← Aavistus Training

Methodology

The harness, not the model

These courses are AI-made, and we publish exactly how. The short version: we never ask you to trust the model — we assume every draft is wrong until it survives verification.

Most AI-generated content fails for predictable, human reasons: it sounds authoritative, it rounds a qualified statement up to a confident one, it repeats what every other source repeats, and nobody checks it against the primary text. Our pipeline is built as a countermeasure to those exact failure modes.

How a lesson gets published

1

Grounded generation. A lesson is drafted only from the current consolidated official text (EUR-Lex), fetched and versioned by us. Every unit of source text carries an anchor — regulation, article, consolidation date — and every statement in the lesson must cite one.

2

Deterministic checks. Code, not judgment: citation anchors must resolve to real source units, quotations must appear verbatim in the cited text, structure and coverage rules must hold.

3

Adversarial audit. An independent verification pass reads the draft with one job: refute it. It hunts overstated obligations, dropped qualifiers ("where appropriate", "may"), invented distinctions, and uncited claims — and compares every challenged sentence against the source provision.

4

Fail-closed. A lesson that does not verify cannot be approved and cannot get a quiz. There is no override path. Failed drafts are regenerated carrying every audit finding ever raised for that topic, so the next draft avoids them.

5

Human curation. A person approves each verified lesson before publication. Approval is recorded against the exact lesson version and source basis.

6

Open audit trail. Citations on every lesson link to the official text so you can check us at any time — the same check our own auditor ran.

A real rejection, from our own logs The first draft of our NIS2 governance lesson (Article 20) overstated management liability — it converted "can be held liable" into automatic liability and invented duties the Directive doesn't state. The adversarial audit caught it, the pipeline blocked both approval and quiz generation, and the regenerated draft — written against the recorded findings — passed verification before publication. That lesson shipped late. That is the system working.

Why this much machinery

Because the failure modes of confident content are known. We build our checks against five of them:

The point Verification is what makes AI-generated material trustworthy — not the size or price of the model that drafted it. The harness is the product. That is also why these courses can be free: the same engine, pointed at an organisation's own policies and procedures, produces private, role-scoped compliance training with an audit trail — which is what we sell.

For organisations

The AI Act (Article 4) makes staff AI-literacy a duty for providers and deployers; NIS2 (Article 20) requires management bodies to follow cybersecurity training and offer it to employees regularly. An organisation tier of these courses — your own policies as a cited content layer, private courses, named-staff completion records against the exact version of the regulation — is in pilot preparation. Interested in being the pilot? Contact us via aavistus.ai.