AI Act in the office: safe use of ChatGPT, Copilot and other AI tools
An 8-hour workshop for people who use AI for writing, analyzing, translating, and making decisions. Participants go through 15 realistic workplace situations, classify data, verify AI responses, and define human oversight. The course ends with an implementation package: an AI policy, a data checklist, an incident card, a tool register, and a certification quiz.
Access to the full course
30 USD
- ✓One-time payment
- ✓Lifetime access
- ✓Certificate
- ✓8 hours
Who this course is for
Office workers, managers, HR, marketing, sales, finance, customer service, internal trainers, compliance, DPOs, information security, procurement, and people preparing company rules for using AI. Beginner level; simple language, without legal or technical jargon.
The course shows how to translate the AI Act, GDPR, confidentiality, and trade secret protection into everyday decisions made by employees and managers. The workshop follows the service company Norda, where marketing, HR, sales, finance, and customer service teams begin using ChatGPT, Microsoft Copilot, and other AI assistants without common rules. Participants bring order to this chaos: they identify the roles of the provider and the deployer, separate legal requirements from good practices and organizational decisions, classify data as green, yellow, or red, improve flawed prompts, check hallucinations, design human-in-the-loop processes, and respond to an incident. Each rule is discussed through examples of “allowed / not allowed / allowed under conditions.” The material reflects the regulatory status verified on 20 July 2026, including the application of Article 4 and prohibited practices from 2 February 2025, as well as official European Commission information on the AI Act timeline. References to official EU sources included in the course materials: the text of Regulation (EU) 2024/1689 in EUR-Lex, the European Commission portal dedicated to the AI Act, the Commission FAQ on AI literacy, guidelines on prohibited AI practices, GDPR rules published by the European Commission, and the EDPB opinion on AI models. The course is educational in nature and does not constitute individual legal advice.
What you will learn
- Explains in their own words what AI literacy under Article 4 of the AI Act is and why simply sending employees tool instructions may not be enough.
- Distinguishes the provider of an AI system from the deployer of AI and indicates when a company may perform more than one role.
- Separates three layers of decision-making: a legal requirement, a recommended good practice, and an internal organizational decision.
- Classifies information as green, yellow, or red before using it in an AI tool.
- Applies the principles of data minimization, pseudonymization, confidentiality, and trade secret protection.
- Recognizes prohibited uses, potentially high-risk uses, and ordinary office uses that require local safeguards.
- Verifies hallucinations, numbers, quotations, legal bases, and sources provided by AI.
- Designs human-in-the-loop with a named decision owner, control criteria, and an approval trail.
- Makes “allowed / not allowed / allowed under conditions” decisions in 15 realistic employee scenarios.
- Completes the checklist before pasting data and the AI incident report form.
- Creates a register of AI tools and uses with owner, purpose, data categories, risk, and approval status.
- Adapts a template AI use policy to the organization’s real processes, roles, and reporting channels.
- Documents AI literacy development activities without treating the certificate as the only proof of compliance.
Prerequisites
No legal or technical knowledge is required. Basic experience with ChatGPT, Microsoft Copilot, or a similar tool will be helpful. The participant should be familiar with typical documents used in their organization, such as emails, offers, CVs, reports, meeting notes, or customer requests. Exercises are carried out on anonymized training materials, without pasting in real confidential data.
Course syllabus
- Monday, 9:10: marketing pasted a client brief into a private ChatGPT
- Art. 4 of the AI Act without legal jargon: what an employee really needs to learn
- ChatGPT delivers, Norda applies: who is responsible for which piece of the puzzle
- Three Columns Instead of One Ban: Law, Good Practice, Norda’s Decision
- The first AI usage inventory: 27 tools, 41 use cases, and only three owners
- Green, yellow, red: 12 document fragments land on the table
- GDPR in prompts: less data, a specific purpose, and the right legal basis
- Removed surname is not enough: pseudonymizing a CV step by step
- Customer price list, discount code and workforce reduction plan: where the company secret begins
- Checklist Before Pasting: Seven Questions That Stop a Bad Prompt
- Camera assesses the consultant’s mood: an HR idea we are not implementing
- Candidate ranking for hiring: red light for an autonomous decision
- Scoring “difficult customers”: when segmentation turns into a harmful assessment of people
- Email translation or a decision about a person: a quick risk-level test
- Nordy implementation committee: four applications, four different decisions
- Nonexistent Art. 73: an AI answer that looks like a lawyer’s opinion
- Weak and improved prompt: a full comparison of customer complaint analysis
- Primary source or summary blog: the credibility ladder
- Whoever signs, checks: human-in-the-loop with a name and criteria
- Sales report overstated by 18%: fixing the process before the board meeting
- Scenarios 1–3: Teams note, offer translation, and client presentation
- Scenarios 4–6: candidate CVs, annual feedback, and layoff plan
- Scenarios 7–9: complaint, call transcription, and response to a difficult customer
- Scenarios 10–12: sales forecast, contract analysis, and a report for the board
- Scenarios 13–15: advertising graphics, recruitment chatbot, and employee private account
- AI policy in four pages: rules, exceptions, roles, and a questions channel
- Register after the cleanup: owner, data, risk, provider, and review date
- Client data ended up in the wrong tool: incident report card without looking for a culprit
- Proof of AI literacy: a plan for marketing, HR, managers and administrators
- Certification quiz: 80% and decisions instead of a memorization test
- Quarterly review: update date, EU sources, and three decisions for the next 30 days
FAQ
You will learn how to translate the AI Act, GDPR, confidentiality, and trade secret protection into everyday decisions. You will recognize what data can be entered into AI tools, when additional verification is needed, and how to reduce the risk of errors, information disclosure, and unauthorized use of content.
For employees, managers, and people responsible for implementing AI in marketing, HR, sales, finance, customer service, and other departments. The course does not require technical or legal knowledge.
Yes. The course shows the principles of safe use of ChatGPT, Microsoft Copilot, and other AI assistants. Participants learn to assess not only the tool name, but also its configuration, purpose of use, type of data processed, and the provider’s terms.
Participants distinguish the roles of the provider and the deployer of AI, learn the basics of classifying uses, and separate legal obligations from good practices and internal company decisions. This is especially important because AI literacy rules have been in force since 2 February 2025, and the main part of the AI Act starts applying from 2 August 2026.
Yes. The course explains how to identify personal data, confidential information, and trade secrets before sharing them with an AI tool. It also shows safer alternatives, such as anonymization, data minimization, using an approved environment, or abandoning a given use case.
Participants follow the service company Norda, where different departments begin using AI without common rules. By analyzing realistic situations, they organize use cases, assess risk, and co-create rules that allow AI to be used responsibly without blocking innovation.
After the course, the participant can assess a specific AI use idea, ask the right questions before entering data, verify the result, and recognize situations requiring consultation with a manager, legal department, IT, security, or data protection.
- 8 hours
- Beginner
- Certificate on completion
- Access immediately after purchase
Full course
30 USD