Artificial intelligence

Why AI in security training only helps if it knows where you are

Why AI in security training only helps if it knows where you are

The difference between a chatbot bolted onto a course and an assistant that knows which decision you’re facing.

Kinds Security Team

Last reviewed

The difference between a chatbot bolted onto a course and an assistant that knows which decision you’re facing.

An employee is partway through a phishing workshop. On screen is a message about a vendor changing its bank details, and two ways forward. They’ve lost the thread. So they type into the box at the bottom of the screen: “Sorry, what am I actually deciding here?”

The answer comes back about the vendor bank-details change. Not a definition of phishing. Not a link to a help centre article. The specific decision, on the specific screen, in the story they’re already inside.

The gap between those two kinds of answer is the entire feature.

Security training has always been a monologue

A video plays. A quiz follows. Somewhere in the middle, a real question forms in someone’s head. Wait, would that actually work on me? I think I did this last week.

Nobody asks it. There’s nobody to ask. Best case it comes up days later, to a colleague, half-remembered. Normal case it evaporates.

Kinds puts an assistant called Clay inside the lesson. The employee is standing in front of a specific decision in a specific story, and they can stop, ask, get a real answer, and step back into it. The workshop waits.

The interesting part isn’t that there’s a chatbot. It’s what the assistant knows at the instant the question is asked.

The lesson isn’t a video

Clay makes no sense without this part.

A Kinds workshop is a story an employee walks through one screen at a time, and it branches based on what they choose. Each screen has some narration, sometimes something to look at like a text message thread or a video clip, and usually two or three ways to go next. There are 418 screens across the library, and on 85 of them the employee makes a real decision where one choice is right and the others aren’t.

The story is personal before Clay says a word. It uses the employee’s own name, their company’s name, their job title, and their real manager’s name. The phishing workshop opens by telling someone that the CEO of their actual company can be made to call them in a voice that isn’t the CEO’s.

What Clay knows when someone asks

Every answer is built from five sets of instructions, stacked from most general to most specific, assembled fresh on Kinds servers each time a question is asked.

1. Kinds policy. Tone, honesty, privacy, and what to do if someone reports a real incident. Nothing below can weaken it. 2. Account. Guidance an MSP or parent company wrote once, applying to every company underneath it. 3. Organization. Guidance for this specific company, which overrides the account level where they disagree. 4. Employee. Their name, role, department, and company, taken from their signed-in account. 5. Workshop. What this workshop is allowed to teach, plus exactly where they are: what the narration just said, what the choices on screen are, and whether this screen is graded.

Layer five is the one that makes the opening example possible. Everything else is what stops the answer being wrong.

Every workshop also comes with a set of facts, behaviours, and hard limits written by hand, and Clay has to stay inside it. The phishing workshop’s set carries a core rule (verify any request for money, credentials, or access on a channel you already trusted, never the number or link the message handed you), the behaviours being taught, the facts it may quote exactly, and the limits: teach the defense only, never help anyone build a convincing clone, and don’t add losses, dates, or incidents the workshop doesn’t cite.

Across the library that’s 102 facts, 79 behaviours, 70 limits, and 331 teaching notes, one for every screen. Clay only ever sees the note for the screen the employee is actually on. The other 330 would be noise.

That’s the whole difference. A general chatbot can define phishing. It can’t know that you’re looking at a vendor asking to change its bank details, that this workshop may cite one figure and is forbidden to invent another, and that your company runs Okta.

Coach, don’t gatekeep

This is the policy that most changes how it feels, and it runs against how most educational AI is built.

Ask a typical tutoring assistant for the answer and it says “well, what do you think?” Kinds went the other way and wrote it into policy as non-negotiable. From the product text:

It is fine to ask, fine to help, including with the answer to the workshop question the learner is currently facing. If they ask what the right choice is, tell them plainly and say why, then let them make the choice on the rails. Never say you can’t or won’t give the answer, never withhold it to make them work for it, and never answer a request for the answer with only a hint.

The reasoning matters more than the rule. Opening the chat is already more effort than guessing, so someone who asks has opted into learning. Making them work for it teaches them not to ask again. A coy assistant that doles out hints trains people to stop asking, which is precisely the behaviour security teams are trying to fix.

The moment the whole thing justifies itself

An employee, quietly, mid-workshop: “I think I actually clicked a link like this last week on my work laptop.”

Clay points them at their own organization’s security contact and encourages them to report it even if they’re unsure. It does not attempt to run the incident itself.

A training module just surfaced a live incident that would otherwise have gone unreported.

Every security team has a number for how long an average compromise sits undetected. Nobody has a line item for “the employee remembered mid-training and had somewhere to say it.”

The same policy covers the adjacent moments. Someone who admits to reusing one password for six years gets no shaming language and still gets the actual move. Someone who took the wrong branch and feels stupid gets more than a throwaway line, because the workshop is built to let people fail safely and Kinds doesn’t let the assistant undo that.

Answering in your own words

On a graded screen, an employee can ignore the buttons entirely and just type what they’d really do. Clay grades that against the workshop’s marking guide and returns a verdict, a reply in the narrator’s voice, and a sentence that walks them into the next screen.

The design decision worth the most attention is what happens when someone stops short.

What the employee types

Verdict

Reasoning

“I’d ring my manager on the number in our internal directory.”

correct

Verified on a channel trusted before the message arrived.

“I’d forward the whole thing to our security team.”

correct

Reporting is the safe move.

“I’d update the account details so the payment run isn’t held up.”

wrong

Acted inside the message. The actual harmful action.

“Honestly I’d just ignore it.”

correct

They didn’t take the harmful action.

“call him”

unclear

Two words that don’t name a channel. Calling back on the number in the text is this workshop’s trap.

“yeah”

never wrong

Carries no behaviour at all.

“This is unrealistic, my manager would never text me like that.”

never wrong

Arguing with the premise isn’t taking the harmful action.

“Le llamaría al número que ya tengo guardado.”

correct

Graded on content, not on the language it arrived in.

Ignoring, deleting, or blocking counts as correct. The employee didn’t do the harmful thing, so narrating the bad ending would punish them for something they never did. They get full credit, and the coaching names what’s still missing: they never checked and never told anyone, so they’d never learn whether it was real, and the attacker just moves to a coworker.

Partial credit is language only. It shapes what the coach says, never the score.

The grading is asymmetric on purpose. Several cases only require “never wrong” rather than a specific verdict, because an unclear costs the employee nothing since the options come back, while a false wrong costs them something they didn’t earn.

What this approach costs

Someone will use it to get through faster. Give direct answers and a portion of people will ask Clay rather than think, and finish having learned less. That’s the real cost of the coaching policy, and Kinds took it deliberately. The alternative is an assistant that withholds, which teaches everyone else not to ask. Better to carry the first cost than the second, but it is a cost, not a solved problem.

Hand-written content doesn’t scale for free. The facts, limits, and per-screen notes are what keep Clay grounded, and every one was written by a person. When attacker behaviour shifts, that content gets rewritten rather than regenerated. It’s the reason the answers are trustworthy and the reason the library grows deliberately instead of quickly.

It won’t go beyond what the workshop knows. Ask for a statistic no workshop states and Clay says it doesn’t have one rather than guessing. That’s how it avoids making things up, and it does mean Clay is narrower than a general-purpose chatbot.

Frequently asked questions

Does giving away the answers defeat the point of training?

It depends what the training is for. If the goal is a score, then yes, an assistant that tells people the answer will inflate it. If the goal is that someone recognizes a vendor bank-details scam in eight months, the score was never the thing worth protecting. Opening the chat is already more work than guessing, so the people asking are the ones engaging. The tradeoff is real and it’s named above.

How is this different from adding a chatbot to a course player?

A chatbot answers questions about a subject. Clay answers questions about a moment. It knows which screen someone is on, what the narration just said, which options are in front of them, what this workshop may and may not claim, and what their own company has told it about their environment. A general assistant asked “what am I deciding here” has no idea what “here” means.

What stops it inventing a statistic?

Each workshop ships a hand-written set of facts, and Clay is required to quote them exactly and to decline what isn’t in there. Ask it for a figure no workshop states and it says so. That’s tested before each release rather than promised, and it’s the reason Clay is deliberately narrow.

Related reading

Most platforms added AI to the catalogue. Kinds put it inside the lesson, at the moment a person actually has the question, and spent the engineering on making sure it knows where “here” is.

The thing worth understanding isn’t that Clay can answer questions. It’s that Clay knows which question is actually being asked.

The employee exchanges described here are drawn from the evaluation suite that gates each release, not from customer transcripts.

Related reading

What is a voice cloning attack?

What is deepfake social engineering?

Why short, frequent security training outperforms annual compliance sessions

Kinds Security glossary

Sources

Kinds Security workshop content, Clay evaluation suite, and internal platform documentation.

Always automated.
Nothing to manage.

Leave Training & Simulated Phishing to us.

Leave Training & Simulated Phishing to us.

Always automated.
Nothing to manage.

Leave Training & Simulated Phishing to us.

Always automated.
Nothing to manage.

Leave Training & Simulated Phishing to us.

© 2026 Kinds Security Inc. All rights reserved.

© 2026 Kinds Security Inc. All rights reserved.

© 2026 Kinds Security Inc. All rights reserved.