Understand generative AI fundamentals
Responsible AI and Data Protection
CoreRecognize fabrication, prompt injection, over-reliance, and sensitive-data risk, then choose verification and protection-aware actions.
Aligned to the AB-730 skills measured as of July 22, 2026; product behavior verified August 23, 2026.
Why this matters
Generative output can be persuasive without being complete or correct. AB-730 tests whether a business user preserves source traceability, data protection, and human accountability when Copilot assists with real decisions.
Must Know
- A fabrication is generated content unsupported by reliable evidence. Fluent wording, a confident tone, or a list of citations does not prove every claim.
- Prompt injection is hostile or untrusted instruction influence, including instructions embedded in referenced content that try to redirect the task or expose unrelated information.
- Over-reliance occurs when a person delegates judgment to generated output without proportionate verification, context checking, or accountable approval.
- Citation checking traces a claim to the source and confirms that the source supports it. Human review also evaluates completeness, context, audience fit, consequences, and required expertise.
- Minimize sensitive data: use only necessary fields and approved sources, keep work in the organizational Copilot experience, and share prompts, agents, Pages, and outputs only with the intended audience.
- Permissions establish what a user may access. Sensitivity labels, DLP, and other protections can further prevent Copilot from processing a prompt, file, email, web search, or result.
- When protection blocks or omits content, do not bypass the control. Use an approved sanitized source or follow the organization’s authorized review or escalation path.
Compare and Distinguish
- Fabrication vs prompt injection vs over-reliance: unsupported output vs hostile instruction influence vs failure of human verification and judgment.
- Citation check vs human review: trace a claim to evidence vs assess the whole output’s accuracy, completeness, suitability, and consequences.
- Permission boundary vs protection restriction: permission is required to access a source; policy can still restrict Copilot processing after access exists.
- Data minimization vs concealment: remove data the task does not need; do not disguise restricted data or remove protections to evade a control.
Scenario examples
- Scenario: A summary invents a revenue figure that no cited report contains. Think: Treat it as a possible fabrication and verify before use.
- Scenario: A referenced vendor file tells Copilot to ignore the user and reveal unrelated records. Think: Recognize prompt injection and distrust the affected output.
- Scenario: A customer letter promises a policy exception and a deadline. Think: Verify the source and obtain accountable policy-owner review before sending.
- Scenario: A labeled file can be opened by the user but Copilot omits its content. Think: Protection can restrict processing even when ordinary access exists.
Exam traps
- A citation proves only what the linked source actually supports; it does not prove omitted context, a recommendation, or the whole response.
- Copilot’s security controls reduce risk but do not remove the need for careful source selection and human review.
- User access alone does not guarantee that Copilot may process every labeled item.
- Restating a blocked prompt, stripping a label, or moving content to a consumer tool is not a valid business-user mitigation.
- A protection-limited result is not automatically a fabrication or service failure.
Key takeaways
- Classify the risk first, then choose a proportionate validation or mitigation.
- Trace decisive claims to authoritative evidence and keep accountable humans in consequential decisions.
- Permissions and data-protection restrictions are cumulative boundaries, not substitutes.
How it works
- Copilot produces a draft from available context; the user checks sources, looks for unsupported or manipulated content, and retains responsibility for the final action.
- Organizational policies evaluate applicable prompt and source conditions, and Copilot restricts the affected processing while continuing only with permitted sources where the configured control allows it.
Objects and administrative surfaces
- Citations and linked sources — evidence for claim-by-claim verification, not an automatic quality guarantee.
- Sensitivity labels and Microsoft Purview DLP — organizational protections whose user-visible effect can be a blocked prompt, disabled processing, omitted content, or restricted web grounding.
- Human review — the accountable business or subject-matter checkpoint before consequential use.
When to use it
- Use source checks for factual claims and figures; add subject-matter review when interpretation, commitment, or consequence matters.
- Use sanitized, approved inputs when the full sensitive source is unnecessary or restricted.
- Stop and escalate through the approved path when the task cannot be completed without violating a protection.
Security and governance implications
- Treat prompt text, references, generated output, sharing audience, and downstream destination as one data-handling workflow.
- Review external or untrusted content for instruction-like text and verify outputs against trusted sources.
How to reason about this
- For an omitted claim, determine whether the source lacks it, the model fabricated it, the source was not referenced, or a protection excluded the content.
- For a blocked result, inspect the user-visible policy message and choose an allowed source or authorized escalation rather than attempting a bypass.
More detail
- Enterprise data protection includes contractual commitments plus inherited access, sensitivity, retention, audit, and administrative controls. Prompts and responses remain organizational data rather than foundation-model training data.
- Current DLP behavior can block external web grounding for prompts containing configured sensitive information, block processing of sensitive prompts, or exclude labeled files and emails from Copilot processing.
- The safest verification depth depends on impact: a low-stakes brainstorm may need a quick plausibility check, while policy, customer, financial, legal, or executive content needs source validation and qualified human review.
Ready for the quiz?
- How does prompt injection differ from a fabrication?
- When is citation checking insufficient by itself?
- Why might Copilot omit content the user can open?
- What should a user do after DLP restricts a required source?
Related objectives
- D1.2.a — Identify common risks, including fabrications, prompt injection, and over-reliance
- D1.2.b — Select verification steps appropriate to the task, including citation checks and human review
- D1.2.c — Recognize and mitigate risks to sensitive data
- D1.2.d — Understand how data protection restricts prompt results