1Protect confidential and restricted information
Unpublished manuscripts, proposals, reviewer material, participant information, proprietary data, export-controlled technology, credentials, and sensitive institutional records should not be entered into unapproved tools.
Procurement and security review should examine data retention, training use, access, vendors, subprocessors, location, deletion, and incident response.
2Test accuracy, bias, and reproducibility
Generative systems can produce plausible but incorrect text, citations, policy interpretations, and calculations. Staff should verify source material and preserve a record of consequential review.
Evaluation should include varied users and cases, false positives and negatives, accessibility, bias, drift, and the burden placed on people who challenge an output.
3Keep governance proportional and visible
An inventory, risk classification, approved-use rules, training, monitoring, and escalation route can support responsible adoption. People should know when AI materially shapes a service or decision.
Automation should not hide who remains accountable for the final action.