Academy A017 · 10 courses

AI Security courses

Protect AI systems across their lifecycle — from threat modeling and prompt injection to RAG and agent security, model supply chains, red teaming, monitoring and incident response.

Designed forSecurity, risk, compliance and technical teams responsible for the safe deployment of AI systems.

AI Security at a glance

The AI Security Academy is a set of 10 EduCut.ai courses (A017.01–A017.10) designed for security, risk, compliance and technical teams responsible for the safe deployment of AI systems. It covers Threat Modeling, Prompt Injection, RAG Security, Agent Security, Red Teaming and Incident Response, from foundation to advanced level. Each course takes 9 hours (6 h online + 3 h personal work) and combines instructor-led online sessions with self-paced personal work.

Academy codeA017
Courses10
LevelsFoundation (2) · Intermediate (4) · Advanced (4)
Course duration9 hours per course (6 h online + 3 h personal work)
LanguageEnglish (translation available)
CertificationCertificate awarded upon completion
FormatBlended: instructor-led online sessions combined with self-paced personal work
Catalogue updated
Free assessment focus areaResponsible AI, Governance & Security — see how the assessment recommends courses

What the AI Security courses cover

  • Threat Modeling
  • Prompt Injection
  • RAG Security
  • Agent Security
  • Red Teaming
  • Incident Response

Courses in the AI Security Academy

10 courses, from foundation to advanced level. Open a course to see its programme.

Foundation level · 2 courses

A017.01

AI Security Fundamentals

Foundation · 9 hours (6 h online + 3 h personal work)
Programme
  • Understand the security landscape of machine learning, generative AI, large language models, Retrieval-Augmented Generation systems, and AI agents, including how their security requirements differ from conventional software systems.
  • Explore how AI introduces new attack surfaces across data, models, prompts, applications, infrastructure, integrations, external tools, and users.
  • Identify common AI threats, vulnerabilities, misuse patterns, and security failures that can compromise confidentiality, integrity, availability, reliability, or organizational trust.
  • Build a foundational framework for securing AI systems throughout their lifecycle, from design and development through deployment, operation, monitoring, and retirement.
A017.02

Threat Modeling for AI Systems

Foundation · 9 hours (6 h online + 3 h personal work)
Programme
  • Learn how to systematically identify and analyze threats across AI architectures, workflows, integrations, and operational environments before they become exploitable weaknesses.
  • Map critical assets, trust boundaries, data flows, models, APIs, tools, identities, infrastructure components, and external dependencies within an AI system.
  • Analyze realistic attack scenarios involving models, users, applications, retrieved content, external services, and third-party components.
  • Build practical AI threat models and prioritize preventive, detective, and corrective security controls according to likelihood, impact, exposure, and business risk.

Intermediate level · 4 courses

A017.03

Prompt Injection, Jailbreaks & LLM Attacks

Intermediate · 9 hours (6 h online + 3 h personal work)
Programme
  • Understand direct and indirect prompt injection, jailbreaks, instruction manipulation, adversarial inputs, and other techniques used to influence or bypass intended LLM behavior.
  • Analyze how attackers can exploit system prompts, external content, retrieved documents, user inputs, conversation context, and application instructions to manipulate model behavior.
  • Test LLM applications against representative attack patterns, control bypasses, unexpected model behaviors, and malicious contextual inputs.
  • Implement layered defenses using isolation, validation, permissions, least privilege, content handling controls, monitoring, and secure application architecture rather than relying on prompts alone.
A017.04

Securing RAG & Knowledge Systems

Intermediate · 9 hours (6 h online + 3 h personal work)
Programme
  • Identify security risks across document ingestion, transformation, embeddings, vector databases, indexing, retrieval, context construction, and generation in RAG systems.
  • Understand knowledge-base poisoning, malicious documents, unauthorized retrieval, retrieval manipulation, sensitive-information leakage, and compromised source provenance.
  • Implement document-level permissions, identity-aware access, metadata filtering, authorization checks, secure ingestion, and controlled retrieval strategies.
  • Build RAG architectures that preserve confidentiality, integrity, provenance, access boundaries, and trust throughout the complete knowledge-to-generation pipeline.
A017.05

AI Agent & Tool-Use Security

Intermediate · 9 hours (6 h online + 3 h personal work)
Programme
  • Understand the security implications of giving AI agents access to APIs, databases, enterprise applications, files, code execution, communication systems, and other external tools.
  • Address excessive agency, insecure tool execution, permission escalation, unintended actions, unsafe chaining of capabilities, and exploitation of agent decision-making.
  • Implement least privilege, authentication, authorization, sandboxing, execution constraints, validation, transaction controls, and human approval mechanisms.
  • Design agent architectures that remain controlled, observable, and recoverable even when model behavior is probabilistic, unexpected, or influenced by malicious inputs.
A017.06

AI Data, Model & Supply Chain Security

Intermediate · 9 hours (6 h online + 3 h personal work)
Programme
  • Protect training, fine-tuning, evaluation, retrieval, and inference data against poisoning, manipulation, leakage, corruption, and unauthorized access.
  • Understand model theft, tampering, malicious or compromised models, unsafe dependencies, vulnerable libraries, poisoned datasets, and untrusted artifacts.
  • Assess security risks associated with open-source models, third-party APIs, external datasets, software libraries, model repositories, cloud services, and AI providers.
  • Establish security controls across the complete AI development and supply-chain lifecycle, including provenance, integrity verification, access management, dependency governance, and vendor assurance.

Advanced level · 4 courses

A017.07

AI Red Teaming & Adversarial Testing

Advanced · 9 hours (6 h online + 3 h personal work)
Programme
  • Design systematic security assessments that simulate realistic adversarial behavior against AI models, applications, retrieval systems, agents, and supporting infrastructure.
  • Evaluate systems for prompt injection, jailbreaks, sensitive-data exposure, harmful behavior, tool misuse, authorization bypasses, control failures, and other application-specific attack scenarios.
  • Build repeatable adversarial test suites and structured red-team scenarios that cover normal operation, edge cases, malicious inputs, and chained attacks.
  • Transform discovered vulnerabilities into prioritized remediation actions, regression tests, measurable security requirements, and continuous adversarial testing processes.
A017.08

Secure AI Engineering & DevSecOps

Advanced · 9 hours (6 h online + 3 h personal work)
Programme
  • Integrate security into AI engineering from architecture and implementation through model integration, testing, deployment, operation, and continuous improvement.
  • Establish secure coding, model-access controls, secrets management, dependency management, artifact integrity, environment isolation, and secure deployment practices.
  • Introduce AI-specific security checks, adversarial tests, policy validation, dependency scanning, and control verification into CI/CD, MLOps, and LLMOps pipelines.
  • Build secure-by-design development processes that continuously identify, prioritize, remediate, and prevent AI vulnerabilities throughout rapid development cycles.
A017.09

AI Security Monitoring & Incident Response

Advanced · 9 hours (6 h online + 3 h personal work)
Programme
  • Monitor prompts, outputs, retrieval activity, tool calls, model behavior, identities, permissions, application events, and infrastructure signals for suspicious or abnormal patterns.
  • Define security indicators, detection logic, thresholds, and alerts for AI-specific attacks, misuse, data exposure, anomalies, policy violations, and control failures.
  • Build incident-response procedures for compromised AI applications, malicious interactions, unsafe autonomous actions, information leakage, and unexpected model behavior.
  • Establish logging, traceability, investigation, containment, recovery, evidence preservation, root-cause analysis, and post-incident improvement processes for AI security events.
A017.10

Enterprise AI Security Architecture & Governance

Advanced · 9 hours (6 h online + 3 h personal work)
Programme
  • Design an end-to-end enterprise security architecture covering AI models, applications, RAG systems, agents, data, infrastructure, APIs, identities, integrations, vendors, and users.
  • Establish security policies, ownership, control requirements, risk assessments, architecture reviews, approval processes, exception handling, and assurance mechanisms for enterprise AI.
  • Align AI security with cybersecurity, privacy, data governance, enterprise risk management, software security, incident response, and broader AI governance programs.
  • Build a scalable AI security roadmap that enables organizations to expand AI adoption while maintaining resilience, appropriate control, regulatory readiness, and stakeholder trust.

See also: AI Governance courses →

Not sure which AI Security courses fit your team?

Start the free assessment →