This certificate treats AI systems as systems, covering the data, the model, the pipeline and the application rather than treating AI as a policy topic. It opens by separating traditional cybersecurity risk from genuinely AI-specific risk, then runs the AI lifecycle from design through retirement with security gates at each stage. The core is adversarial machine learning — poisoning attacks against training data, evasion attacks against deployed models, privacy attacks that target training information, and model extraction — grounded in the NIST adversarial machine learning taxonomy. Generative AI gets its own treatment: direct and indirect prompt injection, insecure output handling, and the risks introduced by retrieval-augmented generation, plugins and external data sources.
It then moves from building to watching, and finally to breaking. An AI system can be compromised without anyone touching the server it runs on, so monitoring has to move from whether the system is running to whether it is behaving the way it is supposed to, on data it is supposed to see. The path covers the four categories of AI monitoring and the signals that distinguish them — a sustained spike in near-identical unusual inputs reads as adversarial probing, a slow accuracy decline reads as drift, an unexplained query spike from one credential reads as an extraction attempt — along with the evidence responders routinely fail to preserve, meaning model version, prompt and response logs, training data lineage and guardrail configuration. Severity is classified by impact rather than technical complexity, on the principle that an incorrect benefits determination caused by a data integrity failure is high severity even though nothing technically broke. It closes on adversarial testing and assurance, separating two things agencies routinely conflate: red teaming is deliberately trying to break a system, while assurance is the documented evidence that it is trustworthy enough for its purpose. That means the engagement lifecycle, rules of engagement, and the assurance case as claim, argument and evidence in a form an oversight body can audit — then extends everything to foundation models and to agentic AI, where the attack surface expands from what a system says to what a system does.