Before we start01

Before the course, a diagnostic

Five questions from your phone, three minutes. It does not count towards anything, your name is not stored and nobody sees it. It exists so that at the end of the session you can measure how much you have changed, which is the only thing that proves training has worked.

Prior diagnostic · 3 minutes
Session code

Anonymous: no name, no email. Only the classroom’s starting level.

At the end, the accreditation test will give the second figure. The difference between the two is your learning, and it is what Article 4 calls a “sufficient measure”.

‹‹‹
Today’s agreement01

Sixty minutes and a certificate

You will not leave here knowing how to code. You will leave knowing how to ask, protect, verify and comply, which is exactly what will be demanded of you.

12 min
Understanding

What the machine does inside.

13 min
Asking

The 5C method and the template.

9 min
Protecting

Traffic light and anonymisation.

8 min
Verifying

Three filters and five alerts.

14 min
Complying

What the Regulation requires.

6 min
Living with it

Test and verifiable certificate.

One rule for the session: everything gets asked. The doubt not voiced today becomes tomorrow’s expensive mistake.

This session is delivered for a minimum of ten participants: the two classroom exercises live on disagreement between people, and with fewer this would stop being a classroom.

‹‹‹
Module 1 · Foundations03

It does not reason: it predicts

Word by word, it computes the most likely continuation. Watch: it is about to complete the best-known line in English literature without ever having read Hamlet.

Demonstration · the machine writing

And here is the problem: it uses exactly the same mechanism when you ask it for a ruling, a figure or a date it does not know. It picks the most probable one and tells you with the same poise it used for “remember”.

‹‹‹
Module 1 · Foundations04
Worked case included

Four principles worth internalising

PrincipleWhat it meansWhat you do
A · It does not reason: it predictsIt converges on what sounds plausible, not on what is correct. It is a satnav suggesting likely routes, not a judge determining truth.Ask it for certainty and it returns fluency. Truth demands a source, a contrast and a context.
B · It speaks as if it knewPeople notice when they do not know and slow down. AI always answers in a confident tone, even when improvising.Require it to flag the uncertain: [VERIFY], [ESTIMATE]. If it does not state its assumptions, it is not reliable.
C · Correlation is not causationIt learns what appears together, not what causes what. Confusing the two in a complex decision is expensive.Always ask: what is evidence and what is hypothesis? Remember: ice-cream sales and drownings rise together in summer, and nobody drowns from ice cream — they share a cause: the heat.
D · The risk is delegating judgementAn orderly, confident text gives a sense of control. But the real control sits somewhere else.In deciding what you accept, what you reject and what you verify. It amplifies your judgement; it does not replace it.
All four, in one real answer

You ask for the deadline to justify a grant and it replies: “The deadline is three months from the end of the activity, under Article 30 of Spanish Law 38/2003.” A: it did not look it up, it predicted it. B: it never once said “I am not sure”. C: it mixes what usually goes together — that law with that deadline — not what your own call for proposals says. D: if you copy it into the report because it sounds right, you have delegated your judgement. One minute in the official gazette settles all four.

Why it never answers the same way twice

It is not a deterministic program: it picks each word by sampling among the most likely ones. That margin is called temperature: the higher it is, the more variation and creativity; the lower, the more repeatable and literal. That is why the same question can give you one answer today and another tomorrow, and why an answer that came out well is no guarantee the next one will.

‹‹‹
Module 1 · Foundations04

Where it is good and where it fails

Reliable, with review
  • Rewriting, summarising and shifting tone
  • Structuring your own ideas and formatting them
  • Translating and adapting the register
  • Generating variants and first drafts
  • Explaining something you can already check
Do not delegate without verifying
  • Figures, dates, percentages and statistics
  • Legal citations, articles and case law
  • Bibliographic references and links
  • Calculations with financial consequences
  • Anything you are going to sign
Example from the green column

“Take this six-paragraph email of mine and cut it to three, same content, more direct tone.” It works first time: the material is yours and only the form changes.

Example from the amber column

“How much did the minimum wage rise in 2025 and in which instrument was it published?” It will give you a figure and a decree number with total poise. It may be right or it may not exist: you have to go to the gazette.

Pocket rule: if the mistake costs you money, reputation or a file, verify before use.

‹‹‹
Module 1 · Risk number one05

The hallucination

An invented fact that the AI presents as true. It is not a connection failure: it is the system filling a gap with whatever seems to fit. It happens precisely because it predicts.

Real case · court document filed“Under Supreme Court ruling 4412/2023, of 14 September, the cure period is fifteen working days.” · The ruling does not exist. · The number has the correct format. · The date is plausible. · The tone is that of a lawyer.
Letras AI dibujadas sobre la arena
What sounds firm may have no ground under it

AI is never a citable source. It is an intermediary: it brings you closer to the source, it does not replace it.

‹‹‹
Exercise 1 · three minutes06
Classroom exercise

Which of these four are invented?

An assistant drafted this paragraph for an internal report. Two statements are true and two are invented. Without searching online: only with what we have seen so far.

A · The European AI Regulation was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. B · Its Article 4 requires organisations to ensure AI literacy among staff from 2 February 2025. C · According to European Commission report COM(2025)318, 73.4 % of European SMEs have already appointed an AI officer. D · Supreme Court Ruling 4412/2023, of 14 September, set the cure period at fifteen working days.
True · A and B

Official dates of Regulation (EU) 2024/1689. They can be checked in the Official Journal in under a minute: they have somewhere to be looked up.

Invented · C and D

The an exact figure with a decimal and a report code that does not exist, and a case citation in perfect format. The two most frequent alert signals, together in the same paragraph.

What matters is not getting it right: it is realising that all four sound exactly as credible as each other. That is precisely why a verification method is needed.

‹‹‹
Module 2 · Method08

The 5C

C1
Context

Who you are, where you are and who this is for.

“I am the administration manager of a 13-person SME”

C2
Criterion

How you will know the answer works. The bar, stated upfront.

“It works if it is firm but not aggressive”

C3
Content

What must be included and what stays out.

“Amount, due date and option to pay in instalments”

C4
Constraints

The form: length, tone, structure, language and format.

“150 words maximum, with a subject line”

C5
Checking

What it must verify and what it must flag as doubtful.

“Flag as [ESTIMATE] anything you cannot confirm”

If you do not set the Constraints, the AI chooses them for you. And it rarely gets them right first time.

‹‹‹
Module 2 · Template09
Worked case included

Copy it today and fill it in

The template · blankAct as [role] and prepare [output] for [who will read it]. Context: [two sentences about your situation] Criterion: it works if [how you will judge it] Content: include [...] and leave out [...] Constraints: [language], [length], [tone], [output format] Checking: flag as [ESTIMATE] anything you cannot confirm and, if a detail is missing, ask me; do not invent it.
The same template · filled in with a real caseAct as administration manager and prepare a payment reminder email for a customer who has been with us since 2019. Context: 13-person SME; invoice of €4,200 overdue by 21 days. Criterion: it works if it collects without breaking the relationship. Content: include amount, due date and instalment option; leave out legal threats. Constraints: English, max. 150 words, cordial and firm tone, with subject. Checking: if a detail is missing, ask me; do not invent it.
Why it works

Role, recipient and bar are defined before it writes a single word. The difference between a colleague who knows what you want and one who guesses.

The line you never drop

The last one. Without an explicit way out for when it does not know, the model fills the gap. With it, it asks you.

Keep it

One template per task, with its tag: [SUMMARY], [EMAIL], [ANALYSIS]. Fifteen of them cover 80 % of what you do.

Download the pocket card

You are going to see this exact case working two slides from now.

‹‹‹
Module 2 · Before and after12
Worked case

The same task, with method and without it

Aim of this slide: to see, with the same tool and the same task, how much the result changes according to what you write. On the left, no method; on the right, the 5C.

The assignment: chase a €4,200 invoice three weeks overdue with a long-standing customer.

ComparisonNo method · 11 wordsWith the 5C · 62 words
What you write “Write me an email for a customer who is not paying.”
11 words · 5 seconds
“I am in administration at a 13-person SME. Customer since 2019, invoice of €4,200 overdue by 21 days. I want to collect without breaking the relationship. Include amount, date, option to pay in two instalments and a deadline. English, 150 words, with subject. If a detail is missing, ask me.”
62 words · 90 seconds
What you get “Dear customer: we write regarding the outstanding non-payment. We kindly ask you to regularise your situation at your earliest convenience…” “Subject: invoice 2026/184 · proposed schedule. Hi Marta: I am writing about the €4,200 from 6 June, due on 6 July. Since we have worked together for seven years, I would rather propose a way out than keep chasing…”
What happened No amount, no date, no way out. Tone of a solicitor’s letter. Three rounds of corrections and a bruised relationship. Correct data, a concrete way out and a human tone. Sent after a single read.

Eighty-five extra seconds of writing. The difference is not in the tool: it is in what you gave it.

‹‹‹
Module 2 · Examples13
Worked cases

Five real assignments, one per function

They all share the same shape: a concrete situation, what is asked and what comes back. Copy them and change the details.

FunctionThe situationWhat you ask forWhat it saves you
ManagementYou have four pages of quarterly notes and a board meeting on Thursday. “From these notes, give me six points for the board. Each with the concrete decision to be taken, 20 words maximum per point.” From four pages to a six-line script. One hour.
AdministrationYou have to chase a payment and you do not know what tone to open with. “Rewrite this reminder in three tones: cordial, firm and final notice. Same content, 120 words each.” Three versions ready to pick from depending on how the customer replies.
SalesFirst visit tomorrow to a customer you do not know. “From this public company profile, give me five questions for the first visit and the three most likely objections with an answer to each.” You arrive with a script instead of improvising. Twenty minutes.
PeopleA job ad has to go out and the internal description is a brick. “Turn this job description into a 200-word advert, inclusive language, without unnecessary requirements that push candidates away.” A publishable advert and more useful applications.
OperationsA fifty-minute recorded meeting and nobody writes it up. “Turn this transcript into a seven-step procedure, with an owner and a deadline per step. If a detail is missing, flag it; do not invent it.” The procedure exists. Before, it never got written.

None of the five carries personal data inside. That is exactly the next module.

‹‹‹
Module 2 · Mistakes12

The seven mistakes made by everyone

The mistakeThe fix
Assuming it knows your contextEvery conversation starts from zero: tell it who you are, who you are writing for and within what limits.
Using vague adjectives: “professional”, “creative”Define with an example what that means to you, or give it one of your own texts as a reference.
Settling for the first answerThe value is in the second and third instruction. Ask for adjustments and alternative versions.
Not asking it to flag the uncertainDemand tags: [VERIFY], [ESTIMATE], [ASSUMPTION]. What is not flagged slips through.
Asking for everything at onceBreak it into steps and validate the first before moving on. A long assignment multiplies errors.
Not specifying the formatTable, bullets, maximum word count. If you do not say it, it chooses.
Not controlling the assumptionsAlways close with “if you are missing information, ask; do not invent”.
The seven mistakes in a single request · and its corrected version

Bad: “Make me something professional for the meeting.” Seven mistakes in seven words: it does not say who you are, “professional” means nothing, there is no format, no length, it asks for everything at once, it does not require flagging the uncertain and it accepts whatever comes out first.
Good: “I am the purchasing manager. Prepare the script for a thirty-minute meeting with a supplier who has raised prices by 8 %. Five points, with the objective of each in one line. Direct tone. If you are missing any detail, ask me before writing.”

None of the seven is technical. All of them are craft.

‹‹‹
Module 3 · Protecting · 9 minutes14

Data traffic light: three colours, no doubt

Green
Free to use

What is already public: legislation published in an official gazette, press releases, open websites, published reports, your own texts.

Amber
Anonymise first

Internal documentation without personal data: budget drafts, procedures, minutes. Strip names, sensitive amounts and identifiable references.

Red
Never in a public AI

ID numbers, payslips, contracts, health data, credentials, personal emails, customer databases. No exceptions, and it makes no difference whether the tool is paid for.

A case from this very week

You want the AI to prepare the script for a difficult meeting with a supplier. Red: pasting the signed contract with its tax number and the commercial terms. Amber: pasting the contract with the supplier as [SUPPLIER_A] and the amounts as [HIGH_AMOUNT]. Green: pasting the published sector rule you want to cite in the meeting. All three serve the same purpose, but only two may leave the building.

Three-second test before pasting anything: would this identify someone if it appeared in a newspaper tomorrow? If the answer is yes, it is red.

‹‹‹
Module 3 · How it is done15
Worked case

Anonymising in thirty seconds

Amber is not forbidden: it is pending a clean-up. Substitute, do not delete: if you delete, the text loses meaning and the answer gets worse.

What appearsWhat it is swapped for
People’s names[PERSON_A], [PERSON_B]
Companies and customers[COMPANY_1], [CUSTOMER_X]
Cities and sites[CITY], [NORTH_OFFICE]
Exact dates[2_MONTHS_AGO], [Q3]
Sensitive figures[HIGH_AMOUNT], [>500K]
Internal projects[PROJECT_A]
Before“At the meeting of 14 March, Marta Silva proposed a 12 % cut on the contract with Talleres Ourense, which bills €480,000.”
After · same meaning, zero exposure“At the [Q1] meeting, [PERSON_A] proposed a 12 % cut on the contract with [CUSTOMER_X], which bills [HIGH_AMOUNT].”

The key test, the one that fails audits: if anywhere you keep the table that lets you undo the change, that is not anonymising: it is pseudonymising, and the data is still personal and protected by the GDPR. There is anonymisation only when nobody, not even you, can work out who is who again.

‹‹‹
Exercise 2 · three minutes16
Classroom exercise · interactive

Classify these six cases

Tap each card to choose its colour: every tap cycles green → amber → red. Once the room has argued it out, check the answer: the system marks card by card.

Case 1

The minutes of the last board meeting, with the names of those attending.

Tap to choose a colour
Case 2

The grant call published yesterday in the official gazette.

Tap to choose a colour
Case 3

The CV a candidate has just sent in.

Tap to choose a colour
Case 4

The price list that is already on your website.

Tap to choose a colour
Case 5

The draft budget for next year, with no names.

Tap to choose a colour
Case 6

A colleague’s medical leave certificate.

Tap to choose a colour
Green · 2 and 4

Already public: the official gazette and your own website. They go in whole.

Amber · 5

Internal but with no people in it. Change the company name and any revealing amounts and it can go in.

Red · 1, 3 and 6

The minutes are red because of the names, not because of the content: anonymised they would become amber. The CV and the medical certificate are not up for discussion.

‹‹‹
Module 4 · Verifying · 8 minutes17

Three filters, thirty seconds

1 · Source

Where does the fact come from? If there is no checkable origin, the fact does not exist yet.

2 · Coherence

Does it make sense internally? Do the percentages add up? Do the dates fit together?

3 · Contrast

Would someone who knows the subject accept it? The human expert is still the referee.

The triad applied to a real sentence

The AI tells you: “Digital Kit grants for companies with 3 to 9 employees go up to €6,000, open until December”. Source: where is that call published? If it gives no official link, it does not exist yet. Coherence: do the employee band and the amount fit what you know about the programme? Contrast: would your adviser accept it? Thirty seconds, three questions, and you do not file an application after the deadline.

Thirty seconds is all it costs. The more critical the decision, the more rigorous the verification: that is the whole rule.

‹‹‹
Module 4 · Alerts20

Five signals to distrust instantly

Signal 1
Exact figure with no source

“73.4 % confirm it”

You ask for the origin. If it does not give one, it is not used.

Signal 2
Categorical statement

“Always”, “all SMEs”

You ask for the exceptions. Reality has nuance.

Signal 3
Quotation with no attribution

“As Einstein said…”

You find the line in its source before putting it on a screen.

Signal 4
Specific recent date

“On 14 March last…”

Recent events are what it knows worst. To the gazette.

Signal 5
Internal contradiction

It says A and two lines later, not A

You point it out and ask for clarification: there is usually an invented fact behind it.

All five, together, in a real paragraph

“According to report COM(2025)318, 73.4 % of SMEs already have an AI officer. All companies will have to appoint one before 14 March. As Drucker said, what gets measured gets managed.”Three signals in forty words: a figure with no checkable source, a categorical claim with a specific date and an unattributed quotation. None of the three is used until it is checked.

And the one that sums up the rest: AI is never a citable source. Cite the origin, not the intermediary.

‹‹‹
Module 5 · Complying · 14 minutes19

The Regulation clock and the four levels

1 · AUG · 2024

Regulation (EU) 2024/1689 enters into force.

2 · FEB · 2025

Prohibited practices and the AI literacy duty (art. 4).

2 · AUG · 2025

General-purpose models, governance structure and penalties.

2 · AUG · 2026

General application: art. 50 transparency and an operational penalty regime.

DEC · 2027

Annex III high risk, deferred by the Omnibus package. After that, the kind embedded in regulated products.

Unacceptable

Prohibited: social scoring by authorities, subliminal manipulation, sensitive biometric categorisation.

High risk

Recruitment, credit, education, critical infrastructure. Risk management, registration and human oversight.

Limited

Chatbots and generated content. Duty to inform the user. This is where 90 % of SMEs sit.

Minimal

Filters, spellcheckers, recommenders. No specific obligations.

Where your company falls · example

A twenty-person advisory firm uses AI to draft reports, has a chatbot on its website and an automatic spellchecker in its email. The spellchecker is minimal risk: nothing to do. The reports and the chatbot are limited risk: disclose that there is AI behind them. High risk, only if they used it to decide who gets hired. In other words: the date that affects them is 2 August 2026, and what they have to do fits in two sentences.

‹‹‹
Module 5 · Where we stand20

Two milestones define the moment

Spain · 26 May 2026
AI Bill

The Council of Ministers approves the Organic Bill on the good use and governance of artificial intelligence. It is going through parliament: it is not final law yet, but it shows where the Spanish regime is heading.

Penalties envisaged of up to €35M or 7 % of turnover

In practice: if your website publishes AI-generated text without identifying it, the regime now in the pipeline already puts a price on it.

Europe · 2 August 2026
Full application of the Regulation

General application of Regulation (EU) 2024/1689, with the transparency obligations of Article 50. Annex III high risk is deferred to December 2027 by the Omnibus package.

This date is already here: it is not a forecast, it is a legal calendar in motion

In practice: from that day, the chatbot on your website must say it is an AI, and your synthetic content must be identified. This is the date that switches on art. 50.

Who supervises in Spain

AESIA, the Spanish Agency for the Supervision of Artificial Intelligence: it is the central body that monitors compliance and runs the regulatory sandbox , the testing environment where a company can trial a system under supervision before deploying it. Based in A Coruña.

Put another way: the European rule already applies, the Spanish law is on its way and the supervisor has a name, an address and powers.

‹‹‹
Module 5 · In practice20

Train, disclose and govern

Everything the Regulation asks of a normal organisation fits into these three obligations.

Train · art. 4 · since Feb 2025
AI literacy

Whoever uses AI in their own name must ensure their people have sufficient training and be able to evidence it.

When the inspector asks “have you trained your staff?”, the answer is a list of dated certificates

Disclose · art. 50 · since Aug 2026
Transparency

You must inform people when they are talking to an AI and when content has been generated by one. It also reaches whoever deploys it.

One line under the chat and a footnote on AI-assisted texts

Govern · arts. 26 and 27 · high risk
Governance and oversight

Knowing which systems you use, for what, with what data and who answers for them. In high risk it is a legal obligation (human oversight and impact assessment); for everything else, it is what any client or auditor will demand of you.

An inventory, a one-page policy and a named owner

What this looks like in a twenty-person company

Train: all twenty take this course and twenty dated certificates end up in a folder. Disclose: under the website chat, “you are being helped by an automated assistant”; on the blog, “content produced with AI assistance and reviewed by a person”. Govern: one sheet with the uses, one page with the rules and the name of whoever answers. Total time: one afternoon. Cost: zero.

Translation for an SME: one certificate per employee, one line on your website and one page with the rules of the house. That is almost all of it.

‹‹‹
Module 5 · Worked case21
Worked case

The file of 4,200 customers

A thirty-person distributor. The sales manager wants to segment his portfolio and does the most natural thing in the world: he exports the whole CSV — name, ID number, phone, address, consumption, arrears — and uploads it to a free assistant so it can “find patterns”. Nobody acted in bad faith and nobody broke a password: the breach was opened by the process itself.

And now, out loud: are you complying?
  • Do you know which AI tools are used in your team and what for?
  • Has anything red gone out this week without anyone reviewing it?
  • Is there a single page written with the rules of use?
  • Does anyone review what the AI produces before it goes out with your signature?
  • Could you evidence tomorrow that your people are trained?

If you said “no” more than twice, you do not have a technology problem: you have a governance problem. And it is fixed in one afternoon.

Una tirita con las letras AI sobre un documento roto
After the breach there are only patches
‹‹‹
Module 5 · The three layers22

Who gets in, what they see and what is left of the data

The three technical layers your IT person must be able to show you. If one is missing, the defence has a hole.

RGA · Roles and access groupsRLS · Row-level securityAnonymisation
What it protectsWho can get in and which tables or actions they are allowed.Which specific records each user sees inside one and the same table.The data itself: it stops being identifiable.
Everyday exampleThe “auditor” role only reads; it does not write or delete.Each salesperson sees only their own customers in the customer table.The email address is replaced by a fingerprint nobody can reverse.
Is it reversible?Yes: permissions are changed when needed.Yes: policies are adjusted.No. If it is reversible, it is pseudonymisation.
What it brings to the GDPRConfidentiality and integrity (art. 32).Minimisation and granular access (arts. 5 and 32).It can take the data outside the scope of the GDPR if it is irreversible (Rec. 26).
The three layers in your own CRM · example

You have a CRM with 4,200 customers and eight salespeople. RGA: the intern logs in with a role that can only read, so they cannot wipe a portfolio by mistake. RLS: each salesperson opens the same CRM and sees only their own customers, not those of the other seven. Anonymisation: when you export data to analyse sales by area, the name and ID number are replaced by an irreversible code, so that file is no longer a problem if it goes astray. If the third one is missing, Tuesday’s export is a breach waiting to happen.

RGA decides who gets in. RLS decides which row they see once inside. Anonymisation makes the data no longer personal. Complementary, not interchangeable.

‹‹‹
Module 5 · Biases24

The three biases you will run into

They are not random errors: they are systematic patterns the AI inherits from the data and amplifies without anyone noticing.

Historical bias
It learns from the past

A recruitment tool penalised CVs containing the word “women”, because the company had hired mostly men.

Antidote: run the same process with different profiles and compare results

Anchoring bias
The first figure rules

If your instruction mentions “around €200,000”, its estimates will orbit that figure even with no basis whatsoever.

Antidote: ask for the range before you give any number yourself

Automation bias
If the machine says so…

Accepting a recommendation just because it comes from a system. It is the most dangerous of the three because it leaves no trace.

Antidote: the control question on the next slide

‹‹‹
Module 5 · Deciding25

When to delegate and when not to

LevelTasksWhat oversight it needs
AutomateClassifying emails, transcribing, generating drafts, summarising documents.Sample review: one in five.
AssistAnalysing data, comparing suppliers, drafting proposals.A person reviews the output before it is used.
ConsultStrategy, investment, candidate assessment.The AI is one opinion among several. The decision is human.
Never delegateDismissals, crisis communication, binding legal decisions.The AI may inform, but the decision and the responsibility are a hundred per cent yours.
The control question, before every assisted decision

“If this goes wrong, will I be able to explain why I decided it and on what information?”

If the answer is no, you are short of human oversight. This is not advice: it is the standard you will be held to.

‹‹‹
Module 6 · What is already arriving27
Worked case included

From AI that answers to AI that acts

Generative AI · what you use today
  • Generates content
  • Answers what you ask it
  • Needs clear instructions at every step

ChatGPT, Gemini, Claude

Agentic AI · what is coming
  • Executes actions on real systems
  • Completes an objective, not a question
  • Decides the intermediate steps without constant supervision

Autonomous agents that use tools

Projects

It plans, assigns tasks and follows up without anyone reminding it.

Grants

It searches for calls, assesses feasibility and prepares the draft proposal.

Customer service

It resolves incidents by going into the systems, not merely drafting replies.

Market

It gathers data, analyses trends and delivers the executive report finished.

A real assignment to an agent, step by step

“Find open funding calls for [CLIENT_A], discard any requiring more than 40 % co-financing and leave me a draft of the best one ready.” The agent reads the terms, filters, compares and drafts… and stops before submitting anything: that click is yours. Minimum permissions, one human review point and a log of every step: the governance of module 5, applied to what is coming.

The risk changes: it is no longer a wrong text, it is a wrong action on a real system. That is why an agent needs minimum permissions, human review points and traceability of what it does. Your job shifts from writing to supervising.

‹‹‹
Module 6 · The horizon28

Three levels of AI. Only the first one exists

Level 1 · ANI · you are here
Narrow intelligence

Brilliant at one task, lost outside it. It is 100 % of what exists today: ChatGPT, Copilot, Gemini, Claude. That is why human oversight is not optional.

Example: the same model that drafts a flawless report can get a two-digit multiplication wrong

Level 2 · AGI · does not exist
General intelligence

It would learn any new task the way a person does, without being retrained for each one. It is speculated about; it is not on the market.

Example: a system that ran your department end to end, on its own. Nothing like it exists today

Level 3 · ASI · speculative
Superintelligence

Above human beings at everything, creativity included. A theoretical scenario, not a product coming out next year.

Its role today: to explain why the whole ethical and regulatory debate exists

When would AGI arrive? Three positions, no consensus
Optimists2027 – 2030 · part of the industry that is building it
Scientific majority2035 – 2050 · and, if it arrives, it will not be all at once
ScepticsBeyond 2100 · or never with this technology

Nobody knows, and anyone giving you an exact date is speculating. The only certainty: progress is not linear.

What you do today, without speculating
  • Cultivate what the machine does not have: judgement, empathy and ethical sense.
  • Govern well the AI you already use: that muscle is the one that will serve you with the next.
  • Learn to work with today’s AI: it is the working base of tomorrow’s.
‹‹‹
Module 6 · Rules of the house27

Ten rules for tomorrow

  1. Start with the problem, never with the tool.
  2. Write the 5C before you write the request.
  3. Always close with “if you do not know, say so; do not invent it”.
  4. No red data goes into a public AI. None.
  5. Amber goes in anonymised: substitute, do not delete.
  6. Verify source, coherence and contrast.
  7. AI is not a citable source: cite the origin.
  8. Disclose when someone is talking to an AI or reading something generated by one.
  9. Everything that gets signed is reviewed by a person. Always.
  10. If you cannot explain why you decided something, you are short of oversight.

Copy them as they are: they already are the one-page policy of piece 02.

‹‹‹
Module 6 · accreditation29

How you pass, said upfront

Nobody sits an exam blind. These are the exact rules, and no question comes from anything that has not been explained today.

Rule 01
Seven out of ten

Ten questions, one from each block, drawn at random from a bank of forty-seven. Two people sitting together do not see the same exam.

Rule 02
No critical question failed

Two questions always come from data protection, governance or verification. Those cannot be failed, however high the score: they are what the certificate states about you.

Rule 03
No limit on attempts

If you do not make it, you review and retake. Nobody is failed here: they are sent back to study what they are missing, which is a different thing.

And the diploma will not just say “pass”: it will carry your competency profile block by block, so that whoever reads it knows exactly what was verified.

‹‹‹
Home