1. Approve the use case

Identify the exact task, intended user and permitted output before a tool is introduced. A low-risk drafting aid should not quietly evolve into an automated decision or filing process.

2. Control the information entered

Classify information before it is submitted to any external tool. Client identifiers, passwords, unpublished financial data and privileged or contractually restricted material require particular care.

3. Require human verification

AI-generated calculations, citations, classifications and conclusions should be checked against primary records and authoritative sources. Fluency is not evidence of accuracy.

4. Keep responsibility with a named person

Assign responsibility for reviewing inputs, validating outputs, approving use and escalating exceptions. The tool should not obscure who is accountable for the final work product.

5. Record exceptions and improve the process

Maintain a simple record of material errors, confidentiality concerns and overrides. Repeated exceptions are a signal to change prompts, controls, access or the underlying use case.