← Workflows

The AI Safety Setup

Untested security v1
Tools required
Any AI chat; 30 minutes; access to your AI tools' settings
Cost
free
Setup time
~30 minutes once, then habits
Source
original

The AI Safety Setup

What it does

Sets up your personal defenses for living with AI — once — then leaves you with a few habits. It's a firewall between you and the tools: what you paste, what you connect, what you trust, and what you do when something slips. Not paranoia; just the seatbelt.

What you need

  • 30 minutes and the settings pages of the AI tools you actually use
  • The security skills: What Not to Paste, Spot the Prompt Injection, Fact-Check Your Own AI, Spot an AI Scam, Vet a Connector, Data Privacy Check, After a Leak

Setup (one time)

  1. Privacy pass — run Data Privacy Check on your main AI tool. Turn off training on your chats if you can, set history/memory the way you want, and note what each tool is safe to hold. Do this for every AI you use regularly.
  2. Connector audit — list every tool connected to your email, files, or accounts (AI extensions, integrations, agents). Run Vet a Connector on each. Revoke anything you don't use or that has more access than it needs — including ones you forgot you granted.
  3. Account hardening — turn on 2FA on your email first (it's the master key), then your AI accounts and anything money-related. Know where the "sign out all sessions" and "revoke access" switches live.

The habits (ongoing)

  • Before you paste anything sensitive → What Not to Paste. Redact by reflex.
  • Before you feed an untrusted document to an AI (especially an agent that can act) → Spot the Prompt Injection.
  • Before you act on a high-stakes answer → Fact-Check Your Own AI. Verify in a different model.
  • When a message or call feels off → Spot an AI Scam. Verify on a channel they didn't give you.
  • Before connecting anything new → Vet a Connector. Least privilege, always.

If something slips

  • Run After a Leak immediately. Fast and imperfect beats perfect-in-an-hour. Secure email first, then contain the spread.