The duty you carry
Awareness programs are judged on behavior change, and AI misuse is now the behavior auditors ask about. The frameworks are consistent: ISO 27001 and SOC 2 treat awareness as one control among several, never a substitute for enforcement. A prompt-level checkpoint does two things for a program. It prevents the incident during the teachable moment — a nudge at the paste beats a module eleven months prior. And it produces the metric — attempts caught, trends by team, repeat patterns — that turns "we trained everyone" into evidence the training works.
The moment it breaks
Synthetic example. The real version happens on your busiest day.
The employee gets a nudge and a clean path forward. The export never leaves — and your program gets a data point instead of an incident.
Caught, in your vocabulary
Credentials and secrets
Passwords, keys, and tokens pasted for a quick fix — the shortest path from helpful to breached.
Customer PII in exports
The spreadsheets and CSVs people paste whole, names and card digits included.
Internal documents and plans
Strategy, financials, and HR material that ends up in prompts because summarizing is what AI is best at.
The rules you answer to
ISO 27001 and SOC 2
Both expect awareness plus technical controls. A prompt-level checkpoint is the enforcement half auditors look for.
Privacy breach duties
Prevention at the prompt turns would-be notifiable incidents into coaching moments with a log entry.
Program measurement
Catches by team and trend lines are the awareness metrics leadership actually understands — and budget follows measurement.
From our research
Why Your AI Acceptable Use Policy Probably Isn't Working
Most organizations rolled out an AI acceptable use policy sometime in the last 18 months. Most of them aren't working, and the reason isn't what people think.
How to Get Visibility Into Shadow AI Without Banning Every Tool
You can't govern what you can't see, and most organizations have no visibility into nearly 90% of their AI usage. Here's how to get that visibility without driving employees to personal accounts.
What Is Shadow AI, and Why Are Security Teams Worried About It?
Learn what shadow AI is, why employees use unapproved AI tools, what risks it creates, and how organizations can respond without simply banning AI.
Compliance standards that apply
Also built for
See it on your own scenarios
Twenty minutes, your examples, no slideware. Or start with the five-question readiness check. No email required.