/09AI Safety
A plain-English checklist for privacy, hallucinations, permissions, human review, and knowing when not to automate.
Beginner
9 min
Open +
AI Safety
A plain-English checklist for privacy, hallucinations, permissions, human review, and knowing when not to automate.
Beginner
9 min
Most business AI risk is not science fiction. It is ordinary operational risk with a very convincing interface.
Leave knowing / Use AI without being reckless
Five risks
Know these before you connect anything important.
Wrong
AI can produce an answer that sounds certain and is false. Important facts need sources or verification.
Leaky
Do not paste sensitive information into tools your organization has not approved for that data.
Over-permissioned
An agent should get the smallest set of tools and access needed for its job, not the keys to everything.
Unaccountable
A human owner still needs to be responsible for the workflow, especially when people or money are affected.
Invisible
If software can act, you need logs, proof, limits, and a way to stop or recover it.
Traffic light
A simple risk model for everyday AI use.
| Level | Examples | Default |
|---|---|---|
| Green | Brainstorming, rewriting your own text, low-stakes summaries | Use, review, learn |
| Yellow | Customer drafts, internal analysis, operational recommendations | Use approved data, verify, keep a human owner |
| Red | Hiring decisions, legal/medical/financial decisions, moving money, deleting data | Special controls or keep final authority human |
Before an agent can act
Seven things should exist first.
A narrow job and explicit allowed actions.
The minimum permissions needed for that job.
A budget or action limit.
A source of truth for current state.
A deterministic check where one is possible.
A human escalation path for uncertainty or exceptions.
An audit trail that proves what was attempted and what actually happened.
The useful mindset
Trust is not a personality trait you assign to AI. Trust is a property of the system around it: sources, permissions, tests, approvals, observability, and recovery.
Do not ask: "Do we trust AI?" Ask: "What would make this particular action safe enough to trust?"
Notes / Subscribe
Get the next note.
No schedule. No content calendar. A note goes out only when there is something worth understanding.