H Handrail Lesson 2-min video · optional 7-min read
Module 0 · All levels — teaches the 0–4 map

Module 0 — Where Your Firm Stands with AI

A 15-minute orientation before any 'how to use AI' lesson: why AI is already part of your working day whether you've adopted it or not, the plain-language 0-to-4 map of AI use, the one mantra that governs everything in this course, and the 2-minute self-assessment that decides which lessons you see next.

A ~2-minute walk-through. Prefer to read? The full lesson is below. Captions are on.
Listen instead (audio only) — good for a commute or patchy signal
In one line

Most AI-safety training starts by teaching rules. That's backwards for a cautious, non-technical firm, because it assumes everyone is starting from the same place — and they aren't. A firm with nobody using AI on purpose faces completely different risks than a firm with AI quietly running inside its scheduling software. Teach both the same lesson and you either bore one group with irrelevant scare stories or leave the other exposed. This module exists to fix that before anything else happens: it removes the fear ('am I already in trouble?'), gives everyone the same simple map to talk about AI use without jargon, plants the one rule that makes every later lesson make sense ('AI advises, human decides'), and ends with a 2-minute honest self-assessment. That assessment isn't a quiz for a grade — it's a switch. It decides exactly which modules, case studies, and risks this course shows your firm next, so nobody wastes time on scenarios that don't apply to them, and nobody skips ones that do.

The short version — what to remember
  • AI is already part of your working day through vendor software, suppliers, and scammers — whether or not your firm has deliberately 'adopted' it.
  • The 5-level map (0 = no use of your own, up to 4 = autonomous action) is a plain-language way to describe exposure, not a ladder you're supposed to want to climb.
  • Most firms are a mix of levels, not one clean number — a stray higher-level feature hiding inside familiar software is the norm, not the exception.
  • 'AI advises, human decides' is the one mantra behind every later lesson: AI can draft and suggest, but a named person reviews, understands why, and is accountable.
  • The 2-minute self-assessment isn't graded — it's a gate that decides exactly which risks and case studies this course shows your firm next.
A real (anonymized) example

A 10-person facilities-management company assumed this whole topic didn't apply to them: no one had a ChatGPT account, there was no AI policy, and the owner described the firm as 'firmly analogue.' During the Module 0 self-assessment, though, two things surfaced that nobody had connected to 'AI' before: the booking software they'd used for three years had quietly added an AI-powered scheduling suggestion feature in an update, switched on by default: and the office manager recalled a supplier email a month earlier that had felt 'a little too polished' but was dismissed as nothing. Neither fact had seemed worth mentioning before the assessment forced the group to answer the five questions honestly together. The firm's true position was a mix: mostly Level 0 by choice, with one Level 3 feature already live inside software they relied on daily, plus a live Level 0 exposure (the odd supplier email) they'd nearly ignored. That combined, honest picture — not a single tidy number — is exactly what the self-assessment is designed to produce, and it determined which case studies and lessons the firm was shown in every module that followed.

Reflect

A few open questions — nothing to trip on

These are to think through, not a test — there's no score and no wrong answer. Jot a line if it helps, then open the note to see what a careful answer usually considers. Nothing is saved or shown to your admin.

Question 1 of 4

Your firm has never signed up for any AI tool and has no AI policy. Does that mean AI-related risk doesn't apply to you yet?

See what a careful answer considers

A careful answer usually lands on: No — you're still exposed, because vendors, suppliers, and scammers already use AI in ways that reach your firm. This is Level 0: no AI adoption of your own, but still exposed, because AI-generated scams, vendor tools, and software features already reach your firm regardless of your own choices.

Question 2 of 4

What does the mantra 'AI advises, human decides' actually require in practice?

See what a careful answer considers

A careful answer usually lands on: A named person reviews AI output, understands why it's reasonable, and remains accountable for the decision. The mantra isn't about avoiding AI or trusting it more over time — it's about keeping a specific, accountable human check between AI output and any real decision, every time.

Question 3 of 4

Why does this course ask you to complete a self-assessment before teaching any 'how to use AI safely' rules?

See what a careful answer considers

A careful answer usually lands on: Because the result determines which case studies and risks the rest of the course shows your firm. The self-assessment is a gate, not a grade — it decides which real-world risks and examples are actually relevant to your firm, so later modules can skip what doesn't apply and focus on what does.

Question 4 of 4

A firm's booking software added an AI scheduling-suggestion feature automatically during a routine update, and nobody at the firm turned it on deliberately. What does this tell you about the 5-level map?

See what a careful answer considers

A careful answer usually lands on: It can place the firm at Level 3 for that feature, because AI is now built into a system they rely on, whether or not it was a deliberate choice. Level 3 covers AI embedded in tools you already run on, including features switched on by default. Level 4 would require the system to take real actions without a human reviewing them first — a suggestion feature isn't that, since a person still chooses whether to accept it.

Read the full written lesson (~7 min)

You don't need to be worried — you need to know where you stand

If a course about AI safety showed up in your inbox, there's a good chance part of you is already bracing for bad news: a list of things you're doing wrong, jargon you've never heard, a sense that everyone else figured this out already. None of that is true, and it's worth saying plainly at the start.

This course is not built to catch you out. It's built on a much calmer idea: you cannot manage a risk you haven't located. Before we talk about any rule, tool, or case study, we need one honest answer — where does your firm actually stand with AI today? Not where you wish you stood, not where a competitor stands. Just an honest, plain-language read of your own situation.

That's all this module does. Fifteen minutes, no jargon, and by the end you'll have a number (0 through 4) that quietly shapes everything the rest of this course shows you.

The uncomfortable truth: AI is already in your day, even if you never chose it

Here is the fact this whole course is built around: whether or not your firm has 'adopted AI,' AI is already part of your working day. Three things are true at once, even for a firm that has never opened ChatGPT:

  • Software you already pay for — your email, your invoicing tool, your phone system — very likely has AI features quietly switched on: spam filtering, auto-suggested replies, voicemail-to-text.
  • Your suppliers, your bank, your insurer, and your bigger customers are using AI on their end. Their AI-drafted emails and AI-summarized calls land in your inbox looking exactly like everyone else's.
  • People trying to scam or mislead you — fake invoices, cloned voices on the phone, urgent 'from the boss' messages — are using AI to make their attempts far more convincing than anything you've seen before.

So the question was never really "should we use AI?" That decision, in a small way, has already been made for you by the world around your firm. The real question — the one this course answers — is: at what level is AI touching your firm, and what does that mean for how careful you need to be, and about what?

The 5-level map, in plain language

Forget technical definitions. Here is the map this entire course is organized around, described the way you'd describe it to a colleague over coffee:

  • Level 0 — No use of our own, but not immune. Nobody at the firm has chosen to use an AI tool. Your risk isn't from your own mistakes — it's from being a target: scam emails, cloned voices, AI-written impersonation aimed at you from outside.
  • Level 1 — A person or two, here and there. One or two people quietly use a chat tool now and then — tidying up an email, checking a phrase — on their own initiative, with no guidance from the firm. This is the most common way firms drift off Level 0, usually without anyone deciding it should happen.
  • Level 2 — Part of the everyday routine. Several people use AI tools regularly, for real work — drafting quotes, summarizing meeting notes, writing routine correspondence — as an ordinary, if informal, part of how the firm operates.
  • Level 3 — Built into the systems you already run on. AI features live inside the software your firm depends on — your booking system, your accounting package, your CRM — whether or not anyone at the firm consciously switched them on.
  • Level 4 — Acting without a human clicking first. Some process now runs on its own: an assistant that replies, books, or approves routine items automatically, without a person checking each one. Very few small firms sit fully here, but pieces of Level 4 show up earlier than people expect, tucked inside one automated workflow rather than the whole business.

Two things to notice. First, the levels aren't a ladder you're supposed to want to climb — a firm that deliberately stays at Level 1 or 2 forever, carefully, is not "behind." Second, almost no real firm is a single clean number. Most are mostly one level, with a stray feature or habit sitting a level higher somewhere nobody thinks to mention. That's completely normal, and exactly what the self-assessment below is built to surface.

The one sentence to remember: AI advises, human decides

Every lesson in this course — no matter which level it's aimed at — comes back to a single mantra: AI advises, human decides.

That's it. That's the whole philosophy in five words. AI can draft, summarize, suggest, flag, and speed things up. A named person at your firm reviews what it produced, understands why it's reasonable (or catches why it isn't), and is the one who is actually accountable for the outcome — not the AI, and not "the system."

This isn't a rule designed to slow you down or make you suspicious of every tool. It's the opposite: it's what lets a cautious firm use AI confidently, because the safety net isn't "hope the AI got it right" — it's "a person checked, and can say what they checked." You'll see this exact idea again in every later module, applied to a different risk each time. Learning it once, here, means it never has to be re-explained.

The 2-minute self-assessment that decides what you see next

Now the practical part. Answer these questions honestly, as a group if you can, thinking about the whole firm rather than any one person:

  1. Has anyone at the firm ever used a chat tool like ChatGPT, Copilot, or Gemini for work — even once, even for something small?
  2. Do any everyday tools you already use have an "AI" or "smart" feature switched on — auto-reply suggestions, meeting summaries, a chatbot, spam filtering?
  3. Has anyone used an AI voice, photo, or video tool for firm business — even an ordinary phone app that cleans up a photo or generates a voice clip?
  4. Does any system take an action on its own, without a person clicking "approve" first — auto-scheduling, auto-replying, automatically approving a routine invoice?
  5. Has anyone here recently received a message that felt oddly polished, personal, or urgent, and something felt slightly off about it?

There is no passing or failing score. What you answer here sets the gate: it tells this course exactly which case studies, which risks, and which lessons to show your firm first — the ones that match where you actually stand today, plus one level ahead, so nothing that's coming catches you by surprise. A firm that's mostly Level 0 sees scam-and-impersonation cases first. A firm with Level 2 or 3 answers also sees lessons on everyday mistakes and on checking tools already built into their software. Keep your answers — the next module opens by using them directly.

This lesson is written and reviewed by named humans. Content current as of 21 July 2026. See the Trust Center for our review process and AI-assistance disclosure.