# Professional Certificate in AI Security

Canonical URL: https://mtfinstitute.com/programs/ai-security-prompt-injection-llm-risk/
Official publisher: MTF Institute of Management, Technology and Finance
Language: English
Topics: AI Security, Prompt Injection, LLM Risk, Agent Security, Application Security

> Assess prompt injection, agent actions and LLM risk with bounded tests, enforceable controls and clear evidence for security decisions.

## Program facts

- Format: Online, self-paced text lessons, fictional cases and applied exercises
- Recommended duration: Up to 1 month
- Study time: Flexible study across 20 applied lessons and one capstone
- Tuition: €10
- Credential: Professional Certificate in AI Security
- Enrollment: https://edu.gtf.pt/course/view.php?id=113


## Professional Certificate in AI Security

Assess prompt injection, agent actions and LLM risk with bounded tests, enforceable controls and clear evidence for security decisions.

## Who this course is for

The course serves practitioners who review or build AI features and need a disciplined way to test boundaries, explain findings and work with accountable owners.

- AI security practitioners
- Application security engineers
- AI platform engineers
- Security risk and assurance specialists

## What you will be able to do

A review of 113 current U.S.-eligible vacancies helped shape practical work in threat modeling, prompt-injection testing, permissions, implementation, monitoring and owner handoff.

- **AI system boundaries:** Map instructions, retrieval, identities, APIs, tools and data flows before judging risk.
- **Prompt-injection testing:** Run bounded synthetic cases and record the behavior the evidence actually shows.
- **Agent action control:** Define tool permissions and enforce allow, deny and confirmation decisions at execution time.
- **Data and platform protection:** Trace sensitive-data exposure, cloud controls and component provenance to the responsible owner.
- **Control validation:** Check whether a defensive change blocks the unsafe case while legitimate work still succeeds.
- **Decision evidence:** Present monitoring signals, residual risk and a practical recommendation to the authorized decision maker.

## Curriculum

### Module 1: Understand and Bound the AI System

Begin with an authorized review, then map the AI system, threat paths, API controls and delegated permissions.

01. **Scope an Authorized AI Security Review:** Scope an AI security review around the legitimate task, permitted environment and named decision owner. The practice produces a scope-and-owner intake record.
02. **Review AI System Architecture and Controls:** Trace an AI workflow and assess a control at the boundary where it must work. The practice produces a bounded architecture/control review.
03. **Threat-Model an AI Workflow:** Build a threat model that connects attacker control to a plausible outcome and an evidence limit. The practice produces a trust-boundary threat model.
04. **Inspect Application and API Boundaries:** Inspect API calls, caller identities and resource access for a reproducible security finding. The practice produces a API security review checklist.
05. **Map Agent Identity and Delegated Permissions:** Map user, service, agent and tool identities to the actions each may perform. The practice produces a agent identity-and-permission map.

### Module 2: Test Trust Boundaries and Design Controls

Test lower-trust content safely, trace retrieval and data exposure, and design enforceable tool and runtime controls.

06. **Test Prompt Injection in a Safe Scope:** Run an authorized synthetic prompt-injection test and distinguish observation from hypothesis. The practice produces a bounded test-case record.
07. **Secure Retrieval and Context:** Trace retrieval provenance and access so source content cannot silently gain authority. The practice produces a retrieval provenance and access map.
08. **Trace Sensitive Data Exposure:** Follow a synthetic sensitive-data path and recommend a scoped protection. The practice produces a data-exposure control review.
09. **Decide Which Agent Tool Actions Are Allowed:** Decide which agent tool actions are allowed for a particular user, resource and context. The practice produces a tool-action decision table.
10. **Design a Runtime Guardrail:** Place a runtime control at an enforceable action point and check its effect on valid work. The practice produces a runtime policy pattern.

### Module 3: Validate Implementation and Release Evidence

Evaluate control outcomes, implement a bounded sandbox change, inspect platform and component risks, and prepare release evidence.

11. **Evaluate Adversarial and Legitimate Outcomes:** Compare unsafe-action and legitimate-task outcomes using explicit test counts and coverage limits. The practice produces a evaluation plan and result.
12. **Implement and Verify a Defensive Change:** Make one defensive sandbox change and verify both security and regression behavior. The practice produces a sandbox control-implementation record.
13. **Check Cloud and Platform Controls:** Review the platform environment for identity, secrets, network, logging and change controls. The practice produces a deployment control evidence sheet.
14. **Review Model, Data and Reusable Components:** Screen model, data and reusable components for provenance and permission risks. The practice produces a component provenance review.
15. **Assemble Secure AI Release Evidence:** Assemble the evidence, gaps and residual risk a release owner needs for a decision. The practice produces a pre-release security evidence checklist.

### Module 4: Monitor, Escalate and Handoff Decisions

Specify monitoring, prepare an incident handoff, explain risk and tradeoffs, guide a fix, and deliver an integrated review.

16. **Specify AI Security Monitoring Signals:** Specify monitoring that attributes an agent action and policy decision to the right actors. The practice produces a monitoring signal specification.
17. **Prepare an Incident Handoff and Runbook Contribution:** Preserve a safe incident record and hand a runbook contribution to the local incident owner. The practice produces a synthetic incident response record.
18. **Explain AI Security Risk and Tradeoffs:** Explain the observed finding, options, legitimate-task effects and decision needed. The practice produces a risk-and-tradeoff brief.
19. **Guide Developers Through a Security Fix:** Give developers a safe reproduction, feasible fix and agreed retest check. The practice produces a remediation handoff record.
20. **Complete an Integrated AI Security Review:** Deliver a coherent AI security evidence pack with an explicit owner decision request. The practice produces a review evidence pack.

## How the course works

Study online at your own pace. Each lesson uses a connected fictional AI assistant case, an applied method, a blank work-product model, a completed example and AI-supported practice. The four modules move from authorized review to bounded tests and controls, release evidence, monitoring and handoff. Use only approved tools and permitted information when adapting the methods to real work.

The applied capstone is a separate AI Assistant Security Decision Brief. A fictional retail team proposes an assistant that retrieves returns policies and drafts or creates support tickets in a sandbox. A retrieved page asks it to use an unrelated queue. You receive an identity summary, two synthetic tests, a tool-decision log and one unresolved data-access question. Assess the trust and permission boundaries, interpret the supplied evidence and recommend a proportionate control to the named product and platform owners before their pilot decision. Use only the course methods that fit this situation and leave real release decisions with the responsible owner.

The Role Starter Pack contains a model job description, an ATS-friendly resume template with a fictional example and a model operating playbook. Adapt these resources to an employer&#039;s systems, permissions and review process.

## Certificate

The MTF learning platform includes a certificate activity for the MTF Institute professional course-completion certificate titled Professional Certificate in AI Security. The full credential status is stated on the program page.

## Evidence behind the course

The [U.S. vacancy study](https://mtfinstitute.com/insights/ai-security-us-vacancy-requirements-2026/) reviews a purposive sample of 113 current requisitions from 90 employers, coded for concrete AI-security work and requirements. A separate [current-changes article](https://mtfinstitute.com/insights/ai-security-prompt-injection-agent-controls-2026/) examines dated prompt-injection, agent-control and LLM-risk developments from primary sources. The course turns these findings and the model role playbook into transferable practice while local employer processes determine real permissions and decisions.

## Start the course

This online professional certificate contains 20 applied lessons, one capstone and three Role Starter Pack resources. Study time is Up to 1 month. The one-time course price is €10, including applicable taxes.

[ENROLL NOW](https://edu.gtf.pt/course/view.php?id=113)

## Frequently asked questions

### Who is this course for?

It is for professionals who review or build AI-enabled applications, including AI security, application security, AI platform, and security risk or assurance practitioners. The lessons begin with scope and system mapping, then build toward controlled tests, implementation evidence and owner handoffs.

### Do I need previous prompt-injection experience?

No specialist prompt-injection experience is required. Familiarity with basic application security concepts, APIs or identity controls will help. Every practical exercise starts with a defined legitimate task, a safe scope and a worked example.

### How is the course delivered?

The course is online and self-paced in English. It contains four modules, 20 applied text lessons, practical templates and a separate capstone. The study-time guide for this single course is Up to 1 month.

### What will I practise?

You will map AI-system and permission boundaries, test a synthetic prompt-injection case, specify tool authorization and runtime controls, compare unsafe and legitimate outcomes, review implementation evidence, and prepare monitoring and decision records.

### Will the exercises use real systems or sensitive data?

The worked cases use fictional systems and synthetic data. For workplace adaptation, use only an environment, data and test methods your organization has authorized; route live incidents and release decisions through its named owners.

### How can I use AI while practising?

Lessons include structured AI-supported drafting and critique prompts. Use them to organize supplied facts, challenge missing evidence and improve an artifact. Verify technical claims and keep confidential information within your organization&#039;s approved tools and rules.

### What is the evidence behind the curriculum and how do I complete it?

The curriculum draws on a dated MTF Institute study of 113 current U.S.-eligible vacancies from 90 employers and a separate review of recent AI-security developments. Complete the learning activities and capstone, then use the final course section for the MTF Institute completion certificate and Student ID. The vacancy study is available as an open research article and archived record.

## Professional education notice

Professional courses and certificates are taught under the terms of paragraph 3 of article 3 of Decree-Law No. 474/2010, published on July 8th by the Portuguese Ministry of Labour and Social Solidarity. The professional programs are related to professional / business education and are provided without official recognition (certificates are provided at a professional level and not academic degrees or diplomas and do not confer academic credits).

## Citation guidance

When quoting or summarizing this program, cite the canonical HTML page: https://mtfinstitute.com/programs/ai-security-prompt-injection-llm-risk/
