Online professional certificate

Professional Certificate in AI Security

Assess prompt injection, agent actions and LLM risk with bounded tests, enforceable controls and clear evidence for security decisions.

Format
Online, self-paced
Study time
Up to 1 month
Curriculum
20 applied lessons
Language
English

Practical capability

Turn AI security concerns into tested controls and clear decisions.

A review of 113 current U.S.-eligible vacancies helped shape practical work in threat modeling, prompt-injection testing, permissions, implementation, monitoring and owner handoff.

01AI system boundaries

Map instructions, retrieval, identities, APIs, tools and data flows before judging risk.

02Prompt-injection testing

Run bounded synthetic cases and record the behavior the evidence actually shows.

03Agent action control

Define tool permissions and enforce allow, deny and confirmation decisions at execution time.

04Data and platform protection

Trace sensitive-data exposure, cloud controls and component provenance to the responsible owner.

05Control validation

Check whether a defensive change blocks the unsafe case while legitimate work still succeeds.

06Decision evidence

Present monitoring signals, residual risk and a practical recommendation to the authorized decision maker.

Who this course is for

For professionals securing AI-enabled products and workflows.

The course serves practitioners who review or build AI features and need a disciplined way to test boundaries, explain findings and work with accountable owners.

ASAI security practitioners
ASApplication security engineers
APAI platform engineers
SRSecurity risk and assurance specialists

The operating cycle

Follow the work from intake to verified follow-up.

The sequence follows an AI security practitioner's operating procedure: establish scope, examine the boundary, test safely, validate a control and hand the decision to its owner.

Step 1Authorize the intake
Step 2Map the boundaries
Step 3Frame the risk
Step 4Plan a bounded check
Step 5Record observed behavior
Step 6Select a control
Step 7Verify both outcomes
Step 8Hand off and follow up

Curriculum

Four modules, 20 applied lessons and one decision brief.

Module 1

Understand and Bound the AI System

Begin with an authorized review, then map the AI system, threat paths, API controls and delegated permissions.

01Scope an Authorized AI Security Review

Scope an AI security review around the legitimate task, permitted environment and named decision owner.

Five practical steps

  1. Record the request and intended business task
  2. Separate known facts from missing permissions and data classifications
  3. Identify the system, implementation and decision owners
  4. Define a safe initial review scope and stop conditions
  5. Route unanswered access and release questions to the named owner

Primary deliverable: scope-and-owner intake record.

02Review AI System Architecture and Controls

Trace an AI workflow and assess a control at the boundary where it must work.

Five practical steps

  1. Trace instructions, data and actions across components
  2. Label trust and permission boundaries
  3. Inspect a current control and its enforcement point
  4. State a specific finding and feasible recommendation
  5. Name implementation and decision owners, validation evidence and residual risk

Primary deliverable: bounded architecture/control review.

03Threat-Model an AI Workflow

Build a threat model that connects attacker control to a plausible outcome and an evidence limit.

Five practical steps

  1. State the legitimate user task
  2. Map attacker-controlled and trusted surfaces
  3. Trace a plausible boundary crossing and consequence
  4. Assess existing controls and missing evidence
  5. Prioritize one review question without inventing exposure

Primary deliverable: trust-boundary threat model.

04Inspect Application and API Boundaries

Inspect API calls, caller identities and resource access for a reproducible security finding.

Five practical steps

  1. List API operations and callers
  2. Trace user and service authentication
  3. Check authorization at resource and action boundaries
  4. Review input, output and sensitive-data handling
  5. Write a reproducible finding or justified no-finding conclusion

Primary deliverable: API security review checklist.

05Map Agent Identity and Delegated Permissions

Map user, service, agent and tool identities to the actions each may perform.

Five practical steps

  1. Name each actor and credential
  2. Map permissions to actions and resources
  3. Identify where user context is retained or lost
  4. Compare intended and effective authority
  5. Propose a least-privilege change and route approval locally

Primary deliverable: agent identity-and-permission map.

Module 2

Test Trust Boundaries and Design Controls

Test lower-trust content safely, trace retrieval and data exposure, and design enforceable tool and runtime controls.

06Test Prompt Injection in a Safe Scope

Run an authorized synthetic prompt-injection test and distinguish observation from hypothesis.

Five practical steps

  1. Define the legitimate task and prohibited deviation
  2. Choose a synthetic lower-trust carrier
  3. Set scope, stop condition and observation points
  4. Run the bounded case and record tool and answer behavior
  5. Separate a demonstrated failure from an unconfirmed hypothesis

Primary deliverable: bounded test-case record.

07Secure Retrieval and Context

Trace retrieval provenance and access so source content cannot silently gain authority.

Five practical steps

  1. Trace document origin and indexing
  2. Map retrieval permission and user context
  3. Identify lower-trust passages and instruction-like content
  4. Test whether the retrieved context can influence an unsafe action
  5. Propose a control and state its limits

Primary deliverable: retrieval provenance and access map.

08Trace Sensitive Data Exposure

Follow a synthetic sensitive-data path and recommend a scoped protection.

Five practical steps

  1. Classify supplied data and allowed uses
  2. Trace entry, storage, context, output and egress
  3. Check access and minimization controls
  4. Test one synthetic exposure path
  5. Record the proposed protection and residual unknowns

Primary deliverable: data-exposure control review.

09Decide Which Agent Tool Actions Are Allowed

Decide which agent tool actions are allowed for a particular user, resource and context.

Five practical steps

  1. List tool actions and resources
  2. Bind the requesting user and agent identity
  3. Define allow, deny and confirmation conditions
  4. Evaluate representative requests at execution time
  5. Record decision traces and owner-reviewed exceptions

Primary deliverable: tool-action decision table.

10Design a Runtime Guardrail

Place a runtime control at an enforceable action point and check its effect on valid work.

Five practical steps

  1. State the protected action and threat path
  2. Choose an enforcement point outside the prompt
  3. Specify policy inputs and decisions
  4. Test a prohibited action and an allowed task
  5. Record false blocks, residual limits and owner handoff

Primary deliverable: runtime policy pattern.

Module 3

Validate Implementation and Release Evidence

Evaluate control outcomes, implement a bounded sandbox change, inspect platform and component risks, and prepare release evidence.

11Evaluate Adversarial and Legitimate Outcomes

Compare unsafe-action and legitimate-task outcomes using explicit test counts and coverage limits.

Five practical steps

  1. Choose representative cases and a scope
  2. Define expected unsafe and legitimate outcomes
  3. Run or inspect results consistently
  4. Record raw numerators, denominators and deviations
  5. Explain coverage limits and next tests

Primary deliverable: evaluation plan and result.

12Implement and Verify a Defensive Change

Make one defensive sandbox change and verify both security and regression behavior.

Five practical steps

  1. State the intended control and baseline
  2. Make one small sandbox code or policy change
  3. Test prohibited and authorized behavior
  4. Inspect trace evidence and regression results
  5. Document limits and request the local owner’s review

Primary deliverable: sandbox control-implementation record.

13Check Cloud and Platform Controls

Review the platform environment for identity, secrets, network, logging and change controls.

Five practical steps

  1. Map deployed components and environment
  2. Inspect secret, network and workload boundaries
  3. Check identity and configuration drift controls
  4. Review logging and change path
  5. Record supported findings and unresolved checks

Primary deliverable: deployment control evidence sheet.

14Review Model, Data and Reusable Components

Screen model, data and reusable components for provenance and permission risks.

Five practical steps

  1. Inventory the component and source
  2. Inspect provenance and update route
  3. Trace permissions, scripts and data inputs
  4. Identify a plausible misuse or contamination path
  5. Recommend a bounded test and patch/regression owner

Primary deliverable: component provenance review.

15Assemble Secure AI Release Evidence

Assemble the evidence, gaps and residual risk a release owner needs for a decision.

Five practical steps

  1. Identify the release scope and owner
  2. Gather relevant design, test and control evidence
  3. Separate completed checks from gaps
  4. State residual risk and conditions
  5. Send the recommendation for local approval or remediation

Primary deliverable: pre-release security evidence checklist.

Module 4

Monitor, Escalate and Handoff Decisions

Specify monitoring, prepare an incident handoff, explain risk and tradeoffs, guide a fix, and deliver an integrated review.

16Specify AI Security Monitoring Signals

Specify monitoring that attributes an agent action and policy decision to the right actors.

Five practical steps

  1. Name the action or policy decision to observe
  2. Define minimally necessary event fields
  3. Set a synthetic alert condition and owner
  4. Inspect a sample trace for attribution and false positives
  5. Document retention, response route and evidence limits

Primary deliverable: monitoring signal specification.

17Prepare an Incident Handoff and Runbook Contribution

Preserve a safe incident record and hand a runbook contribution to the local incident owner.

Five practical steps

  1. Recognize the trigger and stop unsafe testing
  2. Preserve only necessary evidence
  3. State affected system and observed behavior
  4. Draft a bounded runbook step or postmortem observation
  5. Handoff through the local incident route and record owner response

Primary deliverable: synthetic incident response record.

18Explain AI Security Risk and Tradeoffs

Explain the observed finding, options, legitimate-task effects and decision needed.

Five practical steps

  1. Summarize the legitimate service and finding
  2. Distinguish observed and hypothetical paths
  3. Compare proportionate options and legitimate-task effects
  4. Explain residual risk without false precision
  5. Ask the named owner for a decision

Primary deliverable: risk-and-tradeoff brief.

19Guide Developers Through a Security Fix

Give developers a safe reproduction, feasible fix and agreed retest check.

Five practical steps

  1. Describe the failing boundary and observed path
  2. Provide a safe reproduction and expected behavior
  3. State a feasible fix and constraints
  4. Agree on owner, timing and acceptance check
  5. Record retest result and remaining risk

Primary deliverable: remediation handoff record.

20Complete an Integrated AI Security Review

Deliver a coherent AI security evidence pack with an explicit owner decision request.

Five practical steps

  1. Confirm the approved review scope
  2. Select relevant architecture, test and monitoring evidence
  3. Check consistency and missing proof
  4. Summarize recommendations and residual risk
  5. Deliver an evidence pack to the authorized owner

Primary deliverable: review evidence pack.

Applied capstone

Make a security recommendation for a tool-enabled assistant.

Use the relevant course methods to produce one coherent recommendation from a new case.

The situation

A fictional retail team proposes an assistant that retrieves returns policies and drafts or creates support tickets in a sandbox. A retrieved page asks it to use an unrelated queue. You receive an identity summary, two synthetic tests, a tool-decision log and one unresolved data-access question.

Your task

Assess the trust and permission boundaries, interpret the supplied evidence and recommend a proportionate control to the named product and platform owners before their pilot decision.

AI Assistant Security Decision BriefOne decision-ready brief stating the observed facts, proposed control, effect on legitimate work, residual risk, missing evidence and the decision requested from the owner.

The people behind MTF

Meet MTF faculty and the learner community.

Explore the professional backgrounds of MTF faculty and learn more about the international community studying with the Institute.

Enrollment

Enroll in Professional Certificate in AI Security

One-time course price: €10, including applicable taxes. Payment is processed securely by Stripe. No card details are stored on the MTF Institute website.

You will receive an email with access to the course. If you have any difficulties, please write to welcome@gtf.pt.

Secure payment on this page

Enter your enrollment email to continue in Stripe's encrypted form.

Cards, Apple Pay, Google Pay and other eligible methods

Questions and details

Frequently asked questions

Open the sections that matter to you, including delivery format, AI-supported practice and the evidence used to design the curriculum.

Who is this course for?

It is for professionals who review or build AI-enabled applications, including AI security, application security, AI platform, and security risk or assurance practitioners. The lessons begin with scope and system mapping, then build toward controlled tests, implementation evidence and owner handoffs.

Do I need previous prompt-injection experience?

No specialist prompt-injection experience is required. Familiarity with basic application security concepts, APIs or identity controls will help. Every practical exercise starts with a defined legitimate task, a safe scope and a worked example.

How is the course delivered?

The course is online and self-paced in English. It contains four modules, 20 applied text lessons, practical templates and a separate capstone. The study-time guide for this single course is Up to 1 month.

What will I practise?

You will map AI-system and permission boundaries, test a synthetic prompt-injection case, specify tool authorization and runtime controls, compare unsafe and legitimate outcomes, review implementation evidence, and prepare monitoring and decision records.

Will the exercises use real systems or sensitive data?

The worked cases use fictional systems and synthetic data. For workplace adaptation, use only an environment, data and test methods your organization has authorized; route live incidents and release decisions through its named owners.

How can I use AI while practising?

Lessons include structured AI-supported drafting and critique prompts. Use them to organize supplied facts, challenge missing evidence and improve an artifact. Verify technical claims and keep confidential information within your organization's approved tools and rules.

What is the evidence behind the curriculum and how do I complete it?

The curriculum draws on a dated MTF Institute study of 113 current U.S.-eligible vacancies from 90 employers and a separate review of recent AI-security developments. Complete the learning activities and capstone, then use the final course section for the MTF Institute completion certificate and Student ID. The vacancy study is available as an open research article and archived record.