icon icon

Safe use of AI – security training for employees

icon

Training process

Training needs analysis

If you have specific requirements regarding the training programme, we will carry out a training needs analysis for you. This will guide us on which aspects of the programme should receive greater emphasis, so that the training programme meets your specific needs.

What will you gain?

icon

Use AI safely at work - You will learn when AI is appropriate for emails, notes, summaries, and analysis, and when using it creates risk for data, decision-making, or your organization’s reputation.

icon

Avoid exposing confidential data - You will learn how to distinguish information that can be shared with an AI tool from personal, commercial, HR, and technical data that must never go into public models.

icon

Prepare documents for AI use - You will practice anonymizing and reducing data in contracts, offers, reports, and client communications so you can use AI without unnecessarily exposing people or projects.

icon

Spot risky situations faster - You will recognize warning signs that tell you to stop working with AI and consult your manager, IT, information security, the DPO, or legal and compliance teams.

icon

Verify AI output before using it - You will learn how to check figures, dates, sources, quotations, regulations, and contract terms so your work is not based on answers that sound credible but are wrong.

icon

Reduce the impact of hallucinations - You will understand how to identify fabricated laws, sources, data, and quotes, and how to use control questions to reduce errors in materials created with AI support.

icon

Keep human control over decisions - You will learn which actions require human review and why important decisions must never be made solely on the basis of suggestions generated by an AI system.

icon

Apply clear rules before AI policy rollout - You will get practical minimum rules for approved tools, content labeling, account protection, and incident reporting that you can apply immediately in daily office work.

Training programme

1. AI in office work – applications and areas of risk

  • what tools based on artificial intelligence are and how they work,
  • the most common applications of AI in everyday office work:
    • creating and editing e-mail messages,
    • preparing letters, reports and notes,
    • summarizing documents,
    • translating content,
    • data and document analysis,
    • preparing presentations,
    • generating ideas and recommendations,
    • automating repetitive tasks,
  • differences between public, free AI tools and corporate solutions,
  • identifying moments in which the use of AI may cause risk,
  • employee responsibility for content prepared with the use of AI,
  • examples of safe and unsafe use of AI in business practice.

2. Data, confidentiality and secure work with documents

  • what information can be provided to AI tools,
  • what data should not be entered into publicly available AI, models
  • categories of information requiring special protection:
    • personal data,
    • special category data,
    • financial information,
    • information about clients and contractors,
    • employee data,
    • trade secret,
    • commercial and strategic information,
    • access data, passwords and technical information.
  • secure work with the use of AI for:
    • commercial offers,
    • contracts,
    • project documentation,
    • reports,
    • correspondence with clients,
    • HR and financial documents,
  • principles of data anonymization and pseudonymization,
  • removing data identifying persons, clients, projects and the organization,
  • limiting the scope of information provided to the AI, tool
  • checking the provider's terms and conditions, privacy settings and data processing rules,
  • protection of personal data, confidential information and trade secrets.

3. The most common risks associated with using AI

  • AI model hallucinations AI:
    • what they are,
    • why they arise,
    • how to recognize them,
    • how to limit their impact.
  • generation of incorrect, incomplete or outdated information.
  • creating non-existent:
    • regulations,
    • sources,
    • data,
    • quotes,
    • documents,
    • rulings and interpretations,
  • excessive trust in results generated by AI,
  • the risk of making decisions solely on the basis of the model's response,
  • the risk of disclosure or loss of control over data,
  • threats related to sending files and documents to AI tools,
  • legal risks:
    • violation of personal data protection,
    • breach of confidentiality,
    • copyright infringement,
    • use of content without appropriate verification,
    • responsibility for the content of documents,
  • organizational risks:
    • use of unapproved tools,
    • lack of consistent rules,
    • shadow AI,
    • uncontrolled creation of accounts and integrations,
  • reputational risks associated with publishing incorrect or inappropriate content,
  • the importance of human control over the process of creating, evaluating and approving content.

4. Verification of responses generated by AI

  • the principle of limited trust in AI results,
  • methods of checking the correctness of responses,
  • verification of information in reliable and up-to-date sources,
  • checking:
    • numbers and calculations,
    • dates,
    • names,
    • regulations,
    • sources,
    • quotations,
    • customer data,
    • contractual terms,
  • separating facts from the model's opinions and assumptions,
  • recognizing responses that appear professional but are incorrect,
  • using control questions and verification prompts,
  • documenting the involvement of AI in the preparation of the material,
  • determining which content requires approval by a human.

5. Practical examples of using AI in office work

  • preparing an email message based on general, non-confidential information,
  • drafting a letter containing client data,
  • a summary of a contract or project documentation,
  • translating a document containing confidential information,
  • analysis of a spreadsheet with employee or client data,
  • preparing a commercial offer,
  • creating a report based on internal data,
  • generating a presentation for a meeting with a client,
  • preparing a response to a complaint,
  • preparing a recommendation or decision based on the response AI,
  • using AI during recruitment, employee evaluation or customer service,
  • sending documents to public AI tools.

For each example, discussion of:

  • what can be done safely,
  • what data should be removed or changed,
  • what requires particular caution,
  • what should be avoided,
  • which elements need to be verified,
  • when consent or consultation is needed.

6. When work should be stopped and the use of AI consulted

  • situations requiring consultation with a supervisor,
  • situations requiring contact with the IT department,
  • situations requiring consultation with the information security department,
  • situations requiring consultation with the data protection officer,
  • situations requiring consultation with the legal or compliance department,
  • procedure in the event of:
    • accidental entry of confidential data,
    • sharing a document with the wrong tool,
    • suspicion of an information leak,
    • receiving an incorrect or harmful response,
    • using AI to make an important decision,
    • detecting a violation of security rules.

7. Minimum rules for using AI before implementing the AI policy

  • use only tools approved by the organization,
  • prohibition on entering confidential data into public tools AI,
  • applying the data minimization principle,
  • anonymizing examples and documents,
  • mandatory verification of content generated by AI,
  • prohibition on making important decisions solely on the basis of responses from AI,
  • maintaining human control over the process,
  • labeling content prepared with the support of AI, when required,
  • consulting uses that raise doubts,
  • not installing unapproved add-ons, extensions and integrations,
  • protecting accounts, passwords and access data,
  • responding to incidents and reporting irregularities,
  • regularly updating employees’ knowledge.

8. Organizational and technical recommendations

  • preparation of a temporary instruction for the use of AI,
  • creation of a list of approved and prohibited tools,
  • definition of categories of data that cannot be transferred to AI,
  • designation of persons or units responsible for consultations,
  • introduction of a simple process for reporting new uses of AI,
  • establishment of rules for the use of business and private accounts,
  • limitation of the ability to upload files to public tools,
  • management of access, integrations and extensions,
  • introduction of mandatory verification of results in higher-risk processes,
  • maintenance of a register of used tools and use cases of AI,
  • preparation of the organization for the development and implementation of a formal AI policy.

9. Practical exercises

  • assessment of sample situations according to the scheme:
    • safe,
    • permitted after anonymization,
    • requiring consultation,
    • prohibited,
  • searching for confidential data in sample prompts,
  • anonymization of a document before submitting it to the AI tool,
  • identifying errors and hallucinations in AI responses,
  • verification of a sample response generated by the model,
  • developing a safe version of the prompt,
  • analysis of a case of accidental disclosure of information,
  • preparation of a short list of rules for safe use of AI for employees.

10. Summary and Q&A session

  • the most important rules of safe use of AI,
  • a checklist before using the AI tool,
  • a checklist before using or publishing generated content,
  • discussion of questions and cases submitted by participants,
  • Q&A session,

What are the prerequisites for participating in the training?

icon

Basic office skills - You should be comfortable using email, a word processor, spreadsheets, and company documents, because the training is built around these everyday work tasks.

icon

Experience with documents - You should have practical experience working with documents, correspondence, or data so you can easily relate the guidance to real situations in your daily duties.

icon

Awareness of data confidentiality - You should understand that work involves confidential information and personal data, and be able to recognize them in simple cases before the training begins.

icon

Readiness to verify content - You should be ready to critically check information, figures, and sources, because the training assumes an active approach to reviewing AI-generated responses.