Secure LLM applications, RAG pipelines and tool-using AI agents. Run authorized AI red teaming, validate findings and build regression tests for application, data and agent controls.
Application and cloud security engineers, penetration testers, AI developers and technical security professionals responsible for AI systems.
Entry requirements
Working Python, HTTP/APIs, Git, terminal and container basics. Understand authentication and authorization. Ability to run a small application locally is required; a brief readiness task checks this before entry.
Weekly commitment
Allow 4–6 independent lab hours each week. Live time totals 36–54 hours across 36 sessions; assignments and preparation do not count toward those hours.
Recommended planning baseline: a laptop with 16 GB RAM, 30 GB free disk space, reliable internet and permission to install the agreed local lab tools. Confirm the actual cohort setup before buying equipment. A GPU is not assumed; heavier models may need an approved hosted endpoint with separate usage charges.
WEEK-BY-WEEK CURRICULUM
Learn through security work.
Each week combines explanation, guided practice and evidence review across three sessions. The lab tasks and portfolio outputs below form the assessment trail.
WEEK 1–2
AI application threat modelling
LLM and RAG data flows, trust boundaries, OWASP GenAI guidance, ATLAS and scoped adversarial testing.
Lab: Map a local AI application, classify its data and agree attack scope and success criteria.
Evidence: Threat model, test plan and clean-task baseline.
WEEK 3–4
LLM and RAG attack surfaces
Direct and indirect prompt injection, sensitive-data leakage, unsafe output handling, retrieval poisoning and tenant access checks.
Lab: Reproduce failures in synthetic documents and a local RAG service; enforce role-based retrieval and retest.
Evidence: Reproduction cases, control changes and regression suite.
WEEK 5–6
AI red teaming and adversarial ML
garak, PyRIT, bounded test generation, manual reproduction and severity. Poisoning, evasion, extraction and privacy attacks using toy datasets.
Lab: Compare an automated scanner result with manual evidence and test false alarms and benign performance.
Evidence: Versioned assessment report with attack-success and false-positive measures.
Map threats and controls, justify test scope and trace evidence. These are references, not software subscriptions or AI5 accreditations.
Demonstrated or evidence-led
Cloud-native AI controls, enterprise SOC copilots and larger model attack scenarios
Instructor walkthroughs or sanitized evidence packs; not every platform is a student lab.
Commercial / usage-dependent
Microsoft Security Copilot, Sentinel, Splunk, enterprise AI assistants, cloud accounts and paid model APIs
Hands-on access only when a suitable license, tenant and budget are confirmed. These subscriptions, credits and exams are not automatically included. Equivalent local exercises support the core learning goals.
Use only approved AI endpoints with synthetic or sanitized data. Product names describe training context, not partnerships. Tool versions and the exact lab access list are confirmed for each cohort.
ASSESS THE WORK, NOT THE PROMPT
Portfolio and employer-grade capstone
AI system threat model
Hardened RAG prototype
Reproducible AI red-team test suite
Restricted MCP/tool agent
AI release and containment checklist
Final capstone
Assess an intentionally vulnerable RAG and tool-using agent system. Reproduce scoped attacks, repair data and permission boundaries, prove the fixes with unseen tests and deliver a release decision with remaining risks.
40% · Practical evidence
Reproducible results, source checks, tested controls and useful lab records.
20% · Scenario decisions
Range performance, uncertainty, approval boundaries and communication.
40% · Capstone & defence
Working or auditable deliverables, unseen test cases, handover and individual explanation.
Completion standard: 70% overall, all mandatory submissions and a pass on evidence verification and authorization controls. Unsafe unapproved actions or fabricated evidence must be corrected and reassessed. AI assistance must be disclosed; copied model output without verification is not accepted as proof.
Technical scorecards include false positives, detection or attack-success measures, clean-task performance and reproducibility. Governance scorecards check evidence completeness, control ownership, risk decisions and traceability. An attractive report alone does not meet the standard.
PRACTISE THE WHOLE DECISION
Cyber Range: investigate, verify, respond.
The Cyber Range is a sequence of isolated training scenarios using local applications, synthetic company records and replayed security events. Technical routes test controls; the governance route reviews the evidence and authorizes decisions in tabletop exercises.
Investigate
Work with incomplete evidence, noisy alerts and an AI system that can make mistakes. Record hypotheses and competing explanations.
Verify
Reproduce findings, test benign controls and keep source references, timestamps, configuration and version records.
Respond
Request approval for changes, test containment and rollback, then explain remaining risk in an operational handover.
All testing stays within authorized training targets. No live third-party attacks or real customer secrets. Hosted range subscriptions and continuous access are not assumed; confirm the cohort’s delivery and access arrangements before enrolment.
BUILT TO KEEP LEARNING
AI5 Emerging Threat Lab
Each cohort examines a recent AI-security advisory or research finding within its scheduled lab time. Learners check the source, assess relevance, reproduce a safe bounded example where feasible, test a mitigation and add an evidence-backed advisory to their portfolio.
Topics may include new agent protocols, AI-to-AI trust failures, memory poisoning, impersonation, autonomous tool misuse or changes in defensive models. This prepares learners for increasingly capable AI without speculative claims about AGI. The lab refreshes case material while preserving the program’s core learning outcomes and hours.
Live Online. Built for professional teams worldwide.
English-language live instruction, practical assignments and individual review. International learners should share their country and time zone so admissions can confirm a suitable cohort, local class times and daylight-saving changes before enrolment. Three sessions per week; generally 60–90 minutes each.
AI5 also serves learners in India and Delhi NCR. These programs are listed as Live Online; any on-site company delivery requires a separate agreed scope. Ask for batch dates, fees, applicable taxes, payment currency and international payment instructions. No batch date or commercial-tool access is promised until confirmed.
Companies can request a private cohort around approved tools, sanitized scenarios, team roles and measurable acceptance criteria. Discuss company training.
Questions before you join
How is this different from a conventional cybersecurity course?
AI-assisted security work and the security of AI systems are the starting point. Every workflow requires evidence checks, explicit authority and measurable tests. Conventional foundations are prerequisites or targeted refreshers, rather than the main curriculum.
How many live sessions and hours are included?
12 weeks × 3 sessions = 36 live sessions. At 60–90 minutes each, that is 36–54 instructor-led hours. Independent assignments are additional.
Do I need coding or cybersecurity experience?
Working Python, HTTP/APIs, Git, terminal and container basics. Understand authentication and authorization. Ability to run a small application locally is required; a brief readiness task checks this before entry.
Are paid tools, exams or professional certifications included?
Do not assume a commercial subscription, cloud credit, vendor exam, external certification or CPE entitlement is included. Core practical work uses local/open tools and synthetic evidence where possible. Ask admissions for a written list of any batch-specific access costs and completion documentation.
Can international learners and company teams join?
Yes, through Live Online training in English, subject to a suitable confirmed cohort. Share your time zone and objectives. Companies may request a private cohort with agreed tools and sanitized scenarios.
Does the program guarantee a job or a secure AI system?
No. The assessed output is a portfolio of verified workflows and control evidence. Hiring and production security depend on experience, the environment and ongoing review; a course or scanner cannot guarantee either.
CURRICULUM REFERENCES
Work from current security guidance.
Source pages checked September 2026. Each cohort records the editions, tool versions and advisories used in its lab briefs. Framework use does not imply accreditation, partnership or endorsement.