Infosec NIST AI RMF

AI and Generative AI Security Awareness

Security awareness training on generative AI tools covering prompt injection, data leakage, and safe use of AI assistants, aligned with the NIST AI Risk Management Framework.

~30 min

About this course

Generative AI tools like ChatGPT, Copilot, and Gemini are now part of daily work for most employees, whether or not an organization has formally approved them. This course teaches practical, non-technical security awareness for anyone who uses AI assistants at work: what data is safe to enter into a public AI tool, how attackers exploit AI systems through techniques like prompt injection, and why AI-generated content still needs human verification.

The risks here are current and well documented, not hypothetical. Security researchers and standards bodies have identified prompt injection and sensitive information disclosure as leading concerns for AI-enabled workflows, since large language models process instructions and data through the same channel and can be manipulated into acting on attacker-crafted input. Employees who paste confidential documents, customer data, or source code into a public AI tool may be exposing that data outside company control, sometimes permanently.

This course grounds its guidance in the NIST AI Risk Management Framework (AI RMF), a widely referenced voluntary framework organized around four functions: Govern, Map, Measure, and Manage. Learners don't need to implement the framework themselves, but understanding its logic helps explain why organizations set AI usage policies, require approval for high-risk AI use cases, and ask employees to verify AI-generated output before relying on it.

This training is designed for all employees, especially those using AI writing assistants, chatbots, coding copilots, or AI-powered search and research tools. After completing it, learners will be able to identify what information should never be entered into a public AI tool, recognize signs of prompt injection or manipulated AI output, understand why AI-generated content can be inaccurate or fabricated ("hallucinated"), and know when and how to escalate concerns about AI tool use to IT or security teams.

Topics covered

  • How generative AI tools process and sometimes retain user input
  • Prompt injection and why AI systems can be tricked by crafted input
  • Data leakage: what not to paste into public AI tools
  • Recognizing AI "hallucinations" and verifying AI-generated content
  • Shadow AI: the risk of using unapproved AI tools for work tasks
  • Overview of the NIST AI Risk Management Framework

Want this tailored to your organization's policies? Build your own with AI or book a demo.