AI Security & Governance Training

Your Team Is Already Using AI.
Do They Know the Rules?

AI tools are in use across most businesses — whether IT knows about it or not. Without clear policies, training, and governance, the same tools that make your team more productive can expose client data, breach GDPR, and create serious regulatory and legal risk. Aursec's AI training gives your team the knowledge to use AI ambitiously — and compliantly.

£17.5m Maximum GDPR fine for data misuse
EU AI Act Now in force across the UK
Live Virtual delivery, no travel needed
GDPR & EU AI Act Aligned
Plain English — No Technical Jargon
Policy Development Included
One-Off or Annual Programme

AI Without Governance Is a
Compliance Risk

Most businesses have moved fast on AI adoption. Most haven't moved nearly as fast on the governance needed to make that adoption safe.

Shadow AI

Staff Using Unapproved Tools

When businesses don't provide approved AI tools, staff find their own. Personal ChatGPT accounts, consumer AI tools, browser extensions — none of them covered by a Data Processing Agreement, all of them a potential GDPR breach.

Client Data

Confidential Data Entering AI Systems

Without training and clear classification rules, staff routinely input client data, financial information, and personal data into AI tools. One incident can trigger a 72-hour ICO notification requirement.

EU AI Act

New Legal Obligations Are Already in Force

The EU AI Act introduces risk-based obligations for businesses using AI systems. UK businesses supplying EU clients or using EU-based AI tools need to understand what applies to them now — not later.

Practical AI Governance Training Grounded
in Current Law and Best Practice

Every session is tailored to your business — the tools you use, the data you handle, and the clients you serve. Practical, relevant, and delivered in plain English.

What AI Actually Is — and Isn't

How large language models work, why they hallucinate, what context blindness means in practice, and why human review is always required. Staff who understand the technology make better decisions about when and how to use it.

Data Classification for AI Use

The four classification levels — Public, Internal, Confidential, and Restricted — and how to apply them before inputting anything into an AI tool. The most important habit your team needs to build.

Approved Tools & Safe Use Rules

Why approved tools are different from consumer AI, what a Data Processing Agreement actually protects, and the specific rules that apply to each tool your business uses. Including what happens when staff go off-list.

Client Data & Third-Party Data

Why client data rules vary by contract, how to check before processing any client data with AI, and what to do when the answer is no. Based on real scenarios including drafting responses, summarising contracts, and analysing client-provided data.

GDPR & EU AI Act Compliance

How GDPR applies to AI use — including the 72-hour breach notification clock, lawful basis for AI-assisted processing, and individual rights. Plus a plain-English overview of EU AI Act obligations relevant to UK SMBs and their EU clients.

Incidents & Reporting Obligations

What constitutes an AI-related data incident, why immediate reporting matters, and what not to do — including why staff should never try to contain an incident themselves before reporting. Practical scenarios included.

The 5-Step AI Use Process

Every session teaches your team a repeatable five-step process for every AI task. Simple enough to remember. Robust enough to keep you compliant.

1

Identify

Find the task where AI adds genuine value. Repetitive, time-consuming, or creative work where AI can act as a highly capable assistant.

2

Classify

Before inputting anything, determine the classification of the data involved. Public, Internal, Confidential, or Restricted. Classification is determined by the nature of the data — not how it was provided.

3

Consult

Check the Approved Tool List. If client or third-party data is involved, check the relevant client permissions before proceeding. When in doubt — stop and ask.

4

Execute

Use your company account, not a personal account. Follow the tool-specific guidance. Do not input Restricted data under any circumstances.

5

Review

Verify the output for accuracy, suitability, and compliance before acting on it, sending it, or submitting it. Human accountability is not optional. The AI is not responsible — you are.

More Than Just a Training Session

Every Aursec AI training engagement includes the tools your business needs to maintain compliant AI use after the session ends.

AI Usage Policy

A complete, customisable AI Usage Policy covering approved tools, data classification, client data rules, incident reporting, and staff responsibilities. Drafted for your business and ready to implement.

Approved Tool Review

Review of the AI tools your business currently uses — or wants to use — against GDPR and data protection requirements. Clear guidance on what's safe to approve, what needs conditions, and what should be restricted.

Completion Records & Evidence

Attendance records for every session in the format required for GDPR accountability obligations. Evidence that your organisation has taken appropriate steps to train staff on AI use.

Live, Virtual, and Tailored
to Your Business

The tools your business uses, the clients you serve, and the data you handle all shape how AI governance applies to you. Every Aursec AI training session is built around your specific situation.

Format 1
One-Off Session

Ideal for: Initial AI governance training for all staff, or a focused session for a specific team or tool rollout.

What's included
  • 45–60 minute live virtual session
  • Up to 25 participants
  • Tailored to your tools and data classification requirements
  • Q&A included
  • Attendance record provided
  • AI Usage Policy template included

Per-person pricing available — contact us for a quote.

Format 3
Annual Programme

Ideal for: Businesses needing documented annual AI governance training — for GDPR accountability purposes or as part of a broader security awareness programme.

What's included
  • Regular sessions throughout year
  • Content updated as AI Act guidance and tools evolve
  • Annual completion and attendance report
  • AI Usage Policy maintained and updated annually
  • Priority scheduling

Annual pricing available — contact us for a quote.

AI Governance Training for
Every Part of Your Business

All Staff

The foundation — how AI works, what the approved tools are, data classification, and the five-step process. Delivered in plain English that engages non-technical staff and builds the habits that keep your business compliant.

Leadership & Compliance Teams

Strategic AI governance, EU AI Act obligations, board-level accountability, and how to build an AI governance framework that scales as adoption grows. Includes AI Usage Policy development.

Client-Facing Teams

The specific rules and scenarios that apply when client data is involved. Sales, account management, and customer service teams who regularly handle client information alongside AI tools.

Technical & IT Teams

AI governance for developers and technical staff — agentic tools, coding assistants, credential exposure risks, and the heightened obligations that apply when AI tools have access to systems and data stores.

Could not be happier with the services provided by Aursec in supporting the IT of my Business. From initial engagement, Aursec worked with me to understand my requirements and ensured an efficient rollout of my Company's IT solution. They took the stress out of achieving CyberEssentials Plus certification and now are fully embedded with my organisation as a partner to deliver long term IT Service Support. Aursec would be a great option for any size business but are particularly valuable for smaller businesses that require that additional hands-on knowledge and experience.
NM
Nathan Molnar
CEO, Avencys Group Ltd

Ready to Get Your Team AI-Compliant?

Book a free 30-minute call to discuss your AI training needs. We'll assess your current tools, data classification requirements, and recommend the right programme — including whether you need an AI Usage Policy developed alongside the training.

Book a Training Call

Get in Touch About AI Security Training

Tell us about the AI tools your team uses, your sector, and what's driving the need for training. We'll come back to you within one working day.

info@aursec.co.uk