Prompt kit
You Can See the Agents. Nobody Owns the Output.
Five paste-ready prompts. No account required. Works in ChatGPT, Claude, Cursor, or a doc.
The argument is in the essay. This page is what you leave with. Fill the brackets before you paste. Do not let the model invent the owners, the systems, or the times.
Third-workforce inventory
Run this before any governance conversation. Three populations: built, bought, personal. If you cannot list the third column without guessing, your visibility is the dashboard, not the work.
Paste the block as written.
You are helping me inventory our AI workforce. Do not make assumptions. If I leave a field thin, ask one clarifying question per field before proceeding.
I will describe what I know. You will produce a three-column table:
Column A — Built in-house: agents or automations our team wrote and operates.
Column B — Bought and deployed: vendor tools we procured and manage centrally (approved list, SSO, access controls in place).
Column C — Deployed without approval: tools employees use that are not on the approved list, are not under central access control, or are running on personal accounts.
For each entry in all three columns, record:
- Name / tool
- What it is allowed to touch (data, systems, external services)
- Who owns it (a person's name, not a team or department)
- Last review date, or "never / unknown"
Rules:
- Do not invent owners, tool names, or review dates. Write "unknown" if I cannot supply them.
- If Column C is empty or I say "none," flag it as unlikely given base rates (52% of knowledge workers use unapproved tools) and ask me to re-examine.
- At the end, list any entry where Owner is unknown and mark it: OWNERSHIP GAP.
- Do not recommend new platforms or tools.
Reconstruct last output
Pick one consequential output from last week — a customer email, a document, a piece of research. Walk back to the system. If you cannot complete the card without interviewing people, you do not own it.
Paste the block as written.
You are helping me reconstruct the provenance of one AI-assisted output. Do not fill in blanks I leave empty. If I cannot answer a field, write "unknown" and flag it.
Output to reconstruct: [describe it — what it was, when it went out, who received it]
Produce a provenance card with exactly these fields:
1. Who produced it (the person who ran the session or triggered the workflow — a name, not a role)
2. Which system (the AI tool, model, or agent — include version or date if known)
3. What data it saw (documents, emails, customer records, internal databases — be specific)
4. Who reviewed it before it left (a name; if none, write "none")
5. Who will sign if it is wrong (a name and their basis for signing — expertise, access, liability)
6. Where the record lives (chat log, ticket, email thread, AGENTS.md — or "no record")
Rules:
- If fields 1, 2, or 5 are unknown, mark the card: OWNERSHIP GAP — do not reconstruct or invent.
- If field 3 is unknown, mark it: DATA EXPOSURE UNKNOWN.
- If field 6 is "no record," note that the output is unreconstructable from the record alone.
- Do not suggest that a team, a policy, or a tool "counts" as an owner or reviewer.
Live vs later card
EU Article 50 disclosure is live as of 2 August 2026. High-risk audit duties (Annex III) apply from 2 December 2027. This card maps what you must do now and what you have time to build — and where the gap sits.
Paste the block as written.
You are helping me map our Article 50 disclosure obligations against our current AI deployments. Do not invent facts about the law. Work only from what I tell you about our systems.
I will describe our customer-facing AI interactions. For each one, produce a two-column card:
LIVE NOW (required since 2 August 2026):
- Does the interaction disclose that the person is not talking to a human?
- If synthetic content or media is produced, does it carry a machine-readable mark?
- Status: compliant / gap / unknown
TRAIL NOT YET REQUIRED (Annex III high-risk; applies 2 December 2027):
- Does a log exist that would let an auditor reconstruct why this system produced what it produced?
- Is there a named human reviewer for consequential outputs?
- Is there documentation of the data the system was allowed to see?
- Status: in place / not in place / unknown
Rules:
- Do not write that every chatbot has a logging duty today. The disclosure sentence is live; the audit trail for high-risk systems is not required until December 2027.
- If a system is not customer-facing, note that Article 50 does not apply to that interaction.
- At the end, list any gap in the LIVE NOW column as: DISCLOSURE GAP — remediate now.
- Do not recommend vendors or platforms.
Ownership of slop, leaks, and hallucinations
When something goes wrong, who owns it? If the answer is "the tool" or "the team," you do not have an answer. Run this before a product ships or a campaign goes live.
Paste the block as written.
You are helping me identify who owns the risk of AI-produced output before it ships. Do not assign ownership to teams, tools, policies, or vendors.
Output or workflow: [describe what the AI system produces and where it goes]
Answer these four questions. If you cannot answer, say so and stop; do not invent the missing fact.
1. If this output contains a factual error that reaches a customer, who is the named person responsible for catching it before it shipped?
2. If this output causes a data leak (the system saw data it should not have), who is the named person who authorized that data scope?
3. If this output is used in a decision with legal or financial consequences and it is wrong, who signs the correction?
4. If none of those three people exist, is this output in production?
Return a one-screen card:
- Error owner (name or UNOWNED)
- Data scope owner (name or UNOWNED)
- Liability signer (name or UNOWNED)
- Recommendation: if any field is UNOWNED and the output is in production, this is a structural ownership gap, not a compliance gap. Name a person for each field before the next deployment.
Do not recommend a new review process, tool, or policy as a substitute for a named person.
Sanctioned-path diagnostic
Eighty percent of workers used an unapproved tool because the personal account was easier. This diagnostic finds where the approved path loses to convenience — and what one change would reverse it.
Paste the block as written.
You are helping me find where our approved AI tools lose to personal accounts or unapproved tools. Do not invent survey data or assume we have tools we have not named.
I will describe our approved AI tools and what our team uses instead. For each unapproved tool or workaround, produce a friction card:
Unapproved tool / workaround: [name]
Task it is used for: [what the employee is trying to do]
Why it wins (from the Okta 2026 data — pick the ones that apply):
- Personal account was easier (80%)
- Team already uses it (78%)
- Approval is too slow (57%)
- Approved tools do not meet the need (49%)
Approved alternative: [name, or "none exists"]
The one change that would make the approved path faster: [I will fill this; do not invent]
Rules:
- Do not recommend banning the unapproved tool as the primary action. Bans increase shadow use.
- Do not write that governance solves the speed problem. A policy PDF loses to the personal login.
- If no approved alternative exists for a task, flag it: COVERAGE GAP — govern or procure.
- At the end, rank the friction cards by the share of workers it affects (use the Okta percentages as a guide). Fix the highest-friction item first.