Unit 11 / 12

Authentication, Boundaries, Privacy and Ethics

Gains:

  • Understands that the model can produce hallucinations and that each output must be verified
  • Knows the risks and safe alternatives of putting confidential and personal data on the prompt
  • Applies ethics, copyright and liability limits in the use of artificial intelligence

It is not enough to master how to write prompts; It is also necessary to learn to use artificial intelligence responsibly. This unit is the layer of security that must be placed on top of technical skill. AI produces answers that are fast, convincing and often accurate; But sometimes it produces completely false information with the same confidence, can put sensitive data at risk and push ethical boundaries. In this unit we will cover verifying output, limitations of the model, confidentiality, and ethical responsibility. Without this knowledge, all other techniques remain incomplete.

Hallucination: Fitting the Model

A hallucination is when the model produces unreal information in a confident language. A non-existent source, an incorrect date, a fabricated statistic, or a law that was never written are examples of these. Why does it happen? Because the model is designed not to "know the truth" but to "generate the possible continuation" (remember the logic in the first unit). Just because a sentence is grammatically possible does not mean it is factually true.

The practical implication of this is clear: every fact produced by AI is a claim, not a fact, until independently verified. In particular, always check:

  • Numbers and statistics
  • Names, dates, place names
  • Quotations and source references
  • Legal clauses, technical standards, medical/financial information

Validation Habit

You can reduce but not reset verification with a prompt technique. Work in two layers:

  1. Prompt layer: Give the model restrictions such as "only rely on the source I give, do not add information that does not exist, write 'I don't know' if you are not sure, show the source of each claim." This reduces fitting.
  2. Human layer: Verify each critical fact yourself from the source. This step is non-negotiable; It is especially mandatory for content that will be published, will be the basis for decisions, or will affect others.

Limits: What the Model Doesn't Do Well

area

Risk

right approach

current events

Training data may be outdated

Verify from dated/current source

exact numbers

There is a high probability of fitting

Check with calculator/source

Legal/medical/financial

Risk of serious harm

Consult a real expert, don't rely on it alone

Source/citation

Can produce non-existent resources

Check the authenticity of the source yourself

Rare/niche topic

Superficial or inaccurate

Compare with expert knowledge

The model is an assistant, not the final authority. The responsibility always lies with the person using it.

Privacy and Personal Data

Text you type into a public AI tool is subject to that tool's processing policies and may be out of your organization's control. Therefore, entering confidential and personal data without thinking is a serious risk. Processing of personal data in Türkiye is regulated by KVKK (Personal Data Protection Law); Institutions also often have their own data policies.

Safe ways of working:

  • Anonymize/mask: Write "customer" instead of real name, "[account number]" instead of real number. Most of the time, saying "3-year corporate customer" will do the trick.
  • Use an institution-approved tool: Some institutions offer contracted/institutional tools that do not leak data. Process sensitive data only on them.
  • Don't give away what's not needed: Don't include any sensitive details that aren't actually essential to doing the task.
  • Know the policy: Learn and comply with your organization's artificial intelligence usage rules.

Ethics and Copyright

Responsible use doesn't end with privacy. Three principles:

  1. Transparency: Appropriately credit AI-generated content if the context requires it (for example, where human labor is expected). Avoid deceptive usage.
  2. Copyright and originality: The output of the model may resemble other works. Review originality and rights status before commercial use; Do not imitate someone else's brand/work.
  3. Non-maleficence: Do not use to create content that is misleading, discriminatory, manipulative or targeted. The power of the tool increases responsibility.

Four Copiable Templates

1) Constraint limiting fitting:

Just rely on the source below. Do not add any information that is not in the source. Write "not in the source" where you are not sure. Next to each important claim, indicate the line on which it is based. Source: [text]

2) Extract verification list:

List all the facts (number, date, name, claim) that need to be verified in the text below. Briefly suggest how I can verify for each. Text: [output]

3) Anonymization:

Mask all personal/confidential data in the following text: make names [PERSON], company [COMPANY], numbers [NUMBER]. Give anonymised version with the meaning intact. Text: [text]

4) Ethical review:

Ethically evaluate this content before publishing it: is it misleading, discriminatory or unfair? Flag it if so and suggest corrections. Content: [text]

Weak Prompt / Strong Prompt

Weak (risky):

Find the problems in Ahmet Yılmaz's (TC: ...) contract and compare it with industry averages.

Strong (safe):

Find the risky clauses in the contract text below. - Use of personal data; Let the parties be referred to as [COMPANY-A] and [PERSON].- Only rely on what is written in the text; industry average made up, write "data not available".- Show each risk with its item.Text (anonymised): [text]

The powerful version both protects personal data and blocks fake industry data; The output is ready for review by the legal team.

Three Mini Cases

Case 1 — Fabricated source. A researcher put 3 "academic sources" given by the model into the presentation without verifying them; Two of the sources were not available at all. A colleague noticed it before the presentation. Afterwards, the team adopted the rule of "find and open each resource personally before publishing".

Case 2 — Confidentiality. An employee pasted the actual customer contract intact into a public tool and asked for a summary. When the institution's information security team detected this, the process was reviewed; Sensitive documents are now processed only in the corporate tool approved by the institution and are anonymized.

Case 3 — Decision responsibility. A small business owner was about to take action based on the tax interpretation given by the model; The comment did not comply with current legislation. The mistake was caught when he consulted his financial advisor. The lesson is clear: the AI ​​prepares, the expert and the human decide.

Tip: Make a habit of marking a fact as "unverified". Place a check mark next to each number and source in the output until you confirm it; This simple discipline prevents misinformation from silently spreading.
Caution: "AI said so" is not an excuse. You are responsible for any content you publish, send or base your decisions on. The speed of the vehicle does not relieve you of your inspection obligation.

Common mistakes

  • Mistaking fluent output as correct. Mistaking persuasive language for evidence of truth.
  • Using the source without checking it. Publishing a non-existent source.
  • Entering confidential data without thinking. Pasting sensitive documents without anonymizing them.
  • Leaving the expertise to the model alone. Failure to verify legal/medical/financial decisions.
  • Putting the responsibility on the vehicle. Evading control by saying "AI said so".

In summary

  • Hallucination is when the model confidently produces what is not real; Every fact is a claim until verified.
  • Verification is two-fold: prompt constraints reduce fabrication, human checking catches it.
  • The model is limited to current, precise, legal/medical/financial matters; is not the final authority.
  • Anonymize confidential and personal data or process only in the tool approved by the institution (KVKK and institution policy).
  • Comply with ethical, copyright and non-maleficence principles; The responsibility for the content always lies with the person.

Application task

Take a printout you recently produced and extract all the facts in it (number, date, name, source, claim) as a verification list. Write down the verification method for each and actually check at least three of them. Also, check whether there is confidential/personal data in the input of the same output and anonymize it if necessary.

checklist

  • [ ] I can explain what a hallucination is and why it happens.
  • [ ] I verify factual output from independent source.
  • [ ] I anonymize confidential/personal data or process it in a secure tool.
  • [ ] I consult a real expert on legal/medical/financial matters.
  • [ ] I accept that I am responsible for the content.