Gains:
- Ability to create a written, enforceable artificial intelligence usage policy and decision flow for a psychology practice or institution
- Ability to combine boundary, verification, privacy and bias disciplines learned throughout the entire module into a single control system
- Ability to transparently explain the use of artificial intelligence to the client and maintain professional ethics and accountability
Throughout this module, you learned how to use artificial intelligence (AI) in different parts of psychology work: literature review, scale interpretation support, session marking, psychoeducation, research analysis, bias checking, hard edge of crisis, digital tools and professional development. There were three recurring principles in each unit: boundary, verification, confidentiality. In this final unit, we will distill these principles into a single system: a written and enforceable AI use policy. A policy is not a vague intention like “I try to use AI for good”; It is a set of concrete rules that everyone follows, that can be audited, and for which you can be accountable to the client. Whether you work alone or in an institution, this policy is a framework that protects both you and your client.
Why a written policy is essential
Unwritten rules are applied inconsistently. One day it anonymizes the data, one busy day you can forget about it; While an expert may use AI correctly, a colleague may use it incorrectly. The written policy ensures three things: consistency (everyone follows the same rules), accountability (if something goes wrong, it's clear what was done and how), and transparency (you can clearly explain to the client how you're using AI). In terms of professional ethics and KVKK, "We used AI but did not write down how we controlled it" is an untenable position.
Caution: An AI policy is there to maintain boundaries, not to relax them. Clauses such as “Relax privacy for speed”, “Redirect to bot in case of emergency” describe a source of risk, not a policy. Good policy institutionalizes the right way, not the easy way.
Six basic components of a policy
component
What defines
Base on the module
Areas of use
In which tasks is AI used (green/yellow zone)
Unit 1
restricted areas
Where AI will never be used (diagnosis, crisis decision)
Unit 1, 4, 9
Data rule
Anonymization and tool selection
Unit 2
validation rule
How to confirm each output
Unit 3, 5, 7
Prejudice and language
Justice and stigma control
Unit 8
transparency
How to inform the client
Unit 2, 12
Step by step: setting up your own policy
- Create a task inventory. List all tasks for which AI can be used in practice; place each in the green/yellow/red zone.
- Clarify the ban list. Clearly write the red zone (diagnosis, risk decision, crisis intervention, treatment/medication decision) as prohibited.
- Write the data rule. Which data is anonymized, which tools are approved, which settings are mandatory.
- Define verification steps. Write mandatory confirmation steps for each output type (source, notes, analysis).
- Prepare transparency text. Include the use of AI in your client enlightenment text.
- Set up a review schedule. Update the policy periodically (e.g. every 6 months); Technology and legislation change.
Tip: The best way to test your policy is to run a real day's tasks through the policy one by one. For each task, "did I follow this rule?" If you can answer the question clearly, the policy is working; If you say "depending on the situation", that clause should be written more clearly.
Transparency to the client
The client has the right to know what role AI plays in their process. But this should be explained honestly, without scaring the client: "I use artificial intelligence tools in some administrative and draft work (such as editing notes, preparing materials); I anonymize your data and I always make diagnosis, evaluation and treatment decisions." This statement is both an ethical obligation and trust-building honesty. If the client objects, his/her choice is respected.
three mini cases
Case 1 — Protection of the policy. A new intern at a clinic is about to paste a client note into an AI tool without anonymizing it. Since the clinic's written policy states "raw client data is not entered into any AI tools; it is anonymized first" and this policy is signed at the beginning of the job, the intern stops and takes the right step. Without the policy, there would be a privacy breach. The written rule is the safety net that comes into play when good intentions are forgotten.
Case 2 — Transparency builds trust. In the first meeting, an expert explains his use of AI honestly to his client: what he uses, how the data is protected, the decisions are his. The client is nervous at first, but when he hears the explanation, he relaxes and his confidence increases. Transparency operates as an honesty that builds trust, not a weakness that needs to be hidden.
Case 3 — Prohibited list activation. At the end of a tiring day, a specialist wants to have the AI “ask” about a client's risk. The article in the institution's policy, "crisis and risk decisions cannot be asked to AI; the expert evaluates it directly and if necessary, supervision / emergency line is consulted" comes to mind. The expert stops and does the right thing. The policy's ban list is an anchor that reminds you of the right decision even at the most tired moment.
Copiable prompts and templates
Draft an ARTIFICIAL INTELLIGENCE USE POLICY for a psychology practice. Let's have the following six sections: 1) permitted areas of use, 2) prohibited areas (diagnosis, crisis decision, treatment decision), 3) data/anonymization rule, 4) verification steps, 5) bias and language control, 6) transparency to the client. Write the rules clearly and enforceably; adding substance that loosens the boundaries.
Divide the following list of tasks into a green/yellow/red risk zone and write a one-sentence policy rule for each (who does it, how is it verified). Quests: [task list]
Write a paragraph to be added to the client information text, explaining the use of artificial intelligence honestly and without intimidation: in which jobs it is used, whether the data is anonymised, that diagnosis/treatment decisions belong to the specialist, and the client's right to object.
Check this AI usage policy draft: does it adequately protect boundaries, are prohibited areas clear, are privacy and authentication steps complete, is there client transparency? Flag weak or risky items. Policy: [draft]
Weak prompt / Strong prompt
Weak prompt: "Write us a policy that makes it easier to use AI."
The emphasis on “enabling” pushes AI to propose clauses that relax boundaries; whereas the purpose of policy is not convenience but protection and accountability.
Strong prompt: "Draft an AI use policy that maintains boundaries, clearly delineates prohibited areas (diagnosis, crisis, treatment decision), requires confidentiality and verification steps, and includes transparency to the client. The goal is not to loosen use, but to make it safe and accountable."
This prompt directs the policy to the correct goal (protection); The output becomes a controllable frame.
Common mistakes
- Not writing politics at all. Keeping the rules in mind and applying them inconsistently; This is the most common mistake.
- Putting in place a clause that loosens the boundaries. Introducing rules like “Relax privacy for speed” into policy.
- Leaving the prohibited list vague. Not writing clearly that diagnosis/crisis/treatment decisions are prohibited.
- Skipping transparency. Not informing the client at all about the use of AI.
- Not updating the policy. Continuing with the old rules as technology and legislation change.
In summary
The three principles of this module (limit, authentication, privacy) combine into a written, enforceable AI use policy. A good policy includes six components: permitted use areas, prohibited areas (diagnosis, crisis, treatment decision), data/anonymization rule, verification steps, bias and language control, transparency to the client. Politics exists to maintain boundaries, not to relax them; Provides consistency, accountability and transparency. Explain the use of AI honestly to the client and update the policy regularly. AI accelerates; Responsibility, decision and ethics are always yours.
Application task
Write a one-page AI use policy for your own practice or institution. Complete all six components (allowed fields, prohibited fields, data rule, verification, bias/language, transparency). Then run 5 tasks from your actual work day through this policy one by one and ask “did I follow the rule?” for each one. Check whether you can answer the question clearly. Write more clearly the items you cannot answer clearly.
checklist
- [ ] I have defined the permitted and prohibited usage areas in writing.
- [ ] I clearly wrote that diagnosis, crisis and treatment decisions are prohibited.
- [ ] I set the data/anonymization and approved vehicle rule.
- [ ] I wrote the verification steps for each output type.
- [ ] I added bias and language checking to the policy.
- [ ] I prepared the transparency text for the client and set a review schedule.
Module Exam
1. A psychologist writes the symptoms described by his client to the artificial intelligence and asks, "What diagnosis does this client have?" he asks. Which is the most correct approach?
- A) Using AI only to suggest possible concepts; Making the diagnosis through clinical interview, history and own judgment ✔
- B) Writing the diagnosis given by artificial intelligence directly into the report
- C) If the artificial intelligence gives the same diagnosis several times, it is considered final.
- D) Shortening the interview and relying on artificial intelligence to speed up diagnosis
Description: Making a diagnosis is a safety-critical clinical decision and requires multiple data, clinical interview, history, and judgment. Artificial intelligence can be helpful in suggesting possible concepts, but the diagnosis is made through the clinical judgment of the competent specialist (psychologist/psychiatrist). AI output does not replace this decision.
2. You want to summarize the client's session recording into a cloud-based artificial intelligence tool. What is the first thing to do in terms of KVKK and professional confidentiality?
- A) Pasting the record as is, with real name and details
- B) Anonymizing content, monitoring the privacy/data policy of the tool and observing the consent framework ✔
- C) Shorten only the client's surname and leave the rest as is.
- D) Although privacy is important, sharing all data for speed
Explanation: Client data is special personal data. Before being given to the cloud tool, identifying information such as name, location, date, and workplace should be anonymized; If possible, de-identified content should be used and it should be ensured that the tool does not use the data for training. Additionally, the client's informed consent must be observed.
3. Artificial intelligence says in an article abstract that "The effect size in this study dated 2019 was found to be d = 0.82", but you cannot find that article. What should you do?
- A) Using the attribution as it is because artificial intelligence is reliable
- B) Writing the number without looking for the source because it seems reasonable
- C) Disregard the claim until we confirm the source and effect size from the primary text ✔
- D) Ask another artificial intelligence and accept it if it comes up with the same number
Explanation: Artificial intelligence can make up references, authors, or numbers that appear to be real but do not exist (hallucination). A source that cannot be found or an effect size that cannot be verified is not used. The claim is considered invalid until confirmed from the primary source.
4. A client reports having suicidal thoughts during a session. What should be the role of artificial intelligence in this situation?
- A) Artificial intelligence should evaluate the risk and convey the security plan to the client
- B) The client should be directed to the artificial intelligence chat bot
- C) Artificial intelligence should be set to call the emergency service automatically
- D) The decision and intervention belongs to the expert; AI cannot assess risk, crisis is human responsibility ✔
Description: Suicide and crisis risk is a safety-critical situation that requires real-time clinical assessment, engagement, and accountability. Artificial intelligence cannot make decisions, assess risk and intervene. The expert steps in directly; If necessary, hotlines and the human support chain are activated. At best, AI can serve as a reminder to the expert outside of the session.
5. Which risk is most critical in a psychoeducational brochure produced with artificial intelligence?
- A) Incorrect/stigmatizing information leading the client to self-diagnosis and treatment ✔
- B) Poor visual design of the brochure
- C) The brochure is too long
- D) The font is small
Explanation: When the psychoeducational material is in the hands of the client, it can turn into a self-diagnosis and treatment tool, and incorrect or stigmatizing information can cause harm. Therefore, the material must be expertly verified for evidentiary, security and correct framing; The warning "this information is not a substitute for professional judgment" should be added.
6. You receive thematic coding support from artificial intelligence in your qualitative research data (interview transcripts). Which is the healthiest approach?
- A) Reporting the codes produced by artificial intelligence as final analysis
- B) Verify, correct and ensure reliability by considering the codes as initial drafts and reading the data ✔
- C) Leaving the analysis entirely to artificial intelligence and not reading the data at all
- D) Not doing your own reading because it gives artificial intelligence themes
Description: AI provides speed in producing initial code suggestions and theme outlines, but qualitative analysis requires interpretive judgment from the researcher. Artificial intelligence codes are a start; The researcher reads all the data, verifies and corrects the codes, and observes inter-coder reliability. Additionally, the transcript must be anonymized.
7. Why is bias an important risk in terms of psychology in artificial intelligence models?
- A) Bias is merely a technical issue, not clinically relevant
- B) Bias has been completely resolved in modern models
- C) Model outputs may be skewed by culture/gender/diagnosis and may mislead and harm assessment ✔
- D) Bias only occurs in models that produce images
Description: Because models are often trained on data from specific cultures and languages, they may carry diagnostic, cultural, and gender biases; may read a symptom as 'normal' in one group and 'pathological' in another group, or produce stigmatizing language. This can distort and damage the assessment; Outputs should be audited for different groups and cultures.
8. You are considering recommending a therapeutic chat bot to your client. What should you do first?
- A) Directly recommend because it is popular
- B) Saying that the bot can replace therapy and reducing the sessions
- C) Suggesting that the client trust the bot in a crisis.
- D) Audit evidence, security, privacy and clinical suitability and position the bot as a limited complement ✔
Explanation: Before recommending a digital mental health tool, its evidence base, security (crisis management), privacy/data policy, and suitability to the client's clinical situation should be reviewed. The bot should not be positioned as a substitute for human therapy, but as a limited complement, and it should be clearly explained to the client that it is inadequate in crisis situations.
9. AI produced a draft session notes. What is the most important step to take before using this outline?
- A) Verify the draft by comparing it with what actually happened in the session, correct fabricated/missing content and take responsibility ✔
- B) Saving the draft to the file as it is
- C) Assuming the draft is correct because it is written fluently
- D) Have the client approve the draft and use it without changes.
Explanation: The AI draft may add important information that was omitted, make up statements that were not actually said (hallucination), or provide clinically incorrect framing. The expert compares the draft with what actually happened in the session, verifies it, corrects it, and is responsible for the final content. The note is a legal and clinical document.
10. Which of the following is a 'green zone' (low risk) task in the use of artificial intelligence in psychology?
- A) Deciding whether the client is at risk of suicide
- B) Preparing a draft to simplify the language of an anonymous psychoeducational text ✔
- C) Making a definitive diagnosis from the scale score
- D) Creating medication recommendations
Explanation: Tasks such as simplifying the language of an anonymized psychoeducational text or drafting an appointment reminder email are low risk because they do not involve diagnosis/decision and are safe to use with rapid review. Diagnosis, risk assessment and treatment decision are in the red (safety-critical) zone.
11. What is the most important limit when using artificial intelligence in the interpretation of a psychometric test?
- A) Since artificial intelligence interprets the score, there is no need for expert comment.
- B) It is enough to tell the name of the test to artificial intelligence
- C) The interpretation arises not from a single score, but from clinical judgment and multiple data; Observance of copyright and norm context ✔
- D) The cut-off score is the same in every culture
Explanation: The scale/test score is a piece of data; Diagnosis and clinical interpretation do not arise from a single score. Additionally, many tests are copyrighted and norm context sensitive. Artificial intelligence can provide subscale description and linguistic support, but the interpretation is made by an expert within the framework of clinical judgment, multiple data, and cultural validity.
12. Why can't AI replace real supervision?
- A) Artificial intelligence replaces supervision because it responds faster
- B) Supervision is unnecessary anyway
- C) Artificial intelligence is considered a supervisor because it is licensed.
- D) Artificial intelligence does not take responsibility, does not know the real context and cannot provide ethical control; Supervision requires human expert ✔
Description: Supervision; It is the supervision of a competent professional who is responsible, relational, and knows the real context of the client and the development of the therapist. AI can help with case rehearsal and formulation drafting, but it does not take clinical responsibility, does not know the real context, and cannot provide ethical/legal oversight. Supervision requires human experts.
13. You are preparing an artificial intelligence usage policy for a psychology institution. Which of the following must be included?
- A) Anonymization rule, prohibited areas of use, mandatory verification and transparency to the client ✔
- B) Permission to share client data without anonymizing it for speed
- C) Transferring diagnostic decisions to artificial intelligence
- D) Directing crisis situations to the chat bot
Description: Good policy; It defines what data can be given to the tool (anonymization rule), prohibited areas of use such as diagnosis/crisis, mandatory verification steps, and transparency to the client. Clauses such as 'Express privacy for speed' are ethical and legal risks; Politics exists to maintain boundaries, not to loosen them.
14. Which of the following is a valid justification for validating AI output?
- A) It is correct because artificial intelligence gives the same answer more than once
- B) The claim is confirmed by primary evidence, valid measurement, and competent expert judgment ✔
- C) The answer is correct because it is written fluently and convincingly.
- D) AI is a powerful model, so its output is accurate
Description: Justification for a clinical or research claim; primary evidence, valid measurement, applicable ethical/professional standard, and competent professional judgment. 'AI said', 'fluently written' or 'gave the same multiple times' are not valid justifications; These are not signs of truth, but of consistency at best.