Most AI training starts with a list of prohibitions and ends with a team that is more afraid and no more capable. This one runs the other direction. We start with the work your people actually do, put the right tool on each job, and leave them faster by Monday. Where regulation genuinely binds you, the compliance layer gets added on top — after the capability, not instead of it.
Work first. Then the AI.
Plan your workshop Prefer email? Send me the details →Four commitments that decide what happens in the room. If a training doesn't hold these, it produces caution instead of capability.
The first question is never "which AI should we buy." It's what work your people are doing that they shouldn't have to, and what they'd do instead with the time back. The tool falls out of that answer.
"Don't paste client names" survives until the first deadline. Understanding where data actually goes — training ingestion, retention, sub-processor fan-out — survives permanently, and it generalises to tools that don't exist yet.
Rules taught before competence read as distrust and get quietly ignored. We establish what the team should be doing first. The guardrails then read as protection for work they already value.
The day ends with an artifact — a working standard your team wrote themselves, not a policy I handed you. That is the difference between training that fades in three weeks and training that becomes how the place operates.
The kind of work that disappears is not the same as the kind of jobs that disappear. Training that only teaches restriction misses that entirely — and your people can tell.
I map how work and data actually move through your organization and hand you a sequenced roadmap. I do the analysis.
I take the one task your team repeats most and leave it running by itself, inside the tools you already use. The software does the work.
I transfer judgment and working habits into your people. They do the work, better, and they can keep doing it after I leave.
The Audit tells you what to change. The Build changes one thing for you. The Workshop makes your team able to change things themselves.
Both run as a half-day or full-day, virtual or on-site. The difference is who's in the room and what they walk away with.
For teams adopting AI who want to actually use it well — the right tool for each job (ChatGPT to create, Claude to analyze, Perplexity to research, Copilot in the workflow), the prompts and workflows that make people faster this week, with the safety basics built in.
For regulated teams — law, healthcare, finance, real estate — where data can't leave the building and output has to survive an audit. Everything in Track 1, plus the obligations that bind you and a documented, defensible standard.
What you buy is the format. Virtual or on-site is how it's run — every format is available either way.
Not a whole team, just one broken workflow? Start with a One Workflow Built 60-minute AI Strategy Session at $250.
Need the governance artifact, meaning an acceptable-use policy, a data-flow map and a vendor review, rather than training? That is the Workflow Audit at $3,500.
Skip this section if you are not in a regulated field. If you are under Rule 1.6, HIPAA, FERPA, GLBA, or SEC scrutiny, this is the part that matters — and the reason Track 2 exists. "Exposing data" isn't one thing called "leaking"; it's losing control of where sensitive data goes once it enters the tool. Three concrete mechanisms, none with a clean human analog — taught from the engineering side.
Paste into a consumer tool and, by default, your input can be absorbed into a future model — and resurface in a stranger's output. The data doesn't go to someone; it becomes part of a system that repeats a version of it to everyone.
Your input sits on the vendor's servers under their policy — staff-accessible, breachable, and discoverable or subpoenable. Even if it's never trained on, a copy now exists outside your control.
The vendor routes it to sub-processors and jurisdictions you never vetted. One paste, N systems — and you can't say where it ended up.
Why it's categorically different from telling a person.
Human disclosure is bounded and clawback-able — one recipient, themselves bound by duty, information that doesn't self-replicate, and you know who has it. AI disclosure is unbounded and persistent — you can't scope who sees a derivative, can't retract it, can't guarantee it won't reappear in someone else's answer, and can't tell a regulator where it went. That contrast is the point: your data is supposed to stay inside your walls and under your control.
Built as stackable modules: the half-day runs the first five, the full-day adds the labs. Same spine, escalating depth.
The mental model most people have never had: input → vendor → maybe training → maybe retained → maybe subpoenable.
Training leakage, retention and breach, and confident-wrong output on high-stakes calls — how to spot each in the wild.
Consumer vs. Enterprise/Edu vs. API-with-a-DPA. What a DPA or BAA actually guarantees, and how to read the badge.
The minimum-necessary discipline. Live exercise: sanitize a real (fake) record, then prompt it safely.
What you should do — the workflows that make people faster on de-identified work. Leave capable, not paralyzed.
Human-in-the-loop verification, cross-checking, and citation discipline — the fake-case-law disasters exist for a reason.
What documentation the org should hold — DPA, acceptable-use policy, data-flow map — and how an individual protects themselves.
Convert the day into a policy the organization keeps using after I leave.
Do you handle sensitive or regulated data? If not — general operations, client service, marketing, ops — Track 1 (Enablement) gets your team productive with AI fast, with the safety basics built in.
If yes — client files, patient records, student data, deal terms, financial records, proprietary IP, anything a regulator, client, or opposing party could later ask about — Track 2 (Compliance-ready) maps the training to the rules that actually bind you.
Not sure? The free AI-Readiness check sorts it in five minutes — and points regulated teams to the Workflow Audit if you need the governance artifact rather than training. Rules covered where they apply: Rule 1.6, HIPAA, FERPA, GLBA, state privacy law.
They run in price order and in dependency order, and that isn't a coincidence. Each one produces the input the next one needs. You can stop after any of them and still be better off than when you started.
Decide what to change and in what order. One workflow, priced in dollars, with a written implementation plan you keep. Nothing here obligates you to spend another dollar.
See what happens in the hour →The single workflow from that plan, running by itself inside the tools you already use. Built on your real documents, living in your own Google or Microsoft account. Your $250 comes off the price.
See the five days, day by day →For work that crosses departments, where building one workflow only fixes one seam. An end-to-end map of how the work and the data actually move, then a roadmap of what to automate and in what order.
See what the two weeks produce →Two things get built in the room. Your AI tech stack, meaning which tool belongs on which job and the workflows that make people faster by Monday. And your governance standard, meaning what leaves the building and what never should, written by your own team so they actually keep it.
A production system deployed inside your own infrastructure, scoped from a completed Workflow Audit. This is the only one with a prerequisite, because building at this size without the map is how six-figure AI projects get written off.
See what is in scope →Before any of them, the free AI-Readiness Check takes five minutes and tells you what the work is costing you a year. Most people should start there.
Tell me your field and roughly who's in the room. You'll get a straight recommendation on format and a fixed number — no drawn-out sales process.
Plan your workshop Prefer email? Send me the details →