Online professional certificate
Professional Certificate in AI Security
Assess prompt injection, agent actions and LLM risk with bounded tests, enforceable controls and clear evidence for security decisions.
- Format
- Online, self-paced
- Study time
- Up to 1 month
- Curriculum
- 20 applied lessons
- Language
- English
Practical capability
Turn AI security concerns into tested controls and clear decisions.
A review of 113 current U.S.-eligible vacancies helped shape practical work in threat modeling, prompt-injection testing, permissions, implementation, monitoring and owner handoff.
Map instructions, retrieval, identities, APIs, tools and data flows before judging risk.
Run bounded synthetic cases and record the behavior the evidence actually shows.
Define tool permissions and enforce allow, deny and confirmation decisions at execution time.
Trace sensitive-data exposure, cloud controls and component provenance to the responsible owner.
Check whether a defensive change blocks the unsafe case while legitimate work still succeeds.
Present monitoring signals, residual risk and a practical recommendation to the authorized decision maker.
Who this course is for
For professionals securing AI-enabled products and workflows.
The course serves practitioners who review or build AI features and need a disciplined way to test boundaries, explain findings and work with accountable owners.
The operating cycle
Follow the work from intake to verified follow-up.
The sequence follows an AI security practitioner's operating procedure: establish scope, examine the boundary, test safely, validate a control and hand the decision to its owner.
Curriculum
Four modules, 20 applied lessons and one decision brief.
Understand and Bound the AI System
Begin with an authorized review, then map the AI system, threat paths, API controls and delegated permissions.
01Scope an Authorized AI Security Review
Scope an AI security review around the legitimate task, permitted environment and named decision owner.
Five practical steps
- Record the request and intended business task
- Separate known facts from missing permissions and data classifications
- Identify the system, implementation and decision owners
- Define a safe initial review scope and stop conditions
- Route unanswered access and release questions to the named owner
Primary deliverable: scope-and-owner intake record.
02Review AI System Architecture and Controls
Trace an AI workflow and assess a control at the boundary where it must work.
Five practical steps
- Trace instructions, data and actions across components
- Label trust and permission boundaries
- Inspect a current control and its enforcement point
- State a specific finding and feasible recommendation
- Name implementation and decision owners, validation evidence and residual risk
Primary deliverable: bounded architecture/control review.
03Threat-Model an AI Workflow
Build a threat model that connects attacker control to a plausible outcome and an evidence limit.
Five practical steps
- State the legitimate user task
- Map attacker-controlled and trusted surfaces
- Trace a plausible boundary crossing and consequence
- Assess existing controls and missing evidence
- Prioritize one review question without inventing exposure
Primary deliverable: trust-boundary threat model.
04Inspect Application and API Boundaries
Inspect API calls, caller identities and resource access for a reproducible security finding.
Five practical steps
- List API operations and callers
- Trace user and service authentication
- Check authorization at resource and action boundaries
- Review input, output and sensitive-data handling
- Write a reproducible finding or justified no-finding conclusion
Primary deliverable: API security review checklist.
05Map Agent Identity and Delegated Permissions
Map user, service, agent and tool identities to the actions each may perform.
Five practical steps
- Name each actor and credential
- Map permissions to actions and resources
- Identify where user context is retained or lost
- Compare intended and effective authority
- Propose a least-privilege change and route approval locally
Primary deliverable: agent identity-and-permission map.
Test Trust Boundaries and Design Controls
Test lower-trust content safely, trace retrieval and data exposure, and design enforceable tool and runtime controls.
06Test Prompt Injection in a Safe Scope
Run an authorized synthetic prompt-injection test and distinguish observation from hypothesis.
Five practical steps
- Define the legitimate task and prohibited deviation
- Choose a synthetic lower-trust carrier
- Set scope, stop condition and observation points
- Run the bounded case and record tool and answer behavior
- Separate a demonstrated failure from an unconfirmed hypothesis
Primary deliverable: bounded test-case record.
07Secure Retrieval and Context
Trace retrieval provenance and access so source content cannot silently gain authority.
Five practical steps
- Trace document origin and indexing
- Map retrieval permission and user context
- Identify lower-trust passages and instruction-like content
- Test whether the retrieved context can influence an unsafe action
- Propose a control and state its limits
Primary deliverable: retrieval provenance and access map.
08Trace Sensitive Data Exposure
Follow a synthetic sensitive-data path and recommend a scoped protection.
Five practical steps
- Classify supplied data and allowed uses
- Trace entry, storage, context, output and egress
- Check access and minimization controls
- Test one synthetic exposure path
- Record the proposed protection and residual unknowns
Primary deliverable: data-exposure control review.
09Decide Which Agent Tool Actions Are Allowed
Decide which agent tool actions are allowed for a particular user, resource and context.
Five practical steps
- List tool actions and resources
- Bind the requesting user and agent identity
- Define allow, deny and confirmation conditions
- Evaluate representative requests at execution time
- Record decision traces and owner-reviewed exceptions
Primary deliverable: tool-action decision table.
10Design a Runtime Guardrail
Place a runtime control at an enforceable action point and check its effect on valid work.
Five practical steps
- State the protected action and threat path
- Choose an enforcement point outside the prompt
- Specify policy inputs and decisions
- Test a prohibited action and an allowed task
- Record false blocks, residual limits and owner handoff
Primary deliverable: runtime policy pattern.
Validate Implementation and Release Evidence
Evaluate control outcomes, implement a bounded sandbox change, inspect platform and component risks, and prepare release evidence.
11Evaluate Adversarial and Legitimate Outcomes
Compare unsafe-action and legitimate-task outcomes using explicit test counts and coverage limits.
Five practical steps
- Choose representative cases and a scope
- Define expected unsafe and legitimate outcomes
- Run or inspect results consistently
- Record raw numerators, denominators and deviations
- Explain coverage limits and next tests
Primary deliverable: evaluation plan and result.
12Implement and Verify a Defensive Change
Make one defensive sandbox change and verify both security and regression behavior.
Five practical steps
- State the intended control and baseline
- Make one small sandbox code or policy change
- Test prohibited and authorized behavior
- Inspect trace evidence and regression results
- Document limits and request the local owner’s review
Primary deliverable: sandbox control-implementation record.
13Check Cloud and Platform Controls
Review the platform environment for identity, secrets, network, logging and change controls.
Five practical steps
- Map deployed components and environment
- Inspect secret, network and workload boundaries
- Check identity and configuration drift controls
- Review logging and change path
- Record supported findings and unresolved checks
Primary deliverable: deployment control evidence sheet.
14Review Model, Data and Reusable Components
Screen model, data and reusable components for provenance and permission risks.
Five practical steps
- Inventory the component and source
- Inspect provenance and update route
- Trace permissions, scripts and data inputs
- Identify a plausible misuse or contamination path
- Recommend a bounded test and patch/regression owner
Primary deliverable: component provenance review.
15Assemble Secure AI Release Evidence
Assemble the evidence, gaps and residual risk a release owner needs for a decision.
Five practical steps
- Identify the release scope and owner
- Gather relevant design, test and control evidence
- Separate completed checks from gaps
- State residual risk and conditions
- Send the recommendation for local approval or remediation
Primary deliverable: pre-release security evidence checklist.
Monitor, Escalate and Handoff Decisions
Specify monitoring, prepare an incident handoff, explain risk and tradeoffs, guide a fix, and deliver an integrated review.
16Specify AI Security Monitoring Signals
Specify monitoring that attributes an agent action and policy decision to the right actors.
Five practical steps
- Name the action or policy decision to observe
- Define minimally necessary event fields
- Set a synthetic alert condition and owner
- Inspect a sample trace for attribution and false positives
- Document retention, response route and evidence limits
Primary deliverable: monitoring signal specification.
17Prepare an Incident Handoff and Runbook Contribution
Preserve a safe incident record and hand a runbook contribution to the local incident owner.
Five practical steps
- Recognize the trigger and stop unsafe testing
- Preserve only necessary evidence
- State affected system and observed behavior
- Draft a bounded runbook step or postmortem observation
- Handoff through the local incident route and record owner response
Primary deliverable: synthetic incident response record.
18Explain AI Security Risk and Tradeoffs
Explain the observed finding, options, legitimate-task effects and decision needed.
Five practical steps
- Summarize the legitimate service and finding
- Distinguish observed and hypothetical paths
- Compare proportionate options and legitimate-task effects
- Explain residual risk without false precision
- Ask the named owner for a decision
Primary deliverable: risk-and-tradeoff brief.
19Guide Developers Through a Security Fix
Give developers a safe reproduction, feasible fix and agreed retest check.
Five practical steps
- Describe the failing boundary and observed path
- Provide a safe reproduction and expected behavior
- State a feasible fix and constraints
- Agree on owner, timing and acceptance check
- Record retest result and remaining risk
Primary deliverable: remediation handoff record.
20Complete an Integrated AI Security Review
Deliver a coherent AI security evidence pack with an explicit owner decision request.
Five practical steps
- Confirm the approved review scope
- Select relevant architecture, test and monitoring evidence
- Check consistency and missing proof
- Summarize recommendations and residual risk
- Deliver an evidence pack to the authorized owner
Primary deliverable: review evidence pack.
Applied capstone
Make a security recommendation for a tool-enabled assistant.
Use the relevant course methods to produce one coherent recommendation from a new case.
The situation
A fictional retail team proposes an assistant that retrieves returns policies and drafts or creates support tickets in a sandbox. A retrieved page asks it to use an unrelated queue. You receive an identity summary, two synthetic tests, a tool-decision log and one unresolved data-access question.
Your task
Assess the trust and permission boundaries, interpret the supplied evidence and recommend a proportionate control to the named product and platform owners before their pilot decision.
The people behind MTF
Meet MTF faculty and the learner community.
Explore the professional backgrounds of MTF faculty and learn more about the international community studying with the Institute.
Enrollment
Enroll in Professional Certificate in AI Security
One-time course price: €10, including applicable taxes. Payment is processed securely by Stripe. No card details are stored on the MTF Institute website.
You will receive an email with access to the course. If you have any difficulties, please write to welcome@gtf.pt.
Questions and details
Frequently asked questions
Open the sections that matter to you, including delivery format, AI-supported practice and the evidence used to design the curriculum.
Who is this course for?
It is for professionals who review or build AI-enabled applications, including AI security, application security, AI platform, and security risk or assurance practitioners. The lessons begin with scope and system mapping, then build toward controlled tests, implementation evidence and owner handoffs.
Do I need previous prompt-injection experience?
No specialist prompt-injection experience is required. Familiarity with basic application security concepts, APIs or identity controls will help. Every practical exercise starts with a defined legitimate task, a safe scope and a worked example.
How is the course delivered?
The course is online and self-paced in English. It contains four modules, 20 applied text lessons, practical templates and a separate capstone. The study-time guide for this single course is Up to 1 month.
What will I practise?
You will map AI-system and permission boundaries, test a synthetic prompt-injection case, specify tool authorization and runtime controls, compare unsafe and legitimate outcomes, review implementation evidence, and prepare monitoring and decision records.
Will the exercises use real systems or sensitive data?
The worked cases use fictional systems and synthetic data. For workplace adaptation, use only an environment, data and test methods your organization has authorized; route live incidents and release decisions through its named owners.
How can I use AI while practising?
Lessons include structured AI-supported drafting and critique prompts. Use them to organize supplied facts, challenge missing evidence and improve an artifact. Verify technical claims and keep confidential information within your organization's approved tools and rules.
What is the evidence behind the curriculum and how do I complete it?
The curriculum draws on a dated MTF Institute study of 113 current U.S.-eligible vacancies from 90 employers and a separate review of recent AI-security developments. Complete the learning activities and capstone, then use the final course section for the MTF Institute completion certificate and Student ID. The vacancy study is available as an open research article and archived record.