ai · security · skills

For the security newcomer

About to paste something into an AI? Read this first.

Track 2 · Your skills path is one click away. The story below is depth; the path names what to learn.

Build the defender’s skills

You use AI every day — it makes you faster.

But nobody’s shown you where the line is, and the policy reads like it was written for lawyers.

22%

of AI decision-makers say unpredictable outputs are what worries them most — the same worry you feel when you paste something into a chatbot and hope.

Forrester · State of AI Survey, 2025 · base 1,528 AI decision-makers

You’re not the problem. The missing line is — and drawing it is someone else’s job that hasn’t been done yet.

So here it is, in plain English: the everyday risks, your part in each, and a way to just ask when you’re not sure.

Am I allowed to do this — and how would I even know?

Here’s the line, in plain English. And when you’re not sure — just ask, in your own language. It answers with the actual rule.

Three things, no jargon. Promise.

Your line

The everyday risks, with your part in each.

Not a policy document — a plain-English list of the things that actually go wrong when people use AI at work, and the one habit that avoids each of them.

Every risk names your part in it. No acronyms, no scolding.

The everyday risks, in plain English →

Just ask

Your question, the actual rule, side by side.

When you’re not sure, you shouldn’t have to read a framework — you should get to ask, in your own words, in your own language.

The answer arrives citing the actual rule it came from. If the rules don’t cover it, it says so instead of guessing.

Ask it something, in your language →

One clause, eight languagesEnglish
AI Controls Matrix (AICM) DSP-15 · v1.1.0AÑÃÉ

Asked in English

Can I use real customer data to test our new AI feature?

Same answer, same clause: AI Controls Matrix (AICM) DSP-15Limitation of Production Data Use, cited every time.

Ask in your language — watch the answer arrive with its clause attached.

The org play

What your company should be building around you.

Behind the plain-English line sits an organizational answer: Responsible AI as a practice, a Center of Excellence that owns the rules, and an AI-first way of working that doesn’t leave you guessing.

That’s the part to forward to whoever owns policy.

The org play — Responsible AI, the CoE, AI-first →

Your reskilling list

5 controls have your name on them.

Your list is short on purpose: know where the line is, and work clean. Every skill on it is in plain words.

1 to build · 4 to coordinate with a provider. Nobody reskills for what the provider already owns.

Know the line

3 controls

Work clean

2 controls

This is the same spine the assessment reads. Score your mastery on four concrete rungs per prompt, or run the function diagnostic — every gap lands on this list: the named skill, the group it belongs to, and who learns it.

Browse skills personalities →Run the diagnostic. Your gaps land on this list →

28 everyday risks, each with your part in it.

Answers in 8 languages — always citing the actual rule it came from.

See where the line isAsk it a question
Every number above has a method page behind it: each piece opened up as inputs → mechanism → outputs, with provenance — and the deeper tables named, content owner-gated.The method, piece by piece →

Not your role?

Each role has its own way in. Here is where the others start.