AI in IT and information security
M26
Position IT as architect of the approved-tools catalogue.
Training by function
IT is the architect of the approved-tools catalogue and the first line against shadow AI. This path equips your teams to secure AI adoption across the organization.
Why this path
Without a framework, every employee deploys their own tools, often free and poorly protective. IT assesses security and data location, applies least privilege to agents and makes shadow AI visible through logging. This path provides the vocabulary and reflexes to hold that role.
M26
Position IT as architect of the approved-tools catalogue.
The baseline reflexes your whole team shares, whatever the job.
M01
Demystify the probabilistic engine and distinguish it from predictive AI.
A probabilistic engine predicts the most plausible word without understanding meaning: brilliant, but sometimes wrong. Never feed it confidential data in a public tool.
RegisterM02
Identify fabricated information and how to verify it at the source.
A hallucination is fabricated information presented confidently. The risk is real on expert tasks (figures, citations): every output must be verified at the source.
RegisterM03
Structure your prompts (Role + Context + Task + Format) and iterate.
Good results come from a structured prompt and an iterative approach. Providing examples of the desired output markedly improves quality.
RegisterM04
Sort your data and de-identify rigorously before every prompt.
Anything entered into a public AI can be retained and reused. Never client names, salaries or API keys; removing just the name is not enough.
RegisterM05
Recognize shadow AI and have tools approved by IT.
Shadow AI is the use of unapproved tools, often free and poorly protective. The reflex: check the IT allowlist and get the tool approved before using it.
RegisterM06
Apply "human-in-the-loop" and the "four eyes" method.
AI is a gifted junior assistant with no judgment: final responsibility stays human. Review and validate every deliverable as if you had written it yourself.
RegisterThe modules most relevant to the risks specific to your function.
M13
Understand hidden instructions and apply least privilege.
An injection hides instructions in content read by the AI (email, PDF, web page). Protect against it with least privilege and human validation of sensitive actions.
RegisterM14
Adopt SSO, least privilege and incident reporting.
Log in through enterprise authentication (SSO), without sharing access. Limit extension permissions and report any leak to IT immediately.
RegisterM05
Recognize shadow AI and have tools approved by IT.
Shadow AI is the use of unapproved tools, often free and poorly protective. The reflex: check the IT allowlist and get the tool approved before using it.
RegisterEnroll your teams in our AI-literacy and governance training paths, from the common core to function-specific use cases.
Immediate access · 100% online · at your own pace