PMP lesson · Business Environment · Strategy and value · lesson 3 of 4 · about 6 minutes
AI tools in projects: benefits, risks and governance
All approachesFree preview
Goal: After this lesson you can identify good uses of AI in project work, recognise the confidentiality, accuracy and accountability risks, and apply simple rules for responsible use.
1The situation
Faster, but at what risk?
MES developers discovered that a public AI chatbot is great at debugging. They began pasting large parts of the customer's control software into it. The customer contract has strict confidentiality clauses, and the company's AI policy is unclear.
Meanwhile, the PM uses an AI assistant to draft meeting minutes and translate status reports, which saves hours every week.
Both are AI in projects. One is a productivity gain; the other is a potential contract breach.
2Where AI helps
AI tools can speed up drafting, summarising, analysis, translation and idea generation. They are most useful as an assistant whose work is checked.
Policy
Allowed?
Use tools approved by the organisation and permitted by contracts.
Data
Protected?
Don't put confidential or personal data into unapproved tools.
People
Accountable
Humans verify outputs and own decisions.
Unclear policy + confidential data → pause the practice and get guidance from legal, security or compliance. Don't ban all AI on your own, and don't “just remove the comments”.
3Good uses and risks
Good uses (with checks)
✔ Drafting reports, meeting minutes and emails ✔ Summarising long documents ✔ Generating risk ideas or test cases to review ✔ Analysing schedule or cost data ✔ Translating and simplifying language
Watch out
✘ Pasting confidential customer data or code into public tools ✘ Trusting outputs without checking (AI can be confidently wrong) ✘ Letting AI make decisions people are accountable for ✘ Bias in AI-based assessments of people ✘ Using tools not approved by company policy
AI is a powerful assistant, not a decision-maker.
4How it looks on the exam
Exam-style question 1. Developers have begun pasting parts of the customer's proprietary control software into a public generative AI chatbot for debugging help. The organisation's AI policy is unclear, and the contract has strict confidentiality clauses. What should the project manager do FIRST?
A. Encourage the practice
B. Ask the developers to stop sharing customer code with external AI tools until assessed against the contract and policy, and seek guidance from legal, security or compliance
C. Allow it if comments are removed
D. Ban all AI tools organisation-wide
Show the answer and the decode
Answer: B.
In simple English
Confidential code shared with an external service.
What is the question really asking?
The first action.
Key words / trigger
“pasting … proprietary … public … chatbot”
PMP logic
Pause, then get specialist guidance; confidentiality comes first.
Why the wrong answer looks attractive
Removing comments seems safer, but the code is still confidential.
5Remember this
Your memory card
AI = powerful assistant: drafting, summarising, analysis, translation
Four checks: allowed? protected? verified? accountable?
Unclear policy + confidential data → pause and get guidance