Using AI Tools Responsibly at Work

Using AI Tools Responsibly at Work

Practice making compliant AI decisions throughout a typical workday.

What Is Using AI Tools Responsibly at Work?

Most AI compliance decisions are made by employees, not lawyers, and they are made quickly. You'll work through a day of ordinary AI use where each choice carries an obligation: picking a tool with a valid data processing agreement, judging what data is safe to paste in, and disclosing AI assistance where company policy or the EU AI Act's chatbot rule (Article 50) requires it. You'll leave with rules you can apply without asking.

What You'll Learn in Using AI Tools Responsibly at Work

Using AI Tools Responsibly at Work — Training Steps

  1. A Day of AI Decisions

    This is a practical, day-in-the-life exercise. No abstract regulation - just real choices. Every AI interaction at work has compliance implications. The EU AI Act requires AI literacy (Art. 4), deployer obligations (Art. 26), and transparency (Art. 50). Today, you will see how these translate into the decisions you make every time you open an AI tool.

  2. An Urgent Request

    Alice's manager needs a quarterly marketing report by end of day. He wants it polished and data-driven, and he is fine with Alice using AI tools to get it done.

  3. Choosing the Right Tool

    Before starting the report, Alice checks which AI tools are approved for use at Horizon Enterprises. The approved tools list lives behind a sign-in on the internal IT portal. The company has one approved AI assistant - OpenClaw - which has a business data processing agreement. Alice also knows about SmartDraft, a free consumer tool that is arguably faster but has no DPA and retains all input data for training.

  4. What Data to Input

    Alice opens the approved AI tool on her second machine and starts drafting the report. She considers pasting last quarter's revenue figures and specific client names into the prompt. Even with an approved tool, you should evaluate what data you input. Client names combined with revenue figures are competitively sensitive. Check whether the DPA covers this data category before proceeding.

  5. Knowledge Check: Tool Selection

  6. Disclosing AI Assistance

    The AI has drafted a complete report. Alice must now decide how to handle attribution. Present it as her own work? Label it as AI-assisted? Something else? Horizon Enterprises' policy requires disclosure of substantial AI assistance in work deliverables. The EU AI Act does not require a label on an internal report; this rule is the company's, and a sound one.

  7. Submit the Q2 Report

    The draft is solid and Alice has decided how to handle attribution. Time to send it to Tom.

  8. The Internal Chatbot Question

    A colleague reaches out with a question about setting up an internal chatbot. Jamie wants to create an AI-powered FAQ bot to answer common HR questions for the team.

  9. The Shadow AI Risk

    Another email arrives - this time from a colleague recommending an unapproved AI tool. Ryan has been using it for weeks without IT approval.

  10. Knowledge Check: Shadow AI

Security Framework Coverage

CIS Controls

  • CIS 14.4 Train Workforce on Data Handling Best Practices

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

EU AI Act

  • Art. 4 AI literacy
  • Art. 50 Transparency obligations for providers and deployers