26 minutesHow to Use NotebookLM (Google's AI "Tool for Understanding")
Observe a source-based notebook workflow and identify the retrieval, citation, provenance, and permission checks needed before relying on it.
IBM Technology. Jeff Crume's "buy an SUV for $1" example is the cleanest 10-minute explanation of why direct and indirect prompt injection are different problems, and why filtering can't fully solve either. It pairs directly with the article's argument that you need least-privilege scopes, a dedicated agent account, and a human in the loop on anything irreversible — not a cleverer system prompt.
Treat this as conceptual guidance. Do not use real company data until permissions, retention, logging and human-review boundaries are clear.
Distinguish direct and indirect prompt injection and why filtering alone is not enough.
None — watchable cold.
Last reviewed: May 18, 2026
Continue through the same learning path with the next curated companion videos.
26 minutesObserve a source-based notebook workflow and identify the retrieval, citation, provenance, and permission checks needed before relying on it.
69 minutesBuild intuition for chunking choices before tuning a real retrieval system.
16 minutesExplain what MCP changes in plain language and decide whether a tool connection should use MCP or a simpler integration.
Hand-picked external courses that go deeper on this topic.
AWS Training and Certification
A cloud-vendor-specific complement to the Macquarie specialization: AWS's own Generative AI Security Scoping Matrix, OWASP Top 10 for LLMs, and MITRE ATLAS, walked through governance, legal, and compliance controls for five different AI deployment scopes — from consumer apps to self-trained models. Not GDPR-specific, but a genuinely practical advanced pick for teams whose AI workloads actually run on AWS and need concrete data-governance and compliance controls, not just theory.
Macquarie University Cyber Security Hub faculty
An advanced pick for professionals responsible for both GDPR compliance and AI security: a three-course specialization from Macquarie University's Cyber Security Hub that goes from GDPR/CCPA fundamentals and privacy-by-design, through privacy impact assessments, to a dedicated third course on securing AI systems against adversarial attacks and model leakage. It genuinely bridges the two rather than treating them as separate topics.
CyberSuite
The rare AI Act course written for the companies the Act actually reaches: SMEs adopting AI, not the labs building it. Hosted on the European Commission's own skills platform, it pairs the legal side — roles, obligations, risk classification — with the security side (prompt injection, data leakage, supplier due diligence) that most compliance courses skip. For an Estonian SME deploying AI, this is the practical starting point.