Use AI at work without exposing your data or your company
Sort your information, configure your tools by plan, protect people and the company, and write your team’s AI policy.
Use AI assistants at work knowing what you can put into them, with which settings and with what transparency. You learn to sort your information into green, amber and red, to check what each tool does with your inputs depending on the plan (Claude, ChatGPT, Gemini, Mistral, Copilot), to apply GDPR basics and pseudonymise data before pasting it, to protect your company's secrets and to know when to disclose the use of AI, AI Act included. You finish with a team AI policy ready to be adopted. This course gives practical guidance, not legal advice.
What you will be able to do
- Sort the information in your work into green, amber or red based on its nature (public, internal, personal, sensitive, trade secrets, contractual commitments) and the tool considered.
- Check and configure, for each tool and plan, what happens to your inputs (training, retention, human review, business terms), based on the vendors' dated pages.
- Apply GDPR basics to the use of an AI tool (personal data, purpose, minimisation, sensitive data, processor, transfers) and prepare data by distinguishing pseudonymisation from anonymisation.
- Protect the company in everyday AI use (trade secrets, contractual confidentiality, shadow AI, rights over generated content and third-party content).
- Decide when to disclose the use of AI and who approves an output, placing the AI Act obligations in context (Article 50 transparency, Article 4 AI literacy).
- Write a team AI policy (green, amber, red data, tools and settings, transparency, human approval, incidents, review) and organise its adoption.
Prerequisites
- Using an AI assistant, even occasionally (Claude, ChatGPT, Gemini, Mistral's Vibe or Copilot); a free plan is enough for the exercises, which use fictional data.
- No legal knowledge is required. This course is for people who use AI tools, not for the data protection officer (DPO).
- Recommended before this course: "Understand what LLMs do well, and where they fail", for the delegate / verify / keep grid.
- This course does not cover designing a product that embeds AI (prompt injection, guardrails, provider obligations): that is the subject of a dedicated course on securing AI products.
Syllabus
What will I be able to do at the end of this course, and in what order?
- Course overview3 steps
Objective · By the end of this overview, you will know what you are going to produce (a team AI policy ready to be adopted), which incident the running case starts from and which four modules take you there.
What can I put into an AI tool, and what happens to what I put in depending on the tool and the plan?
Objective · By the end of this lesson, you will be able to sort a piece of information from your work into green, amber or red based on its nature and the tool considered, and to justify borderline cases.
Objective · By the end of this lesson, you will be able to say, for your tool and your plan, whether your conversations can be used for training, how long they are kept, whether people can read them, and which settings to turn on, based on the vendor's dated pages.
What does the GDPR change for me when I use an AI tool, and how do I prepare data before pasting it?
Objective · By the end of this lesson, you will be able to say whether an AI use involves personal data, whether some of it is sensitive, whether the purpose and the amount of data are justified, and whether the tool provides the necessary contractual framework.
Objective · By the end of this lesson, you will be able to pseudonymise a work text in six steps before submitting it to an approved tool, spot what would still allow a person to be re-identified, and explain why pseudonymised data remains personal data.
How do I avoid an AI use that discloses a secret, breaches a customer commitment or creates a rights problem?
Objective · By the end of this lesson, you will be able to spot, in an everyday AI use, what touches on trade secrets or a confidentiality commitment, propose a response to shadow AI that goes beyond a ban, and say what you can claim over content produced with AI.
When must I say I used AI, who approves, and how do I write rules the team will actually follow?
Objective · By the end of this lesson, you will be able to decide, for content produced with AI, whether a disclosure is mandatory, recommended or unnecessary, to designate who approves it before it is shared, and to explain what the AI Act requires of an organisation whose employees use AI.
Objective · By the end of this lesson, you will have written your team's AI policy (one to two pages), checked it with a self-assessment grid, and planned its adoption over 7 and 30 days.