Book 1 · Chapter 7: What AI Gets Wrong (and How to Protect Yourself)
This page gives you a printable personal AI safety checklist and a never-share list.
This page assumes you've read the chapter. It hands you the tools, not the lessons.
Personal AI Safety Checklist
Before you start
- Am I on the right plan for the sensitivity of this information?
- Have I checked my privacy settings?
- Am I describing the situation rather than pasting confidential details?
- If this is personal (health, finances, relationships), am I comfortable with this information being on a remote server?
Before you use the output
- Did I read the full output? (Not skim. Read.)
- Did I run the three-check verification from Chapter 5? (Smell test, key facts, what's missing)
- Are there specific facts, citations, or numbers I need to verify independently?
- Does anything sound too good to be true, too specific without a source, or suspiciously convenient?
- Would I stake my professional reputation on every claim in this document?
Before you send (or act on it)
- Is this going to a client, boss, regulator, or public audience? If yes, extra scrutiny.
- If this is a personal decision (health, money, legal, family), have I consulted an actual professional or trusted person, not just AI?
- Did I add my own judgment, experience, and personal knowledge?
- Have I checked for bias in assumptions or defaults?
- Would I be comfortable if someone asked me to explain or defend any part of this?
The reputation test: before you send anything AI helped create, ask yourself: if someone discovered this was partially AI-generated, would I be embarrassed by any part of it?
From the Building Your Personal AI Safety Checklist section.
The “Never Share” Poster
- Client or customer personal data.
Names paired with financial details, health information, social security numbers, account numbers. Even if your plan doesn't use data for training, you may be violating data protection laws (GDPR, HIPAA, state privacy laws) by sending this data to a third-party processor without proper agreements in place.
- Passwords, API keys, and authentication credentials.
This sounds obvious, but people paste code containing hardcoded credentials, paste configuration files with API keys, and describe their system architecture including access methods. Don't.
- Confidential business information without training opt-out.
Trade secrets, proprietary formulas, unreleased product plans, M&A details, legal strategy. If it would be a problem if a competitor saw it, don't put it into any AI tool where your conversations might be used for training, whether that's a free plan or a paid plan where you haven't turned the training toggle off.
- Other people's private communications without consent.
Pasting a colleague's private email, a friend's text messages, or a patient's records into AI raises ethical issues even if it doesn't violate a specific law. This goes for personal life too: pasting your partner's texts to get AI's take on an argument, sharing your friend's confidential situation to get advice, uploading your kid's school records. Ask yourself: would this person be comfortable knowing I shared this with an AI tool?
From the “Never” List section.