Secure use of generative AI tools

For all employees using AI tools, plus IT and security staff: recognize AI-specific threats, use AI tools securely and report problems fast.

For: All employees using AI tools, and IT and security staff

  • 2 contact hours
  • 8 modules
  • 8 interactives
  • 5 job aids
  • Updated October 11, 2026

What you will be able to do

  • Recognize the main security risks of generative AI tools, including data leakage, prompt injection, supply chain and poisoning risks, using OWASP and NIST terms.
  • Avoid shadow AI and protect AI accounts, sessions, extensions and API keys.
  • Review AI-generated code and scripts for security flaws and risky dependencies before use.
  • Recognize AI-generated deception such as voice clones, deepfake video and AI phishing, and verify requests through trusted channels.
  • Configure and use enterprise AI tools and AI agents with least privilege, human approval and logging.
  • Report AI security incidents promptly with the right facts through internal and external routes.

Learn the security side of generative AI: how data leaks through connectors, shared links and extensions; what prompt injection is and how to limit it; why shadow AI and lookalike apps are dangerous; how to protect AI accounts and keys; how to review AI-generated code; how criminals use voice clones and deepfakes; how to set up enterprise AI and AI agents with least privilege; and how to report incidents.

Built for everyone who uses AI tools at work, with extra depth for developers, power users and IT staff. Cases follow a county government in Lancaster, a software consultancy in Ann Arbor, a university lab in Champaign and a construction company finance office in Las Cruces.

Generative AI adds new inputs, new data paths and new tools for attackers. This course uses the OWASP Top 10 for LLM Applications, NIST guidance and joint CISA, NSA and FBI guidance to give you practical, defensive habits. It teaches prevention, recognition and reporting only, never offensive techniques.

What you’ll be able to do Monday morning

  1. Remove any unapproved AI extensions or apps from your work devices and request approved alternatives.
  2. Replace secrets with placeholders before asking AI for help with code, logs or configuration.
  3. Turn on approval prompts for any AI tool that can send, share, buy or delete on your behalf.
  4. Verify any payment or credential request through a known phone number, however familiar the voice or face.
  5. Save your IT security reporting route and use it for anything odd an AI tool does.

Curriculum

8 modules · 32 lessons · about 2 contact hours

01Why does generative AI change the security picture?Free preview14 min
  1. What is new about generative AI security?
  2. What are the main risks, in plain terms?
  3. Who is responsible for AI security?
  4. What does good AI security look like in a normal workday?
  • Matching activity: Match the AI risk to an example

Diagram · In practice checklist · 2-question knowledge check

02How does data leak through AI tools?14 min
  1. What are the main technical leak paths?
  2. Why are secrets in prompts so dangerous?
  3. How should organizations reduce leakage?
  4. What should you do when an AI tool shows you data you should not see?
  • Sort activity: Safer or riskier AI habit?

Diagram · In practice checklist · 2-question knowledge check

03What is prompt injection, and how do you spot it?15 min
  1. What is prompt injection?
  2. What does injected content look like?
  3. How do you defend against prompt injection?
  4. What happened in the lab, and what changed?
  • Spot the issue: Spot the prompt injection in this email

Diagram · In practice checklist · 2-question knowledge check

04How do shadow AI, extensions and weak accounts create risk?14 min
  1. What is shadow AI, and why does it happen?
  2. Why are extensions, plugins and fake AI apps so risky?
  3. How do you protect AI accounts and keys?
  4. What should Taavi have done, and what now?
  • Ethics dilemma: A coworker's favorite AI extension

Diagram · In practice checklist · 3-question knowledge check

05How do you use AI-generated code safely?15 min
  1. What security problems show up in AI-generated code?
  2. How should AI-generated code be reviewed?
  3. What about AI tools that write code for non-developers?
  4. How do you prompt for more secure code?
  • Spot the issue: Spot the security problems in AI-generated code

Diagram · In practice checklist · 2-question knowledge check

06How do criminals use AI against you, and how do you verify?15 min
  1. How are criminals using generative AI?
  2. Why do old detection tips no longer work alone?
  3. How do you verify a request safely?
  4. How can organizations reduce deepfake and AI phishing risk?
  • Branching scenario: The Friday afternoon video call

Diagram · In practice checklist · 2-question knowledge check

07How should enterprise AI tools and AI agents be set up?15 min
  1. What should be configured in any enterprise AI tool?
  2. What makes AI agents riskier than chat assistants?
  3. How do you set up an agent with least privilege?
  4. What should everyday users do with agents and connected tools?
  • Decision tree: Should the AI agent do this on its own?

Diagram · In practice checklist · 2-question knowledge check

08How do you report AI security incidents?14 min
  1. What counts as an AI security incident?
  2. How and when should you report?
  3. Which outside agencies receive reports?
  4. What happened with Monday's reports?
  • Self-assessment: How secure are my AI habits?

Diagram · In practice checklist · 2-question knowledge check

Final assessment: 23 questions, 70% to pass, then your certificate

Try it now, no account needed

The Friday afternoon video call

A branching scenario from this course. Your choices are not saved.

Free sample activity

The Friday afternoon video call

You work in accounts payable. At 4:45 p.m. on Friday, a video call from someone who looks and sounds like your CFO asks you to wire $186,000 for a confidential land deal before the bank closes.

Inside the course

Practice activities

  • Matching activity1
  • Sort activity1
  • Spot the issue2
  • Ethics dilemma1
  • Branching scenario1
  • Decision tree1
  • Self-assessment1

Job aids you keep

  • AI Account Security ChecklistChecklist
  • AI-Era Phishing and Deepfake Verification ChecklistChecklist
  • AI Security Incident Report TemplateTemplate
  • AI-Generated Code Review ChecklistChecklist
  • Secure Prompt SheetReference sheet

Credit and approval status

Certificate of completion

This course awards a certificate of completion for 2 contact hours of instruction. It is not approved or accredited by any licensing board, state agency, certification body or continuing education accreditor. Employers decide what counts toward their security awareness training programs, so check with your employer or certifying body whether this course meets your specific requirement.

Pathways we may pursue include review by a training accreditor. None of these approvals exists today; the course page will show an approval only after it is granted.

Our full approvals list

Questions about this course

Who is this course for?

Every employee who uses AI tools at work, plus IT and security staff who approve and configure them. It covers threats specific to generative AI: data leaks, prompt injection, shadow AI and extensions, AI-generated code, deepfakes and AI phishing, AI agents, and incident reporting.

Does it teach hacking or attack techniques?

No. The course is about prevention, recognition and reporting. Examples of attacks are high level and defanged. Security testing should only ever be done by authorized staff with written approval.

Does this course earn continuing education credit?

You receive a certificate of completion for 2 contact hours of instruction. The course is not approved or accredited by any board or accreditor today. Check with your employer or certifying body whether it accepts this certificate for your security awareness requirement.

How is it different from general cybersecurity awareness training?

General courses cover passwords, phishing and safe browsing. This course builds on them with AI-specific risks and uses the OWASP Top 10 for LLM Applications, NIST AI guidance and joint CISA, NSA and FBI guidance as reference points.

How long does it take, and how is it assessed?

About 2 hours: eight modules with a deepfake call simulation, an AI agent decision tool, spot-the-issue exercises and knowledge checks, then a 23-question final assessment with a 70 percent pass mark. Spaced reminder questions follow at 3, 10 and 30 days.

What can I download?

An AI account security checklist, an AI-era phishing and deepfake verification checklist, an AI security incident report template, an AI-generated code review checklist and a secure prompt sheet.

This course is general education and training awareness from CE Courses Hub on secure use of generative AI tools. It is not legal, medical or professional advice and does not replace your employer's policies, your licensing board's rules, or advice from a qualified professional. Completing it earns a certificate of completion for the stated contact hours; it is not approved or accredited by any licensing board, state agency or accreditor unless an approval is shown on the course page. Check with your board, employer or state agency whether this course meets your specific requirement.