Module 1: Why Public LLM Use Is a Compliance Risk for SMBs
This module introduces generative-AI use as a business-risk issue, not just a productivity topic. It explains why public LLMs create a new exposure pathway when employees enter customer, employee, financial, legal, or proprietary company information into tools outside the organization’s controlled environment.
Module 2: What Counts as Public AI, and Why It Matters
This module defines public generative-AI tools in plain language and distinguishes them from approved internal tools or enterprise environments. It helps learners understand that where a prompt is entered matters just as much as what is entered.
Module 3: Data Types Explicitly Banned from Public LLMs
This module provides the core governance rules employees need most: what information must never be entered into a public LLM. It turns broad policy language into concrete data categories and examples employees can recognize in their workflows.
Module 4: Safe Prompting and Acceptable-Use Rules
This module teaches employees how to use AI responsibly when use is permitted. It focuses on safe prompting, approved business uses, redaction, anonymization, and staying within policy-defined guardrails.
Module 5: Privacy, Confidentiality, and Intellectual Property Risks
This module explains the harms that can occur when sensitive data is entered into public LLMs, including privacy violations, confidentiality loss, contractual risk, and exposure of intellectual property. It explains the business consequences behind policy rules.
Module 6: Role-Based Scenarios and Real-World Risk Examples
This module applies the rules to common employee scenarios in HR, marketing, sales, customer support, finance, operations, and administrative work. It shows how innocent-seeming prompts can cross policy boundaries when they include actual names, account details, contracts, health information, or internal strategic content.
Module 7: Reporting Mistakes, Questions, and Suspected AI Data Exposure
This module teaches employees what to do if they accidentally paste sensitive data into a public LLM or suspect someone else has done so. It emphasizes immediate escalation, accurate reporting, and avoiding informal cleanup attempts that could make matters worse.
Module 8: Final Review, Employee Commitments, and Annual Certification
This final module reinforces the course’s core governance rules and ties them to annual compliance documentation. It supports LMS-based completion tracking and provides a repeatable training record aligned with a SCORM-ready compliance catalog.