# AI Data Safety Micro-Course

A free Jericho AI Studio giveaway package for security, GRC, L&D, MSP, vCISO, and AI governance teams.

Use this as a reviewable starter course for employees who use AI tools at work. Replace placeholders with your approved AI tools, data classification language, reporting path, and policy owner before publishing.

**Attribution landing page:** https://contentstudio.jerichosecurity.com/campaigns/course-giveaway-ai-data-safety

**CTA for teams:** Start free at https://contentstudio.jerichosecurity.com/signup?lp=course-giveaway-ai-data-safety&utm_source=owned&utm_medium=giveaway&utm_campaign=ai_data_safety_course_giveaway&utm_content=micro_course_download&utm_term=ai_data_safety

---

## Course snapshot

- **Title:** AI Data Safety at Work: What Not to Paste
- **Audience:** Employees using AI tools, managers approving AI workflows, L&D teams, GRC teams, security awareness leads, MSPs, and vCISOs
- **Format:** 5-7 minute micro-course
- **Recommended delivery:** AI acceptable-use rollout, new-hire onboarding, manager refresher, security awareness campaign, or remediation after risky tool-use patterns
- **Human review required:** Security owner, GRC/compliance owner, AI policy owner, L&D/training owner, and legal reviewer if the module references regulated data, contracts, customer data, CUI, or employee data
- **Primary learner decision:** Before pasting work content into an AI tool, pause and check whether the information is approved for that tool and use case.

## Learning objectives

By the end of this short course, learners should be able to:

1. Recognize common types of information that need extra care before use with AI tools.
2. Explain why public or unapproved AI tools may not be appropriate for sensitive work content.
3. Choose an approved AI workflow or escalation path when the data or tool is uncertain.
4. Ask for help without treating AI policy questions as a personal failure.

## Opening lesson copy

AI tools can help employees summarize, draft, brainstorm, translate, and organize information. That usefulness is exactly why data safety matters.

The question is not whether AI is good or bad. The useful question is: **what information is appropriate for this tool, this account, and this purpose?**

Some information may be fine to use in an approved internal AI tool. Other information may require redaction, a different workflow, or review before it leaves an approved system. Customer details, confidential business plans, employee records, credentials, security findings, contracts, regulated data, source code, and controlled technical information deserve extra caution.

If you are unsure, do not guess. Use **[INSERT APPROVED AI TOOL OR WORKFLOW]**, check **[INSERT AI ACCEPTABLE-USE POLICY LOCATION]**, or ask **[INSERT APPROVED CONTACT/CHANNEL]** before pasting the information.

## Scenario 1: The fast summary

You need to summarize notes from a customer call before a follow-up meeting. The notes include names, account details, pricing discussion, and a customer concern about their internal security process. A public AI chat tool would make the summary faster.

**Decision point:** What should you do first?

A. Paste the notes into any AI tool because you are only asking for a summary.

B. Remove the customer name but leave the rest of the details.

C. Check whether the tool and data type are approved, then use the approved workflow or redact details according to policy.

D. Ask a coworker to paste the notes so the request is not tied to your account.

**Best answer:** C

**Teaching feedback:** Summarization can still expose sensitive information. Before using AI, confirm whether the tool is approved for that data and whether redaction is required. Moving the request to another person does not reduce the risk.

## Scenario 2: The helpful spreadsheet

A manager asks you to use AI to spot trends in a spreadsheet. The file includes employee names, departments, performance notes, and manager comments. You are not sure whether the AI tool stores prompts or uses them for model improvement.

**Decision point:** What is the safest next step?

A. Upload the spreadsheet because the goal is internal productivity.

B. Ask for guidance before using the tool, and use an approved data-handling workflow if analysis is allowed.

C. Replace employee names with initials and upload the rest.

D. Copy only the most interesting rows into the tool.

**Best answer:** B

**Teaching feedback:** Employee information can be sensitive even when the project is internal. Initials or partial rows may still identify people. When tool behavior or data rules are unclear, pause and ask through the approved channel.

## Scenario 3: The policy shortcut

You are writing a training reminder about a new AI acceptable-use policy. You want to paste the full draft policy into an AI tool and ask it to write a friendlier version for employees.

**Decision point:** Which question matters most before pasting?

A. Is the AI tool popular?

B. Does the policy allow this tool and data type for this use case?

C. Can the tool write in a friendly tone?

D. Will the output be shorter than the original policy?

**Best answer:** B

**Teaching feedback:** Usefulness is not the same as approval. A tool can be popular and still be wrong for a specific data type or policy document. Confirm the approved workflow, then review the draft for accuracy before publishing.

## Knowledge check

### Question 1

Which information should usually trigger extra review before using an AI tool?

- A. A public blog post from the company website.
- B. A list of customer incidents, contract details, or employee records.
- C. A generic brainstorming prompt with no company details.
- D. A public job posting.

**Answer:** B

**Feedback:** Customer, contract, incident, employee, regulated, security, and confidential business information may require approved tools, redaction, or review before AI use.

### Question 2

Why is redacting only a name sometimes not enough?

- A. AI tools cannot read redacted documents.
- B. Other details can still identify a person, customer, project, or security issue.
- C. Redaction always makes data public.
- D. Names are the only sensitive information.

**Answer:** B

**Feedback:** Context can identify people or organizations even when names are removed. Treat redaction as a policy-guided workflow, not a quick find-and-replace.

### Question 3

What should you do if you are unsure whether a tool is approved for the information you want to use?

- A. Use the tool anyway if the deadline is close.
- B. Paste a small sample first to test it.
- C. Check the approved AI workflow or ask through **[INSERT APPROVED CONTACT/CHANNEL]**.
- D. Use a personal account instead of a work account.

**Answer:** C

**Feedback:** Uncertainty is a reason to verify, not improvise. Personal accounts and small samples can still create exposure if the tool or data use is not approved.

## Remediation note for follow-up

If a team has been using unapproved tools or pasting sensitive data into AI prompts, keep the follow-up practical and non-shaming:

- Explain which data types need care.
- Show the approved tool or workflow.
- Give two examples of safe prompt patterns.
- Give two examples that require review or redaction.
- Tell learners where to ask questions.

Avoid framing employees as reckless. Many risky AI behaviors come from trying to move quickly with unclear guidance. The training should make the safer path easier to find.

## LMS packaging notes

- Suggested seat time: 5-7 minutes.
- Suggested completion rule: view lesson and answer knowledge-check questions.
- Include captions and transcript if converted into video or voiceover.
- Include a printable job aid: “Before you paste into AI, check tool, data, purpose, and policy.”
- For SCORM/xAPI export, include a clear lesson title, short description, and quiz completion metadata.
- If this course supports a compliance or AI governance program, document the source policy and human review record alongside the LMS package.

## Jericho AI Studio prompt to recreate or adapt

Paste this into Jericho AI Studio and replace bracketed placeholders before generating:

> Create a 5-7 minute cybersecurity awareness micro-course titled “AI Data Safety at Work: What Not to Paste.” Audience: employees who use AI tools at work. Goal: teach learners to pause before pasting sensitive work information into AI tools and to use the approved AI workflow. Include a short opening lesson, three realistic workplace scenarios, three quiz questions with teaching feedback, a remediation note, captions/transcript guidance, and LMS-ready packaging notes. Use a practical, non-shaming tone. Mark assumptions for human review. Approved AI tool/workflow: [INSERT APPROVED TOOL OR WORKFLOW]. AI acceptable-use policy location: [INSERT POLICY LOCATION]. Reporting or questions channel: [INSERT APPROVED CONTACT/CHANNEL]. Sensitive data categories to mention: [INSERT INTERNAL DATA CATEGORIES].

## Review checklist before publishing

- Does the course match the current AI acceptable-use policy?
- Are approved tools and unapproved tools described accurately?
- Are data categories aligned with the organization’s policy and contracts?
- Does the course avoid implying legal advice or guaranteed compliance?
- Are examples realistic without exposing sensitive internal details?
- Does quiz feedback teach the next action, not just the correct answer?
- Are captions, transcripts, accessibility needs, and LMS completion settings ready?
- Has the appropriate human reviewer approved the final version?

## Safe positioning language

This course is designed to support AI data safety awareness and reviewable training workflows. It does not provide legal advice, guarantee compliance, or prove that AI use is risk-free. Use it as a starter asset that your security, GRC, legal, L&D, and policy owners can review and adapt for your organization.
