sounds confident | Keep a qualified human accountable for the decision |
| Ignoring bias because the output reads neutral | Fluency masks skew | Prompt neutrally; use representative inputs; review |
| Passing AI work off as solely your own | Convenience/pressure | Disclose per policy; don’t misrepresent authorship |
| Treating workplace policy as optional | A shortcut is faster | Policy takes precedence over convenience |
| Students submitting AI text where prohibited | Deadline pressure | Use AI to learn within integrity rules; follow the syllabus |
| Assuming ‘internal use’ removes obligations | The label reassures | Sensitivity and stakes follow the data and its use |
Scenario challenge
Scenario. Marco, a recruiter, wants to speed up screening. He pastes 40 candidate CVs — full names, addresses, and one candidate’s disclosed disability — into his personal free ChatGPT account and asks it to “rank the candidates and tell me who to reject.” His company has an enterprise ChatGPT workspace and an AI-use policy that prohibits candidate PII in personal accounts and requires human decisions in hiring. The output confidently ranks everyone and recommends rejections.
Expert reasoning trace.
- Classify the data. The CVs contain PII and a protected characteristic (disability) — restricted/regulated data. Pasting them into a personal account breaches both the data class rule and the company policy naming the sanctioned enterprise workspace.
- Limit. He included far more than needed and highly sensitive specifics; the disability detail in particular should never have been included and risks discriminatory handling.
- Evaluate for bias. An AI ranking that “recommends rejections” can encode bias, and doing so on data including a protected characteristic is exactly where unfair, and potentially unlawful, outcomes arise.
- Authorise. Even the summarising help must happen in the sanctioned workspace under policy, not a personal account.
- Review / decision ownership. Hiring is regulated and consequential: the model may assist (e.g., neutral summaries of stated qualifications), but a qualified human must make and own the decision — the model cannot “decide who to reject.”
Exam-correct outcome: stop; do not paste candidate PII into a personal account; move any assistance to the sanctioned enterprise workspace under policy; remove protected-characteristic and unnecessary data; use AI only for neutral, criteria-based support; and keep the hiring decision with an accountable human — with bias review before any adverse action.
Assessment traps
| Trap | Why it is tempting | The discriminator |
|---|---|---|
| “It’s just internal, so any tool is fine” | The label reassures | Sensitivity follows the data class, not the label; use sanctioned tools |
| “Include the personal detail for better context” | More context feels helpful | Minimise; PII/protected data should be stripped unless required |
| “Let the AI decide the hiring shortlist” | It ranks confidently | Regulated decisions need an accountable human |
| “The output reads neutral, so no bias” | Fluency hides skew | Bias can be subtle; prompt neutrally and review |
| “No need to disclose AI use anywhere” | Simpler | Disclosure is context-dependent; academic/professional norms may require it |
| “Policy is a guideline, speed matters more” | Deadlines | Policy takes precedence over convenience |
| “Students can submit AI text freely” | It’s allowed for learning | Only within integrity rules; submitting as your own may be misconduct |
Practice questions
Q1 · An employee wants to summarise a spreadsheet containing customer names and emails. What is the MOST responsible approach? (Select one)
A. Paste it into a personal free account for speed. B. Remove or anonymise the PII, or use the sanctioned enterprise workspace per policy. C. Include everything for better context. D. Post it in a public forum for help.
Answer: B. PII should be minimised/anonymised and only handled in sanctioned settings per policy. A uses an unsanctioned account. C over-shares regulated data. D exposes it publicly.
Q2 · Which data class should generally NOT be pasted into ChatGPT unless explicitly sanctioned? (Select one)
A. Published marketing copy. B. A general, non-sensitive internal note. C. Personal health data and other regulated PII. D. A public blog post.
Answer: C. Regulated PII such as health data is restricted and needs explicit authorisation. A, B and D are public or low-sensitivity and generally acceptable per policy.
Q3 · A hiring manager wants ChatGPT to 'decide who to reject'. What is the correct posture? (Select one)
A. Let the model decide to remove human bias. B. Use AI only for neutral support; a qualified human must make and own the hiring decision. C. Accept the model’s ranking as final. D. Ask the model twice and average.
Answer: B. Hiring is regulated and consequential, so a human owns the decision while AI may assist neutrally. A, C and D hand a regulated decision to the model.
Q4 · A vendor comparison lists many pros for Option A and mostly cons for Option B. What is the issue and fix? (Select one)
A. Hallucination; ask for citations. B. Framing bias; request a symmetric, criteria-based comparison and review it. C. Context overflow; shorten it. D. Non-determinism; regenerate.
Answer: B. Asymmetric treatment is framing bias; a neutral, symmetric structure plus review mitigates it. A, C and D address unrelated issues.
Q5 · When is disclosure of AI use MOST clearly expected? (Select one)
A. A personal rough draft you will rewrite entirely. B. An academic submission where the institution’s rules require it. C. A private brainstorm for yourself. D. Reformatting your own paragraph.
Answer: B. Academic settings often require disclosure per policy. A, C and D are private/low-stakes where disclosure is generally not expected.
Q6 · A company policy names an enterprise workspace as the only sanctioned tool for confidential data, but a personal account is faster. What should an employee do? (Select one)
A. Use the personal account to save time. B. Follow policy and use the sanctioned enterprise workspace. C. Ask ChatGPT which is fine. D. Split the data across both.
Answer: B. Workplace AI-use policy takes precedence over convenience. A and D breach policy. C misplaces the decision onto the model.
Q7 · Which TWO practices protect sensitive data when using ChatGPT? (Select two)
A. Include only the data the task genuinely needs. B. Use the sanctioned workspace/settings per policy. C. Paste full records for maximum context. D. Use a personal account for confidential work. E. Share the data in a public channel for help.
Answer: A and B. Data minimisation and using sanctioned settings are core protections. C over-shares. D and E expose confidential data inappropriately.
Q8 · A student wants to use ChatGPT for an assignment. What is the responsible approach? (Select one)
A. Submit AI-written work as their own regardless of rules. B. Use it to study and get feedback within the institution’s academic-integrity rules, disclosing where required. C. Never use AI for anything academic. D. Assume all uses are permitted.
Answer: B. Using AI to learn within integrity rules is generally acceptable; submitting AI text as one’s own where prohibited is misconduct. A is misconduct. C is overly restrictive. D ignores the rules.
Q9 · An educator uses ChatGPT to draft a quiz. What responsible-use step is essential before using it with students? (Select one)
A. None; the model is authoritative. B. Educator review for accuracy and appropriateness, applying professional judgment. C. Publish it unreviewed to save time. D. Let students grade each other’s AI answers.
Answer: B. Educators must review AI output for accuracy and appropriateness before classroom use. A over-trusts the model. C skips review. D is unrelated to the review obligation.
Q10 · An output personas 'the engineer' as male and 'the nurse' as female by default. What is this and the fix? (Select one)
A. Hallucination; add citations. B. Demographic/stereotype bias; specify diverse, representative attributes and review before use. C. Inconsistency; recompute. D. A context issue; shorten the prompt.
Answer: B. Default stereotyped attributes are demographic bias; specifying representative attributes and reviewing mitigates it. A, C and D address unrelated problems.
Q11 · Which TWO outputs require a mandatory human review gate before acting? (Select two)
A. A medical-advice draft for a patient. B. A financial recommendation to a client. C. A personal to-do list. D. A rough brainstorm you will rewrite. E. Reformatting your own notes.
Answer: A and B. Medical and financial advice are regulated, high-stakes outputs needing human sign-off. C, D and E are low-stakes and reversible.
Q12 · A colleague argues 'if it's for internal use, we don't need to worry about data sensitivity'. What is the MOST accurate response? (Select one)
A. Correct; internal use removes all obligations. B. Sensitivity follows the data class and its downstream use, not the ‘internal’ label; confidential and personal data still need protection. C. Only external use matters. D. Data sensitivity only applies to published content.
Answer: B. Obligations follow the data’s class and use, not the internal label. A, C and D all wrongly treat ‘internal’ as an exemption.
Key takeaways
- Classify data before pasting; keep confidential and regulated/PII data out of unsanctioned tools.
- Minimise and de-identify — include only what the task needs.
- Mitigate bias with neutral prompting, representative inputs and human review.
- Irreversible, regulated, external or personal-data outputs require a human review gate; a qualified human owns regulated decisions.
- Disclose AI use where honesty or policy requires; do not misrepresent authorship.
- Workplace policy takes precedence over convenience; sensitivity follows the data and its use, not the ‘internal’ label.
- In education, use AI to learn within academic-integrity rules; educators review everything with professional judgment.
Last updated Sep 18, 2026