theCommons Academy
All micro-lessons
LESSON 05 · FREE20–25 min

The Guardrails: Ethics, Risk, and Zero-Trust

How to use AI safely. Check every output. Strip sensitive details before you paste. Keep a person on the final call.

Next action

Start Lesson 0520–25 min

Opens in a new tab. First time? We'll ask for your name and email.

What this is

About this micro-course

A 20–25 minute lesson on the two risks that derail AI at work. Hallucination is when a model states something false with full confidence. Shadow AI is when people use tools nobody approved. You get a four-step check to run on every output, and practice at cleaning sensitive details out of a prompt before you send it.

  • 5 chapters
  • The four-step Zero-Trust verification workflow
  • Input sanitization rules and examples
  • The Human-in-the-Loop standard explained

What you'll learn

AI has no sense of truth. It predicts patterns. It does not check facts. By the end you will be able to spot the two risks that matter most: hallucination, where the model makes something up, and Shadow AI, where people use unapproved tools. You will be able to run a four-step check on any output before a client or your boss sees it. And you will be able to strip names, client details, and numbers out of a prompt before you send it.

Curriculum

5 chapters · 20–25 min

  1. Hallucination and Shadow AI

    How and why AI fails, and what it costs when it does.

  2. The Zero-Trust standard

    Zero-Trust means you check the output every time, no matter how good it looks. Why "trust but verify" is dead and what replaces it.

  3. The four-step verification workflow

    Prompt construction, sanity check, fact audit, human oversight.

  4. Input sanitization

    Sanitizing an input means removing anything private before you paste it. The Red Light rules for what never goes into a public model.

  5. Human-in-the-Loop

    Human-in-the-Loop means a person signs off before the output is used. Your role as the final guardrail.

Practice assignment

Run your Zero-Trust audit

Take the last three AI conversations you had. For each one, apply the four-step verification workflow. Document the gaps and write one rule you'll apply to every AI conversation going forward.

Time
45 minutes
Deliverable
A one-page mini-policy your team can actually follow next week.
Review
Self-scored with the safety rubric. Bring it to a live session for staff feedback.
  1. Open the last three AI conversations you had.
  2. For each one: did you sanitize the input? Did you do a sanity check on the output? Did you verify key facts against an authoritative source? Did a human review it before it was acted on?
  3. Count the gaps across all three conversations.
  4. Write one personal rule — one sentence — that you'll apply to every AI conversation going forward.
How the practice assignments work
  1. 1. Finish the lesson
    Each lesson ends with a short prompt that turns the concept into a one-page deliverable you'd actually use at work.
  2. 2. Build your artifact
    Use the copy-paste template inside the course. Most assignments take 15–30 minutes and produce a doc, prompt, or checklist you keep.
  3. 3. Self-review with the rubric
    Every assignment ships with a 4-point rubric (clarity · specificity · safety · usefulness). Score yourself in two minutes.
  4. 4. Optional: share what you built
    Bring your artifact to a live session — Office Hours or the weekly build-along — for real-time feedback from our team. Prefer to share publicly? Post it and tag us on LinkedIn (Fear of Becoming Obsolete.).

Assignments are ungraded and self-paced. There's no deadline, no quiz, no certificate gate — the deliverable is the proof you did the work.

Preview · try before you launch

Try this before you launch

“Open the last three AI conversations you had. Count how many contained a name, a client, an internal document, or a financial figure. That count is your current data-exposure baseline.”

What you walk away with

  • Run the four-step check on a real output and name every gap you found
  • Rewrite a prompt so it carries no name, client, document, or figure you should protect
  • Decide which of your tasks must have a person review the output before it is used

Ready when you are

Start Lesson 05 · 20–25 min