Protect what goes in.
Use approved tools and keep confidential, regulated, proprietary, client, and security information out of unapproved AI services.
RESOURCE / RESPONSIBLE AI
A practical employee guide for making better decisions before information goes into an AI tool, while it acts, and before its work is used.

THE TEN-SECOND CHECK
THREE RULES
Use approved tools and keep confidential, regulated, proprietary, client, and security information out of unapproved AI services.
Limit permissions and integrations to the task. Use logging and human approval for actions that can affect people, systems, money, or customers.
Check accuracy, sources, assumptions, bias, confidentiality, and technical or professional correctness before relying on the work.
INFORMATION TO PROTECT
If you are unsure whether a platform or use case is approved, stop and ask before proceeding.
HIGHER-AUTONOMY AI
When AI can connect to systems or take actions, treat it like a privileged operator—not merely a writing tool.
Give the workflow only the information and permissions required for the approved task.
Keep enough activity history to understand what happened, when, and under whose authority.
Require review before consequential changes, communications, transactions, or decisions.
Maintain a clear way to pause access or disable the workflow when behavior or risk changes.
FOR AEC & PROFESSIONAL WORK
Contracts, drawings, models, specifications, calculations, estimates, and code-related work can carry client, legal, safety, and professional obligations.
Confirm jurisdiction, code edition, source material, assumptions, and technical accuracy. A qualified professional should review work before it affects a project or deliverable.
Evaluating a new platform?
Open the AI evaluation guide Explore AI operations →LET’S TALK ABOUT WHAT’S NEXT