AI FOUNDATIONS · COURSE 05

THE AI INSTITUTE

Source-led executive learning · reviewed August 2026

What boundaries make this use proportionate and accountable?

Responsible use is an operating design, not a promise to “be ethical”. It specifies permitted purpose and data, affected people, human authority, support, controls and the point at which work stops and escalates.

Your decision

By the end of this module, you will set a safe-use boundary for one AI-enabled task and design an escalation path that matches the consequence if the system is wrong.

1. Start with intended use, affected people and consequence

The same technical capability can carry very different risk. Summarising an internal planning meeting for participants is not equivalent to recommending an employee performance rating. Both may use generated text, but the second use affects a person’s employment, may amplify incomplete or biased support, and requires stronger authority, transparency, contestability and assurance.

Write the intended use as a permitted action, not a broad aspiration. Name who is affected directly and indirectly. Then describe the plausible consequence of error, misuse, exclusion or non-use. Consider privacy, security, unfair treatment, misleading information, loss of access or opportunity, physical or psychological harm, legal and contractual exposure, and the ability of a person to challenge an outcome.

Australian Government guidance frames responsible adoption as a set of practices spanning accountability, risk, data, testing, transparency and monitoring [C005-S04]. The course uses a practical synthesis, not a legal determination. Obligations depend on the organisation, sector, jurisdiction, people and use. Seek qualified advice where needed.

Proportionate control model showing that as consequence and difficulty of correction increase, controls rise from approved tools and verification to independent assurance, notice, contestability and senior approval.
Proportionate control model. Control depth rises with consequence, scale, opacity and difficulty of correction. A full text alternative follows the lesson.

2. Define the safe-use boundary

A boundary tells a learner what is permitted, prohibited and conditional. It contains at least seven parts.

  1. Purpose: the task and outcome the system may support.
  2. Users: authorised roles and required capability.
  3. Information: approved classifications, sources and minimisation rules.
  4. Output use: whether output may inform, draft, recommend or act.
  5. Human authority: who verifies, overrides and owns the consequential decision.
  6. Affected-person protection: notice, explanation, correction, contestability or alternative channel.
  7. Escalation: triggers, immediate containment, recipient and documentation.

“Do not enter sensitive data” is incomplete if staff cannot recognise information classes or know which environment is approved. “Human review required” is incomplete if the reviewer lacks time, source access, authority or a route to disagree. Convert slogans into observable practice.

3. Minimise and protect information

Use the least information needed for the task. De-identification can reduce exposure but is not a magic state: combinations of details may re-identify a person, free text may retain names or circumstances, and the service may have access, retention or training terms the user does not understand. Removing a customer name from a complaint does not necessarily remove account details, locations, health information or a distinctive incident.

Confirm the approved environment, access controls, provider terms, storage location, retention and deletion pathway, logging, onward disclosure and incident process before use. OAIC guidance for commercially available AI products highlights privacy due diligence, transparency and accuracy considerations in the Australian context [C005-S05]. ASD/ACSC guidance supports careful assessment of security and information risks [C005-S06]. Apply your organisation’s policy and obtain expert review rather than relying on a prompt such as “do not remember this”.

4. Design meaningful human accountability

Responsibility remains with people and organisations when a task is delegated. A reviewer must understand the decision, receive support needed to check the output, have authority to change it and enough time to intervene before consequence. Automation bias—the tendency to accept a system suggestion—becomes more likely when the interface presents confidence without limitations, when workload is high or when overrides attract friction.

Match review to the failure. A source-linked draft may need passage verification and a checklist. A risk score may require access to relevant underlying support, a documented override and periodic segmented analysis. A decision affecting a person may also require notice, a meaningful explanation, a non-AI pathway and a way to correct information or challenge the outcome.

Do not describe a system as merely advisory if people routinely follow it, lack time to review it, or are measured against its recommendation. Evaluate real operating behaviour, not only the policy diagram.

5. Use proportionate tiers, not one universal checklist

Low-consequence uses can be enabled with clear approved-tool rules, information boundaries, user verification and incident reporting. Higher-consequence uses need deeper evaluation, affected-person protections, specialist review, independent challenge, monitoring and senior approval. Consequence, scale, reversibility, opacity and vulnerability of affected people all influence the tier.

Proportionality works both ways. Excess controls on harmless drafting drive work into unmanaged channels and prevent learning. Weak controls on consequential recommendations expose people and the organisation. The design objective is the minimum control set that makes the named use acceptable—not the minimum paperwork that allows launch.

6. Build escalation before an incident

An escalation trigger is an observable condition: personal information entered into an unapproved service; a materially unsupported recommendation; an affected person challenges the data; anomalous results for a group; a security event; a source or model change; or use outside the approved boundary.

The first step is usually containment: pause the affected action, preserve relevant records without spreading sensitive content, and prevent further consequence. Next notify the named owner and the appropriate privacy, security, legal, people or operational channel. Record what happened, who may be affected, the current consequence and what has been contained. Do not investigate beyond your authority or promise an outcome. The owner decides notification, remediation, review and whether use may resume.

Escalation must be safe for the reporter. A control that depends on users admitting error will fail if reporting creates blame or career risk. Track near misses and boundary questions as learning support, not only confirmed incidents.

7. Worked case: meeting summary versus performance recommendation

Composite teaching case

A team uses an approved assistant to draft meeting summaries from agendas and participant notes. The permitted purpose is a draft record for participants. Attendees are told the tool is used; the organiser verifies decisions and actions; sensitive employee matters are excluded; records follow the approved retention rule. Errors are correctable before the summary becomes final.

A manager then proposes using the same tool to recommend performance ratings from meeting notes and messages. The technology is similar but the purpose, data, affected person and consequence change. Meeting records are incomplete proof of performance; language may reflect role and manager behaviour; employees may not know the secondary use; the recommendation can affect pay and opportunity. The original boundary does not transfer.

The organisation does not quietly extend the first approval. It creates a new high-consequence decision requiring people, privacy and legal review; documented necessity and alternatives; representative support; affected-person notice and correction; meaningful manager accountability; contestability; monitoring and senior approval. It may decide the use is disproportionate and prohibit it.

8. Contrast case: “We removed the names”

Misconception

An employee removes customer names from complaint narratives and pastes them into a public AI service. The text still contains account fragments, store locations, dates, health details and a distinctive event. The employee assumes de-identification and types “do not train on this data”.

The prompt does not override provider terms or organisational policy, and deleting names alone may not prevent re-identification. The employee should stop, follow the incident or advice channel, contain further use and move the task into an approved workflow using the minimum permitted information.

9. Practice: boundary and escalation card

Produce support

Use the template for one fictional or de-identified use. State permitted purpose, users, information, output use, human decision, affected-person protection and monitoring. Then write three escalation triggers and the first containment, notification and recording actions.

Completion support: a boundary a new employee could follow, a named decision owner, one prohibited use, one affected-person protection and an escalation sequence that begins with containment.

Download editable boundary and escalation card (CSV)

10. Decision summary

Responsible use is specific. Name the use, people, information, consequence, authority and escalation. Increase control depth when consequence, scale, opacity or difficulty of correction rises. Reassess whenever purpose, data, model, workflow or affected population changes.

Transfer prompt

Ask the owner of one proposed use: “What is prohibited, and what happens in the first ten minutes after a boundary breach?” Do not paste actual incidents, identities or sensitive records into Moodle or the Learning Partner.

Review the annotated exemplar

Educational material, not legal advice. Do not enter confidential, personal or commercially sensitive information into an unapproved AI service.