TALAMANA · THE AI LITERACY MAP FOR ARCHITECTURE AND DESIGN · Ethics & Provenance · AGE 16—19 · POSITIONAL · METHOD
Four risks before you upload anything
Answer privacy, confidentiality, copyright and security separately before any file leaves the studio.
When to use
Every time a file is about to go into an outside AI service: a photo, a plan, a survey, a report, a client's email, a classmate's sketch. Not only the big uploads. The quick ones are the ones that get through.
The method
Four risks, four questions, in this order. Privacy: does this hold a person's data — a name, a face, an address, a phone number? That person has rights, and in India a child's data needs a parent's consent. Confidentiality: does it belong to a client or an institution who trusted you with it? A contract, an NDA or plain professional duty may say it does not leave the office. Copyright: is it someone's work — a photograph, a drawing, a text? Having a copy is not having the right to upload it. Security: what does the service do with what you give it — keep it, read it, train on it, share it? Read the terms, this week's version. Then the seven questions, which are the same four risks in working form: Do I own this? May I upload it? Does it hold another person's data? Does the client or institution allow this service? Can I redact what is not needed? Do I need an approved account? What does the provider do with it? A "no" or a "don't know" on any of the seven stops the upload until it is a "yes".
Watch for this
Answering one risk and believing you have answered four. "It is my own drawing" clears copyright. It says nothing about the client's name on the title block (privacy), the NDA (confidentiality) or the tool's training setting (security). And redaction that stops at the name: a plot number, a budget and a consultant's stamp identify a project as surely as a name does.
The Lab's note
The four risks and the seven questions are the Lab's gate. They are not the only way to sort this; some offices use a three-pile rule, some keep a single "never" list. Ours is built so that a sixteen-year-old can pass through it alone, in a minute, and can say afterwards which question did the work. It is a habit, not a policy document, and it is judged by whether it gets used at eleven at night.
Try it
Take the last three files you uploaded to any AI tool. For each, answer the seven questions in writing, honestly, including "don't know". Count the don't-knows. Then find the answer to one of them — usually by reading the provider's data page — and note how long it took.
Prove it
Take one real file that is about to leave the studio. Show the four risks answered separately, say which question would have stopped it, and say what you changed so that it could go.
How it works
The four risks belong to four different owners, which is why they do not collapse into one question. Privacy belongs to the person in the data. In India the Digital Personal Data Protection Act, 2023 gives that person rights and requires a parent's verifiable consent for anyone under eighteen; the Rules notified in November 2025 give companies eighteen months for their duties, which lands in May 2027. Confidentiality belongs to the client or institution and is set by contract and professional duty, whether or not any personal data is involved — THE CLIENT'S FILE on this map takes that one further. Copyright belongs to whoever made the work. Security is the provider's conduct, and it is the one that changes most. One major provider's privacy policy, read in August 2026, says it may use what you type and what it answers to train its models unless you switch that off in your account settings, and that some material flagged for safety review is used even then. Terms like that change without notice, which is why the card carries a review date. The law is checkable. The habit is what protects you before the law does.
What this idea builds on
What this idea opens up
Sources
Open this idea on the map · The complete map · Logika · RBDS AI Lab, India · revised every edition.