What they did
Summarized a client contract
What actually happened
Confidential terms now sit on a third-party server.
Your team already uses AI every day — quietly, and with company data. Five minutes per employee turns that invisible risk into certified, auditable competence.
what you can't see today
Move your cursor across the dark.
Five minutes of training turns this into daylight.
Not a participation trophy — an audit artifact. Every completion generates evidence you can put in front of an auditor, mapped to the exact clauses they check.
ISO 27001, A.6.3 — covers the awareness and training control in your next audit.
EU AI Act, Article 4 — documents the AI-literacy duty, in force since February 2025.
NIS2, Article 20 — evidence of the training the directive expects entities to extend to their employees.
Verifiable serial — every certificate carries a number an auditor can check against our registry.
noshadow.ai
Training record
This certifies that
María Fernández Ruiz
Andaltec SL
has completed the noshadow.ai Shadow-AI training programme, supporting the AI-literacy duty under Regulation (EU) 2024/1689, Article 4, and the training controls of ISO/IEC 27001:2022 A.6.3 and Directive (EU) 2022/2555, Article 20.
Verify at noshadow.ai/verify/NS-0000-000000
What they did
Summarized a client contract
What actually happened
Confidential terms now sit on a third-party server.
What they did
Drafted a patient report faster
What actually happened
Health data left the EU.
What they did
Fixed a spreadsheet formula
What actually happened
The payroll went with it.
Blocking AI tools doesn't stop this — it moves it to personal phones. Training does. And EU law now agrees.
EU AI Act, Article 4 — every company using AI must ensure its staff are AI-literate. Applicable since 2 February 2025.
NIS2, Article 20 — management must follow cybersecurity training — and entities are expected to extend it to their employees.
Auditors won't ask if you trained people. They'll ask you to prove it.
Five modules, 35 minutes end to end. The first one is free.
1 · 7 min
What Shadow AI is, why it happens in every office, and what actually leaves the building when work data goes into a free AI tool.
2 · 7 min
How to recognize personal data, special categories and company secrets on sight, and why AI tools handle your text differently from other software.
3 · 7 min
How to strip identifiers from any prompt while keeping the task intact, and how to spot the cases where redaction alone is not enough.
4 · 6 min
Why your company approves specific AI tools, how to find the golden path for any task, and why reporting a slip early always beats hiding it.
5 · 8 min
What the EU AI Act, NIS2, and ISO 27001 actually ask of your company, what your certificate proves, and the final assessment for the whole course.
Every completion is recorded against a serial your auditor can check.
€0 no card
Start module 1€29 per employee / year + VAT
Get your team certifiedVolume billed annually + VAT
Talk to usAll prices exclude VAT.
For AI literacy, yes. Article 4 of the EU AI Act (Regulation (EU) 2024/1689) requires providers and deployers of AI systems to take measures ensuring a sufficient level of AI literacy of their staff — applicable since 2 February 2025. NIS2 (Directive (EU) 2022/2555, Article 20) additionally requires the members of management bodies of essential and important entities to follow cybersecurity training, and expects those entities to offer similar training to employees on a regular basis.
Blocking doesn't stop Shadow AI — it moves it to personal phones and private accounts, where you have zero visibility. It also doesn't discharge your AI Act literacy duty: your team still deals with AI embedded in the tools they use every day. Training changes behaviour where blocking can't reach, and produces the evidence blocking never will.
No. The course is hosted at noshadow.ai — employees just need a work email to start, on any device. Nothing to install, nothing to integrate.
About 35 minutes end to end, on any device, and it can be done in short sittings. The first module is free and takes 5 minutes — try it before rolling anything out.
The certificate itself doesn't expire: it's a dated record that a named person passed the assessment on a given day, and that stays true. What changes is the tooling and the rules around it, so companies generally refresh awareness training about once a year and keep each year's certificates in the evidence file.
It's a named, dated training record with a serial number an auditor can verify against our registry. It supports your evidence for ISO 27001 control A.6.3 (awareness, education and training), the AI-literacy duty of EU AI Act Article 4, and the training expectations of NIS2 Article 20. No certificate makes you compliant by itself — this one is built to slot into the evidence file that does.
Five minutes to try it, 35 to certify someone, and evidence your auditor can check by serial.