Safety Center

Guardrails and responsible-use guidelines for AI tools.

Protecting Your Privacy

When you use an AI chat tool or agent, you are having a conversation with a system that processes data. What you share matters. Treat public AI tools like a conversation in a crowded coffee shop: do not say anything you would not want others to overhear.

Here is a simple rule: never share passwords, access codes, private health data, confidential client information, financial identifiers, or protected work material.

To help you decide what is safe to share, use this quick guide:

| Category | Examples | Action | |---|---|---| | Safe to Share | General questions, hobby ideas, public recipes, brainstorming topics. | Go ahead. These do not contain personal or sensitive details. | | Ask First | Work emails without names, general financial concepts, anonymized data. | Review carefully. Remove any identifying information before sharing. | | Never Share | Passwords, Social Security numbers, bank details, medical records, private client files. | Stop. Do not enter this information into any public AI tool. |

The Independent-Channel Scam Rule

Scammers are using AI to clone voices and create convincing messages that sound exactly like your boss, a friend, or a family member asking for urgent help or money. The Federal Trade Commission (FTC) warns that these deepfakes can make fraud much more believable.[1]

The most important defense is not trying to guess if a voice sounds real. Instead, use the Independent-Channel Rule: Do not verify a suspicious message through the same call, text, email, or link that delivered it.

If you get a strange or urgent request:

  1. End the contact immediately.
  2. Verify the story by calling the person on a phone number you already know belongs to them.
  3. If you cannot reach them, contact another trusted family member or friend.

Deepfake and Voice-Clone Guidance

A deepfake is an image, video, or audio recording that has been edited or generated by AI to look and sound like someone else. They can be used for harmless entertainment, but they are increasingly used for deception.

When you see a surprising video or hear an alarming audio clip:

  • Pause before reacting or sharing. Emotion is the enemy of verification.
  • Check the source. Is this coming from a recognized, reputable news organization?
  • Look for inconsistencies. Sometimes deepfakes have strange lighting, unnatural blinking, or audio that does not quite match the lip movement, though these errors are becoming harder to spot.
  • Rely on the Independent-Channel Rule. If it involves someone you know, verify it separately.

High-Stakes Decision Boundaries

AI is a helpful assistant for drafting and brainstorming, but it must not be the final decision-maker for anything that seriously affects a person's life, rights, or well-being. The National Institute of Standards and Technology (NIST) emphasizes the importance of human oversight and risk management.[2]

We use a simple matrix to determine when AI can act and when a qualified human must take charge:

| Tier | Type of Decision | Rule | Examples | |---|---|---|---| | Low-Stakes | Harmless, reversible, no significant impact. | AI can draft or suggest; you review quickly. | Drafting a polite email, planning a weekend itinerary, suggesting dinner recipes. | | Review-Required | Important, moderate impact, requires accuracy. | AI can assist, but a human must carefully verify every detail before action. | Summarizing a long public report, drafting a business proposal, analyzing non-sensitive market data. | | Do Not Delegate | High impact, irreversible, involves rights, safety, or compliance. | A qualified human authority must make the final decision. AI is not sufficient. | Medical diagnoses, legal advice, financial investments, hiring/firing decisions, security access, approving large transactions. |

Always preserve qualified-human review for medical, legal, financial, employment, security, and account-access decisions.

Workplace Confidentiality

If you use AI at work, you must protect your employer's and your clients' information. Many organizations are still developing their AI policies. The International Labour Organization notes that individual experimentation often outpaces official company guidance.[3]

Until your workplace provides clear rules, follow these steps:

  • Assume everything you type is saved. Do not use public AI tools for confidential company business.
  • Ask for permission. Before using an AI tool for work tasks, check with your manager or IT department.
  • Use approved tools. If your company provides a secure, enterprise version of an AI tool, use that instead of a free public version.

Family Safety Plan

Talk to your family about AI safety before a problem happens. A family safety plan should include:

  1. The Independent-Channel Rule: Agree that if anyone receives an urgent request for money or help, they will hang up and call back on a known number.
  2. A Family Code Word: Choose a unique word or phrase that only your family knows. If someone calls claiming to be a family member in trouble, ask for the code word. (Remember, this supplements the Independent-Channel Rule; it does not replace it.)
  3. Open Conversation: Encourage everyone to talk about strange messages or videos they see online without judgment.

Incident Response Steps

If you realize you have shared sensitive information or fallen for an AI-generated scam, do not panic. Take these steps immediately:

  1. Stop communicating. Do not reply to the scammer or send any more information.
  2. Secure your accounts. Change your passwords for any accounts that might be compromised. Enable two-factor authentication if you have not already.
  3. Contact your bank. If financial information was involved, call your bank or credit card company immediately to freeze your accounts and report the fraud.
  4. Report the incident. If you suspect a scam, report it to the FTC at ReportFraud.ftc.gov.[4]
  5. Tell someone. Scammers rely on shame. Tell a trusted friend or family member so they can support you and help you navigate the next steps.