Programme · AI05

AI Security and Safe Use for Business Professionals

Know the threats. Verify the output. Own the policy.

Next cohort 14 Oct 2026Live and interactive via ZoomVerifiable certificate

Programmes · AI Security and Safe Use for Business Professionals

About this programme

Organisations across the globe are adopting AI tools faster than they are putting rules around them. Staff are pasting client data into free chatbots, accepting AI output into reports without checking it, and receiving scam messages that AI has made far more convincing. Most organisations have no policy, no training, and no idea what their exposure is.

This course closes that gap. It treats AI security (protecting the organisation from AI-enabled threats) and AI safe use (preventing harm from ordinary, well-intentioned use) as two distinct disciplines, then brings them together in a written policy each participant drafts for their own organisation.

The course is non-technical — no coding, no mathematics, and no prior AI experience required. Across three days, participants move from threats (AI security), to reliability (AI safe use), to governance, and leave with a draft AI acceptable-use policy ready to take to management.

On completion, participants will be able to

  • Explain in plain language how generative AI systems work and why they fail.
  • Distinguish AI security threats from AI safe-use risks, and recognise where the two overlap.
  • Identify the main AI-enabled attack methods targeting organisations, including deepfake and social-engineering fraud.
  • Classify organisational data and decide what may and may not be entered into an AI tool.
  • Detect hallucination, fabrication and silent error in AI output, and apply proportionate verification.
  • Assess the fairness and legality of AI-assisted decisions affecting individuals.
  • Apply Ghana's data protection framework to AI use in their organisation.
  • Draft and implement an AI acceptable-use policy.

Who should attend

  • Managers and team leads whose staff are already using AI tools, with or without permission
  • Finance, treasury and payment-approval staff exposed to deepfake and email-compromise fraud
  • Accountants, auditors, and compliance and risk officers accountable for AI-assisted work and disclosures
  • HR professionals using or reviewing AI in recruitment, performance and disciplinary decisions
  • Data protection officers, legal and company secretarial staff responsible for Act 843 compliance

Also suitable for

  • Executives and directors who will approve the organisation's AI policy
  • IT managers and administrators who will own the approved-tools list — no technical background needed
  • Marketing, communications and customer service teams using AI in daily client-facing work
  • Procurement and vendor-management officers vetting AI features in third-party software
  • Anyone whose organisation is adopting AI tools, regardless of function

Programme curriculum

Module 1

Understanding AI: what it is and what it isn't

  • Generative AI in plain language: prediction, not retrieval
  • Why AI produces confident, fluent, wrong answers — the structural reason
  • Types of deployment: consumer chatbots, enterprise/business tiers, embedded AI features, agents that take actions
  • What "the AI is learning from my data" does and does not mean
  • Where AI genuinely adds value in business work, and where it is a poor fit
  • The three terms people confuse: AI security, AI safe use, AI safety (alignment research)

Activity: Tool audit — participants list every AI tool already in use in their organisation, including embedded features they had not counted as AI. Outcome: Participants can explain to a colleague why an AI tool cannot be trusted the way a calculator can.

Module 2

The AI threat landscape

  • Prompt injection: hidden instructions in documents, emails and web pages that hijack an AI assistant
  • Jailbreaking and misuse of company-deployed tools
  • Data poisoning and model manipulation (overview level)
  • Credential and API key exposure
  • AI-enabled fraud: deepfake audio and video, cloned-voice payment instructions, AI-generated phishing and business email compromise, synthetic identity and document forgery, and investment and romance scams at scale
  • Shadow AI: unapproved tools staff use without IT's knowledge
  • Third-party and vendor risk: what your software provider's AI feature does with your data

Activity: Live demonstration of prompt injection against a document-reading assistant, followed by a deepfake detection exercise using local case examples. Outcome: Participants can name the attack methods most likely to target their organisation and describe at least one control for each.

Module 3

Data, confidentiality and tool selection

  • Where your data actually goes: hosting, retention, training use, sub-processors
  • Consumer versus business versus enterprise tiers — the differences that matter
  • Reading the settings that matter: training opt-out, chat history, workspace controls
  • Data classification for AI purposes: public / internal / confidential / never
  • Special categories: client financial data, personal data, health data, salary and disciplinary records, legally privileged material, unpublished results
  • Cross-border data transfer and data sovereignty
  • Anonymisation and redaction before use — and its limits
  • Selecting and approving tools: a due-diligence checklist

Activity: Data classification workshop — participants sort a set of realistic documents into permitted and prohibited categories, then defend borderline calls. Outcome: Participants can produce a data classification list for their own function.

Module 4

The reliability problem

  • Hallucination: what it is, why it cannot be fully eliminated
  • Fabricated sources, citations, case law, standards references and statistics
  • Silent arithmetic and aggregation errors
  • Plausible-but-wrong summarisation: what gets dropped
  • Overconfidence and the absence of "I don't know"
  • Context limits, stale knowledge and cut-off dates
  • Automation bias: why people stop checking, and how quickly
  • Where errors are cheap and where they are catastrophic

Activity: Error hunt — participants are given AI-generated outputs (a summary, a set of figures, a referenced note) seeded with realistic errors, and must find them under time pressure. Outcome: Participants have personally experienced being misled by a fluent output.

Module 5

Verification and human oversight

  • Proportionate verification: matching checking effort to consequence
  • Verification techniques: source tracing, independent recomputation, requiring working to be shown, adversarial re-prompting, second-tool cross-check
  • Prompting for verifiability rather than fluency
  • The human-in-the-loop principle: which tasks may be delegated, which require qualified sign-off
  • Professional accountability — the output is the professional's, not the tool's
  • Disclosure: when to tell clients, employers, regulators or readers that AI was used
  • Record-keeping and audit trail for AI-assisted work
  • Over-reliance and skill erosion in junior staff

Activity: Participants take a flawed AI output from Module 4 and design a verification procedure for that class of task, sized to its risk. Outcome: Participants can define a review standard for AI-assisted work in their own team.

Module 6

Bias, fairness and decisions about people

  • How bias enters AI systems: training data, proxies, feedback loops
  • High-risk use cases: recruitment screening, promotion and performance review, credit and loan decisions, customer risk scoring, disciplinary matters
  • Why "the system decided" is not a defence
  • Explainability: can you tell the affected person why?
  • The right to human review of automated decisions
  • Local relevance: bias against African names, languages, contexts and data
  • Accessibility and inclusion in AI-assisted service delivery

Activity: Case analysis — an AI-assisted recruitment shortlist that has quietly excluded a category of candidates. Participants identify the failure and design the control. Outcome: Participants can identify which decisions in their organisation must not be automated without human accountability.

Module 7

The Ghana legal and regulatory position

  • Data Protection Act, 2012 (Act 843) — the operative law today: scope, core obligations, data subject rights, and registration of data controllers
  • No AI exemption — the Act applies as written, including to processing by AI systems
  • Cybersecurity Act, 2020 (Act 1038) and the Cyber Security Authority — incident reporting and protected systems
  • The National AI Strategy, the proposed Responsible AI Office, and what they signal for regulated sectors
  • What is coming: a new Data Protection Bill covering AI, automated decision-making and cross-border transfers, and a draft Emerging Technologies Bill
  • Sector overlays: BoG directives for financial institutions, ICAG and professional body expectations, GRA and record-keeping implications
  • Where cross-border rules bite: using a US-hosted AI tool on Ghanaian personal data
  • Practical compliance steps: lawful basis, notices, DPIAs for high-risk use, vendor contracts

Activity: Compliance gap check — participants assess one AI use case in their organisation against Act 843. Outcome: Participants can state, for a given AI use case, whether personal data is being processed and what that requires of them.

Module 8

Building your organisation's AI policy

  • Anatomy of an AI acceptable-use policy
  • Approved tools list and the approval process for new tools
  • Data classification rules and the short, absolute list of prohibited uses
  • Review and sign-off requirements by task risk
  • Disclosure requirements — internal and client-facing
  • Incident reporting: what counts as an AI incident and who is told
  • Training, onboarding and periodic refresh
  • Roles: who owns AI governance, and where it sits relative to IT, risk and compliance
  • Monitoring adoption without policing staff into shadow AI
  • Getting the policy approved: making the business case to leadership

Activity: Guided policy build using a supplied template — participants work on their own organisation, present a two-minute summary, and receive peer and facilitator critique. Outcome: A completed draft AI acceptable-use policy ready to take to management.

Course format

Course code
AI05
Delivery
Live online via Zoom
Duration
Three days, 9:00 AM – 3:00 PM with a 30-minute break
Total training
16 contact hours
Class size
Maximum 30 participants
Assessment
Continuous exercises plus a final policy deliverable
Support
Cohort WhatsApp group with the facilitator
Learner portal
Personal portal for meeting links and materials
Facilitator
Stephen Kwame Aikins, CA

Prerequisites

  • None — the course is non-technical, with no coding, mathematics or prior AI experience required
  • Participants should have used an AI chatbot at least once

What your registration includes

  • Live, instructor-led training across three days
  • Course workbook with all slides and exercise sheets
  • Editable AI acceptable-use policy template
  • Data classification worksheet and AI tool due-diligence checklist
  • Verification procedure templates by task type
  • Ghana AI regulation reference sheet and a curated further-reading list
  • Access to a personal learner portal
  • A cohort WhatsApp support group with the facilitator
  • A verifiable certificate of completion
  • A credential anyone can confirm through our public certificate verification page.

Training a team?

Companies registering five or more participants receive a 15% discount, plus a Corporate Portal to track attendance, download certificates, and manage employees from one account.

Frequently asked questions

Do I need previous AI experience?

No. The course is non-technical — no coding, no mathematics, and no prior AI experience required. You should simply have used an AI chatbot at least once.

How will the training be delivered?

Live online via Zoom across three days, 9:00 AM to 3:00 PM with a 30-minute break each day.

How is the course assessed?

Through continuous exercises across the modules — including an error-hunt exercise and a compliance gap check — plus a final AI acceptable-use policy that you draft and present.

Will I receive a certificate?

Yes. Participants scoring 70% or above receive a verifiable certificate of completion.

What will I take back to my organisation?

A completed draft AI acceptable-use policy for your own organisation, plus the templates, worksheets and checklists used to build it.

Will I receive learning support?

Yes. Participants receive access to a learner portal and a cohort WhatsApp group with the facilitator.

Is there a shorter version for executives?

Yes. A condensed one-day executive version is available for corporate groups — contact us to arrange it.

Ask about AI Security and Safe Use for Business Professionals

Not ready to register? Leave your question and a real person will get back to you.

Ready to join?

Secure your place on the next cohort.