It complements security awareness training, which focuses on phishing and good security habits; in its publication on tailored training (ITSAP.10.093), the Canadian Centre for Cyber Security lists awareness of artificial intelligence technologies among the topics an organization may want to offer. The rules to teach come from your AI usage policy: the training shows how to apply them day to day.
Short answer
You describe your teams, your AI tools and your policy, if you have one: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote. The content, format and schedule are set with you.
What the quote should cover
- Analysis of the tools used, the roles and the policy in place
- A common module for all employees
- Role-based modules: customer service, human resources, development, management
- Practical exercises with your own cases, without real sensitive data
- A quick-reference sheet for participants
- The format: in person, remote or online, and the languages
- Updating the content when tools or the policy change
The steps of an AI training program
- Overview of the tools used and needs by role
- Alignment with the AI usage policy
- Design of modules and exercises
- Training sessions and handout of the quick-reference sheet
- Follow-up questions and adjustments
- Updates when a tool or the policy changes
Content tailored to roles
The Centre's ITSAP.10.093 publication describes several types of training, including role-based training for specific job functions, and suggests incorporating practical exercises into all types of training. The same principle applies to AI: a common module on rules and risks, then cases specific to each role.
- Customer service and sales: drafting a reply without pasting in the client's information
- Human resources: what changes when a tool affects a decision about a person
- Development: reviewing suggested code, since the Centre notes that developers may inadvertently introduce insecure and buggy code
- Management: approving a tool, setting expectations, answering teams' questions
Checking outputs: hallucinations and automation bias
The Government of Canada guide on the use of generative AI, written for federal institutions, clearly describes the two pitfalls to teach. The first is content that appears to be well developed, credible and reasonable but that is in fact inaccurate, nonsensical or inconsistent with source data, sometimes referred to as a "hallucination". The second is automation bias, the tendency to favour results generated by automated systems, even in the presence of contrary information from non-automated sources.
The same guide recommends not considering generated content as authoritative, and not using these tools as search engines unless sources are provided so that the content can be verified. Good training turns these principles into concrete habits: checking figures, names and references, asking for sources, and having a competent person review before any external use.
Data to protect
The training does not rewrite the policy: it illustrates it. Participants sort examples from their own work into your policy's data categories, learn to strip personal or confidential information from a request and to recognize useful settings, such as deleting history or opting out of training use, when the tool offers them.
It also explains what to do if information has been entered by mistake: whom to report it to, and quickly. The Incident response page describes the obligations that may follow.
The link with the Act
Quebec's Act respecting the protection of personal information in the private sector requires policies and practices that set out the roles and responsibilities of staff members throughout the life cycle of personal information (s. 3.2). The person in charge of the protection of personal information may also suggest, in an information system project, personal information protection training activities for project participants (s. 3.4).
If a tool is used to make a decision based exclusively on automated processing, section 12.1 requires that the person concerned be able to submit observations to a member of staff who is in a position to review the decision: employees in that role need to understand how the tool works and its limits. The AI governance page covers these obligations.
Questions to ask yourself before requesting a quote
- Which AI tools do your employees use, and with which accounts?
- Do you have an AI usage policy to roll out?
- Which roles have particular needs or risks?
- What sensitive data do your teams handle?
- Do you prefer in-person, remote or online sessions?
- How will new employees be trained?
Pitfalls to avoid
- A tool demo with no rules or company-specific examples
- Training that contradicts the internal policy, or that precedes a policy never adopted
- The same content for every role
- Using real client data during exercises
- Forgetting to cover output verification
- Content that is never updated
What to specify in your request
- The approximate number of participants and their roles
- The AI tools used or approved
- Whether you have an AI usage policy
- The format and languages wanted
- Priority topics
- Your date constraints, if any
You can then describe your project: the team will contact you to clarify your needs and provide a quote.
Frequently asked questions
How is it different from security awareness training?
Security awareness training covers attacks and security habits, such as phishing and passwords. AI training covers the use of AI tools: appropriate tasks, data to protect, output verification and internal rules. The two can complement each other.
Do we need an AI usage policy before the training?
It is preferable, since the training teaches the policy's rules. If it does not exist yet, the mandate can include drafting it first; the AI usage policy page describes its content.
Does the training cover a specific tool, such as ChatGPT?
It first covers the tools your company uses or approves, whether a chatbot or AI features built into your software. The principles taught, such as data protection and verification, apply to all tools.
What is automation bias?
According to the Government of Canada guide, it is the tendency to favour results generated by automated systems, even in the presence of contrary information from non-automated sources. The training teaches people to guard against it, notably by checking outputs before use.
How often should the training be repeated?
Plan it as part of onboarding for new employees, then whenever a tool or the policy changes significantly. A short periodic refresher, set with you, helps keep the rules in mind.