Safe AI use comes down to a short set of habits every employee can hold in their head: know what's off-limits to share, verify anything specific before you trust it, review before anything goes external, and use an approved tool rather than whatever's convenient. This checklist turns those habits into something concrete enough to actually follow day to day - not a policy document you read once and forget.
Print it, pin it, or fold it into onboarding. It's meant to be used, not filed away.
Before You Type Anything In
☐ Is this an approved tool?
Confirm you're using a company-approved AI tool on a business-tier account, not a personal free account, especially for anything involving real company or customer information. See is ChatGPT safe for company data for why this distinction matters.
☐ Does this contain anything on the "never share" list?
Before pasting anything in, run a quick mental check: customer personal data, financials, legal matters, credentials, or anything under NDA. If in doubt, leave it out or redact it. The full list is in what not to share with AI.
☐ Could I redact this instead?
If the task doesn't actually need the real name, exact figure, or specific identifying detail, swap it for a placeholder - "Client A," "$X," "Employee 1." Same usefulness, lower risk.
While You're Working With AI
☐ Am I treating this as a draft, not a finished product?
AI output is a fast starting point, not a final answer. Plan to read it critically and edit it, the same way you'd treat a first draft from a junior colleague.
☐ Have I flagged anything specific and checkable?
Numbers, dates, names, quotes, and citations are the categories most likely to be confidently wrong (see AI hallucinations explained). Mentally flag these as "needs verification" as you go, rather than trying to remember at the end.
Before You Send, Publish, or Act on It
☐ Have I verified every checkable claim?
For anything specific and factual, confirm it against a real source before it goes anywhere important. Our how to verify AI output guide walks through the process step by step.
☐ Has a human reviewed this before it goes external?
Anything client-facing, published, or decision-driving should get a real read-through by a person - not just a glance - before it leaves your hands. This is non-negotiable for anything with real consequences if wrong.
☐ Does this need disclosure?
Some contexts (contracts, published content, certain client relationships) call for disclosing that AI was involved. If you're unsure, ask - don't guess, and don't assume it never matters.
☐ Am I comfortable if this became visible internally?
A useful gut-check: if a colleague or manager saw exactly what you typed into the AI tool, would you be comfortable with that? If not, that's usually a sign something on the "never share" list slipped through.
Quick Reference: The Four Habits
If you remember nothing else, remember these four:
- Use the approved tool, not a personal account, for anything involving real company data.
- Never share customer data, financials, legal matters, or credentials - redact instead when possible.
- Verify anything specific - numbers, quotes, citations - before you trust or send it.
- Get human review before anything AI-assisted goes external.
Four habits, repeated consistently, cover the overwhelming majority of realistic AI risk at a typical business. Nothing on this list requires technical expertise - it requires knowing the rules and actually applying them, which is a training problem more than a technology problem.
What This Checklist Doesn't Replace
This is a quick-reference tool for daily use, not a substitute for a full AI acceptable use policy, which should spell out approved tools, escalation contacts, and consequences in more detail. Think of the checklist as the everyday habit and the policy as the reference document it's built from.
Making the Checklist Stick
A checklist pinned to a wall or buried in a wiki only works if people actually internalize it. What makes it stick:
- Walk through real (redacted) examples during onboarding rather than just handing over the list.
- Repeat it in context - reference it during actual AI-related training, not as a standalone document.
- Make it visible - a shared doc, a Slack pinned message, or built directly into the tools your team already uses.
- Revisit it periodically, especially after adopting a new AI tool or feature.
Build These Habits Into Real Training
A checklist is a great memory aid, but habits actually form through practice - seeing real examples, making a mistake in a low-stakes setting, and correcting it. That's exactly how CourseFluent's courses are built: every learner practices safe AI use with realistic, department-specific scenarios and a knowledge check to confirm it landed, not just a document they skim once.
Start your free CourseFluent account and turn this checklist into a habit your whole team actually follows. See our features page for how safe-use training fits into the full curriculum.
FAQ
How often should employees revisit this checklist?
Ideally it becomes second nature after a few weeks of conscious use, similar to how spellcheck habits form. Revisiting it formally during onboarding and after any major AI tool change is a reasonable cadence.
Is this checklist different for different departments?
The core habits are universal, but the specific examples of "what's sensitive" vary - a finance team's checklist examples center on financial figures, while a support team's center on customer PII. Department-specific training makes the checklist concrete rather than abstract.
What if an employee isn't sure whether something is safe to share?
Default to "don't share, or redact first" and ask. A quick question to a manager or the person who owns your AI policy is always faster and safer than guessing on something that can't be undone once it's typed in.



