# AI Security Awareness Training Deck

**Organisation:** [ORGANISATION NAME]
**Owner:** [NAME / ROLE]
**Date:** [DATE]
**Version:** 1.0

---

## Purpose

A complete, ready-to-present AI security awareness training for all staff. The deck teaches employees what shadow AI is, what happens to data pasted into AI tools, which data may and may not be shared, how to prompt safely, how to recognise AI-generated phishing and deepfakes, and how to report an AI incident without fear of blame.

This document is the full deck outline: every slide with its on-slide content and a speaker script a facilitator can read aloud. It accompanies the 28-slide widescreen PowerPoint version of the same training, and doubles as a handout or pre-reading document for attendees.

---

## How to Use

1. Download the PowerPoint deck for presenting and keep this document as the facilitator outline and attendee handout.
2. Replace every [BRACKETED] placeholder with your company specifics: names, contacts, links, and tools.
3. Customise three slides before delivery: the traffic-light data rules (slide 11), your approved AI tools (slide 14), and your incident reporting path (slide 20).
4. Deliver as a live session, a recorded video, or a self-paced module in your LMS. The session runs 45 to 60 minutes including the knowledge check.
5. Score the four-question knowledge check and record completion. Collect signed acknowledgments using the Employee AI Training Acknowledgment template.
6. Re-run the training at least annually, and whenever your AI toolset, policy, or threat landscape changes materially.

---

## Customisation Checklist

| Placeholder | Where it appears | Replace with |
|-------------|------------------|--------------|
| [COMPANY NAME] | Title, footers, slides 14 and 28 | Your organisation's name |
| [FACILITATOR NAME / ROLE] | Slide 1 | Who is presenting |
| [SECURITY TEAM CONTACT / CHANNEL] | Slides 11, 12, 20, 27, 28 | Named contact, email, or chat channel |
| [TOOL NAME / ACCOUNT TYPE / APPROVED USES] | Slide 14 | Your sanctioned AI tools |
| [REQUEST FORM / CHANNEL] | Slide 14 | How staff request a new AI tool |
| [INCIDENT EMAIL / PHONE] | Slide 20 | Your incident reporting route |
| [AUP LINK / INTRANET LOCATION] | Slide 28 | Where your AI acceptable use policy lives |
| [ACKNOWLEDGMENT FORM LINK] | Slide 28 | Your training acknowledgment form |

---

## Session Run Sheet

Suggested timing for a 50-minute live session. Adjust to your audience and format.

| Segment | Slides | Minutes | Facilitator focus |
|---------|--------|---------|-------------------|
| Welcome and framing | 1 | 3 | Set the tone: enablement, not prohibition |
| Part 1: Why this matters | 3 to 5 | 8 | The show-of-hands moment on slide 5 drives engagement |
| Part 2: Where your data goes | 6 to 9 | 10 | Slow down on slide 8; training vs retention is the key concept |
| Part 3: The everyday rules | 10 to 14 | 12 | Your customised slides; invite questions on the approved list |
| Part 4: New threats | 15 to 19 | 9 | Keep it practical: procedures beat perception |
| Reporting | 20 | 3 | Deliver the no-blame message personally and sincerely |
| Knowledge check and answers | 21 to 26 | 4 | Revisit any question the group misses widely |
| Takeaways and close | 27 to 28 | 1 | Point to the AUP and the acknowledgment form |

---

## Delivery Formats

| Format | How | Notes |
|--------|-----|-------|
| Live session | Present the deck; use the speaker notes as your script | Highest engagement; the quiz works well as a group vote |
| Recorded video | Record a voiceover of the deck using the notes | Keep it under 40 minutes; run the quiz separately in your LMS |
| Self-paced (LMS) | Export slides plus this document as reading; quiz as an LMS assessment | Set a pass mark (suggested: 3 of 4) and require acknowledgment on completion |
| Team briefing | Run one part per team meeting over four weeks | Parts are self-contained; always end each with the reporting slide |

---

## Deck Outline

28 slides, 16:9 widescreen. Dark slides are the title, section dividers, and closing; all content slides are clean white with brand accents.

### Slide 1: AI Security Awareness Training (title)

**On slide:** [COMPANY NAME]. Subtitle: "Using AI safely at work: what to use, what to share, what to watch for." Presented by [FACILITATOR NAME / ROLE], [DATE].

**Speaker notes:** Welcome, everyone. This session takes about 45 minutes, and it is about one thing: how to get the benefits of AI at work without putting our customers, our colleagues, or the company at risk. This is not a session about banning AI. Most of us already use AI tools, and they are genuinely useful. It is about using them with your eyes open. Please ask questions at any point.

### Slide 2: How to run this training (facilitator slide)

**On slide:** Session length 45 to 60 minutes including the knowledge check. Audience: all staff and contractors, no technical background assumed. Replace every [BRACKETED] placeholder before presenting. Slides 11, 14 and 20 need your data rules, approved tools, and reporting contacts. Speaker notes on every slide provide a full script. Works live, recorded, or self-paced in your LMS.

**Speaker notes:** This slide is for you, the facilitator. Hide or delete it before presenting. Read the speaker notes end to end once before you deliver, and adapt the wording to your own voice. Record attendance and knowledge check completion as compliance evidence, and pair this deck with your AI acceptable use policy and a signed acknowledgment form.

### Slide 3: Part 1, Why this matters now (divider)

**On slide:** Part 1. Why this matters now. "AI is in everyday work. Security has to be too."

**Speaker notes:** Let us start with why we are all here. Not because AI is bad, but because it has moved faster than the safeguards around it, and every one of us now makes small security decisions every day, often without realising it.

### Slide 4: Why AI security matters now

**On slide:** AI tools are now part of everyday work: writing, analysis, code, meetings, and support. Most AI tools are cloud services: what you type leaves the company. New tools appear every week, often adopted before any security review. Attackers use AI too: phishing and impersonation are more convincing than ever. Customers and regulators, including under laws like the EU AI Act, expect organisations to control how AI is used.

**Speaker notes:** Three shifts happened at once. First, AI became useful enough that everyone wants it, so it is everywhere. Second, almost all of it runs in someone else's cloud, so using it means sending data outside the company. Third, the same technology powers the attackers: the scam emails and fake voices targeting us are now machine-made and convincing. None of this is hypothetical, and that is why this training exists.

### Slide 5: What is shadow AI?

**On slide:** Definition: shadow AI is any AI tool or feature used for work without approval or oversight. A personal ChatGPT, Claude, or Gemini account used for work tasks. AI features switched on inside tools we already use. Browser extensions that read every page to "help". A free trial signed up with a work email. The problem is not the tool: it is that nobody has reviewed it, there is no contract, and we cannot get the data back.

**Speaker notes:** Show of hands, and be honest: who has pasted something work-related into a personal AI account? In most rooms that is nearly everyone, and that is exactly the point. Shadow AI is rarely malicious. It is a helpful person with a deadline and a good tool. The risk is invisibility: if security does not know a tool is in use, nobody has checked where the data goes, there is no agreement protecting it, and there is no way to pull it back. Our goal today is to move that use into the open.

### Slide 6: Part 2, Where your data goes (divider)

**On slide:** Part 2. Where your data goes. "The prompt box looks private. It is not."

**Speaker notes:** This is the heart of the session. When you type into an AI tool, where does that text actually go? Once you can picture the journey, the rules later in this deck will feel obvious rather than arbitrary.

### Slide 7: What happens when you paste data into an AI tool

**On slide:** Your prompt is sent to the provider's servers, often in another country. It is usually logged and retained for a period you do not control. On consumer plans it may be reviewed by people or used to improve the model. Once submitted, there is no reliable way to recall or delete it. Account type matters: free and personal plans carry far weaker protections than enterprise agreements.

**Speaker notes:** Picture pasting a customer spreadsheet into a chatbot to draft an email. The moment you press enter, that spreadsheet travels to the provider's infrastructure, quite possibly overseas. It sits in logs. On a consumer account, the provider's terms may allow staff review or use for model improvement. And there is no undo. Nothing dramatic has to happen for this to be a problem: you have disclosed customer data to a third party we have no agreement with. That can be a reportable breach all by itself.

### Slide 8: Training versus retention: two different questions

**On slide:** Training: will my data end up inside the model? Enterprise plans usually exclude this by contract; consumer plans vary. Retention: will the provider keep my prompts? Usually yes, in logs, at least for a period, even when training is off. Retained data can surface later: provider breaches, legal discovery, account compromise. Working rule: assume anything you submit is stored somewhere you do not control.

**Speaker notes:** This is the most misunderstood point in AI security, so let us slow down. "This tool does not train on my data" answers one question. It does not answer the other: is my prompt stored? Almost always, the answer is yes, at least in logs, at least for a while. Stored data can leak in a provider breach, be produced in litigation, or be exposed if an account is compromised. So the honest working rule is on the slide: assume anything you submit is stored somewhere you do not control, and choose what you share accordingly.

### Slide 9: How AI data leaks actually happen

**On slide:** The helpful paste: source code, contracts, or customer lists pasted in to debug, summarise, or draft. The meeting recorder: an AI notetaker joins a confidential call, emails the transcript, and keeps a copy. The connected account: an AI tool granted access to email or file storage reads far more than intended. The quiet extension: a browser add-on with AI features reads internal pages as you work.

**Speaker notes:** These four patterns cover most real AI data incidents, and none of them involves a hacker. They are ordinary people being helpful. The helpful paste is so common that several large companies publicly restricted chatbot use after staff pasted confidential source code. The meeting recorder and the connected account are quieter: one consent click can hand a third party your calendar, inbox, or every word of a board call. Recognising these patterns is half the defence.

### Slide 10: Part 3, The everyday rules (divider)

**On slide:** Part 3. The everyday rules. "Simple rules you can apply in the moment, without a policy manual."

**Speaker notes:** Now the practical part. You do not need to memorise a policy document. You need three things: the traffic light for data, a few prompting habits, and where to find the approved tools.

### Slide 11: Data classification: the traffic light

**On slide:** GREEN, fine for approved AI tools: information that is already public, general knowledge questions, drafts with no personal or confidential content. AMBER, approved tools only, with care: internal working documents, de-identified data and summaries [ADJUST TO YOUR DATA CLASSIFICATION POLICY]. RED, never in any AI tool: customer or employee personal data, passwords and credentials, financial, legal, or health information, source code and trade secrets [ADJUST TO POLICY]. Not sure? Treat it as red and ask [SECURITY TEAM CONTACT / CHANNEL].

**Speaker notes:** One mental model to remember: green, amber, red. Green is anything already public or generic; use approved AI tools freely. Amber is everyday internal material; keep it inside approved, company-managed tools and share only what the task needs. Red never goes into any AI tool without explicit approval: personal data about anyone, credentials, and our most sensitive business information. If you are unsure which colour applies, that uncertainty is your answer: treat it as red and ask. Asking takes two minutes; a breach report takes months.

### Slide 12: Safe prompting: do

**On slide:** Use approved tools with your work account, never personal accounts, for work tasks. De-identify first: strip names, IDs, and account numbers before you paste. Use placeholders: [CUSTOMER] or [PROJECT X] work as well as real names. Review AI output before it leaves your hands: models state wrong things confidently. When unsure, ask [SECURITY TEAM CONTACT / CHANNEL] first.

**Speaker notes:** Five habits that remove most of the risk. Work accounts on approved tools mean company protections apply. De-identifying before you paste is the single highest-value habit: the model gives you the same quality answer whether the customer is called Jane Citizen or Customer A. And always review output before it goes anywhere that matters, because models are confidently wrong often enough that unchecked output is its own incident category.

### Slide 13: Safe prompting: don't

**On slide:** Do not paste whole documents when a description of the problem will do. Do not enter credentials, API keys, or anyone's personal data. Do not connect AI tools to email, calendars, or files without approval. Do not act on AI output for legal, HR, financial, or medical matters without human review. Do not assume "temporary" or "incognito" chats mean nothing is kept.

**Speaker notes:** The mirror image. Share the minimum: describe the problem instead of uploading the file. Credentials and personal data are always red. Connecting an AI tool to your inbox or drive is not a small step; it is granting a third party standing access to everything in there, so it needs approval. And the last point matters: a "temporary chat" setting changes what you see, not necessarily what the provider stores. Do not let a privacy-flavoured label change what you are willing to paste.

### Slide 14: Approved AI tools at [COMPANY NAME] (customise before delivery)

**On slide:** Table: Tool, Account type, Approved for. [TOOL NAME 1], [ENTERPRISE / TEAM PLAN], [APPROVED USES]. [TOOL NAME 2], [ENTERPRISE / TEAM PLAN], [APPROVED USES]. [TOOL NAME 3], [ENTERPRISE / TEAM PLAN], [APPROVED USES]. Need something not listed? Request it via [REQUEST FORM / CHANNEL]. Typical decision within [N] business days.

**Speaker notes:** Here is what you can use today, on which account, and for what. [WALK THROUGH EACH APPROVED TOOL AND ITS INTENDED USES.] Two things to stress. First, use these tools through the company account, not a personal one, because that is where our contractual protections live. Second, the request process exists to say yes safely. If a tool would help you, ask for it. A quick request is how tools get approved; going around the process is how incidents happen.

### Slide 15: Part 4, New threats to watch (divider)

**On slide:** Part 4. New threats to watch. "The same AI that helps you write emails helps attackers write better ones."

**Speaker notes:** So far we have talked about our own AI use. Now the other side: how attackers use AI against us, and what to do about meeting bots, browser extensions, and AI agents.

### Slide 16: AI-generated phishing

**On slide:** Fluent, personalised phishing at scale: bad spelling is no longer a warning sign. Attackers mine LinkedIn, company pages, and breach data to sound exactly like a colleague or supplier. Judge by context, not polish: unexpected urgency, changed payment details, secrecy, unusual channels. Verify requests for money or credentials through a second channel you initiate.

**Speaker notes:** We all learned to spot phishing by clumsy language. That signal is gone: AI writes flawless, personalised messages in any tone, referencing real projects and real names scraped from public sources. So shift your detection from polish to context. Is the request unexpected? Is there urgency or secrecy? Are payment details changing? Those signals survive AI. And the golden rule: verify through a second channel that you initiate, like calling a number you already have. Never verify through the channel the request arrived on.

### Slide 17: Deepfakes and voice cloning

**On slide:** A few seconds of recorded speech is enough to clone a voice. Live video can be faked: employees have been talked into large transfers on calls with fake "executives". Agree callback and verification procedures for payments and sensitive requests in advance. If a call feels off: hang up and call back on a number you already have.

**Speaker notes:** Voice cloning is cheap and fast, and video deepfakes are good enough to run live on a call. There are well-documented cases of finance staff transferring large sums after video meetings where every other participant was fake. The defence is procedural, not perceptual: you will not reliably spot a good fake, so we verify by procedure instead. Payments and credential changes follow the agreed process every time, no matter how senior or urgent the requester sounds. Hanging up and calling back on a known number is not rude; it is the control working.

### Slide 18: Meeting bots and browser extensions

**On slide:** AI notetakers are participants: they record, transcribe, and store your meeting on their servers. Before recording: get consent, check where the transcript goes, and remove bots nobody invited. AI browser extensions can read every page you open, including webmail and internal systems. Install extensions only from [APPROVED EXTENSION LIST / SOFTWARE POLICY].

**Speaker notes:** Two quiet channels for data to leave. An AI notetaker is effectively another attendee that never forgets: the transcript of your confidential call now lives on a third party's servers, and often gets emailed around automatically. Treat bots like people: if you do not know who invited one, remove it and ask. Browser extensions are the same story in your browser: an extension with page access can read everything you see, including internal systems. Only install what the company has approved.

### Slide 19: AI agents and automation

**On slide:** Agents do not just answer, they act: sending email, editing files, calling systems, browsing. An agent with your access can make mistakes at machine speed, in your name. Agents can be manipulated by content they read: a poisoned email or web page can redirect them (prompt injection). Use approved agents only, grant the minimum access needed, and review what they did.

**Speaker notes:** The newest frontier. An AI agent is software that takes actions on your behalf: it can send the email, change the file, book the thing. That is powerful, and it means an agent inherits your access and your authority. Two risks follow. Mistakes happen at machine speed and scale. And agents can be hijacked by the content they process: instructions hidden in an email or web page can redirect an agent, which is called prompt injection. So: approved agents only, least access necessary, and keep a human check on what they did in your name.

### Slide 20: If something goes wrong: report it

**On slide:** Report fast, no blame: speed limits damage, silence multiplies it. Report near misses and "not sure" moments too. What to include: which tool, which account, what data, when. Contact: [SECURITY TEAM CONTACT / CHANNEL] or [INCIDENT EMAIL / PHONE]. You will not be punished for reporting an honest mistake. [ALIGN WITH YOUR HR POLICY]

**Speaker notes:** If you remember one slide, make it this one. If data went somewhere it should not have, or you even suspect it did, tell us straight away. A report within the hour is usually a contained, manageable event: we can request deletion, revoke access, and meet any notification deadlines. The same event surfacing weeks later is a crisis. That is why our position is no blame for honest mistakes: the person who reports fast is doing exactly the right thing. Tell us the tool, the account, the data, and the time. That is all it takes.

### Slide 21: Knowledge check (divider)

**On slide:** Knowledge check. "Four scenarios. Pick the best answer for each."

**Speaker notes:** Four quick scenarios to make this concrete. Answer individually or shout it out, depending on the format. The answers, with reasons, follow on the answer slide.

### Slide 22: Question 1

**On slide:** You need to summarise a 40-page supplier contract by end of day. What do you do? A: Paste it into a free AI chatbot on your personal account. B: Use the approved AI tool and check the traffic-light rules first. C: Ask a colleague to paste it for you instead. D: Retype the key clauses so the text is "new".

**Speaker notes:** Read the scenario and options aloud, take answers, then move on. The trap options matter: C is the same disclosure with an extra witness, and D changes the format, not the sensitivity. The habit we want is B: reach for the approved tool, then apply the data rules before anything is pasted.

### Slide 23: Question 2

**On slide:** A long-time supplier emails new bank details for their next invoice. The email is polished and references your last order. A: Update the details, the email checks out. B: Reply to the email asking them to confirm. C: Call a known contact at the supplier on a number you already have. D: Forward it to a colleague to decide.

**Speaker notes:** The polish and the accurate order details prove nothing anymore: that is exactly what AI-assisted fraud looks like. B fails because you would verify through the attacker's own channel. The only reliable move is C: a second channel that you initiate, using contact details you already had before the request arrived.

### Slide 24: Question 3

**On slide:** An AI notetaker you do not recognise joins your confidential project call. A: Ignore it, it is probably fine. B: Assume someone approved it. C: Remove it, then check who invited it and report if unclear. D: Ask in the meeting chat and carry on.

**Speaker notes:** Treat unknown bots like unknown people: you would not let an unrecognised stranger sit in on a confidential call while you carried on. C is the answer: remove first, then verify. If it turns out a colleague invited an approved tool, nothing is lost. If nobody did, you may have just contained an incident.

### Slide 25: Question 4

**On slide:** You realise you pasted a customer list into an unapproved AI tool an hour ago. A: Delete the chat and move on. B: Report it to [SECURITY TEAM CONTACT / CHANNEL] straight away. C: Wait and see whether anything bad happens. D: Mention it only if someone asks.

**Speaker notes:** This one is the culture test. Deleting the chat does not delete the provider's copy, and waiting only burns the time in which we could act. The right answer is B, and the crucial message is that reporting is the safe choice for the reporter too: fast, honest reports are protected here.

### Slide 26: Answers

**On slide:** Q1: B. Approved tool first, then apply the traffic-light rules before pasting. Q2: C. Verify through a second channel you initiate; polish proves nothing. Q3: C. Remove unknown bots first, verify after; treat bots like uninvited guests. Q4: B. Report immediately; fast reports contain incidents and are never punished.

**Speaker notes:** Walk through each answer briefly and invite questions. If the group missed one widely, revisit that slide rather than moving on: the quiz exists to find exactly those gaps while everyone is still in the room.

### Slide 27: Key takeaways

**On slide:** Assume anything you enter into an AI tool leaves the company and is stored. Follow the traffic light: green freely, amber in approved tools, red never. Use approved tools on work accounts, and request new ones rather than going around. Trust context, not polish: verify unusual requests on a second channel. Report fast and blame free: [SECURITY TEAM CONTACT / CHANNEL].

**Speaker notes:** Five sentences to keep. If the detail fades, these carry you: assume prompts are stored, follow the traffic light, stay on approved tools, verify by procedure rather than instinct, and report fast. Everything else in this session was supporting material for these five habits.

### Slide 28: Thank you (closing)

**On slide:** Thank you. Next steps: read the AI Acceptable Use Policy at [AUP LINK / INTRANET LOCATION]. Sign the training acknowledgment: [ACKNOWLEDGMENT FORM LINK]. Questions and tool requests: [SECURITY TEAM CONTACT / CHANNEL].

**Speaker notes:** Thank you for the time and the honesty in the discussion. Three small actions before you close this tab: read the acceptable use policy, sign the acknowledgment so we can record completion, and bookmark the security contact. And remember the spirit of all of this: we want you using AI, safely, in the open, with tools we can stand behind. Thanks, everyone.

---

## Knowledge Check Answer Key

| Question | Answer | Why |
|----------|--------|-----|
| 1 | B | Approved tool plus the traffic-light check; retyping or delegating does not change the data's sensitivity |
| 2 | C | Verify through a second channel you initiate; replying verifies through the attacker's channel |
| 3 | C | Remove unknown bots first, then verify who invited them; report if unclear |
| 4 | B | Immediate reporting enables deletion requests, access revocation, and timely notifications |

---

## Measuring Effectiveness

Track these after each delivery cycle so the training earns its slot in the calendar.

| Measure | Target | Source |
|---------|--------|--------|
| Completion rate | [95]% of staff within [30] days of joining or of the annual cycle | LMS or attendance register |
| Knowledge check pass rate | At least 3 of 4 correct; re-take on failure | Quiz results |
| Acknowledgment rate | 100% of completers sign the AI acceptable use acknowledgment | Signed forms register |
| AI incident reports | Reports increase after training (more reporting is success, not failure) | Security team incident log |
| Shadow AI trend | Unapproved tool usage declines quarter on quarter | AI discovery tooling or DLP reports |
| Tool requests | New-tool requests increase (staff use the front door) | Request form volume |

A quiet quarter with zero reports and zero requests usually means low awareness, not low risk. Treat rising reports and rising requests as the training working.

---

## Attendee Quick Reference (one-page handout)

Copy this section into a one-pager or intranet page for attendees to keep.

**The traffic light**

| Colour | What it covers | What to do |
|--------|----------------|------------|
| Green | Public information, general questions, non-sensitive drafts | Use approved AI tools freely |
| Amber | Internal documents, de-identified data | Approved tools only; share the minimum |
| Red | Personal data, credentials, financial, legal, health, source code, trade secrets | Never enter into any AI tool; ask first |

**The five habits**

1. Assume anything you enter into an AI tool leaves the company and is stored.
2. Follow the traffic light. When unsure, treat it as red and ask.
3. Use approved tools on your work account. Request new tools via [REQUEST FORM / CHANNEL].
4. Verify unusual requests (payments, credentials, urgency) on a second channel you initiate.
5. Report incidents and near misses fast, blame free: [SECURITY TEAM CONTACT / CHANNEL].

---

*Provided free by [Aona AI](https://aona.ai). Aona discovers every AI tool in use across your organisation, monitors what data flows into them, and keeps your AI inventory audit-ready.*
