
AI, Ethics, Safety and Privacy: How We Actually Approach This at re:ampd
Ethics, safety and privacy aren't a compliance checkbox at re:ampd - they shape which tools we recommend, how we set them up, and what we teach in every masterclass.
A quick note before we dive in: we build everything to be agnostic and portable, and we teach Claude in our workshops. Portability still holds regardless (more on that further down), but anywhere we mention specific settings, retention periods, or privacy controls below, we're talking about Claude's.
Our approach
There's a version of 'ethical AI' that gets thrown around a lot. We don't believe this phrase is completely accurate. What we do believe is that you can choose to use AI more ethically, in a more informed way - one that starts by being honest about its implications, what it costs, and what it's actually good for.
Understanding gives you a voice, and understanding the foundations of AI is the most important part of using it well. Firstly, for personal risk management, so you know where the exposure sits if something goes wrong. That matters for your business, and it matters closer to home too: if AI is something your kids are going to grow up around, understanding how it actually works is part of keeping them safe in it.
There's a difference between having a foundational understanding of AI and being a heavy user who's never looked under the hood. A critical mass of business owners who are the former can make a real difference locally - holding suppliers and stakeholders to better-informed standards, asking better questions in your industry or community, and, further out, having input into how this gets talked about and regulated nationally. When we say 'understanding gives you a voice,' we don't mean a seat at a global AI platform's table. We mean understanding what to actually say, because you understand what's going on - and that starts in your own circle, with a ripple effect from there.
In practice, our approach comes down to three things:
Foundations + Relevance
We don't teach every AI concept in existence - most of it isn't commercially relevant to your business, and trying to learn all of it would be a waste of your time. What matters is understanding the basic mechanics of how these tools work, where your data actually lives when you use them, and the handful of core concepts that show up again and again no matter which platform you're on. This is what lets you make an informed call about your own risk, hold your suppliers and stakeholders to a decent standard, and be one of the more informed voices in your community's conversation about this - and it's what makes everything else you build portable.
We build things to be portable, not locked in
This doesn't mean every system we build with you will work identically if you plug it into a different AI tool - it won't. What it means is: if Claude ever became too expensive, shut down, or you simply decided you no longer wanted to work with Anthropic, you'd know exactly where your instructions and systems live, and you'd understand the logic behind them well enough to rebuild or move them elsewhere. The economics of frontier AI are genuinely unstable, and the people running major AI companies have said publicly that getting demand forecasting wrong by a year or two could be ruinous for them. That's not a reason to avoid choosing one tool. It's a reason to deeply understand how it's built, so you're never dependent on any single provider to keep your business running.
We keep a human in the loop, always
You stay the strategic lead - asking the questions, applying your judgement, and directing the work yourself, prompt by prompt. The AI isn't doing the thinking or the writing for you in any meaningful sense; it's doing the doing. Your critical thinking, your judgement, your actual knowledge of your business, and your trust and relationship with clients get translated by you, and Claude executes on the task. AI drafts, a person reviews before anything goes external. AI supports a decision, a person makes the final call.
To be direct about where this does and doesn't hold up: having Claude write an invoice or draft a routine email isn't where anyone's critical thinking is at risk (that's low-stakes execution, not judgement). The risk is real when high-stakes thinking itself (the actual reasoning, not just the output) gets handed over rather than directed. 'You're the strategic lead, AI does the doing' is a genuinely good discipline for keeping that line in the right place. But it doesn't solve the underlying problem. This is a real, ongoing concern - noticeably so amongst younger people still in school or study, where the boundary between directing a tool and outsourcing your thinking is much easier to blur. Even with a good framework, you can still end up leaning on the tool more than your own judgement without noticing. That responsibility ultimately sits with you, using your own brain - no framework, ours included, removes that.
On New Zealand, specifically
we're not teaching this in a vacuum. New Zealand doesn't have a standalone AI law - we operate under the Privacy Act 2020, which applies to every business regardless of size, and its rule on sending information offshore (Information Privacy Principle 12) is directly relevant every time you use a cloud-based AI tool. We only got our first national AI strategy in July 2025, making us the last OECD country to have one. The most recent KPMG-University of Melbourne Trust in AI research found only 36% of New Zealanders feel they have the skills to use AI tools appropriately, just 24% have had any AI-related training or education, and 81% want clearer regulation. That's a country with low trust and low AI literacy at the same time - a combination that doesn't obviously improve on its own. What we're here to do is help close that literacy gap specifically, so 'I don't trust this' can become 'I understand exactly what I'm trusting, and why.'
On why we built this for women-owned businesses
The businesses we work with most often name two things as their biggest hesitation around AI - the safety and privacy of their data, and a sense that this whole space is too technical, too jargon-heavy, and not really built with them in mind. The research backs both up (more on that below), and most of our clients also carry a disproportionate share of the unpaid care and admin that comes with running a business and a household. The time AI can hand back matters more for our audience.
The problem with how AI gets taught (and sold)
AI genuinely is complex. If it weren't, this wouldn't be a subject people need to actually learn, and workshops like ours wouldn't need to exist. For most of the business owners we work with, 'how do I actually use this properly in my business' isn't yet a normal, worked-out conversation happening at the community level the way, say, basic bookkeeping or GST is. It's a skill gap, and it takes time to close.
Where we think things go wrong isn't the existence of that complexity - it's how it gets sold. There's a pattern among some people who know a lot about AI of inflating that complexity further than it needs to go, creating an extra layer of intricacy as part of the pitch. If something sounds more arcane than it actually is, the expert standing over your shoulder becomes very hard to walk away from, and a lot more expensive to keep. This isn't just our opinion - it's been written about extensively in the context of the broader AI consulting industry, where critics have pointed to a business model built on manufactured scarcity around skills that don't need gatekeeping, and a level of opacity that protects premium pricing far more than it protects the client.
Terms like MCP, LLM, ML, agentic, semantic, generative, second brain, RAG, vector embeddings, orchestration, and operating model get thrown around constantly. Some of that matters if you're building AI infrastructure for a living. Most of it isn't something the average user needs to know to use AI well and safely.
There's a second piece to this we care about just as much: commercial relevance. A huge amount of what gets taught in this space simply isn't going to give you any return. We're not interested in teaching you something because it's impressive or trending - only if it's actually going to save you time, reduce your risk, or make your business run better. If a concept is going to cost you hours or dollars to implement and hand you nothing back, we're not going to hand it to you. That's also why we don't sell one-size-fits-all frameworks. What works for your business depends entirely on what your business needs - a solo consultant and a five-person retail team need completely different things from AI, even on the exact same tool. Our recommendations are always bespoke for that reason, not because bespoke sounds nice, but because 'one size fits all' is usually where the wasted time and money creeps in.
We also want to be upfront about what this isn't. We're not going to tell you AI is going to change your business overnight, because it might not, and that promise is exactly the kind of oversell we're pushing back against. And we're not going to tell you how much money you could be making with AI - that's not what this is about for us. This is about buying back your time, helping you feel like you're part of the conversation instead of falling behind it, and making sure you're not paying someone else to gate-keep something you're entirely capable of understanding yourself.
Let's debunk some misconceptions
We're not going to pretend AI is uncomplicated, because it isn't. But a few of the fears we hear most often from clients are missing important context. Here's what the evidence actually says.
'AI is destroying the environment'
This one's a significant issue. Creating these AI models requires huge amounts of energy and water, and data centre expansion to keep them running has massive land-use and grid consequences. The International Energy Agency's 2025 report on AI and energy put data centre electricity use at roughly 1.5% of global electricity consumption in 2024, growing at around 12% a year - a pace the IEA's base case expects to roughly double again by 2030.
Here's the context that usually gets left out: that training cost is a one-off per model, and the day-to-day cost of using an already-built model (which is the part that's relevant to you as a user) is dropping fast. Google reported that the energy used per typical Gemini prompt fell 33-fold, and its carbon footprint 44-fold, over just twelve months to mid-2025, almost entirely through software efficiency gains rather than new hardware. Worth flagging that this is Google's own reported figure, based on median usage, not an independent audit.
The bigger, still-open question isn't really about how efficient a single prompt is - it's about the aggregate build-out this is driving. Specifically, the new gas-fired power plants being built to serve data centre demand, the strain on local electricity grids in the regions where these facilities cluster, and the significant water use needed to cool the data centres. None of that is offset by a single prompt getting cheaper to run. Whether the aggregate scale-up of AI globally is worth its aggregate infrastructure cost is an open question, and it needs resolution - through regulation, grid planning, and industry-wide accountability for how new capacity gets built - not through individual guilt, and not through pointing at efficiency gains and calling the question answered.
What we can say with more confidence is that your business running admin tasks through Claude isn't in the same universe as building a new data centre - the lever that moves the bigger number is industry and policy, not your personal usage.
'AI is going to take everyone's jobs'
The often-cited figure here is the World Economic Forum's 2025 Future of Jobs report, which projects around 92 million roles displaced globally by 2030, alongside roughly 170 million newly created (a net gain, not a net loss). Worth being precise about what that number actually measures, though: it's a combined estimate across technology, the economy, demographics, and the green transition - not an AI-specific forecast. AI is one driver among several, folded into a much broader labour-market model.
The honest answer is that nobody has clean, AI-specific displacement data yet - most of what exists measures exposure at the level of individual tasks, not entire roles disappearing, meaning specific parts of a job change hands long before, if ever, the whole role does. That uncertainty is, fairly, a lot of what people are actually scared of. We don't think there's a tidy answer to give you there. What we can say is that, from what a macro view does show so far, things are tracking better than a lot of the early, more alarmist predictions suggested - net job creation rather than net loss, restructuring rather than wholesale elimination. That's not a guarantee about your industry specifically, and it's not us telling you the uncertainty isn't real. It's just the most honest read of the data we have right now.
For the small businesses we work with, the practical version of this looks like: AI takes the repetitive admin off your plate, and the parts your clients actually pay you for - the relationship, the judgement calls, the creative decisions - stay exactly where they should, with you or your team.
'Using AI is making people stop thinking for themselves'
We take this one seriously, and it's a big part of why 'human in the loop' isn't a throwaway phrase for us - it's the whole model, in the specific sense we described above: you stay the strategic lead through prompting; the AI does the doing, not the thinking.
There's emerging research worth paying attention to here. A 2025 peer-reviewed study published in the journal Societies (Gerlich, 2025) surveyed and interviewed 666 participants and found a significant negative correlation between frequent AI tool usage and critical thinking scores, mediated by increased cognitive offloading - with younger participants showing both higher dependence on AI tools and lower critical thinking scores than older participants. A widely discussed MIT Media Lab preprint using brain-activity data points the same direction, suggesting heavy, unsupervised reliance on AI tools is linked to weaker critical engagement and worse recall of your own work afterwards. Worth being upfront about the limits of that MIT study specifically: it's a preprint that hasn't been through peer review, with a small sample (54 participants, only 18 completing the full follow-up session), and its own lead author has publicly pushed back on media coverage overstating the findings. Even the stronger, peer-reviewed Societies study is correlational, not experimental - it shows AI usage and lower critical thinking scores moving together, not that one causes the other. Taken together, it's a genuine, early signal worth taking seriously - not proof of a settled effect.
Even with all that in mind, we think the underlying concern is real, and we don't think our own approach fully solves it. Directing Claude to execute low-stakes tasks (an invoice, a routine reply) isn't where anyone's critical thinking is at risk. But we do think this is a live, ongoing issue, especially for younger people currently in school or early study, where the line between directing a tool and quietly outsourcing your own thinking is much easier to lose track of. A good framework helps keep that boundary in the right place. It doesn't remove the responsibility that sits with the person actually using their own brain - that part is always on the user, not the tool.
'AI isn't secure or private enough for client data'
This is the one we hear most often, and it depends entirely on how you're using it. A free consumer account and a properly configured business account are not the same product with the same protections, and treating them as interchangeable is where the actual risk lives. We walk through exactly what 'properly configured' means for Claude below.
Best practices for safety and privacy (Claude-specific)
These are the concrete things we tell every client to actually do. Some of this is good practice no matter which AI tool you're using - but the specific settings below are Claude's.
1. Share data through a connector (MCP) rather than pasting it in manually
Where you can, connect Claude to your data through an official connector (one Google Drive folder, one Slack workspace) instead of copying and pasting sensitive information straight into a chat. Three reasons why:
- Scoped, revocable access. A connector gives Claude permission to a specific, limited slice of your data via OAuth, and you can review or revoke that access anytime under Settings → Connectors. Once you've pasted something into a chat, there's no 'revoke' - it's already there.
- No manual handling risk. Pasting means opening the sensitive file yourself, copying it to your clipboard, and pasting it somewhere else - every one of those steps is a chance for human error: the wrong window, a shared screen during a demo, a clipboard synced across devices. A connector pulls data straight from the source without it ever touching your clipboard.
- An audit trail. Connector access is logged and tied to a specific, authorised grant. Pasted text isn't.
What's not different: once your data is inside a conversation (whether it arrived by paste or by connector) Anthropic's systems treat it exactly the same from that point on: the same default retention period, the same training opt-in/opt-out behaviour, and the same possibility of human review if something's flagged. Connectors don't hide your data from Anthropic. What they do is reduce how much sensitive data ends up loosely floating around in a chat in the first place.
2. Turn data-for-training off
This is a setting, and we recommend switching it off: Settings → Privacy → Help improve Claude.
- Off: new chats are kept for roughly 30 days and aren't used to train the model.
- On: your chats may be used for training, and can be retained for up to five years.
If you're using Claude on a personal (Pro or Max) account for business work, check this setting today - it's easy to have left it on without realising. Business-tier accounts (Claude for Work, Enterprise, or API access) run under different, generally stricter commercial terms that don't train on your data by default - worth knowing if you're regularly handling client information.
3. Enable two-factor authentication on the account tied to your Claude login
Make sure the email account behind your Claude login (Google or otherwise) has 2FA switched on. Claude's login security is only ever as strong as the account underneath it - this is the simplest, highest-leverage thing you can do today.
AI wasn't built on entirely clean foundations, it does have a real environmental cost, it is genuinely changing the shape of work, and it absolutely deserves a healthy amount of scepticism. We're not offering you a way around any of that, because there isn't one. What we're offering is a way to be properly informed enough to make your own call, use these tools well, and keep your business, your time, and your judgement firmly in your own hands - while also being one of the more informed voices in your own community, industry, and country, instead of standing outside the conversation wondering what happened.
Want help doing this properly?
Every AI Masterclass we run includes the ethics, safety and privacy conversation - not as a compliance module, but woven into how we set up the tools. If you want AI in your business and you want to sleep at night, that is what we do.
Want more like this?
Join the Members Lounge for monthly live coaching with Marisa, members-only resources, and the wider community.
Join the Members Lounge →