Your team is already using AI, usually without training — or you've banned it and they're falling behind. This workshop gets your people genuinely productive with it, fast. And for teams that handle sensitive or regulated data, it does that without creating the exposure that ends up in an audit.
Plan your workshop Prefer email? Send me the details →I map where your AI use is exposed and hand you a written plan. I do the analysis.
I build and deploy defensible AI inside your environment. The software does the work.
I transfer judgment and safe habits into your people. They do the work — better, and without creating new exposure.
The Audit tells you where you're exposed. The Build removes the exposure. The Workshop makes sure your team doesn't create new exposure every day.
Both run as a half-day or full-day, virtual or on-site. The difference is who's in the room and what they walk away with.
For teams adopting AI who want to actually use it well — the right tool for each job (ChatGPT to create, Claude to analyze, Perplexity to research, Copilot in the workflow), the prompts and workflows that make people faster this week, with the safety basics built in.
For regulated teams — law, healthcare, finance, real estate — where data can't leave the building and output has to survive an audit. Everything in Track 1, plus the obligations that bind you and a documented, defensible standard.
If you're under Rule 1.6, HIPAA, FERPA, GLBA, or SEC scrutiny, this is the part that matters — and the reason Track 2 exists. "Exposing data" isn't one thing called "leaking"; it's losing control of where sensitive data goes once it enters the tool. Three concrete mechanisms, none with a clean human analog — taught from the engineering side.
Paste into a consumer tool and, by default, your input can be absorbed into a future model — and resurface in a stranger's output. The data doesn't go to someone; it becomes part of a system that repeats a version of it to everyone.
Your input sits on the vendor's servers under their policy — staff-accessible, breachable, and discoverable or subpoenable. Even if it's never trained on, a copy now exists outside your control.
The vendor routes it to sub-processors and jurisdictions you never vetted. One paste, N systems — and you can't say where it ended up.
Why it's categorically different from telling a person.
Human disclosure is bounded and clawback-able — one recipient, themselves bound by duty, information that doesn't self-replicate, and you know who has it. AI disclosure is unbounded and persistent — you can't scope who sees a derivative, can't retract it, can't guarantee it won't reappear in someone else's answer, and can't tell a regulator where it went. That contrast is the point: your data is supposed to stay inside your walls and under your control.
What you buy is the format. Virtual or on-site is how it's run — every format is available either way.
Need the governance artifact — an acceptable-use policy, data-flow map, and vendor review — not just training? That's the AI Readiness Audit, scoped to a project budget.
Built as stackable modules: the half-day runs the first five, the full-day adds the labs. Same spine, escalating depth.
The mental model most people have never had: input → vendor → maybe training → maybe retained → maybe subpoenable.
Training leakage, retention and breach, and confident-wrong output on high-stakes calls — how to spot each in the wild.
Consumer vs. Enterprise/Edu vs. API-with-a-DPA. What a DPA or BAA actually guarantees, and how to read the badge.
The minimum-necessary discipline. Live exercise: sanitize a real (fake) record, then prompt it safely.
What you should do — the workflows that make people faster on de-identified work. Leave capable, not paralyzed.
Human-in-the-loop verification, cross-checking, and citation discipline — the fake-case-law disasters exist for a reason.
What documentation the org should hold — DPA, acceptable-use policy, data-flow map — and how an individual protects themselves.
Convert the day into a policy the organization keeps using after I leave.
Do you handle sensitive or regulated data? If not — general operations, client service, marketing, ops — Track 1 (Enablement) gets your team productive with AI fast, with the safety basics built in.
If yes — client files, patient records, student data, deal terms, financial records, proprietary IP, anything a regulator, client, or opposing party could later ask about — Track 2 (Compliance-ready) maps the training to the rules that actually bind you.
Not sure? The free AI-Readiness check sorts it in five minutes — and points regulated teams to the Audit if you need the governance artifact, not just training. Rules covered where they apply: Rule 1.6, HIPAA, FERPA, GLBA, state privacy law.
Tell me your field and roughly who's in the room. You'll get a straight recommendation on format and a fixed number — no drawn-out sales process.
Plan your workshop Prefer email? Send me the details →