Handbook · Tools · 16 min read
AI, ethically and safely: data, responsibility, boundaries
Last reviewed:
Where the lines are that don't get crossed even when nobody's watching: what data can go where, who owns responsibility for the output, what to disclose to whom, and why decisions about people can never leave human hands.

In this article
- Classifying data: a habit that replaces the list of prohibitions
- Two defenses you already have available
- The signature: hallucination doesn't change who's responsible
- Authorship and fairness: what to disclose to whom
- Mechanics versus thinking: what to keep doing yourself
- Decisions about people: the one place a human can never step out of the loop
- Regulation, plainly and briefly
- Trust is a condition, not a bonus
- What to take away
Thursday afternoon, an unpleasant complaint comes in. A colleague opens the contract, pastes the whole thing into chat — client name, address, amounts, date of birth — and types: “Write me a reply that sounds accommodating but doesn't admit anything.” Two minutes later she has a draft better than what she'd have written in an hour. She sends it and goes home. Nothing happens. Nobody calls, nothing blows up, no warning ever appears.
And that's exactly the problem. Mistakes in handling data and responsibility almost never show up right away. They show up a year later, in an audit, in a dispute with a client, or the moment someone on the team leaves for a competitor and takes the history of their personal account with them. Until then, everything looks perfectly fine, which is the worst possible feedback for building habits: risky behavior feels exactly the same as safe behavior.
This chapter closes out a four-part series. Five levels of working with AI described how deeply to involve AI, Briefing AI is a skill covered the skill without which none of it works, and Routines and agents covered operations that run on their own. What's left is what holds all of that together. The key idea: safe, fair use of AI doesn't rest on a list of prohibitions nobody remembers — it rests on a handful of habits and one rule that never bends: there's a person's signature under every output, and that signature can't be delegated to a tool.
Classifying data: a habit that replaces the list of prohibitions
Most corporate AI policies fail the same way: they're lists of forbidden things nobody remembers, and that don't actually answer the question of whether you can paste this specific document into chat in this specific moment. Something else works, and it's much simpler — the habit of asking one question before you paste anything in: what kind of data is this?
Four categories are useful, and anyone can tell them apart in a few seconds. Public data is data that's already out there or could easily be: text from your website, an annual report, public legislation, general questions. Internal data is operational material that isn't secret but has no reason to leave the organization: meeting notes, draft procedures, internal presentations. Confidential data is data whose leak would harm someone: non-public contracts, prices, business strategy, source code, client material. And personal data stands apart, because the decision about it isn't yours to make — it belongs to the person it concerns: a name, contact details, date of birth, health information, an employee review, anything about a child.
Kvadrant „Důležité, neurgentní" je místo, kde vzniká skutečný pokrok — plánujte si pro něj čas dřív, než ho urgence sežerou.
By far the most common mistake isn't bad intent — it's failing to distinguish. Anyone who carries one blanket category in their head — “work documents” — treats a meeting note the same as an unsigned contract. Once the habit of distinguishing sets in, most situations resolve themselves automatically, and you'll recognize the rest by the fact that you hesitate — and hesitation is a good signal to ask, not to just go ahead and try.
A second thing worth saying out loud: classification also applies to other people's data that's been entrusted to you. A client's materials, tender documents, a vendor's files aren't yours, even though they're sitting on your computer, and decisions about them can be bound by a contract or an NDA. For a lot of engagements, the only correct answer is asking the client first — which almost never gets a no, quite the opposite in fact.
Two defenses you already have available
Between “I can't use anything” and “I paste in everything” sit two concrete measures. Both are available right now, and both do more good than any training session.
The account matters more than the tool
This is the most commonly overlooked distinction in the whole area. What matters isn't which model you use, but what mode you're accessing it in. A free personal account is a consumer service: the provider usually has broader latitude in what it does with the content of your conversations, and you have no counterparty to raise that with. A paid or enterprise account, by contrast, is a business relationship — it has contractual terms, usually an explicit agreement that your data isn't used for further training, a configurable retention period, and someone who bears contractual liability for it.
The difference is both legal and practical, and above all asymmetric in time: with sensitive input, you won't find out something went wrong until it's too late. That's why a simple rule holds across this whole site: sensitive data belongs only in an account with contractual data protection. Not because free tools are inherently dangerous — for public and general data they're perfectly fine — but because with them, you have no recourse.
There's one more consequence at company level that people forget. When an organization bans AI without giving people a working alternative, they don't stop using it — they just start using it on personal accounts, out of sight. A ban with no alternative is therefore the riskiest policy possible: it moves the exact same behavior somewhere nobody can see it. The guide AI at your company covers how to do the opposite.
Anonymization as routine, not exception
The second defense is a habit that takes a few seconds and handles most situations that would otherwise require a hard no. The model almost never actually needs to know who this is. It needs to know what the situation is.
Instead of a name, write a role and a sequence label: client A, student #7, candidate B, a vendor from out of state. Instead of exact figures, use round numbers where precision doesn't matter. Drop identifiers that have no effect on answer quality — addresses, national ID numbers, contract numbers, phone numbers. The result is just as good, and the risk sits elsewhere. This is exactly the approach the guide Written feedback and talking to parents takes, where children are involved and the line is the hardest of all.
Two caveats, so this doesn't turn into false confidence. First, swapping a name for a label isn't the same as anonymization. If you describe “client A” with an industry, region, size, and a recent dispute, they may be identifiable more reliably than by name. Anonymity breaks on the combination of details, not on a single field. Second, keep the who's-who key to yourself, not in the conversation — and fill in names in the finished text by hand, at the end. That's the last step, it takes a minute, and without it the whole routine loses its point.
Anonymization has a side effect people only notice after a while: it forces you to state the actual substance. When you can't write “that's the guy who keeps calling,” you have to write what's actually going on — and a more precise brief returns a better answer.
The signature: hallucination doesn't change who's responsible
A language model doesn't return truth — it returns a probable continuation of text. That means it states a mistake with exactly the same confidence as a fact — it invents a citation, garbles a statute, cites a figure that appeared nowhere. The mechanism and concrete verification steps are covered in the tip AI makes things up with total confidence; here the point is different — the consequence for responsibility.
That consequence is simple and uncomfortable: responsibility hasn't gone anywhere. If you send a client a proposal with the wrong number, it's your wrong number. If a report cites a study that doesn't exist, it's your report. “AI wrote it” is not a defense, because a tool has no capacity to bear consequences, no reputation to lose, and nobody can hold it accountable. You can be held accountable. A signature under an output means you stand behind its content exactly as if you'd written it from start to finish yourself — and it doesn't matter whether it took two minutes or two hours to produce.
That doesn't mean everything needs the same level of scrutiny. Nobody could sustain that, and in practice it backfires — it turns into checking for show. The sensible approach is to scale effort to the cost of a mistake. An internal note only you will see can survive a quick read-through. Text that leaves the organization deserves verification of every checkable claim. And anywhere a mistake carries legal, medical or financial consequences, AI may prepare the material, but the decision and the final wording have to go through an expert.
One subtle effect deserves naming, because it catches even people who know all of this. The more confident text sounds and the better it's written, the less critically we read it. A confident phrasing triggers our trust before we've had a chance to notice that confidence in the voice has nothing to do with truth. The practical defense is banal and effective: check the claims, not the impression. Pull out the checkable statements from the text and go through them one by one. How the text feels tells you nothing about whether it's correct.
Authorship and fairness: what to disclose to whom
The question of when to disclose AI use often gets treated as a moral dilemma, when it's really more a matter of basic courtesy. The guideline isn't a universal rule — it's a simple test: disclose wherever the recipient is assuming something different from what they're actually getting, and where that difference would matter to them.
At school, the answer is the hardest and simplest, because what's being graded is your thinking, not a finished text. The specific school or department's rules apply, and where they exist, they take precedence over your own judgment. The general guideline: nothing goes into the work that you couldn't defend without AI on hand. Mechanical help — proofreading, formatting, converting a table, suggesting a structure — is usually fine and gets disclosed however the school requires. Having an argument generated and handing it in as your own is cheating no matter how well it's written. The guide Your thesis with AI walks through the whole honest workflow.
At work, the outcome decides, not the tool. Nobody discloses that they used a calculator or a spellchecker, and there's equally no point declaring that you had a sentence in an email polished up. The line falls elsewhere, and it's twofold. First, for texts where authorship is itself part of the message — a personal recommendation, condolences, a colleague's review, a speech. Second, for professional output where the client is paying for your judgment: there it's fair to say what's your own work and what's material preparation.
With a client, a good rule of thumb applies: a client is buying a result and your accountability for it, not a count of your keystrokes. You don't need to disclose AI use in every sentence, but you can't use it to claim something that isn't true — for example, that a team of analysts did the research when a model did. And if the client has an expectation that only people covered by their contract are handling their materials, that belongs on the table before they find out otherwise. The worst version is always the one where the other side learns the truth from someone other than you.
Mechanics versus thinking: what to keep doing yourself
There's a risk that gets discussed less than data, because it has no victim and no date attached: the gradual loss of a skill you stopped using. Someone who has all their proposals written for them for six months won't forget how to write entirely, but they'll lose ease and speed. Someone who has every text summarized for them stops noticing where the gap is in an argument. Recovery is possible, but it costs time — and above all, the loss happens invisibly, so it's only noticed the moment the tool isn't there.
A useful distinction is between mechanics and thinking. Mechanics is work that carries little learning: formatting, retyping, converting data, hunting for typos, layout, assembling a table, a first rough translation. It's reasonable to hand that off with no guilt at all — nothing is lost. Thinking is the part where judgment gets formed: framing the question, choosing the argument, deciding what matters, evaluating quality. That part is your profession, and handing it off means handing off the one thing someone is actually paying you or grading you for.
A practical habit that reconciles both: for things you care about, write your own version first, and only then bring in AI. It doesn't need to be finished text — a skeleton and three arguments are enough. Your own thinking forms exactly in that uncomfortable moment of facing a blank page, and skipping it hands you someone else's structure that you're now just filling in. The reverse order — model first, you second — produces text that's smooth and doesn't go anywhere.
And one deliberate exception: for skills you're still learning, the shortcut is the most expensive option of all. A student who has their problems solved for them doesn't learn the subject, just turns something in. One who writes their own solution and then asks for it to be critiqued gets feedback nobody else would have given them. It's the same technology, used in two different orders, and the difference between them is an entire education.
Decisions about people: the one place a human can never step out of the loop
One area has stricter rules than all the others combined, and that's neither an accident nor excess caution. When AI decides about people — who to hire, how to evaluate an employee, what grade a child gets, what gets disclosed to whom or not — a mistake doesn't look like a typo. It looks like a person who got hurt and can't get an explanation why.
There are three reasons, and any one of them alone would be enough. Bias carries over from the source material. A model learned from what people wrote, prejudices included, and in an evaluation it can reproduce those in a polished form that looks objective. Explainability is missing. A decision you can't justify any other way than “the tool said so” is indefensible to the other party, and in plenty of situations legally defective too. And accountability needs an address. Someone has to be able to stand behind a judgment of a person, explain it, and revise it if needed.
In practice, this leads to a division of labor that works and saves plenty of time. AI may prepare structure and material: writing out criteria in advance, turning your notes into readable form, preparing the same questions for everyone, flagging that information is missing for one candidate, checking whether an evaluation is clear and free of clichés. It may not rank people by suitability, recommend who to hire, or generate an evaluation out of nothing. The guides Hiring with AI and Written feedback and talking to parents show the concrete shape of this.
Extra caution is warranted wherever children are involved. A school context carries three sensitivities at once: minors' personal data, an unequal relationship between the one evaluating and the one being evaluated, and the fact that an evaluation shapes a child. That's why student names don't belong in chat, why a teacher signs off on an evaluation, and why a reply to a parent is always text you've read and stand behind — not whatever appeared in the window.
Regulation, plainly and briefly
There's a lot of noise around AI regulation and not much practical information. For ordinary work, it's enough to understand two things in outline — and to know where general orientation ends and a question for a lawyer begins.
The European AI Act rests on simple logic: obligations track the risk of a given use, not the technology itself. At the top are prohibited practices (social scoring or manipulative techniques, for example), below them high-risk areas, which typically include hiring and HR decisions, access to education, access to essential services, and similar situations that decide something about people's lives. These carry requirements like documented human oversight, transparency, and process records. Below that are uses with a transparency obligation — the user should know they're talking to a machine, or that content was artificially generated — and finally a broad area of ordinary use with minimal obligations. The rollout timelines for individual parts have shifted over time, so check the current text for specific dates; the logic of the categories doesn't change, though, and it's enough to decide whether this applies to you.
For GDPR, what matters for working with AI is that the fundamentals don't change. Personal data needs a legal basis for processing, should be processed to the smallest extent necessary, and a person has the right to know what's happening with their data. Only one question is new: who exactly are you sharing the data with. When you paste personal data into a tool, the provider becomes, from a regulatory standpoint, a data processor, and the organization should have a data processing agreement with them. This, incidentally, is the main substantive reason a business account isn't a luxury but a prerequisite: without an agreement, an organization has no way to document the basis on which the data is leaving.
And now the important part that has to be said explicitly: this site is not legal counsel. General orientation doesn't replace an assessment of your specific situation, obligations differ field by field, and the wording of regulations keeps evolving. If you're working with health data, with children, with employee data, or in a regulated industry, a consultation with a lawyer is cheaper than any consequence. This section has exactly one goal: helping you recognize the situation where someone should be asked.
Trust is a condition, not a bonus
Everything above can be summed up in one quantity that decides whether AI survives longer than a year in your work. That quantity is trust, and it's needed in three directions at once.
First, other people's trust in you. A client, colleague, parent or student hands you material assuming you handle it responsibly. That credit builds slowly and is lost in a single incident — and worse, it's lost across the board. When it turns out one employee uploaded client data to a personal account, nobody says that person failed. They say your organization isn't safe with data.
Second, your own trust in the tool, and it should be deliberately conditional. Blind trust leads to rubber-stamping without reading; distrust leads to not using it at all. The healthy state sits in between: I know where the model is reliable, and I know where I always check it. Nobody can hand you that map — everyone has to earn it through their own experience — which is exactly why it's worth starting on work you know well, where you can spot a mistake.
And third, an organization's trust in its people. Companies that got this right don't have the strictest rules — they have the clearest ones. A few sentences everyone understands, a clear split of data categories, one approved tool, and an open door to ask without risking embarrassment. Where people are afraid to admit they used something, it keeps getting used anyway — just with nobody knowing about it, which is the worst combination of all.
That brings the whole series full circle. It started with a ladder of levels and the question of how high to climb. The answer: as high as you can maintain control, and as high as the data you're working with allows. It isn't the technology but the ability to stand behind the result that determines how far up it makes sense to go — and whoever holds onto that can go quite far, without worry.
What to take away
- Classifying data is a habit that replaces a list of prohibitions. Four categories — public, internal, confidential, personal data — resolve most situations in a few seconds.
- The account matters more than the tool. Sensitive data belongs only where you have contractual data protection; a ban with no alternative just moves the same behavior out of sight.
- Anonymize as routine, not exception. The model needs to know what the situation is, not who it is — and watch out, a combination of indirect details can identify someone too.
- Responsibility can't be delegated. The model isn't accountable for anything, the signature is yours, and how much you check scales with the cost of a mistake, not with how confident the text sounds.
- Disclose wherever the recipient is assuming something different, and where the difference would matter to them. At school, the school's rules apply; with a client, they're buying your judgment and your accountability.
- Hand off mechanics, not thinking. For things that matter, write your own version first; for skills you're still learning, the shortcut is the most expensive option.
- Decisions about people can never leave human hands — because of bias in the source material, the need to explain a decision, and the fact that accountability needs an address.
- It's enough to know regulation in outline: the AI Act's risk categories, and a data processing agreement for personal data. The specific case belongs with a lawyer, not a productivity website.
Want to keep the momentum?
One tip from the handbook by email each week — in an order that makes sense.
1 tip a week · no spam · unsubscribe in one click