Myelin Learning LabDashboardBriefsToolsStatus
Three applied courses · non-credit

Practise the decision, not the vocabulary.

Evidence, privacy and governance — six lessons and eight decisions each, with a written scenario in every lesson and a record you can export.

Non-credit boundary: These courses award 0.0 CE credits. They do not verify identity, confer an accredited certificate, or satisfy a licensing requirement.

How the lab works

Three courses, six lessons each, and an eight-question decision check at the end of every one. All three are on this page in full — nothing is unlocked, and you can read every lesson and every question without answering anything. The picker above simply jumps you to one.

Each lesson ends in a scenario, and the order matters. Write your own answer in the box before you open the model response. Reading a good answer first feels like learning and is not: recognition is much easier than recall, and the gap between them is precisely what shows up when you have to make the call yourself, unprompted, on a Tuesday afternoon. Your writing stays in this browser and is never sent anywhere.

Which one to take first. If you publish, file, or send anything a model helped produce, take EV-10 — it is about the distance between a claim and the evidence for it. If you are the person deciding what may be pasted into a tool, take PR-12. If you are accountable for a system other people use, take GV-15. If you are unsure, EV-10 is the one whose habits the other two assume.

What commonly goes wrong: completing the reading and skipping the scenarios. The lessons describe a procedure; the scenarios are where you find out whether you can actually run it when the facts are ambiguous and the deadline is real. A course finished without the scenarios has taught you the vocabulary and not the judgement.

The boundary, stated plainly: every course here awards 0.0 CE credits. Myelin is not an accredited or approved continuing-education provider, no identity is verified, and nothing is reported to any licensing board. See credential status for the full statement.

EV-10 · 6 lessons · approximately 55 minutes

Claims, Sources & Citations

Build a reproducible path from a generated claim to evidence a qualified reviewer can actually defend.

0 of 6 lessons complete

Lesson 1 of 6

Find the claims hiding in prose

Objective: Convert polished language into discrete propositions before evaluating it.

A sentence can hide several claims. “AI improves access to mental-health care” may assert increased availability, actual use, equitable reach, clinical benefit, and a causal relationship. Each needs different evidence.

Method: circle the actor, action, population, comparison, outcome, place, and time. Label the result fact, inference, opinion, recommendation, or forecast. Rank it high, medium, or low consequence if wrong.

Apply it: A briefing says “automated intake reduces clinician burden and improves outcomes.”
Reveal a defensible response

Separate at least four claims: the intake is automated; clinician time or workload changed; patient outcomes changed; and automation caused the change. Do not evaluate the bundle as one claim.

Framework: NIST AI RMF · NIST GenAI Profile

Lesson 2 of 6

Match evidence to the proposition

Objective: Determine which source type can establish the exact proposition.

Authority depends on the question. Enacted text establishes what a statute says. A regulator explains its administration but may not resolve a court’s interpretation. A randomized study may estimate an intervention effect in its sample but not prove universal effectiveness.

Build an evidence hierarchy for the claim—not for the topic. Prefer original decisions, rules, standards, datasets, and reported results; use commentary to discover and contextualize them.

Apply it: A vendor blog links to a peer-reviewed study and says its product is “clinically validated.”
Reveal a defensible response

Open the study. Confirm the tested product/version, sponsor, population, comparator, endpoint, follow-up, attrition, effect size, uncertainty, and whether “clinical validation” is language the study supports.

Framework: NIST AI RMF · NIST GenAI Profile

Lesson 3 of 6

Read beyond the abstract

Objective: Test design, denominator, comparator, and limitations before repeating a result.

Ask who was included and excluded, how exposure and outcomes were defined, what the comparison actually was, whether missing data could change the result, and whether the analysis was prespecified. Relative change without the baseline can exaggerate practical importance.

Write both the supported claim and the strongest material limitation. If you cannot explain the denominator and comparator, you are not ready to publish the number.

Apply it: A study reports a 50% reduction, from 2 events per 10,000 to 1 per 10,000.
Reveal a defensible response

Report the absolute and relative change, timeframe, population, and uncertainty. “50% reduction” alone conceals the small baseline risk.

Framework: NIST AI RMF · NIST GenAI Profile

Lesson 4 of 6

Verify legal and policy claims

Objective: Check jurisdiction, authority, procedural status, effective date, and later history.

Distinguish a bill from enacted law, guidance from a binding rule, a trial ruling from controlling appellate authority, and publication from effectiveness. Track amendments, stays, appeals, repeals, corrections, and agency updates.

A reliable ledger records jurisdiction, issuing body, document type, identifier, date, effective status, pinpoint, and later treatment.

Apply it: A generated memo says “the state banned automated hiring decisions in 2025.”
Reveal a defensible response

Identify the state, instrument, covered decisions and entities, exceptions, effective date, implementing rules, enforcement, and current status. The sentence may be overbroad even if a relevant law exists.

Framework: NIST AI RMF · NIST GenAI Profile

Lesson 5 of 6

Use citations as evidence infrastructure

Objective: Create proposition-level citations another reviewer can reproduce.

Place a citation where its support is visible. Record title, issuer/author, stable identifier or URL, pinpoint, version, access date, and the proposition it supports. Archive permitted copies or metadata when link rot matters.

One citation at the end of a paragraph rarely supports every sentence. Never retain a plausible citation you have not opened.

Apply it: Three claims in one paragraph share one footnote to a 60-page report.
Reveal a defensible response

Create a claim-to-source table. Give each material proposition its own pinpoint or mark it unsupported. Narrow or remove anything the report does not establish.

Framework: NIST AI RMF · NIST GenAI Profile

Lesson 6 of 6

Write the verification record

Objective: Document the human judgment that turns research into defensible work product.

For each material claim record: exact wording, claim type, consequence of error, source, pinpoint, support summary, limitations, currency check, reviewer, date, and disposition—retain, narrow, qualify, remove, or escalate.

Close with unresolved uncertainty and the condition that would change the conclusion. Verification is complete when another qualified person can reproduce the path, not when the prose sounds convincing.

Apply it: A deadline arrives with two claims still unverified.
Reveal a defensible response

Do not silently publish. Remove them, label uncertainty with its decision impact, or escalate for an explicit risk decision. Record what remains open and who accepted it.

Framework: NIST AI RMF · NIST GenAI Profile

Applied mastery check

Eight decisions — not trivia

Complete all six scenarios and answer at least 7 of 8 questions correctly. Each response receives explanatory feedback.

1. A statement contains actor, outcome, and causation. What comes first?
2. A vendor says its tool is clinically validated. Best first move?
3. A 50% reduction from 2/10,000 to 1/10,000 should be reported as:
4. A bill introduced last month is:
5. One footnote after three factual sentences:
6. If a source cannot be opened:
7. A limitation that changes applicability should be:
8. Verification is complete when:

Browser-generated learning record

EV-10 completed

Completed
Mastery
Credit0.0 CE
Record ID

Not a certificate. Identity was not verified and no accreditor or licensing board approved this activity.

PR-12 · 6 lessons · approximately 55 minutes

Data Before Prompts

Decide what may enter an AI system before convenience turns into an unauthorized disclosure.

0 of 6 lessons complete

Lesson 1 of 6

Map the data and the duty

Objective: Identify the data, people, source, authority, and duties before choosing a tool.

Inventory direct identifiers, quasi-identifiers, communications, records, metadata, and inferred attributes. Ask who provided the information, for what purpose, under which notice, consent, policy, contract, privilege, or professional duty.

“Publicly available” is not a universal permission. Accuracy, context, terms, expectations, intellectual property, anti-discrimination rules, and reuse restrictions may still matter.

Apply it: A team wants to paste public employee biographies and internal performance notes into a ranking tool.
Reveal a defensible response

Treat the combined dataset as employment information. Identify decision purpose, authority, notice, discrimination risk, vendor handling, and whether the ranking is permitted—not merely whether biographies are public.

Framework: NIST AI RMF · NIST GenAI Profile

Lesson 2 of 6

Minimize and transform

Objective: Use the least information needed and choose the safest workable representation.

Remove fields unrelated to the task. Prefer synthetic records for design, aggregate data for trends, local processing where feasible, and tokenization or redaction when identifiers are unnecessary. Test whether combinations can re-identify someone.

Minimization reduces exposure; it does not create authority, eliminate bias, or make a prohibited use lawful.

Apply it: A contract summary needs payment dates but not party identities.
Reveal a defensible response

Use a verified local/redacted workflow containing only relevant clauses and dates. Preserve a secure mapping outside the AI tool only if the task truly requires it.

Framework: NIST AI RMF · NIST GenAI Profile

Lesson 3 of 6

Interrogate the actual product

Objective: Verify plan-specific retention, training, access, transfer, deletion, and security controls.

Consumer, team, enterprise, API, and embedded versions can have different terms. Record the exact service, plan, settings, contract version, subprocessors, storage regions, logging, training/reuse, administrative access, deletion mechanics, incident notice, and exit process.

A privacy toggle, marketing page, or model answer is not a complete technical and contractual assessment.

Apply it: A colleague says, “It is enterprise, so our data is private.”
Reveal a defensible response

Confirm the signed agreement, enabled settings, administrator configuration, subprocessors, retention, support access, training terms, and whether the proposed data category is approved.

Framework: NIST AI RMF · NIST GenAI Profile

Lesson 4 of 6

Separate privacy from confidentiality and security

Objective: Apply the right control to the right risk.

Privacy concerns appropriate processing of information about people. Confidentiality limits disclosure. Security protects systems and data. Privilege, trade-secret protection, records law, research rules, and professional ethics create additional layers.

Encryption can protect transit and storage while the use itself remains unauthorized. De-identification can reduce identifiability while the output still creates discriminatory effects.

Apply it: A tool encrypts all uploads but retains them indefinitely for product improvement.
Reveal a defensible response

Encryption does not answer purpose, reuse, retention, authority, or deletion. Evaluate each dimension separately.

Framework: NIST AI RMF · NIST GenAI Profile

Lesson 5 of 6

Use a proceed–escalate–stop gate

Objective: Translate uncertainty into an operational decision.

Proceed only when purpose is authorized, data is minimized, the tool is approved, controls are known, and human responsibility is assigned. Escalate sensitive categories, new vendors, new purposes, cross-border transfers, vulnerable populations, or uncertain authority. Stop prohibited data, missing authority, or unacceptable access, reuse, retention, or inability to mitigate.

Apply it: A deadline is near and the vendor has not answered whether prompts are used for training.
Reveal a defensible response

Do not infer the answer. Use an approved alternative with synthetic or non-sensitive data, or stop and escalate. Urgency does not resolve authority.

Framework: NIST AI RMF · NIST GenAI Profile

Lesson 6 of 6

Document and revisit the decision

Objective: Create a data-use record that survives staff, vendor, and system changes.

Record purpose, owner, data categories, source and authority, minimization, tool/version/plan, contractual and technical controls, risk decision, approver, date, retention, deletion, and reassessment triggers.

Reassess when the use, population, data, model, vendor, integration, law, or policy changes. A prior approval is not a blanket license for function creep.

Apply it: An approved summarization tool adds memory and new third-party connectors.
Reveal a defensible response

Pause affected workflows until data flows, defaults, permissions, retention, and contract implications are reassessed and documented.

Framework: NIST AI RMF · NIST GenAI Profile

Applied mastery check

Eight decisions — not trivia

Complete all six scenarios and answer at least 7 of 8 questions correctly. Each response receives explanatory feedback.

1. The first pre-prompt question is:
2. Data minimization:
3. “Enterprise” alone proves:
4. Encryption resolves:
5. Unanswered training terms plus sensitive data should trigger:
6. Public information:
7. An approved tool adds memory and connectors. You should:
8. A good data-use record includes:

Browser-generated learning record

PR-12 completed

Completed
Mastery
Credit0.0 CE
Record ID

Not a certificate. Identity was not verified and no accreditor or licensing board approved this activity.

GV-15 · 6 lessons · approximately 60 minutes

Human Oversight That Works

Turn “human in the loop” into decision rights, evidence thresholds, appeals, and operational accountability.

0 of 6 lessons complete

Lesson 1 of 6

Map the real decision

Objective: Identify where AI changes a person’s rights, access, resources, safety, or opportunity.

Trace inputs, model contribution, human action, downstream system, affected people, consequence, reversibility, and feedback loops. Distinguish brainstorming from ranking, recommendation from approval, and decision support from effective decision-making.

Risk lives in the sociotechnical system: incentives, staffing, policy, data, interfaces, and organizational use—not only the model.

Apply it: A model “only recommends” which benefit applications receive manual review first.
Reveal a defensible response

The recommendation allocates scarce review attention and can delay access. Map it as a consequential triage decision, including false negatives and appeal routes.

Framework: NIST AI RMF · NIST GenAI Profile

Lesson 2 of 6

Assign decision rights

Objective: Name who may use, review, override, escalate, pause, and approve.

Define accountable owner, qualified operator, independent reviewer where needed, incident lead, affected-person contact, and final approver. Give reviewers time, evidence, training, authority to disagree, and protection from automation pressure.

“A human reviews every output” is empty when that person lacks context, capacity, or power to change the result.

Apply it: A reviewer handles 600 flags per hour and may only click approve or reject.
Reveal a defensible response

The workflow creates automation bias and inadequate review capacity. Reduce volume, improve evidence access, permit escalation, measure overrides, and redesign the decision.

Framework: NIST AI RMF · NIST GenAI Profile

Lesson 3 of 6

Set evidence and release thresholds

Objective: Match validation and approval to consequence, uncertainty, and detectability.

Define prohibited uses, acceptable error boundaries, subgroup testing, security and privacy checks, source verification, stress cases, accessibility, fallback, rollback, and sign-off. Test the actual workflow, population, and version—not just a vendor benchmark.

High-impact uses require stronger independent evidence and safer defaults than reversible administrative assistance.

Apply it: A hiring model performs well overall but poorly for a small subgroup.
Reveal a defensible response

Do not average away the harm. Investigate data and workflow, evaluate lawful and fair use, test mitigations, and withhold or restrict release until the subgroup risk is acceptably addressed.

Framework: NIST AI RMF · NIST GenAI Profile

Lesson 4 of 6

Design explanation, contest, and remedy

Objective: Give affected people meaningful routes to understand and challenge consequential outcomes.

Provide usable notice of AI involvement, decision basis appropriate to context, a human contact, accessible contest process, timelines, evidence preservation, correction, and remedy. Monitor whether people can actually use the route.

An appeal that returns to the same automated logic without independent review is not meaningful contestability.

Apply it: A denied applicant may email support but receives only “the system was applied correctly.”
Reveal a defensible response

Provide the relevant basis, allow correction of erroneous inputs, assign qualified human reconsideration, track outcomes, and remedy improper delay or denial.

Framework: NIST AI RMF · NIST GenAI Profile

Lesson 5 of 6

Monitor operation and change

Objective: Detect drift, misuse, workarounds, unequal effects, and changed conditions.

Monitor performance, subgroup outcomes, overrides, complaints, appeals, near misses, incidents, latency, data shifts, and unauthorized uses. Define owners, frequency, thresholds, and automatic pause conditions.

Reassess after model, prompt, vendor, data, population, policy, integration, staffing, or purpose changes.

Apply it: Accuracy stays stable while human overrides fall to nearly zero.
Reveal a defensible response

Investigate automation bias, interface design, incentives, reviewer time, and whether disagreement is discouraged. Stable accuracy does not prove effective oversight.

Framework: NIST AI RMF · NIST GenAI Profile

Lesson 6 of 6

Respond and learn

Objective: Convert incidents into containment, accountability, repair, and verified improvement.

Protect people, contain the issue, preserve evidence, notify required functions, determine impact, analyze root and contributing causes, assign corrective actions, communicate appropriately, and verify the fix.

Include near misses and complaints. Close an incident only after the control is tested—not when a policy sentence is added.

Apply it: A model exposes confidential text in generated summaries.
Reveal a defensible response

Stop the affected workflow, preserve evidence, assess scope and notification duties, contain access, investigate data pathways, support affected people, fix controls, and verify against recurrence before restart.

Framework: NIST AI RMF · NIST GenAI Profile

Applied mastery check

Eight decisions — not trivia

Complete all six scenarios and answer at least 7 of 8 questions correctly. Each response receives explanatory feedback.

1. A recommendation that controls review priority is:
2. A reviewer processing 600 flags/hour demonstrates:
3. Overall accuracy hides subgroup failure. Best response?
4. Meaningful contestability includes:
5. Overrides fall to zero. This may indicate:
6. A vendor benchmark proves readiness for your workflow:
7. An incident closes when:
8. Governance applies to:

Browser-generated learning record

GV-15 completed

Completed
Mastery
Credit0.0 CE
Record ID

Not a certificate. Identity was not verified and no accreditor or licensing board approved this activity.