Working Safely with AI
Anyone who uses an assistant on work material, and the people who write the rules for them
Prerequisites: Module 101. No legal background needed.
Last verified 2026-09-17
Learning objectives
By the end, participants can:
- Classify a piece of work material into three tiers and say which assistant plan, if any, it may go into
- Name the GDPR touchpoints that apply when personal data goes into an assistant, and the two questions to ask before it does
- Explain the EU AI Act's risk-based approach and the transparency duties that apply to an ordinary deployer
- Draft or improve a one-page acceptable-use policy for a team
- Recognise prompt injection when using connectors, browsing and agents, and apply the read-before-write rule
- Apply a proportionate verification habit and name the accountable human for every AI-assisted output
What's in this module
8 lessons · 5 exercises · ~12 min reading
Starts withThis is practice, not legal advice~1 minExecutive summary
You will learn what may and may not go into an assistant, where personal data and the EU AI Act touch everyday use, how prompt injection reaches you through connectors and browsing, and how to keep a named human accountable for every output that leaves your desk. End state is a one-page acceptable-use policy for your team, a data classification you can apply in five seconds, and a verification habit for anything AI-assisted that goes to a client, a colleague or a regulator. After this module you can answer "can I paste this?" without a lawyer, explain the AI Act's risk tiers and transparency duties in plain language, spot a prompt-injection situation, and say who is accountable when an assistant gets it wrong.
Sources
- European Commission, the regulatory framework for AI, the risk tiers, transparency obligations and the application timeline: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- EU AI Act explorer, Article 4 (AI literacy) and Article 50 (transparency obligations for providers and deployers), the two articles that touch ordinary use: https://artificialintelligenceact.eu/article/4/ and https://artificialintelligenceact.eu/article/50/
- UK Information Commissioner's Office, AI and data protection guidance and the AI and data protection risk toolkit, the practical starting point for personal data in AI systems: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/
- National Cyber Security Centre, "Prompt injection is not SQL injection (it may be worse)", why the defence is constraining actions rather than filtering inputs: https://www.ncsc.gov.uk/blog-post/prompt-injection-is-not-sql-injection
- OWASP GenAI Security Project, LLM01:2025 Prompt Injection, the direct and indirect distinction and the mitigation list: https://genai.owasp.org/llmrisk/llm01-prompt-injection/
- Microsoft Learn, Data, privacy and security for Microsoft Copilot, the vendor position on training, permissions, the EU Data Boundary and injection classifiers: https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy
Prefer the live room?
This module also runs inside our in-person bootcamps and workshops in Copenhagen.
Rolling this out across an organisation?
We run this material as executive briefings and team programmes, tailored to your stack, your data policies, and your pace.