AI TRAINING & ENABLEMENT

Field guides and sources

Use these short templates during real work. Replace bracketed text, keep inputs inside approved tools, and preserve the human review point that matches the risk.

AI task-fit gate

Run this check before sharing data or connecting a tool. If one answer is unclear, pause and use the approved governance or security path.

1. Tool and data

  1. Is the tool approved for this task?
  2. What is the data classification?
  3. Can the task use sanitized or public inputs instead?

2. Action and review

  1. What may the AI read, change, send, or publish?
  2. What evidence will verify the result?
  3. Who approves the next consequential step?

Request canvas

Use the fields that change the work. Leave out fields that add length without changing the result.

Outcome

I need [artifact, decision, or change] for [audience or owner].

Context

Use [approved sources]. The relevant current state is [facts].

Constraints

Stay within [scope]. Follow [policy, tone, standard]. Do not [exclusions].

Example

Use [representative input or approved pattern] as a reference. Keep policy in its approved source.

Format

Return [structure] with [required fields, citations, or labels].

Checks

Before finishing, compare the output with [acceptance criteria, source, tests] and mark uncertainty.

Output release check

Review effort should match the cost of being wrong.

Evidence

  • Facts, numbers, quotes, and citations match the source.
  • Required material is complete and current.
  • Unknowns, assumptions, and model limitations remain visible.

Use

  • The output answers the requested task and audience need.
  • Confidentiality, privacy, security, IP, and licensing rules are met.
  • The accountable owner approves before the work affects clients, systems, money, or people.

Harness task brief

Use this brief for an approved technical harness. Ask it to inspect and propose a plan before changes.

Task

Goal: [requested behavior]

Relevant evidence: [ticket, files, error, logs]

Acceptance criteria: [observable conditions]

Boundaries

In scope: [areas that may change]

Out of scope: [areas and actions excluded]

Ask first: [commands or decisions requiring approval]

Project context

[architecture], [conventions], [approved dependencies], [test commands], [security requirements]

Definition of done

[tests pass], [diff reviewed], [docs updated], [assumptions reported], [required owner approves]

Workflow and agent review

Choose a pattern after the workflow is clear. Prefer a prompt, skill, or fixed automation when it solves the problem with less risk.

Work

Trigger, frequency, inputs, output, current time or quality baseline, and accountable owner.

Pattern

Chat, reviewed template or skill, deterministic automation, supervised harness, or agent.

Access

Approved data, minimum tools, narrow permission scopes, and actions that require approval.

Evidence

Checks, logs, tests, output review, pilot metric, failure signal, and recovery path.

Show-and-tell case card

Keep each case to five minutes and remove confidential or identifying information.

Problem and baseline

What task did you improve? Who performs it? How often? What did the old workflow cost in time, quality, or rework?

Method and controls

Which approved tool and context did you use? What could it access? Where did a person review or approve?

Result and evidence

What changed? Show comparable artifacts, elapsed time, test output, review findings, or repeated examples.

Lesson and next decision

What should the team standardize, test again, or stop? Name the owner and the next evidence needed.

Research and program sources

The curriculum uses EXIST’s internal assessment for program priorities and primary sources for technical and risk guidance.

EXIST Current AI Usage Assessment Summary

Internal survey summary with 113 responses collected from 26 August to 3 September 2026.

EXIST AI Training & Enablement Learning Series v0.1

Program objectives, maturity model, delivery format, session runbooks, and success signals.

NIST AI 600-1 Generative AI Profile

Risk guidance covering confabulation, information integrity, privacy, security, human oversight, testing, and monitoring.

NIST AI Risk Management Framework Core

Govern, map, measure, and manage functions, including explicit human roles and repeatable evaluation.

OWASP Top 10 for LLM and Generative AI Applications

Primary security guidance on prompt injection, sensitive information disclosure, improper output handling, excessive agency, and related risks.

GitHub prompt engineering guidance

Practical guidance on clear goals, specific requirements, relevant context, examples, and avoiding ambiguity.

Model Context Protocol specification

Official overview of prompts, resources, tools, control boundaries, and connection patterns.