Privacy, Ethics, and Organizational Policy
What does it mean to be trustworthy in spirit — to keep a confidence covered?
Chapter 14 — Privacy, Ethics, and Organizational Policy
“The Internet never forgets.” — a common adage of the digital age
“Whoever goes about slandering reveals secrets, but he who is trustworthy in spirit keeps a thing covered.” — Proverbs 11:13 (ESV)
Why This Matters
For thirteen weeks I have been teaching you to reach for AI — to choose the model, write the prompt, generate the image, delegate to the agent, and verify what comes back. This week I teach you to hesitate. Not out of fear. Out of judgment.
Here is the uncomfortable truth about a consumer AI chatbot. It feels like a private conversation — just you and a helpful assistant in a quiet little window. It is nothing of the sort. When you paste text into a free or personal-tier tool, that text leaves your building, travels to someone else’s servers, may be retained, may be reviewed by a human for safety or quality, and — depending on the tier and the terms — may be used to train the next version of the model. The window is quiet. The data pipeline behind it is not. And unlike a bad email, you cannot recall what you sent. The Internet never forgets, and a paste is forever.
Now put a real professional on the other side of that paste. A nurse pasting a patient’s lab result to “word it more gently.” A teacher pasting a struggling third-grader’s reading scores to “draft a kind note to the parents.” A consultant pasting a client’s confidential contract to “explain this clause.” A coordinator pasting the HR spreadsheet — names, salaries, Social Security numbers — to “clean this up.” Every one of those is a normal, well-meaning, five-second decision. Every one of them can be a fireable, sue-able, license-losing, trust-breaking mistake. Not because the person was careless with the work — but because they never learned to ask, before pasting, one question: whose secret is this, and where is it about to go?
That question is the whole chapter. This is a drill week — no new project, but a graded lab called Data Redline where you will classify a stack of realistic workplace snippets as safe / redact / never and write your own one-page AI-use policy. Consider this the week we install the reflex that keeps every other week from getting you in trouble.
And it is where the spine rule of this whole course turns from a slogan into a duty:
You choose the tool. You own the verdict. AI drafts, generates, and accelerates — but you decide what goes into it, you verify what comes out, and you are accountable for both. AI is an assistant, not an authority — and an assistant you would never hand a sealed envelope marked Confidential and say “post this wherever you like.”
This week’s question is a question of trust — the plain, old, human kind. Scripture draws the line cleanly: “he who is trustworthy in spirit keeps a thing covered” (Proverbs 11:13, ESV). You hold other people’s secrets for a living — their health, their grades, their salaries, their contracts, their unannounced layoffs. What does it mean to be trustworthy in spirit — to keep a confidence covered, especially the secrets of the vulnerable, in an age when a careless paste can reveal it to a machine and to the world? Hold that. We will earn it by the end.
Coach’s Note — Everything in this chapter is developed in reference form in Appendix C — the responsible-and-ethical-use appendix. Treat this chapter as the training; treat Appendix C as the card you keep at your desk. When you are unsure in the moment, you will not re-read a chapter. You will glance at a checklist. Build the checklist now, while you have time to think.
14.1 — The One Rule You Cannot Unlearn
Before the nuance, the rule. Memorize it. Say it out loud.
Never paste anything into a public AI tool that you would not be comfortable seeing forwarded to a stranger, posted publicly, or read aloud in a deposition.
That is the test. Not “is this probably fine?” — that is the tone of every mistake ever made. The test is: if this exact text ended up somewhere I don’t control, who gets hurt, and could I defend the decision to send it? If the honest answer is “a patient, a client, a student, a colleague — and no, I couldn’t defend it,” the answer is don’t.
Why is a public tool different from the one your company might approve? Because of where your words go and what may be done with them. Three destinations, three very different risk profiles — this is the single most useful table in the chapter:
| Where your prompt goes | Who can see / keep it | Trained on your data? | Use it for |
|---|---|---|---|
| Public / consumer tier (free or personal ChatGPT, Claude, Gemini, etc.) | Vendor servers; may be human-reviewed; retained per their policy | Possibly — depends on tier & settings; often the default on free tiers | Non-sensitive work only |
Enterprise / business tier (a paid, contracted account — for Concordia people, BoodleBox at box.boodle.ai, the FERPA-compliant, SOC 2 platform CUW licenses) | Vendor, under a contract that usually says no training on your data and adds retention/security terms | Usually no, by contract — BoodleBox states it does not train on your data (as of 2026) | Internal work — plus regulated data only where the tool is certified for that regime (FERPA-covered work in BoodleBox with minimization, §14.4; HIPAA PHI still needs a BAA) — if your policy allows |
| Local / on-device model (Ollama, LM Studio — Week 11) | Nobody. It never leaves your machine | No — there is no “away” for it to go | The most sensitive work, when a tool is required at all |
Read the middle column again. On a consumer tier, the safe assumption in 2026 is: it may be retained, it may be seen by a human reviewer, and it may train the model. Vendors offer settings to opt out of training and “temporary chat” modes — and you should use them — but settings change, get toggled, and don’t undo what already went. Do not build your professional ethics on a checkbox. Build them on the rule: sensitive data does not go into a public tool, full stop.
In BoodleBox (Concordia’s vetted tool). This is precisely why CUW licenses BoodleBox instead of leaving you on a random free chatbot. As of 2026 BoodleBox is FERPA-compliant, SOC 2 certified, and — by its own terms — does not train on your data, which lands it squarely in that middle row: the appropriate home for Concordia coursework and work content that a public consumer tool is not. Sign in at box.boodle.ai with your Concordia account and it becomes your default for the week’s work; a public free assistant is only the off-campus fallback. But — and this is the discipline the whole chapter is about — a vetted tool does not switch off your judgment. It raises the floor; it does not license you to paste needless personal data, and regulated data (a patient’s PHI under HIPAA) still needs its own specific contract, not just a good general one. Right tool first, then right data.
Coach’s Note — “But the box was checked to not train on my data.” Maybe it was. Maybe it defaulted back after an update, or the account wasn’t the tier you thought, or a human reviewer read it anyway for a safety check. The steward’s posture is not “probably protected.” It is “I never sent it.” You cannot leak what you did not paste.
14.2 — Confidential Information and Trade Secrets
Start with the category that has nothing to do with any privacy law: information your organization has simply decided to keep inside. Unannounced financials. A pending acquisition or layoff. A product roadmap. Pricing strategy. A client list. The recipe, the algorithm, the supplier terms — the things a competitor would love to have.
Some of this rises to the legal status of a trade secret: information that has economic value because it is secret and that the owner takes reasonable steps to protect. The moment you paste a trade secret into a tool whose terms may retain or train on it, you have arguably failed the “reasonable steps to protect” test — and you may have handed the secret to a system that could surface a version of it to someone else. That is not a hypothetical harm; it is the exact nightmare that made several large companies ban or tightly restrict consumer chatbots on work devices in 2023, after employees pasted internal source code and meeting notes into public tools.
The tell is usually right on the document: CONFIDENTIAL. Internal only. Do not distribute. Under NDA. If a human put that label there, a machine does not get an exception. And confidentiality is not always stamped — an unannounced deal or an org change is confidential the instant it exists, label or no. When in doubt, treat it as covered.
Coach’s Note — A useful reframing for the office: pasting into a public AI is publishing, not filing. You would never post the acquisition memo to the company blog “just to get a summary.” Pasting it into a consumer chatbot is closer to that than to saving it in a private folder. Same reflex, please.
14.3 — PII: The Data That Names a Person
PII — Personally Identifiable Information — is any data that can identify a specific human being, alone or in combination with other data. It is the workhorse category of privacy, because almost everyone handles it.
It comes in two flavors, and the second is the one people miss:
- Direct identifiers — data that names a person by itself: full name, Social Security or national ID number, email address, phone number, home address, passport number, financial-account or card number, biometric data, a photo of a face.
- Indirect identifiers — data that seems anonymous but re-identifies a person when combined: a birthdate, a ZIP code, a job title at a small company, “the only left-handed VP in the Denver office.” A classic finding in the privacy literature is that a large share of the U.S. population can be uniquely identified from just ZIP code + birthdate + sex — three fields that individually feel harmless.
That second flavor is why “I removed the name, so it’s anonymous” is usually wrong. Strip the name and leave the birthdate, the diagnosis, the address, and the account balance, and you may have handed over a re-identifiable record — worse, one that now feels safe. Real redaction means removing enough of the combination that the person cannot be reconstructed, not just deleting the obvious label.
The professional habit: before you paste, scan for both flavors. If the text identifies a specific person — or could, in combination — either redact to placeholders ([NAME], [ACCOUNT #], [ADDRESS]) so only the shape of the task remains, or, if redaction would gut the meaning, don’t paste it at all. You will drill exactly this on the snippets in code/data-snippets.txt.
14.4 — Regulated Data: HIPAA and FERPA
Some PII is not merely sensitive — it is protected by law, with penalties attached. Two U.S. regimes cover a huge fraction of working professionals; know them by name.
HIPAA (health). The Health Insurance Portability and Accountability Act governs Protected Health Information (PHI) — health data tied to an identifiable person: diagnoses, lab results, medications, appointment details, anything that links a name to a medical fact. If you work in a clinic, hospital, pharmacy, dental office, therapy practice, or health plan — or you’re a vendor handling their data — HIPAA likely applies to you. Here is the AI-specific line, hedged and current as of mid-2026: pasting PHI into a consumer chatbot is very likely a HIPAA violation, because there is no Business Associate Agreement (BAA) — the contract that legally binds a vendor to protect the data — behind a free personal account. Some vendors will sign a BAA for specific enterprise health offerings; a personal login is not that. The safe rule: no patient data into a public tool, ever — redact to nothing identifiable, use an approved BAA-covered service, or do it by hand.
FERPA (education). The Family Educational Rights and Privacy Act protects student education records — grades, test scores, disciplinary records, IEPs, anything in a named student’s file — at schools that receive federal funding (which is nearly all of them). If you are a teacher, aide, counselor, registrar, or administrator, FERPA is your line. The AI-specific rule mirrors HIPAA: identifiable student data should not go into a consumer AI tool. “Draft a note to the parents of the three third-graders who scored below grade level — Aiden, Sofia, and Marcus, who has an IEP” is a FERPA problem the moment it hits a public window, however kind the intent. Strip it to a template with no names and no identifying scores, or keep it off the tool. At Concordia the vetted alternative to a consumer tool is BoodleBox, which is FERPA-compliant and contracted not to train on your data (as of 2026) — a large part of why the university licenses it for coursework and student-facing work. Even there, keep it to the template and strip the identifiers the task doesn’t need: a vetted tool changes where student data may go, not whether you should minimize it first.
Coach’s Note — Two more you will meet by name and should not confuse with the above. GDPR (Europe) and CCPA/CPRA (California) are broad personal-data laws — they govern any personal data of a covered person, not just health or education, and they generally forbid feeding it to a vendor without a lawful basis and proper contracts. If your customers or employees are in the EU or California, assume these apply. I am naming the risk, not giving legal advice — when the stakes are real, ask your compliance or legal team, not a chatbot.
14.5 — Your Organization’s AI Policy (and How to Read It)
Everything so far is the general standard. Your employer’s policy is the specific, binding version — and it may be stricter than the law. As of mid-2026 most organizations of any size have one (or are writing one), and it is your job to read it before you improvise. Three questions answer 90% of what you need:
- Which tools are approved, and at which tier? Many organizations forbid consumer AI on work data but provide a paid enterprise tool that contractually will not train on your inputs. “AI is banned” and “the free version is banned, use the company one” are very different policies — know which you’re under. At Concordia, that approved tool is BoodleBox (
box.boodle.ai, sign in with your CUW account) — the FERPA/SOC-2 platform the university pays for so coursework and work data have a vetted home. Knowing your institution has one, and actually using it, is the line between a policy followed and shadow AI. - What data may go into an approved tool? Even sanctioned enterprise tools usually carve out regulated data (PHI, PII, financials) and confidential material. The tool being approved does not make the data approved.
- What must you disclose, and to whom? Some policies require you to label AI-assisted external documents, log agent use, or get sign-off for certain tasks.
Beware the thing every policy is secretly about: shadow AI — employees using unapproved personal tools for work because they’re faster and nobody’s watching. Security vendors’ 2026 reports consistently rank it among the most common ways sensitive data leaks, and “I was just trying to get my work done” is the epitaph on a lot of incident reports. If the approved tool is too limited for a real task, that is a conversation to have with your manager or IT — out loud, in advance — not a rule to quietly route around. The fix for a bad policy is a better policy, not a secret one.
If your organization has no policy, you are not off the hook — you are the drafter. The one-page template in code/ai-use-policy-template.txt is where you start, and writing it is half of this week’s graded lab.
14.6 — Copyright and Ownership: Who Owns What the Machine Makes
Two questions live here, and they are genuinely unsettled in 2026. Do not let anyone — including me — sell you false certainty.
Who owns the output the AI generates for you? Most consumer AI providers’ terms of service assign you whatever rights they can in the text or images you generate — but a company’s terms cannot grant a copyright the law does not recognize. And as of mid-2026, the U.S. Copyright Office’s stated position has been that copyright protects human authorship: a work with no meaningful human creative contribution — a purely machine-generated image from a one-line prompt — generally cannot be registered for copyright. Human-assisted work can be protected to the extent of the human’s own creative contribution. Practical translation for a professional: the AI-generated logo you got in ten seconds may not be something you can stop a competitor from copying, and other countries draw the line differently. When ownership matters — a brand asset, a published work — get human creative involvement and, for anything high-stakes, real legal advice.
Who owns the training data, and is your output infringing someone else’s? This is the hot litigation of the mid-2020s. Text, image, and music rights-holders have sued AI makers over training on copyrighted work without permission — the outcomes were not settled as of mid-2026. In the music corner, for example, Suno reached a reported settlement with Warner (late 2025) while suits from other major labels remained open. The market’s answer to enterprise nervousness is instructive: Adobe Firefly trains on licensed and public-domain content and offers commercial indemnification — a contractual promise to stand behind you if an output is challenged — which is exactly why risk-averse companies pay for it. The professional posture: for commercial work where infringement would be costly, prefer tools with clear licensing and indemnification, keep a human in the creative loop, and treat “the AI made it, so it’s fine to use” as an open question, not a settled permission.
Coach’s Note — “Is it legal to use this AI output commercially?” is not a question a chatbot can answer for you, and it will happily give you a confident wrong answer if you ask. This is a place where the spine rule bites hard: the AI drafts the asset; you — with your legal team when the stakes warrant — own the verdict on whether you may use it.
14.7 — Responsible AI: Bias, Fairness, and Transparency
Privacy is about what you put in. Responsible AI is about what you do with what comes out. Three ideas you should be able to explain to a colleague.
Bias. A model learns from human-generated data, and human data carries human bias. So a model can reproduce or amplify it — ranking résumés in a way that disfavors a group, describing a “nurse” as she and a “CEO” as he, generating images that stereotype. This is not the model being malicious; it is the model being a mirror of its training data. The professional consequence: the higher the stakes for a real person — hiring, lending, discipline, medical, legal — the more a human must own the decision and check for disparate impact. AI can screen and suggest; it must not be the unaccountable judge of a person’s opportunity.
Fairness. Bias is the flaw; fairness is the obligation. When AI touches a decision that affects people unequally, someone must ask is this outcome fair across the groups it affects? — and be able to answer. That is a human question with a human owner.
Transparency (and disclosure). People have a reasonable interest in knowing when they are dealing with AI rather than a human, and when a document or image was AI-generated. Increasingly this is also policy and, in places, law. Two practical duties fall out of it: provenance — AI-generated media now often carries signed content credentials (C2PA) or invisible watermarks (SynthID) recording that it was machine-made (we met these in the image and video weeks) — and disclosure: say, honestly and proportionately, when AI meaningfully shaped work you present as your own. A one-line “Drafted with AI assistance; reviewed and verified by me” costs you nothing and protects your credibility. Passing off an AI’s confident, unverified claims as your own considered judgment costs you everything the first time it’s wrong.
14.8 — AI Governance in an Organization
Zoom out from your desk to the whole organization. AI governance is the set of rules, roles, and reviews that decide how AI may be used here — the org-scale version of the personal policy you’ll write this week. You don’t have to run it, but you should recognize it, because you live inside it.
The pieces you’ll encounter:
- A written AI policy and an acceptable-use standard — what §14.5 was about, from the organization’s side.
- An owner or committee — often an AI governance group, sometimes anchored by a Chief AI/Privacy Officer or Data Protection Officer, that approves tools, reviews high-risk uses, and answers the hard calls.
- A framework to structure it. The most-cited voluntary one in the U.S. is the NIST AI Risk Management Framework (Govern, Map, Measure, Manage) — a sensible checklist for thinking about AI risk. Internationally, ISO/IEC 42001 offers a certifiable AI-management-system standard. And the EU AI Act is the big regulatory mover: as of mid-2026 its prohibitions and AI-literacy duties are already in force, its rules for general-purpose AI have begun, and its heaviest “high-risk” obligations are on a provisional, shifting timeline — reportedly proposed for deferral toward late 2027, not yet finally adopted. Dates here move; the direction — more accountability, not less — does not.
The reason this matters to a non-technical professional: governance is what turns “please be careful” into something a large organization can actually rely on. It names who approves a tool, who may use it on what data, who reviews the risky uses, and who answers when something goes wrong. Your one-page personal policy is the same instinct at human scale — and the habit of thinking in policies is the habit that makes you promotable in an AI-saturated workplace.
14.9 — The Environmental Cost of a Prompt
One more responsibility, quieter than the others and easy to forget because it is invisible from the chat window: AI runs on data centers, and data centers consume electricity and, for cooling, water. Training a frontier model is energy-intensive, and so — at scale — is inference, the everyday act of answering your prompts, because it happens billions of times a day. A single query’s footprint is small; a planet’s worth of queries is not.
Be careful with the numbers here, because a lot of them are contested. You’ll see claims that “one AI query uses ten times the energy of a web search” or specific milliliters-of-water-per-prompt figures — estimates vary widely, depend heavily on the model and data center, and many are not independently audited. I won’t hand you a precise figure I can’t stand behind. The durable lessons are what matter:
- Bigger models cost more — in dollars and in energy. Running a frontier model for a task a small one handles fine is wasteful twice over. This is the same “count the cost” discipline from Chapter 3, now with an environmental column added to the ledger.
- Right-sizing is a virtue, not just a budget line. Choosing the smallest capable model, batching work, and not re-generating for sport are small, real acts of stewardship.
- It is a factor, not the whole scale. AI’s footprint is a genuine consideration to weigh — alongside the good the work does — not a reason for paralysis or for pretending your individual prompt is a catastrophe.
Coach’s Note — The through-line of this whole book is right valuing — the right tool, the right model, the right amount of trust. Energy is one more thing to value rightly. The professional who reaches for a nano-tier model to reformat a list, and a frontier model only when the problem is genuinely hard, is being a good steward of the budget, the planet, and their own attention. Same discipline, three payoffs.
14.x — Interactive Lab: Can I Paste This? — Data-Sensitivity Classifier
Below this chapter on the website you’ll find an interactive panel: Can I Paste This? — the Data-Sensitivity Classifier. Go use it now. It is not decoration; it is the rep that turns this week’s rule into a reflex you’ll still have at 4:55 on a Friday.
The panel deals you twelve realistic workplace snippets at once — an email, a spreadsheet row, a patient message, a marketing draft, a config with a live API key, your own résumé — and asks you to make the call on each: Safe to paste · Redact first · Never paste. Call all twelve, hit Submit my verdicts, and it walks back through them snippet by snippet, telling you whether you were right and, more importantly, why: which category the data falls in (PII, PHI under HIPAA, FERPA-covered, confidential, a secret hiding in an indirect identifier) and what the redacted version would look like. You will get some wrong. Most people over-trust the “probably fine” snippets and under-notice the birthdate-plus-ZIP re-identification trap. That miss is the lesson.
Run it until you can call every snippet cold — because the muscle you’re building is pausing the half-second before you paste to ask whose secret is this, and where is it about to go? Then take that same eye to code/data-snippets.txt in your graded lab and defend your verdicts in writing.
In BoodleBox. The classifier asks the public-tool question — would I paste this into a consumer chatbot? Now ask the sharper professional version: where does this belong? For Concordia coursework and work content the answer usually isn’t a random free tool; it’s BoodleBox (box.boodle.ai, your CUW login) — the FERPA-compliant, SOC 2, doesn’t-train-on-your-data platform the university vetted for exactly this (as of 2026). That lifts some “never paste into a public tool” snippets into “fine in the vetted tool.” What it does not do is retire your judgment: a snippet stuffed with a real person’s identifiers the task doesn’t need is needless PII in any tool, and regulated data still answers to its own law. Run the stack twice — once for a public chatbot, once for BoodleBox — and watch which verdicts change and which don’t. The ones that don’t change are the ones about minimizing data, not about which vendor. That’s the reflex.
14.10 — Trustworthy in Spirit: Keeping a Confidence Covered
Now the week’s question, given its due. What does it mean to be trustworthy in spirit — to keep a confidence covered, especially the secrets of the vulnerable?
Scripture puts two kinds of people side by side: “Whoever goes about slandering reveals secrets, but he who is trustworthy in spirit keeps a thing covered” (Proverbs 11:13, ESV). Read the two halves as two professionals. One reveals — carelessly, for convenience, for the little rush of having the information move. The other keeps a thing covered — not because a rule forces it, but because that is the kind of person they are, all the way down. Notice the phrase: trustworthy in spirit. Not trustworthy in policy, not trustworthy when audited. In spirit — when no one is watching and the paste would be so easy and no one would ever know.
That is exactly the moment the AI era manufactures a thousand times a day. The quiet window. The helpful assistant. The five-second shortcut. And on the other side of it, almost always, is someone who did not consent and cannot protect themselves: the patient whose diagnosis you were about to “word more gently,” the third-grader whose reading score you were about to send off to be “made encouraging,” the client who trusted your firm with a contract. Scripture has a special tenderness for exactly these — the ones without power, whose only protection is the faithfulness of the person entrusted with their business. “Rescue the weak and the needy” (Psalm 82:4, ESV) is not sentiment; it is a job description for anyone who holds another’s data.
Here the LCMS understanding of vocation makes the ethic concrete rather than abstract. Luther taught that God serves your neighbor through your ordinary work — that the receptionist, the teacher, the analyst are the hands by which the neighbor is cared for. The Eighth Commandment — “You shall not bear false witness against your neighbor” — Luther explained not merely as “don’t lie in court” but as a positive duty to protect the neighbor’s reputation and speak well of them, to defend them, and explain everything in the kindest way. Keeping a confidence covered is that commandment lived out at a keyboard. The patient’s dignity, the student’s privacy, the client’s trust — these are your neighbor, handed to you. To leak them for convenience is to reveal secrets. To guard them, especially when it costs you a slower path and a little more work, is to be trustworthy in spirit.
And this reframes the spine rule one last time. You choose the tool; you own the verdict — because the confidence was entrusted to you, not to the model, and not to the vendor. The temptation of every tool in this book is to let accountability slide onto the machine: the AI summarized it, the app processed it, the model saw it, not me. The trustworthy person cannot speak that way. What was covered was covered into your keeping. Faithfulness is not fear of the tool and it is not refusal to use it; it is the deliberate, sometimes inconvenient discipline of a person who can be trusted with what is not theirs. That is the whole of this week, and it is worth more than any technique in this book.
14.11 — Common Pitfalls
Pitfall: Trusting the “don’t train on my data” toggle as if it were a vault. Example: You paste a client contract into a consumer tool because you turned off training in settings — then an account update, a wrong tier, or a human safety review means the data was retained anyway. Fix: Never build ethics on a checkbox. Sensitive data does not go into a public tool regardless of settings. You cannot leak what you did not paste.
Pitfall: “I removed the name, so it’s anonymous.” Example: You strip the patient’s name but leave the birthdate, ZIP, and diagnosis — a combination that re-identifies the person and now feels safe. Fix: Redact the combination, not just the label. If removing enough to truly de-identify would gut the meaning, it belongs on the NEVER list, not the redact list. (See §14.3.)
Pitfall: Confusing “the tool is approved” with “this data is approved.” Example: Your company sanctioned an enterprise Copilot, so you paste regulated PHI into it — but the policy explicitly carves out health and financial data. Fix: Tool approval and data approval are two separate gates. Read the policy’s data rules, not just its tool list. (See §14.5.)
Pitfall: Shadow AI — quietly using a personal tool because the approved one is slower. Example: The company tool can’t summarize a big PDF fast, so you route the confidential doc through your free personal account “just this once.” Fix: Raise the gap with your manager or IT out loud, in advance. The fix for a limiting policy is a better policy, not a secret one. “Just trying to get my work done” is the most common line in incident reports.
Pitfall: Treating “the AI made it” as legal permission to use it commercially. Example: You ship an AI-generated logo as a brand asset, assuming you own it and it infringes nothing — both of which are unsettled in 2026. Fix: For commercial work where ownership or infringement matters, prefer licensed/indemnified tools, keep a human in the creative loop, and get real legal advice. The chatbot cannot answer this for you. (See §14.6.)
Pitfall: Passing off unverified, undisclosed AI output as your own considered judgment. Example: You present an AI-written analysis — with a fabricated statistic in it — as your own work, no disclosure, no fact-check, and it’s wrong in the meeting. Fix: Disclose meaningful AI assistance proportionately, verify every fact and citation, and own the result. Your name is on it, not the model’s. (See §14.7.)
Pitfall: Reaching for the biggest model for trivial work. Example: You run a frontier-tier model thousands of times a day to reformat short lists — burning budget and energy for no quality gain. Fix: Right-size the model to the task. Small model for small work; frontier only when the problem is genuinely hard. Count the cost — dollars and energy. (See §14.9 and Chapter 3.)
14.12 — Reps
The work is in the exercises, and this week it is also your graded lab. The keyboard is the gym; this is where the reflex gets built into your hands. A preview of what’s waiting:
- Classify the snippet stack in
code/data-snippets.txtas safe / redact / never, with a one-line reason for each. - Redact for real — take a “redact-first” snippet and produce the placeholder version you’d actually be willing to paste.
- Read a policy like a professional — answer the three questions from §14.5 against a real or sample AI policy.
- Draft your own one-page AI-use policy from
code/ai-use-policy-template.txt— including your personal NEVER list. - Catch the re-identification trap — take a “de-identified” record and prove whether it’s actually safe.
This week’s AI policy for the reps: you may absolutely discuss these concepts with an AI — do it in BoodleBox (box.boodle.ai, your CUW login), Concordia’s vetted, FERPA/SOC-2, no-train tool and the right home for this work (a public free assistant works as a fallback off-campus). But this is the one week where the whole point is knowing what not to paste, so use only fabricated or already-public data in any prompt, and end each AI-assisted rep with an honest one-line AI usage note: what you asked, and how you kept real sensitive data out of it. Practice the discipline while you drill it.
A short Check Your Reps quiz is embedded on this page, right under the chapter. Take it before you move on — five questions, grounded in exactly what you just read.
14.13 — This Week’s Lab
There is no new project this week — this is a drill week, and the reps are the graded lab. It’s called Data Redline, and it lives in the exercises. You will do two things a professional actually gets asked to do:
- Redline the snippet stack. Go through the twelve realistic workplace snippets in
code/data-snippets.txt, classify each safe / redact / never, name the category of sensitivity, and — for the redactable ones — write the version you’d be willing to paste. - Write your one-page personal AI-use policy from
code/ai-use-policy-template.txt: your NEVER list, your redact rule, your approved-tools table, your disclosure and verification commitments, and your spine rule in your own words.
It’s graded on a rubric that sums to 100, and it becomes the artifact you actually use for the rest of your career. Do it like it matters, because it does.
14.14 — Coach’s Final Word
Here is what I want you to carry out of Week 14. For thirteen weeks the lesson was reach for the tool. This week the lesson is you are still the one holding the trust. The AI did not take custody of the patient’s diagnosis, the student’s record, the client’s secret — you did, the moment it was handed to you, and no paste transfers that custody to a machine.
The techniques in this book will age. The models will turn over, the tiers will shuffle, the toggles will move. This discipline will not. Whose secret is this, and where is it about to go? — ask it before every paste for the rest of your career, and you will avoid the mistake that ends careers. Redact the combination, not just the label. Know your policy’s data rules, not just its tool list. Never route around it in the dark. Right-size the model. Disclose honestly, verify ruthlessly, and put your name — not the model’s — on the verdict.
And underneath all of it, the old, plain word: be trustworthy in spirit. Not just when audited. Not just when it’s easy. Keep the confidence covered because that is the kind of professional — the kind of person — you have decided to be. The vulnerable on the other side of your keyboard are counting on exactly that, and they will never know how often you protected them. Good. That’s what covered means.
Now go do the reps. The classifier is waiting right below this page, the snippets and the policy template are in code/, and the Data Redline lab is where it all comes together.
See you on Monday.
Up next: Do all of Week 14’s reps and the graded Data Redline lab in the exercises. Keep Appendix C — Responsible & Ethical AI Use — open as your desk reference; it distills this chapter into a checklist. For the tools and tiers named here, see Appendix B; for account setup and the local-model path, Appendix A; and for any term you’re unsure of, Appendix D — the glossary. Then Chapter 15 — Building Your AI-Enhanced Workflow, where you put all of it into one deliberate weekly routine.