
In a previous post we looked at AI literacy: what Article 4 of the AI Act requires, what changed with the Digital Omnibus and, above all, why training people on AI should be treated as a genuine business issue rather than a box to tick.
The figures help explain why. According to the Artificial Intelligence Observatory of Politecnico di Milano, 47% of Italian employees used AI tools at work in 2025. Of those, only 19% say they use exclusively the tools their organisation provides. Which means four workers in five also, or only, use outside tools (shadow AI): personal accounts, free versions, browser extensions and other services that often enter company processes with no formal oversight — and all the risks that come with it.
Adoption that fast has not been matched by companies getting equally fast at setting clear rules on how AI should be used. In the same year, again according to the Politecnico di Milano observatory, only 9% of large Italian companies — the ones with the most budget, in-house expertise and dedicated functions — had structured AI governance in place. Among SMEs, in most cases, the rules, the responsibilities and the acceptable uses of AI have yet to be written down at all.
It is precisely in the gap between those two figures — AI already widely used, AI still barely governed — that most of the problems arise.
Where Axura’s AI training programme starts
In the previous post we explained why AI literacy cannot be reduced to the mythical “mandatory AI Act course”: Article 4 does not prescribe a specific course, a minimum number of hours or a certification. It asks organisations to take measures to support the development of their people’s AI literacy, taking into account their existing skills, the context in which they use AI and the people those systems may affect.
Working from that premise — and, more than anything, from what we actually see happening inside companies — we built an AI training programme at Axura designed for SMEs.
The underlying idea is simple: before asking people to follow rules about AI, you have to put them in a position to understand those rules.
That is why our programme begins with an assessment of how AI is already being used in the company: which tools are in use, in which activities, what data is being entered into them, which rules already exist and which are missing. This is usually the stage where things surface — tools switched on by individual departments, personal accounts used for work, or AI features already embedded in company software that nobody had ever thought of as AI.
The first module: the ten AI rules

The first module of the Axura programme is called “Il Decalogo IA – Fondamenti di IA e AI Act” (The Ten AI Rules – Foundations of AI and the AI Act): a ninety-minute literacy module, delivered as asynchronous e-learning and designed for the entire workforce — not just for the people who handle IT, compliance or innovation, but for anyone who might find themselves using an AI tool in their job.
The module covers what an AI system is, how many machine learning systems work, and what their main strengths and limits are: it deals with hallucinations and bias, the role of human review, the logic of the AI Act and its risk classification. It then moves on to personal data, confidentiality, automated decisions, transparency and intellectual property, before arriving at the organisation’s own rules: approved tools, prohibited uses, policy and reporting channels.
At the end of that path you arrive at ten rules — the ones we set out in this post. They are not meant to replace the training; quite the opposite. They are what remains of the training when what you have learned has to turn into everyday behaviour.
Why learning ten rules isn’t enough
“Always check the output*” sounds like an obvious rule, doesn’t it? It feels far less obvious when AI hands you a piece of information backed by a source that looks entirely credible — title, author, date, link and all — but that never actually existed. Without a check, the risk is simple: you take it at face value and, quite possibly, pass it on.
* By “output” we simply mean whatever AI gives back to you: an answer, a text, an image, a summary, an analysis, a recommendation or any other result the system produces. For instance, if you ask ChatGPT to write an email, the email it generates is the output. It’s a word you’ll see a lot in this post.
“Never enter confidential data into unapproved tools” can sound like yet another piece of corporate red tape — until you grasp that pasting a document into an outside tool means transferring that information to infrastructure your company may not control.
“Whoever uses the output takes responsibility for it” becomes a great deal more concrete once that output leaves the company or is shared with someone else. If we use an AI answer in an email to a client, in a document, in a presentation or in something published online, we are the ones choosing to circulate it, and we are therefore responsible for what we are communicating. Saying “AI wrote it” does not release us from the responsibility of having checked that the information was correct before using it.
This is why reading a set of rules cannot count as training: a rule works when the person applying it understands the reason behind it, recognises the situation in which it becomes relevant, and knows in practical terms what to do. The rules come afterwards — as a quick reference, as shared language, and as a reminder of the choices to make when AI enters daily work.
In our programme, then, we do not hand out a page of ten rules and ask people to memorise them. We build the context that makes them make sense first, and then use them as the module’s practical summary.
Axura’s ten rules for AI at work
So here they are: the ten rules around which we built the first module of Axura’s AI training programme.
1. AI doesn’t know things: it calculates

Generative AI systems do not know facts the way a person knows them. What they do is produce outputs based on patterns and probabilities learned from data.
That is why they can give you a correct answer and, a moment later, invent a fact, a source or a quotation in exactly the same confident tone.
This is the phenomenon we call “hallucination”, and it isn’t simply a defect due to disappear: it follows from the way these systems work in the first place.
For a sense of how concrete the problem is, researcher Damien Charlotin maintains a public database collecting court decisions worldwide in which a judge has established that hallucinated content was used in a filing. As at 19 August 2026 it lists 1,934 cases, 15 of them in Italy — and we are talking about lawyers and other professionals, so, in theory, not the unwary.
The practical consequence is straightforward: a plausible answer is not necessarily a correct one, which is why anything that genuinely matters has to be checked.
2. Every output that matters goes through a person (human in the loop)

The module’s golden rule has four steps: generate, check, correct, own it.
AI can be used to produce drafts, summaries, ideas and preliminary analysis, but facts, figures, names, sources and references have to be verified: the content needs correcting and adapting, and anything that cannot be verified has to come out.
Having at least one person in the process — “human in the loop” — is essential.
Only then can the output leave the company or be used to make a decision.
3. A person signs off, not a tool

“AI wrote it” does not transfer responsibility to the tool.
Anyone using an output in their work has to be able to explain it, verify it and take operational responsibility for it: AI produces; the person decides whether and how to use what it produced.
4. Only what could leave the company goes into an AI system

Data calls for particular caution: before entering information into an AI tool, it is worth asking whether it is genuinely needed to get the result you are after.
Verizon’s 2026 Data Breach Investigations Report shows that the company information most frequently copied or uploaded into external AI tools is source code — the code behind the company’s own software, sites and applications. Images come next, then data organised in tables or databases and, in some cases, research and technical documentation.
The problem is simple: confidential, valuable company information can end up in an outside tool without the company ever having decided to share it. All it takes is someone pasting a snippet of code into ChatGPT to get help fixing it, or uploading a technical document to have it summarised. Convenient, certainly — but if the tool isn’t approved, that information is leaving the company perimeter.
There is a second rule alongside it: personal data, confidential information and company documents must not be entered into AI tools the company has not approved. A personal account or a free service found online may be handy, but the company may have no control at all over how the information we upload there is handled.
And when AI processes personal data, the AI Act isn’t the only thing in play: the GDPR continues to apply. Using artificial intelligence does not change the data protection rules a company already has to follow.
5. Use approved tools, with your company account

The same Verizon 2026 report shows how widespread shadow AI has become — meaning AI tools used at work without ever having been approved by, or even made known to, the organisation. 45% of employees now use AI tools regularly on company devices, up from 15% the year before. Among those who do, 67% sign in with a personal account rather than a company one.
In practice, a lot of people are using AI to work outside the tools and accounts their company controls — which is how documents, data and other company information end up on outside services without the organisation knowing. Unsurprisingly, Verizon finds shadow AI has become the third most common cause of accidental data loss.
The point isn’t to ban anything the company didn’t pick on principle. The point is that the organisation needs to be able to know which systems are in use and on what terms.
So if a needed tool is missing, or the available one isn’t up to the job, the answer shouldn’t be to improvise: it should be to flag it to whoever is responsible internally.
6. AI can inherit the biases in its data

AI systems can reproduce and amplify the distortions present in the data they were trained on.
An example: if a system used to assess CVs was trained on historical data in which certain positions went mostly to men, it may unwittingly learn to associate that kind of profile with the “better” candidate, and end up penalising women applicants.
This is not a remote hypothesis. It is what happened at Amazon. The company had developed a system to score CVs automatically, training it on a decade of applications received, overwhelmingly from men. The system learned to penalise CVs containing the word “women’s” and to downgrade graduates of two women’s colleges. Amazon shut the project down, noting that it was never the sole criterion in a real selection process — but the case remains instructive: if a distortion like that escapes a company with those resources, it certainly isn’t going to be caught one output at a time.
The issue becomes especially delicate when outputs concern people: clients, candidates, employees. A distortion isn’t always visible in a single result. But if, across a hundred CVs, the system consistently favours or penalises people with particular characteristics, the problem is plain enough.
So it isn’t enough to check that an individual answer “looks right”: you also have to watch for recurring patterns across AI outputs.
7. No decision about people without human oversight

The more an output affects someone’s rights and opportunities, the more human oversight — and the ability to contest the decision — matter.
The principle is particularly relevant in areas such as recruitment and people management, credit, health and access to essential services: these are not contexts in which to delegate a decision to AI without understanding and checking the result.
8. Disclose AI use when it matters to the person receiving the content

Not everything produced with the help of AI has to be labelled as such. But beyond the specific obligations set out in the AI Act, there is a question of transparency: would knowing that AI was used change how the person receiving this content reads it?
For instance: using AI to draft a routine commercial email, then having a person check and rewrite it, is very different from publishing a client testimonial on the company website alongside an artificially generated image of that client. In the second case, whoever sees it could reasonably assume the person exists and actually said those words — so knowing the content was AI-generated changes its meaning entirely.
When AI use can make that kind of difference, disclosing it is good practice, for transparency and for trust.
9. Mind copyright: what AI generates isn’t always “ours”

Generative AI also raises questions around intellectual property.
On one side, it can generate content closely resembling existing works protected by copyright. On the other, there is no guarantee that content created with AI can be protected the way work created by a person can.
So particular care is needed when AI is used to create something important for the company — a logo, a claim, an image or any other asset you intend to use and protect over time. When in doubt, check with whoever handles this internally.
10. When in doubt, ask; when something goes wrong, report it

This is arguably the most important rule of all for the company.
People need to know who to turn to when they have a doubt, and what to do when something goes wrong: an unusual output, data entered by mistake, a tool used without approval.
That is why the module includes a section dedicated to the organisation’s own rules, customisable to the client’s policy: approved tools, prohibited uses, internal transparency and reporting channels.
From rules to reality: putting them to the test
Do these rules hold up in everyday working life?
The module uses a very simple scenario: a colleague sends you an AI-generated draft reply to a complaint. It contains the client’s details, a refund percentage and a reference to a regulation supporting the company’s position. It needs to go out immediately, because it’s urgent.
It is a situation in which several of the ten rules stop being theory at once:
- the details and the amounts need verifying;
- you need to check that the regulation cited actually exists and says what the AI claims it says;
- you need to establish which tool was used, and whether it was approved for handling that data.
If something doesn’t add up, it has to be flagged. And above all, urgency does not change the underlying principle: whoever sends that reply takes responsibility for it.
That is the shift we’re after: not memorising ten sentences, but being able to recognise which rules come into play when it counts.
The course’s rules have to become the company’s rules
There is an unavoidable limit to any set of rules published online: some of the most important information cannot be generic.
- Which tools is an employee allowed to use?
- What data may they enter?
- What must never leave the company perimeter?
- Who should they go to when they have a doubt?
Only the organisation can answer those questions. That is why the Axura module includes a section explicitly designed to be populated with the client’s own AI policy: general rules acquire practical value once they are tied to the actual tools, processes, data and people in that company.
It is also why, for example, copying the ten rules and emailing them round is not the same as training.
They can be an excellent reference point; they can become a card people keep within reach. But they really work when they are the shared output of a programme in which people have understood where those rules come from, why they exist and how to apply them in their own work.
A finishing point that’s really a starting point
At the end of the first module of the Axura course, the ten rules gather up everything people have just worked through: how AI functions, where it can go wrong, why outputs need checking, what changes once data and people are involved, what role the AI Act and the GDPR play and, above all, which behaviours to adopt in daily work.
Anyone who completes the module and passes the final test receives a certificate of completion and the card with the ten rules. The certificate documents completion of the programme and can serve as evidence of the training measures the company has adopted; it is not, however, a certification of AI Act compliance, because no course on its own can be that.
From there, the programme can continue with different areas of depth depending on roles, on the systems in use and on the organisation’s actual risks.
A company’s goal isn’t to be able to say “we’ve circulated the rules”. It’s to make sure that when someone opens ChatGPT, Copilot, Gemini or any other AI tool to do their job, they know what they’re doing, what to check and when to stop and ask.
At Axura we built our AI literacy programme with exactly that in mind: start from how AI is really being used in SMEs, and turn training into rules and behaviours that can be applied every day.
The ten rules are the first visible result of that programme — not the programme itself.
Want to know more? Get in touch and we’ll walk you through how it works.



