{
  "curriculum": {
    "id": "ai-security-leaders-2026",
    "title": "AI Security for Leaders",
    "subtitle": "What Every Executive Needs to Know in 20 Minutes",
    "version": "1.0.0",
    "created": "2026-09-29",
    "totalDuration": "20 minutes",
    "targetAudience": "C-suite executives, board members, senior leaders",
    "tone": "Business-focused, direct, actionable",
    "certification": false,
    "prerequisites": "None — designed for non-technical leaders"
  },

  "personas": [
    {
      "id": "ceo",
      "title": "Chief Executive Officer",
      "concerns": [
        "Reputational risk from AI data breaches",
        "Competitive disadvantage if AI adoption is blocked",
        "Regulatory fines and board liability",
        "Balance innovation with risk management"
      ],
      "keyQuestion": "How do I let my teams use AI without putting the company at risk?",
      "relevantModules": ["risks", "protection"],
      "decisionAuthority": "Sets AI governance policy direction"
    },
    {
      "id": "cfo",
      "title": "Chief Financial Officer",
      "concerns": [
        "Cost of AI-related breaches (avg $4.5M per incident)",
        "Insurance implications of AI use",
        "Budget for AI governance infrastructure",
        "Audit and compliance requirements"
      ],
      "keyQuestion": "What is the financial exposure if we get AI wrong?",
      "relevantModules": ["risks", "zerotrust"],
      "decisionAuthority": "Approves AI security investments"
    },
    {
      "id": "coo",
      "title": "Chief Operating Officer",
      "concerns": [
        "Operational disruption from AI policy gaps",
        "Supply chain AI risks",
        "Workforce AI literacy and compliance",
        "Process automation with AI guardrails"
      ],
      "keyQuestion": "How do I operationalize AI safely across business units?",
      "relevantModules": ["zerotrust", "protection"],
      "decisionAuthority": "Implements cross-functional AI policies"
    },
    {
      "id": "board-member",
      "title": "Board Director",
      "concerns": [
        "Fiduciary duty and AI risk oversight",
        "Director liability for AI governance failures",
        "Competitive positioning with AI",
        "ESG implications of AI use"
      ],
      "keyQuestion": "What questions should I be asking management about AI?",
      "relevantModules": ["risks", "protection"],
      "decisionAuthority": "Governance oversight and risk appetite"
    },
    {
      "id": "general-counsel",
      "title": "General Counsel / CLO",
      "concerns": [
        "Contractual obligations and AI vendor terms",
        "IP exposure through AI training data",
        "Regulatory compliance across jurisdictions",
        "Litigation risk from AI decisions"
      ],
      "keyQuestion": "What legal exposure does AI create for us?",
      "relevantModules": ["risks", "zerotrust"],
      "decisionAuthority": "Legal framework for AI use"
    }
  ],

  "modules": [
    {
      "id": "risks",
      "number": 1,
      "title": "AI Risks Your Board Needs to Know",
      "duration": "7 minutes",
      "objective": "Understand the real business risks of uncontrolled AI use",
      "chapters": [
        {
          "id": "data-exposure",
          "title": "The AI Data Exposure Problem",
          "duration": "2 minutes",
          "content": {
            "hook": "Your employees are using ChatGPT right now. The question is: with what data?",
            "keyPoints": [
              "43% of employees have pasted company data into AI tools (Gartner 2026)",
              "Most AI terms of service allow training on your inputs",
              "Free tier users = product, not customer",
              "Data flows: prompt -> model -> potential training data -> other users' outputs"
            ],
            "scenario": {
              "title": "The Monday Morning Surprise",
              "description": "A sales rep pastes your entire pricing strategy into ChatGPT to 'help with a proposal.' That pricing data is now part of OpenAI's training corpus. Your competitor asks ChatGPT for 'typical enterprise software pricing' three months later."
            }
          }
        },
        {
          "id": "real-breaches",
          "title": "Real Breach Examples",
          "duration": "2 minutes",
          "content": {
            "cases": [
              {
                "company": "Samsung Semiconductor",
                "year": 2023,
                "incident": "Engineers pasted proprietary chip source code into ChatGPT for debugging",
                "impact": "Three separate incidents in 20 days. Samsung banned ChatGPT company-wide.",
                "lesson": "Technical teams are the highest risk for sensitive data exposure"
              },
              {
                "company": "Apple Contractors",
                "year": 2024,
                "incident": "Third-party developers used AI coding assistants with Apple proprietary code",
                "impact": "Supply chain AI risk — your vendors' AI use is your exposure",
                "lesson": "AI governance must extend to your entire supply chain"
              },
              {
                "company": "Major Law Firm (anonymized)",
                "year": 2025,
                "incident": "Associates uploaded client documents for 'summarization'",
                "impact": "Potential attorney-client privilege breach, regulatory investigation",
                "lesson": "Regulated industries face compounding liability"
              }
            ]
          }
        },
        {
          "id": "regulatory",
          "title": "The Regulatory Landscape",
          "duration": "2 minutes",
          "content": {
            "overview": "Regulation is catching up fast. Ignorance is not a defense.",
            "regulations": [
              {
                "name": "EU AI Act",
                "effective": "2025-2027 (phased)",
                "keyPoints": [
                  "Risk-based classification of AI systems",
                  "Transparency requirements for AI-generated content",
                  "Fines up to 7% of global annual turnover"
                ]
              },
              {
                "name": "US State Laws",
                "status": "Patchwork but accelerating",
                "keyStates": [
                  "California: CPRA + AI-specific bills",
                  "Colorado: AI Consumer Protections",
                  "Illinois: BIPA implications for AI biometrics"
                ]
              },
              {
                "name": "SEC Guidance",
                "status": "2025 cybersecurity rules apply to AI",
                "keyPoints": [
                  "Material AI risks must be disclosed",
                  "Board oversight of AI governance expected",
                  "Incident reporting includes AI-related breaches"
                ]
              }
            ]
          }
        },
        {
          "id": "key-question",
          "title": "The Question That Matters",
          "duration": "1 minute",
          "content": {
            "question": "Is your company's data being used to train AI?",
            "why": "If you cannot answer this question with certainty, you have a governance gap.",
            "followUp": [
              "Which AI tools are employees using today?",
              "What data have they already shared?",
              "Do your vendor contracts address AI training rights?"
            ],
            "callToAction": "Write down your answers. If they're 'I don't know,' that's your first action item."
          }
        }
      ],
      "assessment": {
        "type": "reflection",
        "prompt": "On a scale of 1-5, how confident are you that your organization knows what data has been shared with AI tools in the last 90 days?"
      }
    },

    {
      "id": "zerotrust",
      "number": 2,
      "title": "The Zero Trust Approach to AI",
      "duration": "7 minutes",
      "objective": "Apply proven security principles to AI governance",
      "chapters": [
        {
          "id": "principle",
          "title": "Never Trust, Always Verify",
          "duration": "1.5 minutes",
          "content": {
            "concept": "Zero Trust is not a product — it's a mindset. Applied to AI: assume every AI interaction could expose sensitive data.",
            "traditional": {
              "label": "Old Thinking",
              "approach": "Trust internal tools, verify external ones",
              "problem": "AI blurs internal/external — your data leaves your perimeter with every prompt"
            },
            "zeroTrust": {
              "label": "Zero Trust Thinking",
              "approach": "Verify every AI interaction, regardless of tool or user",
              "principles": [
                "No implicit trust based on tool vendor",
                "Continuous verification of data classification",
                "Least privilege — minimal data per interaction",
                "Assume breach — log everything"
              ]
            }
          }
        },
        {
          "id": "classification",
          "title": "Data Classification Before AI Touches It",
          "duration": "2 minutes",
          "content": {
            "insight": "You cannot protect data you haven't classified. AI accelerates the consequences of poor data hygiene.",
            "tiers": [
              {
                "level": "Public",
                "description": "Already public or intended to be",
                "aiRules": "Full AI use permitted",
                "examples": ["Marketing materials", "Published research", "Job postings"]
              },
              {
                "level": "Internal",
                "description": "Not public, but not sensitive",
                "aiRules": "Approved AI tools only, no training consent",
                "examples": ["Meeting notes", "Project timelines", "Internal comms"]
              },
              {
                "level": "Confidential",
                "description": "Business-sensitive data",
                "aiRules": "Isolated/on-premise AI only, no external APIs",
                "examples": ["Financial forecasts", "Strategic plans", "Pricing"]
              },
              {
                "level": "Restricted",
                "description": "Highest sensitivity — legal, regulatory, competitive",
                "aiRules": "No AI processing without explicit approval",
                "examples": ["M&A materials", "IP/patents in development", "PII", "PHI"]
              }
            ],
            "action": "Map your data classification framework to AI use permissions. If you don't have a classification framework, start there."
          }
        },
        {
          "id": "vendor-diligence",
          "title": "Vendor Due Diligence Questions",
          "duration": "2 minutes",
          "content": {
            "context": "Your AI vendor's terms of service are your exposure. Ask before you sign.",
            "questions": [
              {
                "question": "Do you train on customer data?",
                "goodAnswer": "No. Customer data is never used for model training.",
                "redFlag": "We may use aggregated, anonymized data to improve our models."
              },
              {
                "question": "Where does my data reside?",
                "goodAnswer": "Data remains in your specified region and is deleted after processing.",
                "redFlag": "Data may be processed in any of our global data centers."
              },
              {
                "question": "Who can access my prompts and outputs?",
                "goodAnswer": "Only your authorized users. We do not have access without explicit permission.",
                "redFlag": "Our trust and safety team may review interactions."
              },
              {
                "question": "What certifications do you hold?",
                "goodAnswer": "SOC 2 Type II, ISO 27001, and industry-specific (HIPAA BAA, etc.)",
                "redFlag": "We're working toward certification."
              },
              {
                "question": "What happens if there's a breach?",
                "goodAnswer": "Immediate notification, defined SLAs, clear liability terms.",
                "redFlag": "Per our terms of service, liability is limited."
              }
            ],
            "tip": "Have your legal team review AI vendor contracts with the same rigor as cloud provider agreements."
          }
        },
        {
          "id": "ai-bom",
          "title": "The AI Bill of Materials",
          "duration": "1.5 minutes",
          "content": {
            "concept": "Just as software has SBOMs (Software Bill of Materials), AI needs AI-BOMs.",
            "definition": "An AI Bill of Materials documents every AI system touching your data, who uses it, and under what terms.",
            "components": [
              {
                "element": "AI System Inventory",
                "description": "Every AI tool in use (sanctioned and shadow IT)"
              },
              {
                "element": "Data Flow Map",
                "description": "What data goes into each AI, what comes out, where it's stored"
              },
              {
                "element": "Terms Matrix",
                "description": "Training rights, data residency, and liability by vendor"
              },
              {
                "element": "User Registry",
                "description": "Who has access to which AI tools, under what policies"
              },
              {
                "element": "Risk Assessment",
                "description": "Severity rating per AI system based on data it can access"
              }
            ],
            "callToAction": "Ask your CISO: Do we have an AI Bill of Materials? If not, who owns creating one?"
          }
        }
      ],
      "assessment": {
        "type": "checklist",
        "items": [
          "We have a data classification framework",
          "Our AI vendor contracts prohibit training on our data",
          "We know which AI tools employees are using",
          "We have documented AI data flows"
        ]
      }
    },

    {
      "id": "protection",
      "number": 3,
      "title": "Protecting Your Organization",
      "duration": "6 minutes",
      "objective": "Leave with concrete actions you can take this week",
      "chapters": [
        {
          "id": "quick-wins",
          "title": "Quick Win: AI Acceptable Use Policy",
          "duration": "1.5 minutes",
          "content": {
            "context": "You need a policy before you need technology. Most organizations have neither.",
            "policyElements": [
              {
                "element": "Scope",
                "content": "Covers all AI tools — not just 'approved' ones"
              },
              {
                "element": "Data Rules",
                "content": "What data can and cannot go into AI systems, by classification"
              },
              {
                "element": "Approved Tools",
                "content": "Specific tools sanctioned for use, with any restrictions"
              },
              {
                "element": "Prohibited Actions",
                "content": "No PII, no source code, no confidential financial data, etc."
              },
              {
                "element": "Consequences",
                "content": "Clear enforcement — this is a real policy, not guidelines"
              },
              {
                "element": "Exception Process",
                "content": "How to request approval for edge cases"
              }
            ],
            "timeline": "A basic policy can be drafted in a week. Don't let perfect be the enemy of done.",
            "resource": "Template available in supplementary materials"
          }
        },
        {
          "id": "three-tier",
          "title": "The 3-Tier Approach: Block/Gate/Allow",
          "duration": "2 minutes",
          "content": {
            "framework": "Every AI interaction falls into one of three categories. Define the rules once, enforce everywhere.",
            "tiers": [
              {
                "tier": "BLOCK",
                "description": "Prohibited AI uses — no exceptions without executive approval",
                "examples": [
                  "Personal AI accounts for work data",
                  "AI tools from non-vetted vendors",
                  "Any AI use with restricted data",
                  "AI-generated code in production without review"
                ],
                "enforcement": "Technical controls (DLP, network blocks) + policy"
              },
              {
                "tier": "GATE",
                "description": "Permitted with guardrails — requires training or approval",
                "examples": [
                  "Approved AI tools with confidential data (isolated instances)",
                  "AI for customer-facing content (human review required)",
                  "AI coding assistants (approved tools, sandboxed)",
                  "AI for financial analysis (audit trail required)"
                ],
                "enforcement": "Logging, review workflows, training requirements"
              },
              {
                "tier": "ALLOW",
                "description": "Open use — go fast with public/internal data",
                "examples": [
                  "AI for drafting (public-facing content)",
                  "AI for research on public information",
                  "AI productivity tools with non-sensitive data",
                  "AI for learning and skill development"
                ],
                "enforcement": "Light-touch monitoring, annual training"
              }
            ],
            "principle": "Default to GATE, not ALLOW. Move categories based on evidence, not enthusiasm."
          }
        },
        {
          "id": "checklist",
          "title": "Executive Checklist for AI Governance",
          "duration": "1.5 minutes",
          "content": {
            "intro": "Seven items every executive should be able to check off.",
            "items": [
              {
                "number": 1,
                "item": "AI Acceptable Use Policy",
                "status": "Published, communicated, enforced",
                "owner": "CISO + Legal + HR"
              },
              {
                "number": 2,
                "item": "AI Tool Inventory",
                "status": "Complete list of sanctioned and known shadow AI",
                "owner": "CISO + IT"
              },
              {
                "number": 3,
                "item": "Vendor Contract Review",
                "status": "All AI vendors reviewed for training rights",
                "owner": "Legal + Procurement"
              },
              {
                "number": 4,
                "item": "Data Classification Mapping",
                "status": "AI use rules per data classification tier",
                "owner": "CISO + Data Governance"
              },
              {
                "number": 5,
                "item": "Employee Training",
                "status": "All staff trained on AI policy (not optional)",
                "owner": "HR + CISO"
              },
              {
                "number": 6,
                "item": "Incident Response Plan",
                "status": "AI-specific scenarios in IR playbook",
                "owner": "CISO"
              },
              {
                "number": 7,
                "item": "Board Reporting",
                "status": "AI risk on regular board agenda",
                "owner": "CEO + CISO"
              }
            ]
          }
        },
        {
          "id": "monday-morning",
          "title": "One Question for Monday Morning",
          "duration": "1 minute",
          "content": {
            "setup": "You now know enough to ask the right question. Here it is:",
            "question": "Can you show me — right now — every AI tool our employees used last month and what data they put into it?",
            "whyThisWorks": [
              "If yes: You have visibility. Now optimize.",
              "If no: You've identified your first priority.",
              "If 'we don't track that': You've identified your first investment."
            ],
            "expectation": "Your CISO should be able to answer this. If they can't, that's a resourcing conversation, not a performance issue.",
            "closing": "AI is moving fast. Your governance doesn't have to be perfect — it has to exist. Start Monday."
          }
        }
      ],
      "assessment": {
        "type": "commitment",
        "prompt": "Write down one action you will take in the next 7 days based on this training."
      }
    }
  ],

  "supplementaryMaterials": [
    {
      "id": "policy-template",
      "title": "AI Acceptable Use Policy Template",
      "format": "Word/PDF",
      "description": "Customizable template with all required sections"
    },
    {
      "id": "vendor-questionnaire",
      "title": "AI Vendor Security Questionnaire",
      "format": "Excel",
      "description": "Due diligence questions for AI vendor evaluation"
    },
    {
      "id": "ai-bom-template",
      "title": "AI Bill of Materials Template",
      "format": "Excel",
      "description": "Inventory and risk tracking for AI systems"
    },
    {
      "id": "board-briefing",
      "title": "AI Risk Board Briefing Deck",
      "format": "PowerPoint",
      "description": "Ready-to-present slides for board reporting"
    }
  ],

  "completionCriteria": {
    "required": [
      "Watch all three modules",
      "Complete reflection assessments"
    ],
    "recommended": [
      "Download policy template",
      "Share with leadership team",
      "Schedule CISO meeting"
    ]
  }
}
