Locked
Secure AI Use: Advanced
By the end, you understand how AI systems are actually attacked, can safely deploy AI assistants and agents that take real actions, can govern company data flowing through AI, can evaluate AI vendors, and can help run a secure AI program for your team or org.
AI champions, engineers, team leads, security & IT partners · ~60 min · 6 modules
This course is part of the paid catalog. Purchase it individually, or unlock it with a membership that includes Tier 3 content.
What's inside
- 01~9 minThe AI threat modelFoundations covered the risk of *you* leaking data into an AI. This course covers the bigger surface: when AI reads your data, processes untrusted content, and takes actions, attackers start targeting the AI itself. Five attack surfaces — most real incidents come from just one of them: untrusted content the AI reads.
- 02~11 minPrompt injection and the lethal trifectaPrompt injection is when instructions hidden in content the AI reads get treated as commands. Indirect injection — instructions planted in a document, email, or web page the AI processes later — is the dangerous kind. There is no known way to fully prevent it with wording. You prevent damage by limiting what the AI can access and do.
- 03~10 minAgentic AI and blast radiusAn "agent" is an AI that can take actions — run code, call APIs, browse, send messages, move files — not just answer. The risk is no longer a bad answer; it's a bad action you can't undo. Treat every agent like a new employee with API keys: give it the least access it needs, require approval for anything consequential, and assume any content it reads might be trying to steer it.
- 04~10 minData governance for AIOnce AI reads your company's data — through RAG, connectors, or copilots — the AI inherits your data problems and adds new ones. The big four: (1) the AI surfaces data the user shouldn't see, (2) data leaves your tenancy, (3) people use unapproved shadow AI, and (4) prompts and outputs get retained somewhere you forgot. Govern AI data the same way you govern any sensitive system: identity, least privilege, retention, and visibility.
- 05~9 minVendor and supply-chain riskAI tools, models, and the dependencies they suggest are all part of your supply chain. Three risks worth real attention: (1) AI features bolted onto SaaS tools you already use, often on by default; (2) models and AI packages pulled from public registries, which can be backdoored or typosquatted; and (3) AI assistants inventing package names that attackers then register and ship malware under ("slopsquatting"). Vet AI capabilities like dependencies, not like features.
- 06~11 minRunning a secure AI programA secure AI program is mostly four things: a short usable policy, an approved-tools list people actually like, an AI incident response plan, and a network of AI champions who keep it alive. You don't need a 40-page framework. You need rules people can follow, tools people will use, a clear "I think I messed up" path, and visibility into what AI is doing.