Course · Advanced
Security, data and compliance in everyday work
Classify what you entrust to Learnya, control the risks of an agent that acts and meet your obligations, without slowing down use.
8 lessons · 1 quiz · 1 h 15 min · completion badge
What you will be able to do
- Classify data by sensitivity and attach a rule to each class
- Recognise a prompt injection and the other risks specific to an agent that acts
- Approve an action knowingly and limit tools to what is strictly necessary
- Place the obligations of the revised FADP, the GDPR and the EU AI Act for an organisation that uses AI
- Respond to an incident and make security a routine rather than an emergency
- Who it is for
- Administrators, security officers, data protection officers and champions who oversee the use of Learnya.
- Prerequisites
- Have completed “Running Learnya in an organisation”, or know the console and the audit log.
- Duration
- 1 h 15 min
- Level
- Advanced
Programme
What the course covers.
-
Classify before you entrust· 2 lessons
- Classifying your data 9 min
Four sensitivity classes, and for each one what you can entrust to Learnya and where.
- What must not go in 9 min
Secrets are never entrusted, and everything else is entrusted only as far as needed.
- Classifying your data 9 min
-
The risks of an agent that acts· 2 lessons
- Instructions hidden in content 7 min
A document, a web page or an email can contain instructions aimed at the agent. Recognise them and protect yourself.
- Approving knowingly 9 min
An approval is only a protection if it is read. Avoid approving on autopilot and limit tools to what is necessary.
- Instructions hidden in content 7 min
-
The obligations· 2 lessons
- The EU AI Act, from the user’s side 10 min
What the AI Act asks of an organisation that uses AI, and why it also concerns Swiss companies.
- Carrying out an impact assessment 9 min
When processing presents a high risk to people, an impact assessment is mandatory. Carry it out without turning it into a major project.
- The EU AI Act, from the user’s side 10 min
-
When something happens· 2 lessons
- Responding to an incident 9 min
Data entrusted by mistake, an unwanted action, a suspicious account: contain, understand, report.
- Making security a routine 9 min
Short, regular reviews, trained teams and a culture where people report without fear.
- Responding to an incident 9 min
-
Final quiz· 6 questions