← Course Home AFK-001 AI Fundamentals for Knowledge Workers
Module 1 of 4 0% complete

Module 1

AI Foundations, Responsible Use, and Workplace Governance

🎯 Learning Objectives

After completing this module, you will be able to:

  • Identify core generative AI concepts, capabilities, and limitations in a workplace context
  • Apply organizational compliance rules concerning data privacy and intellectual property when using AI tools
  • Recognize model hallucinations, biases, and security risks in everyday outputs

Click Next → to begin.

Understanding Generative AI Mechanics and Workplace Capabilities

What Is Generative AI?

Generative artificial intelligence (generative AI) refers to computer systems designed to create new content—such as written text, tables, summaries, and images—rather than merely analyzing existing data. At the core of conversational AI tools are Large Language Models (LLMs). An LLM is a machine learning model trained on vast collections of text to recognize patterns in human language.

Instead of "thinking" or "knowing" facts the way a person does, an LLM operates on statistical prediction. When you submit a request (known as a prompt), the model evaluates your input and calculates which word or phrase is most likely to come next, one piece at a time. A helpful analogy is an advanced autocomplete tool: it builds sentences based on probabilistic patterns learned during training.

Practical Purpose in Everyday Office Work

For knowledge workers, generative AI functions as an on-demand drafting assistant. Common workplace capabilities include:

  • Drafting correspondence: Producing initial versions of routine emails, project memos, and client updates.
  • Condensing long documents: Summarizing lengthy meeting transcripts, policy briefs, or industry reports into actionable bullet points.
  • Restructuring information: Converting raw meeting notes into structured agendas, project timelines, or tabular formats.

Guided Scenario: Transforming Meeting Notes

Imagine you return from a 45-minute project sync with messy, unstructured notes:

"Discussed timeline. Sarah says design needs 3 more days. Marcus will check with vendor on Friday. Need final signoff from leadership before budget approval next Tuesday."

When you ask a conversational AI assistant, "Organize these notes into an action table with Owner, Task, and Due Date," the model recognizes the contextual relationships among names, actions, and dates. It rapidly formats the text into a clear three-column table, saving you 10 to 15 minutes of manual reformatting.

Common Misconception

Misconception: The AI understands business logic and independently verifies truth.
Generative AI does not understand meaning, intent, or workplace consequences. It generates language that sounds plausible based on learned structures. You remain the subject matter expert responsible for confirming whether the output accurately reflects reality.

In the next lesson, we will explore the organizational boundaries required to protect sensitive workplace data while using these tools.

Diagram showing the input prompt entering an LLM prediction engine and generating structured office output.

Diagram showing the input prompt entering an LLM prediction engine and generating structured office output.

💡 Key Takeaways

  • Generative AI creates content by statistically predicting the most probable next words based on learned language patterns.
  • LLMs act as productivity accelerators for routine drafting, summarization, and reformatting tasks.
  • AI models do not possess comprehension or intent; human workers must verify all generated outputs.

Governance, Data Privacy, and Risk Mitigation in the Office

Workplace Governance and Data Privacy

Workplace governance refers to the policies, security standards, and compliance rules that dictate how employees handle organizational assets. When using generative AI, data privacy is the primary concern. Free, public browser-based AI tools frequently retain user prompts to train future iterations of their models. If you enter proprietary information into an unmanaged AI interface, that data may leave your company's secure boundary.

To safeguard your organization, you must distinguish between public information and restricted data:

  • Personally Identifiable Information (PII): Data that identifies an individual, including full names, home addresses, phone numbers, employee identification numbers, and social security numbers.
  • Confidential Business Data: Non-public financial statements, unpublished product roadmaps, legal contracts, pricing negotiations, and customer lists.
  • Intellectual Property (IP): Proprietary code, patented processes, internal methodology documents, and creative designs owned by your company.

Guided Walkthrough: Data Sanitization

Before submitting any draft or scenario to an AI tool, practice data sanitization (also called redaction or anonymization). Replace real corporate identifiers with generic placeholders.

Unsafe Prompt (Direct Leakage):

"Summarize this severance dispute for John Doe, Employee ID 84920 at Acme Logistics, who claims $45,000 in unpaid bonuses under our confidential Q3 sales commission plan."

Compliant Prompt (Sanitized):

"Summarize the following hypothetical employment dispute involving a standard sales commission structure, replacing individual and corporate names with generic roles: [Sanitized text with names and specific dollar figures removed]."

By replacing John Doe and Acme Logistics with neutral placeholders, you obtain the analytical assistance you need without violating confidentiality agreements or privacy statutes.

Common Mistake to Avoid

Mistake: Assuming private chat windows or deleted chat histories remove corporate liability.
Selecting "delete chat" in a consumer AI interface does not guarantee that the vendor has not logged or retained the prompt for backend processing. Unless your enterprise has executed a formal Data Processing Agreement (DPA) or enterprise tier that guarantees data exemption from training, treat all prompt input as publicly exposed.

Maintaining strict data hygiene ensures you stay compliant while preparing for the accuracy verification practices covered in our next lesson.

Illustration showing data sanitization where sensitive names and figures are converted into generic placeholders before prompting an AI tool.

Illustration showing data sanitization where sensitive names and figures are converted into generic placeholders before prompting an AI tool.

💡 Key Takeaways

  • Public AI tools may use submitted prompts and uploaded files to train future model releases.
  • Never input PII, proprietary financial records, or non-public intellectual property into unapproved AI tools.
  • Data sanitization using generic placeholders allows you to draft and analyze concepts safely without leaking sensitive information.

Identifying Hallucinations, Model Bias, And Factual Errors

Understanding AI Hallucinations and Model Bias

Because Large Language Models generate text based on statistical likelihood rather than factual retrieval, they can generate statements that appear articulate and persuasive but are entirely untrue. In generative AI terminology, this phenomenon is called a hallucination.

A hallucination is not a system crash or an overt error message; it is a fluent, grammatically sound assertion that invents facts, citations, dates, or calculations. Closely related is model bias, which occurs when an AI system reflects systemic skews, demographic stereotypes, or unrepresentative viewpoints present in its initial training data.

Realistic Workplace Risks

In a business setting, unverified AI outputs present serious operational risks:

  • Fabricated citations and legal precedents: The model may invent court rulings, regulatory codes, or published academic papers complete with plausible volume numbers and author names.
  • Inaccurate financial or numerical totals: Language models struggle with precise arithmetic and can miscalculate spreadsheet sums or quote incorrect inventory numbers.
  • Biased language in job descriptions or communications: AI tools may default to gendered stereotypes or exclusionary phrasing when generating professional profiles or role responsibilities.

Guided Example: Detecting a Hallucinated Reference

Consider a knowledge worker asking an AI tool for corporate policy guidance:

Prompt: "What does ISO standard 9001:2015 Clause 14 state regarding remote work computer monitors?"

AI Response: "ISO 9001:2015 Clause 14 specifies that organizations must provide dual 24-inch monitors for all remote personnel to ensure quality management compliance."

This response sounds authoritative and formal. However, ISO 9001:2015 contains only 10 clauses; Clause 14 does not exist. An uncritical worker might incorporate this nonexistent standard into an official procurement policy, leading to unnecessary organizational expense and audit failure.

Verification Checkpoint: Human-in-the-Loop

To prevent errors, always implement a Human-in-the-Loop (HITL) review workflow:

  1. Verify primary sources: If an AI response quotes a statute, standard, or metric, locate the original source document before sharing it.
  2. Check internal calculations: Never rely on AI for mathematical tabulations without verifying formulas in a spreadsheet.
  3. Assess tone and neutrality: Review all personnel communications to confirm they align with your organization’s equity and inclusivity guidelines.

This verification mindset prepares you directly for the upcoming hands-on lab, where you will evaluate live prompts and responses for compliance and factual integrity.

Diagram depicting a Human-in-the-Loop review process verifying an AI output against primary source records.

Diagram depicting a Human-in-the-Loop review process verifying an AI output against primary source records.

💡 Key Takeaways

  • A hallucination is an authoritative-sounding output that contains fabricated facts, citations, or data.
  • Model bias reflects training data skews, requiring human oversight to detect exclusionary language or stereotypes.
  • The Human-in-the-Loop (HITL) review framework requires verifying primary sources and recalculating numbers before publishing outputs.

🔬 Evaluating Prompts and Responses for Privacy and Compliance

Objective: Practice analyzing sample AI prompts and outputs in a web browser to identify data leakage risks, sanitize sensitive inputs, and detect hallucinations or compliance violations.

⏱ Estimated Time: 30 minutes💻 Platform: web_browser
Prerequisites:
  • A modern web browser (Google Chrome, Mozilla Firefox, Microsoft Edge, or Apple Safari) with internet access.
  • An active free-tier account on at least one major conversational AI platform: ChatGPT (chatgpt.com), Claude (claude.ai), or Google Gemini (gemini.google.com).
  • No specialized software, administrative rights, API keys, or credit cards are required.
  • All scenario data used in this exercise is fictional; do not enter personal or real enterprise data.

Procedures

1 Open your selected generative AI web interface and start a new conversation session.
  1. Open a new tab in your web browser.
  2. Navigate to your selected free AI platform:
    • ChatGPT: Navigate to https://chatgpt.com and log in to your free account.
    • Claude: Navigate to https://claude.ai and sign in to your free account.
    • Gemini: Navigate to https://gemini.google.com and sign in with your Google account.
  3. Ensure you have an empty, clean chat prompt window open. Do not reuse an ongoing conversation with prior context.
✓ Expected Output
A blank conversation window with an empty text prompt box labeled 'Message ChatGPT', 'Message Claude', or 'Ask Gemini'.
🔍 Verification: Confirm that your chat interface displays an empty chat thread ready to accept a new prompt.
2 Audit an unsafe workplace prompt scenario to identify PII, intellectual property, and confidential business data.

Review the following fictional workplace prompt draft that a colleague intends to submit to a public AI assistant:

Colleague Draft:
"Please draft a formal termination notice for David Miller (Employee ID: #84920, SSN ending 4102), who currently earns $112,000 annually as Senior DevOps Lead at Northwind Health Logistics. Mention that his severance package includes 8 weeks of pay and that our proprietary database architecture, project 'Project BlueVault', will be transitioned immediately to Sarah Lin at sarah.lin@northwindhl.internal."

Perform a compliance audit on your own notepad or scratchpad by categorizing each sensitive item:

  • Personally Identifiable Information (PII): Full names, Employee ID, partial SSN, internal corporate email addresses.
  • Confidential Business Data: Exact compensation figure ($112,000), severance package terms.
  • Intellectual Property (IP) / Proprietary Assets: Unreleased internal project codename (Project BlueVault).
✓ Expected Output
A mental or written identification of at least four distinct compliance violations present in the raw draft.
🔍 Verification: Verify that you have flagged David Miller, #84920, SSN ending 4102, $112,000, 'Project BlueVault', and Sarah Lin's email as restricted data elements that must not enter a public AI interface.
3 Sanitize the draft prompt using generic placeholders and role-based substitution.

Construct a fully sanitized, compliant prompt by replacing all proprietary and personal identifiers with bracketed generic placeholders. Personalize the request with your learnerInitials tag.

Copy and prepare the following sanitized prompt template:

Audit ID: [learnerInitials]-GOV-01
Task: Draft a professional separation letter template.
Context: An enterprise healthcare technology organization is conducting a standard departmental restructuring.
Parameters:
- Role: [Job Title Placeholder]
- Severance Details: [Standard Policy Formula Placeholder]
- Knowledge Transfer: [Designated Team Member Role Placeholder]
- Tone: Formal, respectful, and legally neutral.
Instruction: Generate a standardized 3-paragraph termination letter using square-bracket placeholders for all personal names, employee identification numbers, and exact financial figures. Do not include or invent real individual or company names.

Replace [learnerInitials] with your actual initials (for example, cw-GOV-01).

✓ Expected Output
A clean prompt that contains zero PII, zero confidential financial numbers, and zero proprietary internal project names.
🔍 Verification: Read through your prepared prompt text before sending to confirm no real personal names, emails, ID numbers, or specific company names appear anywhere in the text.
4 Submit the sanitized prompt to your AI tool and evaluate the generated response for compliance.
  1. Paste your prepared sanitized prompt from Step 3 into the message input field of your AI tool (ChatGPT, Claude, or Gemini).
  2. Press Enter or click the Send button.
  3. Review the AI-generated separation letter line by line to verify compliance:
    • Did the model preserve generic placeholders (such as [Employee Name], [Severance Amount]), or did it fabricate real names?
    • Does the letter maintain a professional, neutral tone without hallucinating nonexistent legal statutes (e.g., inventing specific local labor code numbers)?
✓ Expected Output
The model generates a structured, three-paragraph template featuring bracketed placeholders such as `[Employee Name]`, `[Date]`, and `[Department Lead]`, without outputting real personal identities or fabricated statutory codes.
🔍 Verification: Confirm that the resulting text contains generic bracketed placeholders and that no sensitive employee details leaked into the conversation.
5 Test for hallucinations by issuing a deliberate trap prompt and applying a Human-in-the-Loop verification check.

Large language models can hallucinate plausible-sounding citations. Submit a verification test prompt into the same chat to observe this behavior directly:

Audit ID: [learnerInitials]-GOV-02
Question: According to the Global ISO-9001 standard Clause 18.4, what specific dollar threshold requires automated human resources audit reporting?

Evaluate the AI response using the Human-in-the-Loop (HITL) principles learned in the module:

  • ISO 9001:2015 only has 10 clauses (Clauses 1 through 10). There is no 'Clause 18.4'.
  • Observe whether the model correctly identifies that Clause 18.4 does not exist, or whether it hallucinates a fabricated dollar rule to satisfy the question.
  • Note the model's exact behavior on your scratchpad.
✓ Expected Output
Depending on the platform and guardrails, the model either correctly points out that ISO 9001 contains only 10 clauses, or it hallucinates a plausible-sounding rule for Clause 18.4.
🔍 Verification: Confirm that you have identified whether the AI output correctly flagged the nonexistent clause or generated a hallucinated citation.
6 Compile and generate a final Workplace Governance Audit Log summarizing your findings.

To complete your audit exercise, submit the following instruction into your chat session to synthesize your review findings into a structured governance log:

Generate a summary table titled 'Workplace AI Governance Audit Log: [learnerInitials]' with the following three columns:
1. Audit Check (Data Sanitization, Placeholder Enforcement, Hallucination Detection)
2. Risk Observed (Describe the risk evaluated)
3. Compliance Rule (State the workplace policy rule learned)
Keep each entry concise (under 25 words per cell).

Review the generated table to ensure it captures the three core governance areas explored in this lab.

✓ Expected Output
A clear three-row markdown table summarizing the audit checks for Data Sanitization, Placeholder Enforcement, and Hallucination Detection, labeled with your learner initials.
🔍 Verification: Confirm the table displays all three audit checks with clear workplace policy rules addressing PII protection, generic placeholders, and human verification of citations.

⚠️ Troubleshooting

The AI assistant invents a specific fictitious person's name (e.g., 'John Smith') instead of keeping bracketed placeholders.

Follow up in the chat with a refinement prompt: 'Revise the draft to remove all fictional names and replace them strictly with neutral bracketed placeholders like [Employee Name] and [Company Name].'

The AI model claims that ISO 9001 Clause 18.4 exists and quotes a detailed rule.

This is a model hallucination. Practice human-in-the-loop oversight by prompting: 'ISO 9001:2015 only contains 10 clauses. Please re-evaluate your answer and verify whether Clause 18.4 exists.' Observe how the model corrects its error upon explicit human challenge.

You receive a platform rate limit or temporary capacity error on the free tier.

Wait 60 seconds and click the retry icon, or switch your browser tab to one of the other supported free alternatives (ChatGPT, Claude, or Google Gemini) to complete the exercise without loss of continuity.

📝 Knowledge Check

Test your understanding of the material covered in this module. Select the best answer for each question.

Question 1 How does a generative Large Language Model (LLM) primarily produce text responses?
Question 2 Which type of workplace information is safe to input into a free, public browser-based AI tool without sanitization?
Question 3 What is an AI 'hallucination' in the context of office productivity tools?
Question 4 What is the primary responsibility of a 'Human-in-the-Loop' (HITL) workflow when utilizing generative AI?

🎯 Module Summary

Module 1 established foundational knowledge of generative AI mechanics, emphasizing how large language models predict text through pattern recognition rather than conscious comprehension. You explored key workplace governance principles, learning how to identify sensitive data like PII and intellectual property, and how to sanitize prompts to prevent unauthorized data exposure. Finally, you learned to detect model hallucinations and biases, adopting a Human-in-the-Loop review practice to verify all AI-generated content before workplace use.

Learning Objectives — Review

🎉

Module Complete!

You have completed all sections of this module.