Every Trust Drill now has its own shareable URL
Six Trust Drills, six clean URLs. Send a colleague straight into the deepfake call, the shadow-AI leak, or the Friday vendor pitch — no picker, no login, nothing stored.
TL;DR
- Each of the six Trust Drills scenarios now has its own public URL under /drills/<scenario> — heist, leak, heat, list, chatbot, vendor.
- The /drills landing page is still the explainer and hub; the per-scenario URLs are what you actually send to a colleague or paste into a staff-meeting agenda.
- Each URL has its own title, description, and social preview, so a link shared in email or Slack shows what the drill actually is instead of a generic landing card.
- Nothing about the experience changed: still two minutes, still on any phone, still no login and nothing stored.
- If you linked to /drills before, those links keep working — the landing page now lists all six scenarios as cards.
A small but useful change to Trust Drills this week: every scenario now has its own permanent URL. Instead of sending someone to /drills and asking them to pick the right card, you can send them straight into the drill you actually want them to run.
The six URLs
- /drills/heist — The Synthetic Trust Heist (deepfake voice call, gift-card ask before 5 p.m.)
- /drills/leak — The Shadow-AI Leak (pasting a member spreadsheet into a public chatbot the night before a grant is due)
- /drills/heat — The Heat-Wave Call (an unknown number claiming Emergency Management, cooling-centre advisory in an hour)
- /drills/list — The Member-List Ask (a Board Chair email from an unusual address asking for the full membership list)
- /drills/chatbot — The Chatbot Mistake (a long-time member at the counter with a screenshot of a wrong answer)
- /drills/vendor — The Vendor Pitch (a Friday discount, a three-year contract, and U.S. data residency)
Why this matters for training
The whole point of Trust Drills is that the training plan is: send the link. When the link goes to a landing page, some people bounce before they pick a scenario. When the link goes straight into a two-minute drill on their phone, they play it. That's the entire difference between a training email that works and one that doesn't.
It also means you can build a small curriculum out of drills without any tooling. Week one: /drills/heist. Week two: /drills/vendor. Week three: /drills/leak. Paste one URL a week into the staff channel. Done.
Better link previews
Each scenario URL now has its own title, description, and Open Graph tags. When you share /drills/heist in Slack, Teams, or email, the preview shows the deepfake-call scenario specifically — not a generic 'Trust Drills' card. The same goes for search engines: each scenario is its own indexable page instead of six identical hash anchors on a single landing page.
What didn't change
- Still free. Still no login. Still no cookie set by the drill itself.
- Free-text responses are still adjudicated by an AI classifier with a deterministic fallback.
- The /drills landing page is still the plain-language explainer, with cards linking into all six scenarios.
- Any existing link to /drills keeps working — nothing to update on your side.
Try it now
Pick a scenario, open the URL on your phone, and send it to one colleague when you're done. That's the whole training plan.
Resources and further reading
Frequently asked questions
Do participants need an account to join a shared drill?
No. Anyone with the scenario URL can join and play from a browser — no sign-in, no install. The host account keeps history and scoring in their /drills dashboard.
Is the shareable link private?
The URL itself is unguessable and only works for the scenario it encodes. Treat it like a meeting link: send it to the participants you want, and don't publish it in public channels if the debrief involves sensitive discussion.
How long does a drill take to run?
Most scenarios are about two minutes of play plus a short debrief. They're designed to fit inside a stand-up, an all-staff huddle, or the first block of a training session — not to eat an afternoon.
Is it free to share drills with our team?
Yes. Sharing a scenario URL is free for everyone. Higher-volume hosting features — unlimited history, cohort dashboards, audio narration budgets — are lifted on Starter and above.
Which drill should we run first?
Start with a deepfake-voice or phishing scenario if your team touches finance or client data; start with a chatbot-leak scenario if staff already use AI assistants informally. The point is to practise the exact judgment failure your policy is trying to prevent, not the most exotic one.
About this post
This post was drafted by Anya, the Got AI Policy AI research assistant, and reviewed by the Got AI Policy team in mid-2026. You can learn more about how Anya works at /author/anya.