AI Ethics & Responsible Use Checklist for Teams

A practical, team-friendly checklist that turns high-level AI ethics principles into concrete actions: what to check, who should own it, how to verify, and what to do when something goes wrong.

How to use this checklist

This checklist helps teams adopt simple, repeatable safeguards when using AI tools. Use it as part of your workflow reviews, content production, code reviews, or change-control steps. Each item shows a short action, who typically owns verification, and clear acceptance criteria you can record or audit.

Checklist

  1. Disclose AI involvement

    State when AI generated or materially influenced an output. Short disclosure is enough if the audience needs to know.

    Who checks: Author or owner of the output. Acceptance criteria: Output includes a clear line such as “Generated with assistance from [tool name]” or an internal tag. Evidence: Published output, metadata, or file header.

  2. Cite sources and attributions

    When the AI output draws on external material (quotes, facts, images), cite the original source or note limitations if exact sourcing isn’t available.

    Who checks: Content reviewer or subject-matter expert. Acceptance criteria: Sources cited where claims require verification or attribution. If model does not provide sources, a human note explains verification steps taken.

  3. Avoid sharing sensitive PII and confidential data with AI tools

    Never paste or upload personal data, proprietary code, patient records, or other confidential information into third-party AI services unless approved and covered by data agreements.

    Who checks: Data owner or compliance lead. Acceptance criteria: No sensitive fields in prompts or attachments; approved secure environment used when necessary. Evidence: Redacted sample prompt or configuration screen.

  4. Run spot checks and verification

    Sample and verify AI outputs for accuracy, hallucination, bias, and safety before publication or operational use.

    Who checks: Responsible reviewer or peer reviewer. Acceptance criteria: A small sample (e.g., 5–10%) of outputs is checked and signed off; unverifiable claims are flagged and corrected.

  5. Maintain versioned artifacts

    Keep records of prompts, model/tool name and version, inputs, and final outputs so you can reproduce or audit decisions later.

    Who checks: Project owner or knowledge manager. Acceptance criteria: Prompt and model metadata stored alongside the artifact with a version identifier.

  6. Require human sign-off for critical outputs

    For decisions that affect people, safety, compliance, finances, or reputation, ensure a named human reviews and approves the AI-assisted output.

    Who checks: Designated approver (manager, legal, clinician, etc.). Acceptance criteria: Signed approval recorded before release; automated suggestions are not deployed without approval.

  7. Log incidents and suspicious outputs

    Record unexpected, biased, or harmful outputs and the corrective actions taken. Use an incident log that captures prompt, model, output, date, reviewer, and remediation.

    Who checks: Team lead or incident owner. Acceptance criteria: Incident entered into the log within 24–48 hours, with follow-up actions assigned.

  8. Assess and mitigate bias

    Consider demographic or stakeholder impacts and run bias checks where relevant (e.g., representative samples, counterfactual tests, subject-matter review).

    Who checks: Diversity, equity, or product owner and a qualified reviewer. Acceptance criteria: Known biases documented and mitigations applied or business case for acceptance recorded.

  9. Define acceptable use and guardrails

    Create simple rules for what AI can and cannot do in your team’s context (e.g., no hiring decisions, no unverified medical advice).

    Who checks: Team lead and compliance/legal. Acceptance criteria: Written acceptable-use rules accessible to the team and enforced in workflows.

  10. Train people on safe prompts and tool limits

    Teach team members how to craft effective prompts, recognize model limits, and escalate uncertain outputs.

    Who checks: L&D or team lead. Acceptance criteria: Basic training completed and job aids available; new users paired with experienced reviewers.

If a checklist item fails

Stop deployment of the affected output if it risks people, compliance, or reputation. Log the incident, notify the owner, and remediate (revise prompt, verify sources, redact PII, or obtain human-reviewed replacement). Escalate to legal or security if necessary.

Quick disclosure templates

  • Simple audience-facing: “This content was produced with assistance from [tool name].”
  • Internal note for reviewers: “AI-assisted draft (model: [name/version]). Please verify facts and sources before sign-off.”

Roles & cadence

Assign a content owner, a reviewer, and an incident owner for every AI-assisted workflow. Re-run the checklist on major releases, monthly for live systems, or when you change model/tool, prompt patterns, or data inputs.


Discussion

Comments and conversation will live here.