
AI drafts. People decide.
Scope a useful AI drafting task, preserve source evidence, validate the output, and keep editorial authority with the reviewer.
Read the guideStart with an inspectable task: a draft, summary, glossary check, or explanation. Keep model suggestions separate from publication and execution authority.
A release-note summary is a better starting task than “manage our documentation.” Define what the output must preserve, what it must not invent, and what the reviewer should do when the source is incomplete. Keep the original material visible beside the draft so evaluation does not depend on fluent wording alone.
Documents can contain instructions that are irrelevant or hostile to the intended task. OWASP describes this class of problem in its prompt injection guidance. Keep source material separate from the authority to choose tools, change destinations, or publish. Review the paths through which input can become markup, links, or action parameters.
Check facts, links, identifiers, and examples against the reviewed source. Separate style edits from technical approval. Preview safety-relevant instructions beside the interface action they describe. A correctly formatted draft is not proof that its claims are correct, and a confident tone is not evidence of compatibility or permission.
Keep representative examples: complete sources, incomplete notes, contradictory wording, and irrelevant embedded instructions. Repeat the evaluation when the model, prompt, source collection, or output handling changes. Assess unsupported additions and omitted facts as well as editing effort. Narrow the task when the reviewer cannot reliably verify the result.
OWASP’s prompt injection guidance describes risks from instructions embedded in model inputs and recommends layered controls.
Read the prompt injection guidanceNot for the editorial workflows described here. First identify the task and its evidence requirements; then decide which components, if any, need network execution.
When the system gains capabilities to act through tools, such as publishing or changing configuration, review the additional permissions and authorization boundary separately.