AI safety and compliance training for SMEs

Find out what you can safely allow AI to do in your organisation!

By the end of the course you will have a ready-to-use action plan and draft policy, tailored to your own organisation

What does the AI compliance training for SMEs cover?

Most SME leaders currently find themselves in one of the following four situations when it comes to using AI:

  1. A decision has been made to adopt AI, but data security was left out of the picture. Connectors, for example, have full access to email, file sharing or the CRM.
  2. You know informally that colleagues are using AI, but there is no organisation-level rollout or policy behind it.
  3. You can see the opportunity AI offers, but data security concerns stop you from approving it, so the whole subject appears to stall.
  4. AI has been adopted and it works, but there is no record of who uses it, for what, and with which data, leaving you with a blind spot on the risks.

In every case the same responsibility sits with the leader: what data goes in, who can see it, where it is stored, and what happens if something goes wrong.

We designed this AI security training for SMEs so that the day produces more than information and theory: a prioritised action plan and a draft AI usage policy in seven chapters, both tailored to your own organisation.

AI safety and compliance training for SMEs

We also offer online, distance learning courses using digital and video conferencing tools!

Our experts

Prerequisites, frameworks, target audience

This programme is designed specifically for SMEs which, given their size, do not have enterprise-level IT or data security capacity and resources, yet want to make sure that AI use across the organisation is both secure and properly documented.

The training starts from the legal fundamentals, so participants need no prerequisites and no prior legal or information security background.

The programme is a one-day, 8-hour course running from 09:00 to 17:00. The morning covers the legal background, an analysis of five documented incidents and the methodology of risk assessment, while the afternoon is built around an individual exercise and two workshop blocks in which you produce material tailored to your own organisation. Each organisation leaves the day with a risk assessment note, a prioritised action plan and a draft AI usage policy in seven chapters.

The programme can also be delivered in-house, in which case the curriculum can be fine-tuned to the client's organisational circumstances.

Training agenda

  • Foundations and shared vocabulary: brief overview and why the topic matters now
  • Legal background: 
    • Article 4 of the AI Act, role-based AI literacy,
    • GPAI obligations,
    • High-risk (Annex III) systems and the omnibus postponement,
    • Penalties
    • GDPR and AI
    • Scope thresholds and deadlines under the Cybersecurity Act and NIS2
  • Risk awareness through real incidents: detailed analysis, categorisation and participants' own cases
  • Risk assessment
    • AI tool inventory and uncovering shadow AI
    • Data categorisation
    • Practical techniques for PII anonymisation and pseudonymisation
    • Data location
    • Criteria for supplier due diligence
  • AI risks of your own organisation
    • AI tools in use and data categories
    • Access rights and permissions
    • DPAs and identifying controls
    • Defining an incident scenario
  • Building your own action plan with owners and deadlines
  • Drafting your own AI usage policy
  • Next steps after go-live

Satisfaction guarantee

We're confident in the quality of our programme, but if you're nonetheless dissatisfied and let us know during the first training block, you naturally won't need to pay! We invoice for the programme after the training, we don't ask for anything in advance.

Training information

We offer discounts for PMSZ and PMI Hungarian Chapter members, groups of two or more applicants, and individuals!

In case of 4 or more applicants, please contact us for a customized proposal, in which case the schedule and topics can be flexibly adjusted! 

An organisational training session is followed by a complimentary 2-hour consultation, which can be used to support AI use cases or AI implementation as needed.

The programme consists of 2 days (9.00 a.m. to 5.00 p.m.) of classroom-based or online training, 80% of which is made up of practical elements.

Request a quote

AI safety and compliance training for SMEs

Currently, we provide our trainings in English for corporate groups in dedicated online or onsite formats. The dates and prices of our open trainings in Hungarian are available at the following link:

If you are interested in English-language training courses, please request a quote using the form below or contact us at info@promanconsulting.hu.

Name *
Email *
Phone *
Message

0 %
5 out of 5 points

quality

0 %
5 out of 5 points

satisfaction

0 %
5 out of 5 points

execution

"The programme was very useful, especially the documents we put together together."

Important

We designed our programme around practices proven in real projects, giving you practical support and hands-on experience in applying AI tools.

10 reasons why you should choose us

Location

H-1118 Budapest, Kelenhegyi str. 29/b.
tel.: +36 30 663 2069
mail: info@promanconsulting.hu

Frequently asked questions:

No. The programme starts from the legal and data security fundamentals, so you need no prior legal or information security background.

The programme runs for 8 hours over a single day, from 09:00 to 17:00, with a lunch break and two short breaks.

We run both formats. For the online format you will need an internet connection, and a microphone and webcam are recommended. We provide the worksheet and the supporting materials electronically.

We have set the group size at 3 to 12 people, to keep the joint work effective.

Three documents: a risk assessment note on your own organisation, a prioritised action plan with owners and deadlines, and a draft AI usage policy in seven chapters.

No, there is no exam or certification attached to the programme. The outcome of the course is an action plan and a draft policy tailored to your own organisation. All participants do, however, receive a certificate of attendance.

Yes. The afternoon exercise and the workshop blocks are completed per organisation, so two participants from the same company can work as a pair, and the draft policy is produced jointly. Typically it is the manager who attends together with the designated AI owner or the IT security contact.

Yes, the programme is designed for this situation too. The morning risk assessment block covers uncovering shadow AI, in other words how to assess the kind of usage that has no decision or documentation behind it.

The focus is on management and organisation. We do not cover tool configuration or system integration. What we do cover is which data can go into AI tools, who can access it, how this is documented, and which controls are worth introducing first.

This differs from one organisation to another, and the legal block of the course is there to clarify exactly that. We work through the obligations under the AI Act and the scope thresholds of the Hungarian Cybersecurity Act and NIS2, so that by the end of the day you know what applies to you.