Skip to content

Lesson 006Field guide · AI Safety & Privacy

Human Review Rules

Decide what always needs your eyes before it ships.

Beginner12–15 min5 sections · exercise · quick check

You'll learn

  • Why pre-made rules beat in-the-moment judgment
  • Three review tiers, sorted by stakes
  • The never-auto-send list
  • Review rituals that survive your busiest week
  • Your personal AI safe-use checklist — assembled and kept

01Section

Rules beat busy moments

You now know what never gets pasted, how to verify claims, where hallucinations cluster, how to guard sensitive work, and how to pass the comfort test. One risk remains, and it's the biggest: none of that knowledge applies itself at 4:55 on a deadline Friday.

The failure mode of AI safety isn't ignorance — it's hurry. The answer looked fine, the day was long, you hit send. The fix is deciding in advance what always gets your eyes, so the decision is already made when you're too busy to make it well.

A useful analogy

Pilots run pre-flight checklists not because they forget how to fly, but because aviation learned that busy, tired, routine moments are exactly when steps get skipped. Your review rules do the same job — they don't doubt your competence, they protect it.

Checkpoint

02Section

Three tiers, sorted by stakes

Checking AI Outputs sized verification to stakes. Review works the same way — three tiers, decided by one question: what happens if this output is wrong?

  1. Tier 1 — Glance: private and reversible: Brainstorms, your own notes, rough drafts nobody sees. Skim for usefulness and move on. Over-reviewing here is how review budgets die.

  2. Tier 2 — Full read: leaves your desk, carries your name: Emails, posts, documents — anything a colleague or customer reads. Read every line as the recipient would, and verify the load-bearing facts.

  3. Tier 3 — Full review plus: money, law, health, people, public: Contract language, pricing, anything about a person's job or health, public statements. Line-by-line review, facts at original sources, and where stakes warrant it, a second qualified human.

Quick knowledge check: An AI drafted your reply to a customer asking about a billing error. Which tier?

Quick knowledge check

An AI drafted your reply to a customer asking about a billing error. Which tier?

Checkpoint

03Section

The never-auto-send list

Some outputs skip the tier debate entirely — they never go out unread, no matter how good the draft looks or how late it is:

  • Anything to a customer or client. Their trust is the most expensive thing an unread draft can spend.
  • Anything about a person — references, feedback, HR notes, introductions. People remember wrong details about themselves for a long time.
  • Numbers anyone will act on — prices, dates, quantities, budgets.
  • Legal or contract language, even the "boilerplate."
  • Anything public under your name or brand.
  • Anything you'd have to apologize for if it's wrong. If you can already picture the apology, review it now instead.

The test for your own list

If sending it unread makes you slightly nervous, it belongs on the list. The list exists to hold exactly the things hurry would skip.

Checkpoint

04Section

Rituals that survive busy weeks

Rules fail when they depend on willpower. Rituals survive because they attach to actions you already take. Four that hold up:

  • The separate-motion rule

    Never send in the same motion as generating. Draft, break contact for even a minute, reread as the recipient, then send.

  • The name-and-number pass

    Before anything ships, point at every name, number, date, and link and confirm each one. Thirty seconds; catches the worst class of error.

  • Read it aloud

    For anything Tier 2 and up. Your ear catches wrong tone and gaps in logic that your eye skims past.

  • The tired-hours rule

    Know your low-focus hours. Tier 3 output doesn't ship during them — it waits for a fresh read.

Quick knowledge check: What makes a review ritual survive a busy week?

Quick knowledge check

What makes a review ritual survive a busy week?

Checkpoint

05Section

Assemble your safe-use checklist

Everything in this path funnels into one artifact: a personal safe-use checklist — short enough to keep in sight, specific enough to act on. Four lines, one from each theme you've covered — plus a fifth for the ritual that keeps them running:

  • What I never share: Your never-paste list, plus whatever is specific to your work — client names, patient details, unreleased plans.
  • What I always verify: Your risk zones: the facts, numbers, and sources you never repeat unchecked.
  • What always gets human review: Your Tier 3 and never-auto-send items, in your own words.
  • My disclosure rule: The one-sentence rule you wrote in Ethical AI Basics.

Copy and fill in — the safe-use checklist template

MY AI SAFE-USE CHECKLIST

1. I never share: passwords or credentials, government or financial IDs, other people's private data, confidential work material — and: [your additions]

2. I always verify before repeating or relying: facts, numbers, names, dates, quotes, links, calculations — especially: [your highest-risk items]

3. Always gets my full review before it ships: anything to a client or customer, anything about a person, numbers people will act on, legal language, anything public — and: [your additions]

4. My disclosure rule: [when I say AI helped]

5. My ritual: [e.g., separate-motion rule + name-and-number pass]

Key takeaway

A checklist you keep beats a course you remember. Five short lines, kept where you work, is the whole system.

Checkpoint

Prompt exercise

Build your personal safe-use checklist

This is the path capstone — it produces the artifact you keep. Copy this prompt into ChatGPT, Claude, Gemini, Copilot, or whichever AI tool you have access to (the website doesn't run AI itself). Answer its questions honestly, and you'll end with a checklist tailored to your actual work. Then put the result somewhere you'll see it — your notes app, a sticky note, the top of your task list.

I've just finished a course on using AI safely, and I want to build my personal AI safe-use checklist. Interview me one question at a time — my line of work, the sensitive information I handle, what I create with AI, and who relies on my output. Then draft my checklist in five short sections: 1) What I never share with AI tools, 2) What I always verify before relying on it, 3) What always gets my full human review before it ships, 4) My disclosure rule for when I say AI helped, 5) My review ritual — the habit I attach to sending. Keep each section to 2–4 plain lines I can act on, make it specific to my answers rather than generic advice, and format the final result as plain text I can copy and keep.

Reflection: Where will this checklist live so you actually see it? A checklist in sight beats every rule you merely remember.

Quick check

4 quick questions — no pressure

There's no pass or fail here. Answer them all, and we'll show you the answers either way.

1. Why decide review rules in advance instead of case by case?
2. Which output belongs in Tier 3 — full review, possibly with a second human?
3. What defines the never-auto-send list?
4. The separate-motion rule means: