FΛForgeAwareness
Locked

Secure AI Use: Advanced

By the end, you understand how AI systems are actually attacked, can safely deploy AI assistants and agents that take real actions, can govern company data flowing through AI, can evaluate AI vendors, and can help run a secure AI program for your team or org.

AI champions, engineers, team leads, security & IT partners · ~60 min · 6 modules

This course is part of the paid catalog. Purchase it individually, or unlock it with a membership that includes Tier 3 content.

What's inside

  1. 01
    The AI threat model
    Foundations covered the risk of *you* leaking data into an AI. This course covers the bigger surface: when AI reads your data, processes untrusted content, and takes actions, attackers start targeting the AI itself. Five attack surfaces — most real incidents come from just one of them: untrusted content the AI reads.
    ~9 min
  2. 02
    Prompt injection and the lethal trifecta
    Prompt injection is when instructions hidden in content the AI reads get treated as commands. Indirect injection — instructions planted in a document, email, or web page the AI processes later — is the dangerous kind. There is no known way to fully prevent it with wording. You prevent damage by limiting what the AI can access and do.
    ~11 min
  3. 03
    Agentic AI and blast radius
    An "agent" is an AI that can take actions — run code, call APIs, browse, send messages, move files — not just answer. The risk is no longer a bad answer; it's a bad action you can't undo. Treat every agent like a new employee with API keys: give it the least access it needs, require approval for anything consequential, and assume any content it reads might be trying to steer it.
    ~10 min
  4. 04
    Data governance for AI
    Once AI reads your company's data — through RAG, connectors, or copilots — the AI inherits your data problems and adds new ones. The big four: (1) the AI surfaces data the user shouldn't see, (2) data leaves your tenancy, (3) people use unapproved shadow AI, and (4) prompts and outputs get retained somewhere you forgot. Govern AI data the same way you govern any sensitive system: identity, least privilege, retention, and visibility.
    ~10 min
  5. 05
    Vendor and supply-chain risk
    AI tools, models, and the dependencies they suggest are all part of your supply chain. Three risks worth real attention: (1) AI features bolted onto SaaS tools you already use, often on by default; (2) models and AI packages pulled from public registries, which can be backdoored or typosquatted; and (3) AI assistants inventing package names that attackers then register and ship malware under ("slopsquatting"). Vet AI capabilities like dependencies, not like features.
    ~9 min
  6. 06
    Running a secure AI program
    A secure AI program is mostly four things: a short usable policy, an approved-tools list people actually like, an AI incident response plan, and a network of AI champions who keep it alive. You don't need a 40-page framework. You need rules people can follow, tools people will use, a clear "I think I messed up" path, and visibility into what AI is doing.
    ~11 min