Training your staff for AI: what to teach and what to skip

Most AI training teaches prompts. What a small business needs is judgement: when to use it, how to check it, what never to paste in.

3 minread 672words last updated

The short answer

Most AI training for staff teaches prompts, and prompt tricks age in months as the tools change. What a small business actually needs its people to have is judgement: when AI is the right tool for a task and when it is not, how to check what it produces, and what must never be pasted into it. Teach that, write the rules down in a short policy, and then practise on each role’s real tasks for a month. Adoption follows usefulness, not workshops.

A curriculum in four parts

PartWhat it coversTime
1. What the tools are and are notPattern prediction, not knowledge; fluent and confident even when wrong; good at drafting, summarising, transforming text; poor at facts it has not been givenAn hour, shared
2. Rules for dataApproved tools and their data agreements; what may never be entered: customer personal data, credentials, contracts, anything under confidentiality; who to askAn hour, shared
3. Verification habitsCheck facts against a source; read drafts as the recipient; never send unreviewed output to a customer; know when an answer needs a human expertAn hour, shared
4. Practice on real workTwo tasks per role, done weekly with help; time saved measured; good examples sharedAn hour a week for a month, per team

What to skip

  1. Long lists of prompt formulas. They are specific to a tool and a moment. Teach asking clearly, giving context and iterating instead.
  2. Tool tours. Features change monthly; a screen-by-screen walkthrough is out of date before the slides are finished.
  3. Theory of how models are trained. Interesting, and irrelevant to whether the sales team’s follow-ups get better.
  4. One-off inspiration sessions with no follow-through. They produce a week of experimentation and no change in how work is done.

The policy, on one page

Approved tools, and for each, what data may be used with it. Data that is never entered anywhere: personal data of customers and staff, credentials, financial details, confidential documents, unless the tool is explicitly approved for it. Review requirements: anything sent to a customer or used for a decision is checked by a person. Disclosure rules where they apply. A named person to ask. Reviewed twice a year, because the tools change.

What this means for you

Skip the prompt workshop. Spend half a day on what the tools are, the data rules and verification habits, write the one-page policy, and provide an approved tool. Then practise real tasks for a month per role and measure the time saved. Judgement and habits are what your staff will still be using when this year’s tools have been replaced.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Should everyone learn to write prompts?

Everyone should learn to ask clearly, give context and iterate, which is communication rather than a technical skill. Beyond that, prompt tricks are specific to tools and versions and go stale. Time is better spent on judgement and on practising the team's real tasks.

How do we stop staff pasting customer data into public AI tools?

A short written rule, approved tools with the right data agreements, and an easy internal way to ask. People paste into public tools when no sanctioned option exists. Provide one, explain why the rule exists, and check occasionally.

How long should training take?

Half a day of shared basics and rules, then an hour a week for a month practising on real tasks per role, with someone available to help. A single long workshop produces enthusiasm that fades by the following Monday.