Home · Mycelium Academy
Stage 03 · Embed

Mycelium Academy

AI training that names your tools, your data and your escalation route, and a signed record of what your people were shown. For everyone who uses AI, and for the people accountable for it. The human pillar, evidenced like every other.
01 · The problem

“Use approved tools.” Which ones?

Most AI training is written for everyone, so it is specific to no one. It tells staff to use approved tools without naming them, to escalate without saying to whom, and to protect sensitive data without defining it.
01

Staff cannot comply

Every instruction ends in a question the module does not answer. People improvise. Improvisation is how shadow AI starts.

02

It evidences nothing

“How did you tell staff which tools are approved?” is not answered by a module that names none.

03

It goes stale invisibly

Your tool register changes in month four. The training does not know. Nobody finds out until an incident.

02 · What changes

The same teaching. Your facts.

Generic awareness training compared with a configured Mycelium module.
 Generic awarenessConfigured
Tools“Use approved tools”Your register, by name, with what each one is cleared for
Escalation“Escalate if unsure”Your team, your channel, your timeframe
Data“Keep sensitive data out”Your classification tiers, with your examples
EvidencesAttendanceThat your rules were communicated, and to whom
Signed byNobodyYour Legal, Risk, Security and Privacy owners

Same module. Same run time. The difference is entirely in what it knows about you.

03 · The modules

The module set.

Two families. Everyone gets the first. The people whose responsibilities carry more than general use also get the second.
All staff

Everyone who uses AI.

The Australian Government policy requires “mandatory training for all staff on responsible and ethical AI use, regardless of their role”, and the National AI Centre asks for understanding built “across the organisation”. These two modules are that baseline.
IV · Enable

AI Foundations

What AI is, and why it is confidently wrong. Where it creates risk: including security, manipulation and synthetic media. When to verify, and against what.

12–15 MIN · 80% TO PASS · RETAKES AND ANSWER REVIEW
IV · Enable

Using AI Here

Your approved tools. Your data rules. Verification, disclosure and records. How to get a new use case approved, and what to do when something goes wrong.

10–12 MIN · 80% TO PASS · FULLY CONFIGURED

Every module carries its own assessment, an 80% pass mark, retakes and answer review. Completion is recorded where the module is deployed.

Role-based

For the people accountable for it.

Additional modules for staff whose responsibilities carry more than general use. The National AI Centre asks organisations to “evaluate the training needs of accountable people and provide appropriate up-to-date training to address gaps”, naming those responsible for legal and regulatory obligations, for handling personal information, for the operation, control, intervention or termination of each system, for oversight and monitoring, and for third-party procurement.
IV · Enable

Approving AI

What an approval commits you to. Testing a risk tier rather than accepting it. The three gates, and what each one asks. Reviewing a decision AI helped produce, and the obligations your approval already sits inside.

16–20 MIN · 80% TO PASS · OBLIGATIONS BY JURISDICTION

Also in this family: AI security and manipulation · AI in recruitment and HR · AI for procurement and vendor management.

04 · How it is configured

Owned by the people who already hold the answers.

Nobody fills in a blank document. Each area routes to the function that already owns it, and is signed off by that function before anything publishes. What you supply is a decision, not a specification.
The publication gate

A module that cannot name your approved tools does not publish. Ten business days from kickoff where your policy artefacts already exist, and where they do not, finding that out is itself the finding.

05 · Staying current

Training that does not go quietly wrong.

Your facts change. Your tool register, your incident route, the regulations that apply to you. Mycelium tracks which modules depend on which facts, identifies every module affected when one moves, and blocks republication of a safety-critical section until its owner has refreshed it.

The alternative is training that was accurate the week it launched and quietly wrong six months later, with nobody accountable for noticing.

06 · The evidence

Every publication produces a Governance Pack.

It lodges alongside your governance, security and operations evidence in the Evidence Platform — not in a separate LMS report. It prints its own expiry date.
01Modules published, versions, build identifier, date and the population coveredEvidenced
02Every organisational statement your staff were shown, in plain languageEvidenced
03Which obligations apply, and who in Legal confirmed the setAttested
04Anything omitted, why, and who decidedAttested
05Each section, its owner, its approver and its next review dateEvidenced
06Accessibility is assessed to WCAG 2.2 AA as part of the buildEvidenced
07 · Start here

Start with the diagnostic.

The Boardroom Diagnostic scores all fourteen dimensions, including D13 and D14. It tells you whether your literacy gap is a content problem or a governance problem. Those need different work.