What goes in a personal AI policy

You will be able to list the decisions a personal AI policy should settle in advance.

Jia Hui, the marketing executive from module 1, is halfway through a busy Tuesday when a supplier emails a spreadsheet of customer delivery addresses and asks her to "get AI to sort out the duplicates". It would take thirty seconds. She pauses, and then she has to think it through from scratch: which tool, which account, is this personal data, does it matter? Ten minutes later she's still not sure.

A personal AI policy exists so you don't have to think it through from scratch every time. It's a short set of rules you write once, in calm conditions, and then follow. This lesson covers what those rules should settle. Most of the answers come straight from the work you've already done in this course.

Your tools, accounts and settings

The first rule says which assistants you use, on which accounts, with which settings.

Your audit table from lesson 1.4, Audit the AI tools you used this month, already holds the raw material. Look at the tools you decided to keep, and write down the account type for each and how you use it. Jia Hui's version reads: "Work tasks go in the company's Copilot. Personal tasks go in my own ChatGPT, with training switched off and memory reviewed once a month."

Include the settings you've chosen, so you can check them when an app updates and quietly changes something. Lesson 1.3, History, memory, temporary chats and deletion, covered the ones that matter most.

What never goes in

The second rule uses the three groups from lesson 1.1, What happens to the words you type into an assistant: fine anywhere, approved account only, and never.

Write down your never list in plain terms. For most people it includes passwords and one-time codes, NRIC numbers, bank and card details, other people's health or financial information, and anything a client or employer told you in confidence. Then write the approved-account-only list, such as internal documents, customer data with identifiers removed, and work plans.

The point of writing it down is the moment Jia Hui had with the supplier's spreadsheet. With a written list, she'd have seen at once that customer addresses are personal data, that they belong in the approved account only, and that removing names first would make the task safer, as lesson 2.2 explained.

What you always check, and your safe word

The third rule covers checking. Which kinds of AI output do you always verify before using them, and how?

Your task map from lesson 7.4, Map your tasks: delegate, assist or keep, gives you this. Pull out the checks you wrote for assist tasks and turn the most important into a single line. Jia Hui's reads: "Any AI-drafted text that goes to a customer gets every price, date and product name checked against the source before sending."

Add the two checking habits from modules 5 and 6. One is your family safe word routine: any urgent request for money or codes gets the safe word, then a callback on a known number. Don't write the safe word itself in the policy. The other is a sharing rule, such as: "I don't forward claims, images or statistics I haven't traced to an original source."

What you keep doing yourself

The last rule names the skills you keep doing by hand, from lesson 7.2, Skills you lose when you stop practising them. This is the rule people most often leave out, because it doesn't protect against an obvious danger. But it's what keeps you able to judge everything else.

Name the skill and the habit. Jia Hui's says: "I write the first draft of every campaign brief myself, then ask AI to critique it." Someone else's might be: "I estimate any number before I check it with a tool."

Short enough to remember

A personal policy only works if you can recall it in the moment, so keep it short. Five to eight rules is plenty. Each should be a single sentence you could say out loud. Write them in your own words, not in policy language, since you're the only reader.

Here's what Jia Hui's first draft looked like, in five lines. Work goes in Copilot, personal in my own account with training off. Never paste passwords, codes, NRIC numbers, bank details or anyone else's private information. Customer data only in Copilot, with names removed first. Anything going to a customer gets prices, dates and names checked against the source. Urgent money requests from family get the safe word and a callback.

She noticed it didn't yet include her by-hand skill or her sharing rule, and she'll add those in lesson 8.4. That's fine. A first draft is meant to be incomplete.

Gather what you made in this course, especially your audit table, your task map and your safe word plan. Your first draft will come mostly from those.

Write the first draft of your personal policy as five short rules you could read in under a minute.

Course

Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).