Everyone Does Cyber Awareness Training. Almost Nobody Does AI Awareness Training.

Every organisation I work with runs cyber awareness training. Nobody argues about it any more. New starters get a module in their first week, everyone gets a refresher once a year, there is a phishing simulation, a completion report, and a slightly awkward conversation for whoever clicked the link. It is not glamorous, and it works well enough that we have stopped questioning whether it should exist.

Now ask the same organisation what training its people have had on AI. The usual answer is a policy that went round on email once, and a general sense that everyone should probably be careful.

That gap is worth sitting with, because the logic behind cyber awareness applies almost perfectly to AI. We train people on phishing because the strongest control against a malicious email is not the mail gateway, it is the person reading it. No tool will stop someone pasting a client’s file into a chatbot on their personal phone, or quietly relying on a summary that turned out to be invented. The control that matters most is the person.

The most expensive AI mistake is usually the one nobody makes

Shadow AI gets all the attention: staff using unapproved tools, quietly, on real work. It is a genuine problem. But the quieter and more costly pattern in most organisations is the opposite. Capable people not using the approved tools sitting on their own desktops, because nobody ever told them they were allowed.

“I didn’t know I was allowed to use AI for that.”

That sentence comes up in almost every awareness session I have seen run properly. Someone spends forty minutes reformatting a report that the licensed assistant on their own machine would have restructured in thirty seconds, entirely within policy, because the only message they ever received about AI was a vaguely worded warning. Caution without specifics does not produce careful use. It produces paralysis in the people who follow instructions, and improvisation in the people who do not.

Awareness training fixes that by being explicit. Here are the tools we have licensed. Here is the work you can hand to them today without asking anyone. Here is what needs a second look first. Framed as permission rather than warning, it is the cheapest adoption lever most organisations have, and it reaches everyone, not just the enthusiasts who were going to find their own way in regardless.

The guidance already assumes you have done this

None of this has been regulated into existence, at least not here. Australia has no AI Act, and the December 2025 National AI Plan confirmed a reliance on existing law and sector regulators rather than a new one. What we do have is the National AI Centre’s Guidance for AI Adoption, published in October 2025, which replaced the ten voluntary guardrails with six essential practices, now shortened to AI6. It is voluntary and it is short. Two of its practices lean directly on staff understanding. “Decide who is accountable” only works if people know where accountability sits and when to escalate. “Maintain human control” is not a control at all unless the human knows what they are checking for.

The voluntary guidance sits on top of law that is not voluntary. The OAIC’s guidance on commercially available AI products puts it plainly: entering personal information into a public AI tool is a use of that information, and has to be justified under the Australian Privacy Principles like any other. That is not an architecture problem. It is one person, at a keyboard, in about four seconds.

That obligation sharpens before the year is out. From 10 December 2026, a new APP 1.7, introduced by the Privacy and Other Legislation Amendment Act 2024, requires any organisation using personal information in a computer program to make, or directly support, a decision that could reasonably be expected to significantly affect someone’s rights or interests to say so in its privacy policy, including the kinds of information used and the kinds of decisions involved. It is a transparency duty rather than a prohibition, and that is precisely what makes it a staffing problem rather than a legal one. You cannot describe your automated decision making in a public document if you do not know where in the business people have quietly started letting AI help make the decisions.

If you go further and work towards ISO/IEC 42001, awareness stops being a good idea and becomes a requirement. Clause 7.2 requires competence where work affects the AI management system, and Clause 7.3 requires that people working under your control are aware of the AI policy, how their work contributes, and what happens if they do not follow it. An auditor will ask how you satisfied that. Completion records against a defined module answer it. A distribution list does not.

And if any part of your business touches Europe, Article 4 of the EU AI Act requires providers and deployers to ensure a sufficient level of AI literacy among staff. It has applied since February 2025, and market surveillance authorities began supervising it on 2 August 2026. No fine attaches to Article 4 directly, but thin literacy is exactly the sort of detail that aggravates whatever else goes wrong.

All of it points the same way, and none of it tells you what the training should actually contain.

Responsible use is a habit, not a rule

The second thing awareness training does is convert policy language into a judgement people can make on the spot. Nobody stops mid-task to consult a framework. What they can do is sort a task into three buckets: green, get on with it; amber, fine but check something first; red, do not, and here is who to ask instead. That single mental model does more day to day work than any amount of written policy.

Alongside it sits the human oversight habit. Not “a human reviewed it” in the abstract, but a specific check: does this claim have a source I can point at, are the numbers right, would I be comfortable if the customer knew how it was drafted. People need to understand why a fluent, confident, well-structured answer can still be completely wrong. Once they know the mechanism, the check stops feeling like bureaucracy and starts feeling obvious.

The same session is where the real risks land in a form people remember: data leakage, hallucination, bias, copyright and ownership, over-reliance and shadow AI. Six things, in plain language, with examples from work they actually do.

And yes, it deters the things you would rather avoid

Deterrence is the part people expect awareness training to be about, and it does work, though not the way it is usually pitched. Fear is a poor teacher. Visibility is a good one. Once a line has been drawn, explained and acknowledged with a completion record, “I didn’t know” stops being available. That changes behaviour, and it changes what happens afterwards, because you can show the effort you made rather than assert it.

The other half of deterrence is making escalation easy. Most AI incidents are small and recoverable if someone speaks up early, and much less so if the person involved is unsure whether they have done something wrong and decides to wait and see. Telling people how to raise a concern, and that raising one is expected rather than a confession, is worth more than another paragraph of prohibition.

Emailing the policy is not awareness

It is worth being blunt, because this is the most common substitute. A policy tells people what the rules are. Training tells them what the rules mean for the task in front of them, and produces evidence that the message landed. If you cannot say what proportion of your workforce has demonstrated they understand your AI policy, you do not have awareness. You have a document.

What good looks like

  • Short. Twenty minutes and an assessment, not a half-day workshop nobody schedules, or worse it gets scheduled and paid for, but nobody shows up.
  • Plain about the technology. Enough to explain why a confident answer can be wrong, without turning into a data science lecture.
  • Specific to you. Your approved tools, your policy, your escalation path. Generic training produces generic caution.
  • Balanced. As much time on what people can do as on what they must not.
  • Assessed and recorded. A pass mark and completion data that lives in your own systems.
  • Repeatable. In induction for new starters, annual refresher and again when the tools or the policy change.

Where to start

If you are building this yourself, start with your approved tool list and your green, amber and red examples, because those are the parts only you can write. The rest, how the technology works, where it fails and what a proper human check involves, is common to every organisation.

Which is why Governance Works built one. AI at Work: Smart, Safe, Supported is a short SCORM module for front line and back office teams, industry-neutral, and customisable with your branding, your AI policy, your approved tools and your escalation path. It runs in your own LMS, so completions and pass rates stay in your system where they are useful as evidence, including for ISO 42001 Clause 7.3. And if you do not have an LMS, do not worry: we can host the course for you and send you weekly completion reports. If that sounds useful, get in touch and I will send you a preview.


.

DEWR’s default answer is No

Since September 2025, eleven providers have applied to use AI in DEWR service delivery. As at Senate estimates in June 2026, none had been approved. The framework’s default position is no, and that costs you whether your application is weak or excellent. Here’s what boards need to ask this quarter.

Read More »

You Don’t Just Need AI. You Need a REASON to Use AI.

If your organisation has decided it needs to “do something with AI” but can’t yet say what, you’re in very good company. The problem usually isn’t governance — it’s that nobody has identified a use case. Here’s how to find yours, build a real AI strategy, and govern it from day one.

Read More »