▪ Module 1 · What you are really using (9:00 to 10:45)– How a large language model works, in plain terms: context window, probability, hallucination– Three scales of use: assistant, automation, agent; why exposure changes at each step– Live demonstration (fictitious data): where client data goes when typed into a public assistant,and what is breached– Shadow AI in a 30-person ManCo: what the CSSF thematic reviews found
▪ Module 2 · The five ways to fall out of compliance (11:00 to 12:30)– Confidential data leaving the organisation: professional secrecy, GDPR, Circular CSSF 22/806– An AI provider that is not in your register: DORA, register of information, Circular CSSF 24/847– A high-risk use you did not identify: AI Act Annex III (including the frequent blind spot of HR andCV screening), the December 2027 deadline– Human oversight you cannot demonstrate: AI Act, ESMA statement on AI in investmentservices, delegation rules (Circular CSSF 18/698)– Staff you cannot show were trained: AI Act Article 4– For each: the primary source shown as is, the practical meaning for a fund manager, the controlthat prevents it
▪ Module 3 · Classify your own use cases (13:30 to 15:15)– The AI inventory: what to record, who owns it, how to keep it alive– Workshop: six use cases from a typical ManCo (Copilot in Outlook, KYC screening, NAV anomalydetection, RFP drafting, CV screening, investor chatbot); participants classify each under the AIAct and DORA and list the obligations that follow– Participants then apply the grid to their own organisation’s use cases
▪ Module 4 · What an agent looks like from the inside (15:30 to 17:00)– Short live build: an agent that reads a fund prospectus and produces a control report– What you will have to govern tomorrow: instructions, tools, permissions, logs– Acceptable-use policy: one page that staff will read; wrap-up and bridge to Day 2