Read the full written lesson (~7 min)
You don't need to be worried — you need to know where you stand
If a course about AI safety showed up in your inbox, there's a good chance part of you is already bracing for bad news: a list of things you're doing wrong, jargon you've never heard, a sense that everyone else figured this out already. None of that is true, and it's worth saying plainly at the start.
This course is not built to catch you out. It's built on a much calmer idea: you cannot manage a risk you haven't located. Before we talk about any rule, tool, or case study, we need one honest answer — where does your firm actually stand with AI today? Not where you wish you stood, not where a competitor stands. Just an honest, plain-language read of your own situation.
That's all this module does. Fifteen minutes, no jargon, and by the end you'll have a number (0 through 4) that quietly shapes everything the rest of this course shows you.
The uncomfortable truth: AI is already in your day, even if you never chose it
Here is the fact this whole course is built around: whether or not your firm has 'adopted AI,' AI is already part of your working day. Three things are true at once, even for a firm that has never opened ChatGPT:
- Software you already pay for — your email, your invoicing tool, your phone system — very likely has AI features quietly switched on: spam filtering, auto-suggested replies, voicemail-to-text.
- Your suppliers, your bank, your insurer, and your bigger customers are using AI on their end. Their AI-drafted emails and AI-summarized calls land in your inbox looking exactly like everyone else's.
- People trying to scam or mislead you — fake invoices, cloned voices on the phone, urgent 'from the boss' messages — are using AI to make their attempts far more convincing than anything you've seen before.
So the question was never really "should we use AI?" That decision, in a small way, has already been made for you by the world around your firm. The real question — the one this course answers — is: at what level is AI touching your firm, and what does that mean for how careful you need to be, and about what?
The 5-level map, in plain language
Forget technical definitions. Here is the map this entire course is organized around, described the way you'd describe it to a colleague over coffee:
- Level 0 — No use of our own, but not immune. Nobody at the firm has chosen to use an AI tool. Your risk isn't from your own mistakes — it's from being a target: scam emails, cloned voices, AI-written impersonation aimed at you from outside.
- Level 1 — A person or two, here and there. One or two people quietly use a chat tool now and then — tidying up an email, checking a phrase — on their own initiative, with no guidance from the firm. This is the most common way firms drift off Level 0, usually without anyone deciding it should happen.
- Level 2 — Part of the everyday routine. Several people use AI tools regularly, for real work — drafting quotes, summarizing meeting notes, writing routine correspondence — as an ordinary, if informal, part of how the firm operates.
- Level 3 — Built into the systems you already run on. AI features live inside the software your firm depends on — your booking system, your accounting package, your CRM — whether or not anyone at the firm consciously switched them on.
- Level 4 — Acting without a human clicking first. Some process now runs on its own: an assistant that replies, books, or approves routine items automatically, without a person checking each one. Very few small firms sit fully here, but pieces of Level 4 show up earlier than people expect, tucked inside one automated workflow rather than the whole business.
Two things to notice. First, the levels aren't a ladder you're supposed to want to climb — a firm that deliberately stays at Level 1 or 2 forever, carefully, is not "behind." Second, almost no real firm is a single clean number. Most are mostly one level, with a stray feature or habit sitting a level higher somewhere nobody thinks to mention. That's completely normal, and exactly what the self-assessment below is built to surface.
The one sentence to remember: AI advises, human decides
Every lesson in this course — no matter which level it's aimed at — comes back to a single mantra: AI advises, human decides.
That's it. That's the whole philosophy in five words. AI can draft, summarize, suggest, flag, and speed things up. A named person at your firm reviews what it produced, understands why it's reasonable (or catches why it isn't), and is the one who is actually accountable for the outcome — not the AI, and not "the system."
This isn't a rule designed to slow you down or make you suspicious of every tool. It's the opposite: it's what lets a cautious firm use AI confidently, because the safety net isn't "hope the AI got it right" — it's "a person checked, and can say what they checked." You'll see this exact idea again in every later module, applied to a different risk each time. Learning it once, here, means it never has to be re-explained.
The 2-minute self-assessment that decides what you see next
Now the practical part. Answer these questions honestly, as a group if you can, thinking about the whole firm rather than any one person:
- Has anyone at the firm ever used a chat tool like ChatGPT, Copilot, or Gemini for work — even once, even for something small?
- Do any everyday tools you already use have an "AI" or "smart" feature switched on — auto-reply suggestions, meeting summaries, a chatbot, spam filtering?
- Has anyone used an AI voice, photo, or video tool for firm business — even an ordinary phone app that cleans up a photo or generates a voice clip?
- Does any system take an action on its own, without a person clicking "approve" first — auto-scheduling, auto-replying, automatically approving a routine invoice?
- Has anyone here recently received a message that felt oddly polished, personal, or urgent, and something felt slightly off about it?
There is no passing or failing score. What you answer here sets the gate: it tells this course exactly which case studies, which risks, and which lessons to show your firm first — the ones that match where you actually stand today, plus one level ahead, so nothing that's coming catches you by surprise. A firm that's mostly Level 0 sees scam-and-impersonation cases first. A firm with Level 2 or 3 answers also sees lessons on everyday mistakes and on checking tools already built into their software. Keep your answers — the next module opens by using them directly.