Appendix C

Responsible and Ethical AI Use

What may never be pasted into public AI, PII/HIPAA/FERPA, copyright, consent and disclosure, and how to cite AI

Appendix C — Responsible and Ethical AI Use

“Whoever goes about slandering reveals secrets, but he who is trustworthy in spirit keeps a thing covered.” — Proverbs 11:13 (ESV)

This is the appendix the whole course leans on. Week 6 rewrites your email with it open; Week 7 summarizes a document with it open; Week 9 generates images, Week 10 clones a voice, and Week 14 builds your personal AI-use policy straight out of it. Read it once, all the way through, before you paste your first real work-thing into a chatbot. Then keep it open. The tools in this book change every quarter. The discipline in this appendix does not.

Let me be plain about the stance, because there is loud bad advice on both sides. We are not AI-fearful and we are not AI-drunk. AI is the most powerful professional tool of your lifetime, and you should be fluent with it. And it is the fastest way yet invented to leak a client’s data, launder someone else’s work, or sign your name to a lie you didn’t check. Both are true at once. The whole appendix is one sentence, the spine of every book in this library:

You choose the tool. You own the verdict. AI drafts, generates, and accelerates; you decide, verify, and are accountable. AI is an assistant, not an authority.

Everything below is that sentence, applied to the places where a professional gets hurt.


C.1 — The Never-Paste List (data that must not go into a public AI)

Start here, because this is the mistake that ends jobs and breaks laws before you’ve even thought about ethics. When you type into a free or consumer chatbot — ChatGPT, Claude, Gemini, Grok, the free tier of anything — you are, in general, sending that text to someone else’s computer, where it may be logged, reviewed by humans, or used to train future models unless a contract says otherwise. Treat the box like a postcard, not a diary. Before you paste anything, run it through one question: is this mine to share?

Never paste any of these into a public/consumer AI tool:

  • Personally identifiable information (PII) about anyone but yourself — full names tied to addresses, phone numbers, dates of birth, Social Security or national-ID numbers, account numbers, driver’s-license or passport numbers, biometric data.
  • Protected health information (PHI) — anyone’s diagnosis, treatment, medications, test results, insurance/claim details, or the fact that a named person is a patient. (See HIPAA, C.2.)
  • Student education records — grades, disciplinary records, disability accommodations, anything identifiable about a specific student. (See FERPA, C.2.)
  • Secrets and credentials — passwords, API keys, access tokens, private keys, security question answers, internal URLs, network diagrams. A pasted key is a leaked key.
  • Confidential or proprietary work product — unreleased financials, M&A or legal-matter details, source code you don’t own the rights to share, trade secrets, unpublished research, contract terms under NDA, customer lists, pricing you’re contractually bound to protect.
  • Other people’s private information, full stop — a colleague’s performance review, a client’s case, a friend’s confession, a message someone sent you in confidence. It is not yours to feed to a machine, even if the machine feels private.

The three-bucket habit — “Can I paste this?” For any snippet, sort it into one of three buckets before it touches the box:

  1. SAFE — public information, your own general questions, text with every identifier already stripped. Paste freely.
  2. REDACT — useful to process, but you must remove or replace names, numbers, and identifiers first. Swap “our client Acme Corp’s $4.2M shortfall” for “a client’s budget shortfall.” Then it’s safe.
  3. NEVER — PHI, PII you don’t own, secrets, confidential/proprietary material. It does not go into a public tool at all. If you genuinely need AI on it, use a tool your organization has vetted and contracted for (an enterprise plan with a no-training / data-processing agreement, or a local model that never leaves your machine — Week 11).

Coach’s Note — The safest instinct is the pause. Before you hit paste, ask: if this appeared on the front page tomorrow with my name attached, would I be fine? If your stomach drops, you’re holding a REDACT or a NEVER. That one-second pause is the single most valuable habit in this book. Build it before you build anything else.

Two more rules that save you:

  • Check your settings. Most consumer tools now offer a “don’t train on my chats” toggle and a temporary/incognito chat mode, and some let you turn off history entirely — turn these on. But never trust a toggle with a NEVER-bucket item; a setting is a preference, not a contract.
  • Know your org’s policy before you paste, not after. Many workplaces have an approved-tools list, a banned-data list, or a required enterprise account. Find it first. Week 14 has you write your own one-page policy so this becomes reflex instead of a scramble.

C.2 — HIPAA, FERPA, and the privacy laws behind the list

The Never-Paste List isn’t just etiquette. For two big categories it’s the law, and a casual paste can be a reportable breach. Here is what a non-lawyer professional needs to hold — enough to stay out of trouble and know when to call someone who is a lawyer. None of this is legal advice; when the stakes are real, ask your compliance office.

HIPAA (U.S. health privacy). If you work in or near healthcare — a clinic, a hospital, a benefits office, a wellness vendor, even an HR desk that handles medical leave — you touch protected health information (PHI): health details tied to an identifiable person. Pasting PHI into a consumer chatbot is, as of mid-2026, a likely HIPAA violation, because the vendor is now handling patient data without the required contract. HIPAA lets a “covered entity” share PHI with a technology vendor only under a signed Business Associate Agreement (BAA) that legally binds the vendor to protect it — and free/consumer AI tools do not come with a BAA. The rule to carry: no patient information goes into any AI tool that your organization hasn’t signed a BAA with. De-identify first, or use the approved system, or don’t.

FERPA (U.S. education privacy). If you work in a school, college, district, or edtech role, student education records — grades, attendance, discipline, IEP/504 accommodations, anything identifiable about a specific student — are protected under FERPA. A teacher or staff member feeding identifiable student data into a consumer AI tool to “help write the report” is exactly the move FERPA is built to prevent, because you’ve disclosed a protected record to an outside party without authorization. The rule: strip student identifiers before any AI help, or use only a tool the institution has formally approved for student data. “It was just to save time on comments” is not a defense you want to test.

GDPR (EU) and CCPA/CPRA (California), in one line: these baseline data-privacy laws govern any personal data of any covered person you put into AI — so don’t paste customers’, employees’, or the public’s personal data into consumer tools without a lawful basis and a vendor contractually barred from training on it; when in doubt, redact.

Coach’s Note — You do not have to memorize statutes. You have to memorize one instinct: other people’s identifiable data is a trust, not raw material. HIPAA and FERPA are just two places where the state agrees with Scripture that a trust kept covered is a moral duty (Proverbs 11:13). Guard the deposit entrusted to you (1 Timothy 6:20, ESV). When the data belongs to a patient, a student, a customer — pause, redact, or ask before you paste.

Why BoodleBox is the safer place for Concordia data

So what are you allowed to run this stuff through? At Concordia you have a real answer, not a shrug. BoodleBox — the AI platform CUW licenses for the whole campus (sign in with your Concordia account at box.boodle.ai) — is exactly the “tool your organization has vetted and contracted for” that C.1 sends you to when a task genuinely needs AI on data you don’t fully own. As of 2026 it is FERPA-compliant, SOC 2 certified, and it does not train on your data. That combination is the difference between an approved system and a postcard: your prompts aren’t quietly folded into someone’s next model, and the vendor is contractually on the hook to protect what you send. So for Concordia coursework, FERPA-covered student records, and internal university work, BoodleBox is the appropriate place to bring the content — where a random public chatbot, with no agreement and a “we may train on your chats” default, is not.

That is a genuine shift, and it’s the reason this edition sends you to BoodleBox first. But read the next two lines twice, because being on a vetted tool does not repeal anything above it:

  • Still no needless PII. “Vetted” is not “dump everything in.” Minimize anyway: if the task doesn’t need a student’s ID number, a home address, or a full roster of names, strip it — data you never send is data that can never leak, even inside an approved tool. The three-bucket habit (C.1) still runs; a vetted tool just widens what the REDACT bucket may safely carry once it’s institutional work.
  • HIPAA/PHI is a separate question. BoodleBox being FERPA/SOC-2 does not by itself mean it carries the Business Associate Agreement that patient health information requires (C.2). Don’t read “safe for school data” as “safe for medical data.” For PHI the BAA rule stands unchanged, and when you’re unsure whether a category is covered, ask CUW’s IT or compliance office before you paste, not after.

The spine doesn’t move: you still own the verdict, you still pause before you paste, you still guard the deposit entrusted to you (1 Timothy 6:20, ESV). BoodleBox simply means that when Concordia work legitimately needs AI, you have a vetted door to walk through instead of a forbidden one. (Off-campus, or after your license lapses, the same task falls back to a public tool with its “don’t train on my chats” setting on — but for real Concordia data, the vetted tool is the point.)


Three questions matter here: Who owns what the AI makes? Can the AI’s makers even legally use what they trained on? And how do I use this stuff without getting sued or embarrassed? As of mid-2026 the honest answer to the first two is “the law is still being written” — so I’ll give you the durable posture, not false certainty.

Who owns AI output? In the United States, Copyright Office guidance as of mid-2026 has held that purely machine-generated content is not eligible for copyright — a protectable work needs meaningful human authorship. Practically: the more you shape, select, edit, and arrange the output, the stronger your claim to the result; a one-click generation you didn’t touch may be no one’s property, which means others can freely reuse it too. Check the current guidance and your vendor’s terms of service, which also spell out what they claim and what they grant you. Rules differ by country. Verify before you build a business on ownership you assumed.

Can the models legally train on their data? Unsettled and litigated. As of mid-2026, music generators (Suno, Udio) are in active litigation with the major record labels — Suno reached a reported settlement with one label in late 2025 while other suits continue — and there are multiple ongoing suits over text and images. Present these as open legal questions, not settled law, and never advise anyone (including yourself) that a given use is “definitely fine.”

Safe-use guidance for professionals (durable regardless of how the suits land):

  • Match the tool to the risk. For client-facing or commercial work, favor tools that train on licensed or public-domain data and offer IP indemnification — Adobe Firefly is the market’s clearest example as of mid-2026, promising commercial safety and standing behind eligible outputs. That indemnity is a real business differentiator, not marketing.
  • Don’t launder someone else’s work. “Make it in the style of [living artist]” or feeding a copyrighted book in to reproduce it is a legal and ethical minefield. Use AI to make your thing, not to photocopy someone else’s.
  • Read the license on what you generate, especially for logos, brand assets, and anything you’ll sell. Terms vary by tool and by plan.
  • Keep humans in the authorship loop — both because it strengthens any ownership claim and because it’s the honest description of the work.

This is the category that has gone from science fiction to a phone app in three years, and it is where AI most easily becomes a weapon against a real person. Cloning a voice or a face from a few seconds of sample is trivial as of mid-2026. That power comes with two hard obligations: consent and disclosure.

Consent — whose voice, whose face, whose words? You may generate a synthetic voice or likeness of a person only with that person’s informed permission — and that includes you. Week 10 has you clone your own voice on purpose, so you feel the mechanics and the ethics from the inside. You may never clone a colleague, a client, a public figure, or a family member “just to test it.” A likeness is part of a person; using it without consent is a form of bearing false witness against your neighbor (Exodus 20:16, ESV).

Disclosure — is the audience being deceived? Synthetic media that a reasonable person would take for real must be labeled as synthetic when it’s used anywhere it could mislead — a narration, an ad, a “photo,” a video of someone saying something. Two technical helps are worth knowing, and so are their limits: C2PA / Content Credentials attach signed “how this was made” metadata to a file (rich, but strippable by a screenshot or re-upload), and SynthID bakes an invisible watermark into the pixels/audio itself (durable through edits, but thin on detail). As of mid-2026 the major makers are converging on using both layers. They help provenance; they do not replace your duty to say “this is AI-generated.”

The fraud angle every professional must internalize: voice-cloning and face-swapping mean “I recognized their voice/face” is no longer proof of identity. The well-documented case: in January 2024 a finance employee at the firm Arup paid out roughly US$25.6 million after a video call in which every “colleague,” including a fake CFO, was a deepfake. The defense is out-of-band verification — call back a known number, use an agreed code word, require dual approval for any money movement or sensitive change. Teach your team this before it’s your turn.


C.5 — How to Disclose and Cite AI Use

Being caught hiding AI use is far worse than the AI use itself. Disclosure is cheap, honest, and protective. The heuristic that makes most decisions easy:

  • Assistive use needs no disclosure. Spell-check, grammar fixes, autocomplete, a tool that polished a line you already wrote. Nobody discloses spell-check.
  • Generative use should be disclosed. When the model originated substantive content — text, images, code, data, analysis, or an idea — that a reader would assume you authored, say so. When the line is fuzzy, disclose.

Disclosing professionally (to a client, employer, reader, or audience). Be brief, specific, and honest about the human role: “Portions of this report were drafted with generative AI and reviewed, edited, and verified by [name].” For a synthetic voice or image: “AI-generated voice” / “Image generated with AI.” Match your organization’s policy, and never let a disclosure imply more human oversight than actually happened — a false disclosure is its own lie.

The everyday version is simpler than it sounds. If a client asks “did you write this?” the honest answer to “I drafted it with AI help and then checked and edited every line myself” is a stronger answer than a nervous “yes,” because it’s true and it shows your value is the judgment, not the typing. The professionals who get in trouble are the ones who hid it and got caught, not the ones who said so plainly.

Citing academically (a class, a paper, a credential). Treat the tool like a source and record what makes it reproducible:

  • Name the tool and the exact model version, plus the date — “Claude Opus 5 (claude-opus-5), accessed July 2026,” not “an AI.” Models drift; an undated model name is unreproducible.
  • Say what you used it for and where — which section, which task (“used to brainstorm section headings,” “used to draft the first version of the summary, then verified against the source”).
  • Keep the prompt if it materially shaped the result; many instructors now ask for it.
  • Follow the required style guide. The major academic styles (APA, MLA, Chicago) have each published generative-AI citation formats as of mid-2026 — check the current version of the one your institution requires, since the formats are still being revised.

Coach’s Note — The rule of thumb that has never failed me: would I be comfortable if the person reading this knew exactly how it was made? If yes, you’ve probably disclosed enough. If the honest answer requires hiding something, that’s not a disclosure problem — that’s a “don’t do it” problem.


C.6 — Bias, Fairness, and Transparency

An AI model learns from an enormous pile of human writing and images, and it absorbs the biases in that pile — about gender, race, age, disability, nationality, and more. So it will, unprompted, produce a “CEO” who is a man and a “nurse” who is a woman, rank résumés in skewed ways, or write about some groups in stereotyped terms. This is not a rare glitch; it is baked in, and a confident, fluent tone hides it well.

What that means for you as a professional:

  • Never let an AI make a high-stakes decision about a person on its own — hiring, firing, promotion, lending, admissions, discipline, benefits, medical triage. AI may inform these; a human owns the decision and must be able to justify it without “the model said so.” This is the spine rule at its sharpest: the higher the stakes for a real person, the more the verdict must stay human.
  • Test for skew when the output touches people. Ask the model to critique its own output for bias; try the same prompt with names or details from different groups and watch what changes; have a second human review.
  • Practice transparency. People affected by an AI-assisted decision deserve to know AI was involved. Hiding the machine to dodge scrutiny is the opposite of the accountability this book is built on.

A concrete example to keep you honest: a manager who asks AI to “rank these ten résumés” has just handed a life-affecting decision to a system that may quietly downgrade a candidate for a gap year, a foreign-sounding name, or a women’s-college degree — and will present the ranking in the same calm, competent tone it uses for everything. The tone is the trap. Use the model to summarize what each résumé contains if you must; own the ranking yourself, on criteria you can state out loud.

Fairness is not a feature you can buy in a model. It’s a responsibility you carry to the output.


C.7 — The Environmental Cost

Every AI query has a physical footprint. Training a frontier model and then answering millions of prompts runs on large data centers that consume real electricity and real water for cooling — a small amount per query, but a material amount in aggregate, and heavier for the biggest “frontier” and reasoning models and for image/video generation than for a short text answer. Exact figures are contested and largely come from vendor or advocacy estimates, so I won’t hand you a number to quote; the durable lesson is one you already met in Week 3: right-size the tool. Don’t spin up a frontier reasoning model to rephrase one sentence when a small, fast model — or your own brain — will do. Counting the cost (Luke 14:28) turns out to be good stewardship of your budget and of the creation you were given to tend. Frugality with the tool is not stinginess; it’s respect for what the tool actually costs.


C.8 — The Human Owns Every Verdict

Everything in this appendix collapses to one operating posture. The model proposes; you dispose. These are yours, never delegated, never “the AI handled it”:

  • What is true — every fact, number, name, and citation, verified by you against the real source before it carries your name.
  • What may be shared — every paste checked against the Never-Paste List; every trust kept covered.
  • What is fair — every decision about a real person owned and justified by a human.
  • What is disclosed — honest about how the work was made, to anyone who’d reasonably want to know.
  • What it all means — the judgment, the interpretation, the “we shouldn’t do this even though we can.” A model gives you a confident answer; only you can give an accountable one.

The line between using AI well and doing harm is not the amount you use. A whole report drafted with AI, fully verified, properly disclosed, is honest work. A single unchecked PHI paste, a single fake citation, a single deepfake without consent is misconduct. The difference is you — in the loop, doing the judgment only a human can be answerable for.

Coach’s Note — The most dangerous sentence in your professional life is “the AI said so.” Said about a grammar fix, it’s nothing. Said about a diagnosis, a hire, a legal claim, a client’s data, or a person’s likeness, it’s the sound of the work slipping out of your hands while your name stays on it. Stay in the loop. AI is the fastest assistant you’ll ever have — and one who is never, on the things that matter, in charge.


C.9 — The Field Checklists (tear these out)

Everything above, compressed into cards you can actually use at your desk. Print them. Tape them near your screen. Run them until they’re reflex.

Before you paste — the 60-second gut check:

  • Is this text mine to share, or does it belong to a patient, student, customer, colleague, or my employer?
  • Any names, numbers, or identifiers to strip first (PII)? Any health (PHI) or student-record (FERPA) data? Any secrets, keys, or passwords?
  • If it’s confidential/proprietary — is this an approved tool (enterprise plan with a no-training agreement, or a local model), or a public chatbot?
  • Front-page test: if this showed up publicly with my name on it, am I fine?
  • Bucket it: SAFE (paste) · REDACT (fix, then paste) · NEVER (don’t).

Before you ship AI-assisted work:

  • Verified every fact, number, and citation against the real source — no “I’ll check it later.”
  • Disclosed the AI use honestly where a reader would reasonably want to know, without overstating my own oversight.
  • For academic work: named the exact model + version + date, said what I used it for, kept the prompt if it mattered.
  • Checked output for bias wherever it touches real people; no high-stakes decision left to the machine.
  • Any synthetic voice/image/video carries consent and a clear “AI-generated” label.
  • For anything high-stakes, I kept a short note of what the AI did and where I stepped in — the agent-log habit from the projects.
  • I can defend every sentence in my own words. If not, it comes out.

When money or identity is on the line (the deepfake defense):

  • “I recognized their voice/face” is not proof of identity.
  • Verify out of band — call back a known number, use a code word.
  • Require dual approval for money movement or sensitive changes.

A theological footnote. “He who is trustworthy in spirit keeps a thing covered” (Proverbs 11:13, ESV). Every rule in this appendix is that verse worked out in a world of pasteable data and cloneable voices. A patient’s record, a student’s file, a client’s secret, a friend’s confidence — each is a deposit entrusted to you, and Paul’s charge to Timothy is exactly the charge to you at the keyboard: “guard the deposit entrusted to you” (1 Timothy 6:20, ESV). The eighth commandment — “You shall not bear false witness against your neighbor” (Exodus 20:16, ESV) — Luther’s Small Catechism widens into the positive duty to defend our neighbor, speak well of him, and “explain everything in the kindest way.” A synthetic voice, a deepfaked face, a hidden AI decision, a quietly leaked confidence — each is a small false witness against a real neighbor. A machine cannot bear the duty to be trustworthy. You can. You choose the tool; you own the verdict; and you answer, before God and neighbor, for what you do with both.


Up next: Back to your work. The on-ramp and free-tier setup: Appendix A. The tool directory behind Weeks 5, 9, and 10: Appendix B. The plain-language glossary: Appendix D. This appendix governs Week 6 (email you verify), Week 7 (summaries you fact-check), Week 9 (image rights), Week 10 (voice consent), Week 11 (privacy and local models), and Week 14 (your own AI-use policy) most directly — re-read it before each of those, and before you paste anything you’re not sure about.