Introducing Trust Drills: six two-minute scenarios for the AI-era front desk
Six free interactive drills — deepfake voice calls, shadow-AI leaks, chatbot mistakes, vendor pitches. On any device. No login. Nothing stored. Some are scams. Some aren't.
TL;DR
- Trust Drills is a new free training feature at /drills — six two-minute scenarios that put community-organization staff inside the AI-era pressure moments they already face.
- Every drill runs on a phone with no login, no cookies, and nothing stored. Free-text replies are adjudicated by an AI helper; a fallback keeps the drill working even when the model is unavailable.
- Scenarios cover deepfake voice calls, shadow-AI data leaks, chatbot hallucinations under pressure, high-pressure vendor pitches, board-meeting synthetic media, and a legitimate-looking request that isn't a scam at all.
- The goal isn't to teach policy — it's to build the reflexes: verify out-of-band, bring in a second person, and treat urgency as the tell.
- Anyone at your organization can run a drill in the time it takes to make coffee. Send the link. That's the training plan.
Most AI-safety training for community organizations is a slide deck about a policy no one has read. Trust Drills is the opposite. It's six short, interactive scenarios you can run on your phone during a coffee break, and each one drops you into a decision the front desk, the executive director, or the board chair is already making — sometimes without realizing it.
You can try it right now at /drills. No login. No account. Nothing stored on our end. Pick a drill, make choices, get a debrief in about two minutes.
Why we built this
Talking to municipal staff and nonprofit teams across Canada, the same pattern keeps showing up: the policy is being drafted upstairs while the pressure lands downstairs. A voice that sounds like the executive director calls the front desk on a Friday afternoon and asks for an urgent wire transfer. A program coordinator pastes a client's intake notes into a free chatbot to summarize them. A council member forwards a slick 'AI-powered' vendor pitch and asks what the team thinks by Monday.
None of those moments are solved by knowing the policy exists. They're solved by having practiced the reflex — the small pause where you notice the urgency, the new banking details, the request for secrecy, or the confident answer that no one has verified.
What's in the launch pack
Six drills, ordered roughly by role and pressure profile:
- The Synthetic Trust Heist — a deepfake voice call to the front desk asking for an urgent vendor payment before 5 p.m.
- Shadow AI at the Front Desk — a well-meaning colleague drafting a client email in a free chatbot, with the intake notes still in the prompt.
- The Confident Chatbot — a public-facing help widget that answered a resident's question wrong, and now the resident is at the counter with the screenshot.
- The Board-Meeting Deepfake — a video clip circulating before Monday's meeting that appears to show a board member saying something they didn't.
- The Friday Vendor Pitch — a high-pressure sales call offering a pilot price that only survives if you sign today.
- The Legitimate Ask — a request that pattern-matches to every scam signal, but is actually real. The point isn't to teach you to say no to everything.
How the drills work
Each drill is a short branching scenario. You see the incoming call, message, or meeting note, and you pick how to respond — or type your own reply. An AI adjudicator classifies the free-text response (verify, escalate, stall, comply, challenge, or channel-shift) and routes you to the next beat. If the AI is unavailable, a deterministic fallback keeps the drill flowing, so nothing depends on a live connection.
At the end you get a debrief: which competencies you exercised, which tells you missed, and three linked resources you can send to a colleague. Nothing about your session is stored — no account, no cookie, no per-user analytics.
The three reflexes we're training
Verify out-of-band. Bring in a second person. Treat urgency as the tell. If a drill teaches nothing else, it should teach those three.
Who this is for
- Front-desk and admin staff who take the first call when something goes sideways.
- Program managers using AI tools day-to-day without a formal policy behind them.
- Executive directors who need a two-minute artifact to send to a board before Monday.
- IT and security leads who want a lightweight tabletop exercise for a staff meeting.
- Council members and volunteers who want to feel the pressure moment once before it lands for real.
Privacy: what we don't collect
Trust Drills is intentionally anonymous. There is no sign-in, no cookie set by the drill itself, and no per-user profile. Free-text responses are sent to the adjudicator to classify the intent, then discarded. We don't attach your responses to an account, because there is no account. If the fictional community, N'Ihu, sounds familiar, that's on purpose — the scenarios are composites, not case studies.
What's next
This is a launch pack, not the finished library. We're planning drills on procurement red flags, records-request handling in an AI-assisted workflow, and a longer 'the day after an incident' scenario. If your team runs a drill and hits a moment we didn't cover — or if you'd like a version with your own organization's playbook wired in — email support@gotaipolicy.ca and tell us what you'd want next.
Try a drill now
Go to /drills, pick any scenario, and give it two minutes. Send the link to one colleague when you're done. That's the whole training plan.
Resources and further reading
- Run a Trust Drill (no login required)
- Canadian Centre for Cyber Security — Generative AI guidance (ITSAP.00.041)
- Canadian Anti-Fraud Centre — Spear phishing and CEO fraud
- Office of the Privacy Commissioner of Canada — Artificial intelligence
- NIST AI Risk Management Framework
- AI for community organizations — starter guide
Go deeper with Starter
If you want to move from drills to a written policy your team can actually follow, Starter includes a 14-day free trial and gives solo practitioners full private policy reviews, comparisons, and exports. See /pricing.
Frequently asked questions
What is a Trust Drill, exactly?
A short, scenario-based exercise where your team practises the moments a policy actually needs to survive: a convincing deepfake voice call, a phishing email that looks like it's from a supervisor, a chatbot asking for private data, a vendor overselling accuracy. You make a judgment call, and the drill shows the consequences and the better move.
Do we need to prepare anything to run one?
No prep. Open /drills, pick a scenario, share the URL if you want colleagues to join. A short intro screen sets context; the debrief prompts the conversation. Bring the team; the drill brings the scenario.
Is it free?
Yes for individuals and small teams — playing drills, sharing URLs, and reading debriefs is free. Starter lifts audio-narration budgets and dashboards; Pro adds team-wide cohort reporting inside a Workspace.
Who is Trust Drills for?
Any team that has to make AI-adjacent judgment calls under time pressure — municipal staff, front-desk teams, nonprofits, finance, HR, communications. If your AI policy has a line like 'staff should recognize suspicious activity,' Trust Drills is how you make that line real.
Does playing a drill collect data on individual staff?
Aggregate choices power the debrief and (on Workspace) org-level trends. We do not publish or expose individual scores back to managers. The point is to build judgment, not to grade people.
About this post
This post was drafted by Anya, the Got AI Policy AI research assistant, and reviewed by the Got AI Policy team in mid-2026. You can learn more about how Anya works at /author/anya.