Centre For Cybersecurity Institute Centre For Cybersecurity Institute
Menu
For business

AI Safety at Work: Empowering Employees to Use AI Securely

Awareness-level training on shadow AI, safe data handling and AI-enabled scams, so your team can use AI tools confidently without putting company or customer data at risk.

What your team will gain

AI tools are already inside your organisation, whether or not they were invited. This workshop gives every employee, technical or not, the habits to use them safely: recognising shadow AI, deciding what data can and cannot go into an AI system, spotting deepfake and AI-written scams, and knowing exactly what to do when something slips. The session is hands-on and grounded in real incidents, not slideware.

Built for Singapore organisations

The PDPA applies to personal data in AI systems exactly as it does everywhere else. We teach against the regulatory context your people actually work in, drawing on PDPC guidance on personal data in AI systems, IMDA’s Model AI Governance Framework and CSA advisories, and we scope examples to your sector and to your own AI policy where you have one.

Born from client demand

Safe use of AI tools at work has been the most requested follow-up topic from our recent corporate deliveries. At Sustinere, a Singapore sustainability consultancy, our awareness workshop lifted self-rated staff awareness by 54.5% in a single session, and safe AI use topped the list of what the team wanted next. This course is the answer, built as the sister programme to Cyber Safety: Empowering Employees in Digital Defence.

How we teach

The session is interactive from start to finish: a live audit of the AI tools in the room, a traffic-light sorting drill on what data can go where, a deepfake detection exercise and, in the extended format, a scenario lab built around an AI-enabled fraud. Sessions run from two hours to a half day, on site or online, and your team keeps the working documents: an AI acceptable-use policy template, an approved-tools register and a desk card with the data rules.

Pair it with Cyber Safety

Most organisations run the two programmes together. A combined full-day engagement covers the classic human-factor threats in the morning and AI-era risks in the afternoon, priced as a single full-day programme rather than two separate bookings. The AI session also slots into our annual awareness programmes as a refresher, which keeps year-two content current rather than repeated.

Take it further

Awareness is the foundation. Add a phishing simulation with AI-written lures to measure how the habits hold, or scope an annual programme that keeps both cyber and AI awareness fresh through the year. Book a consultation and we will design the right version for your organisation.

Course syllabus

What you will cover

The two-hour core covers the first four modules; the three-hour standard and four-hour extended formats add the rest. Every session opens with a live audit of the AI tools actually in use in the room.

Module 01 AI at work: the new risk picture
  • Where AI already sits in daily work, from drafting and meeting notes to coding assistants
  • What a generative AI tool does with the data you give it, in plain language
  • Real incidents: leaked source code, the US$25 million deepfake video call, AI-written spear phishing
  • Why the PDPA and client confidentiality apply to AI tools exactly as they do to email
Module 02 Shadow AI: the tools you cannot see
  • What counts as shadow AI: personal accounts, browser extensions, free tools and AI features inside approved software
  • Why staff reach for unsanctioned tools, and what that risks
  • Data retention and training terms nobody agreed to on your behalf
  • The legitimate route: the approved-tools register and how to request a new tool
Module 03 Data, PII and confidentiality in AI systems
  • What personal data means under the PDPA, and where it hides in everyday documents
  • The traffic-light test: what can go into an AI tool, what must be anonymised first, what never leaves
  • Consumer versus enterprise AI tools, and why the same brand name can be both
  • Redaction habits that take seconds, and prompting with the minimum necessary data
Module 04 AI-enabled scams: deepfakes and machine-written phishing
  • Voice cloning and video deepfakes, and why senior voices are the target
  • Verification rules that beat convincing fakes: call-backs, code words and four-eyes payments
  • Why spotting the typo no longer works, and the tells that survive
  • Prompt injection in plain language: how pasting untrusted text can turn an AI assistant against you
Module 05 Using AI well: verification and prompt hygiene (3- and 4-hour formats)
  • Hallucination and automation bias: why fluent output is not verified output
  • Checking sources, numbers and citations before work leaves your hands
  • Attribution, copyright and disclosing AI use
  • A prompt-hygiene checklist your team keeps
Module 06 Policy and governance essentials (3- and 4-hour formats)
  • Anatomy of a workable AI acceptable-use policy
  • The approved-tools register, and the vendor questions to ask before adopting a tool
  • The first hour after data goes where it should not, and why no-blame reporting matters
  • How this maps to PDPA obligations, IMDA's Model AI Governance Framework and CSA guidance
Module 07 Scenario lab: the voice note from the CFO (4-hour format)
  • A guided tabletop: an AI-enabled fraud plays out and your teams decide what happens next
  • The post-incident hour, including the shadow AI discovery
  • Debrief against the verification playbook
  • Your team drafts its own top five AI ground rules
Trusted by

Organisations who trust us to keep them safe

AirAsia
Maha Chemicals
The Tanglin Club
Tuas Power
Singapore Red Cross
CapitaLand

Frequently asked questions

Who is this for?

Any organisation whose staff use, or want to use, AI tools at work. The content is awareness-level and suits every team, from frontline staff to management; no technical background is needed.

How is this different from your cyber awareness workshop?

Cyber Safety covers the classic human-factor threats: phishing, passwords, social engineering and safe data handling. AI Safety at Work covers the risks that arrive with AI tools: shadow AI, data and PII in AI systems, deepfake and AI-written scams, and practical ground rules for everyday use. They are designed as companion programmes and are often run together as a full-day engagement.

Can it be tailored to our organisation?

Yes. We scope the content to your sector, your regulatory context and the AI tools your teams actually use, and we can teach against your own AI policy where you have one.

Is the training delivered on site or online?

Either. We can run the session on site at your premises or deliver it online, whichever works best for your team. The extended four-hour format with the scenario lab works best on site.

What is the minimum group size?

A minimum of 20 participants is required for a dedicated session.

What do participants take away?

Practical habits and working documents: the traffic-light rules for what data can go into which tools, verification habits against deepfake and AI-written scams, plus an AI acceptable-use policy template, an approved-tools register and a desk card your team keeps.

Is any funding available?

This is in-company corporate training, engaged directly by the organisation, and is not tied to individual SkillsFuture course subsidies. Per employee, a session typically costs less than an hour of payroll, and we are happy to talk through budgeting during a consultation.

Ready to secure your workforce?

Book a 30-minute consultation to scope the right training for your team and your regulatory context.

Chat with us