The Evolving Cybersecurity Workforce is one of six short AI courses I bought from ISC2 in May 2026, and despite the title it is mostly about AI risk and governance, not careers. Running underneath it is a steady note of reassurance that AI is not going to take your security job. The content is non-technical: how to set AI policy, what the risks of AI tools are, how a company should respond, and which privacy regulations bear on AI use. None of it was new to me – I have worked with both AI and privacy regulation in a compliance role – but as a survey of the legal and governance terrain, it holds up. Whether you should believe the reassurance is a different question.

What It Covers

The substance is governance: setting AI policy, the risks of putting AI tools into corporate processes, and how organizations should respond. It spends real time on the privacy regulations that intersect with AI and on the danger of adopting AI without corporate controls in place. It is non-technical throughout – policy and compliance material, not engineering. What it will not do is let you write a policy on its own; no course this short can. What it does is map the challenges and point you at the regulations worth reading in full. That makes it a reasonable starting point from either direction: if you know AI but not the legal landscape, or if you know the legal landscape but not AI. If you want the wider regulatory tour – many more standards and laws, named and mapped – Aligning with Global AI Regulations is the fuller version of this material; this is the lighter pass. I’m not sure the bundle needed both.

The point worth flagging is its treatment of shadow AI – what used to be called shadow IT or skunkworks, here meaning AI quietly woven into company processes without upper management’s knowledge. A leadership team’s first reaction to the catalogue of AI risks, and to the size of the fines European regulators can levy, is often to reach for a restrictive policy or an outright ban. The course’s useful warning: do that before you understand how much of your existing process is already entangled with AI, informally, and you will try to ban something you cannot actually stop – or did not know you were already running.

What’s unique about this one is explaining the risks in corporate language. If you have a non-technical audience very enthusiastic about AI adoption and resisting the need for risk mitigation, this one will scare them straight. And if you have the opposite, this course makes the case that it’s going to happen anyway; the question is whether adoption is guided by risk mitigation policies and procedures, or remains hidden until something goes wrong.

Verdict

Three stars. There was no new information here for me, and there is no technical content to speak of. But as a survey of the legal and governance field around AI, it is useful, and the shadow-AI warning alone is worth a management team’s attention. A starting point for the legal landscape, honestly pitched as one, and more about mapping the safe path through the terrain than naming the obstacles.


Part of The ISC2 AI Course Bundle . More from the bundle: AI for Cybersecurity · Foundations of AI · Aligning with Global AI Regulations · AI Security: Managing Overconfidence · Planning for Secure by Design AI