AI Security & Governance
Secure generative AI systems end-to-end — prompt injection, data exfiltration, model risk, and governance that holds in audits.
Duration
6 weeks · 6-8 hours/week
Level
Intermediate
Delivery
Online
Status
Open for enrollment
Why this technology matters.
AI security and governance is the discipline of keeping LLM and agentic systems safe, compliant, and trustworthy — from prompt-injection defenses to data handling and audit trails. It matters now because AI systems touch sensitive data, call real tools, and generate authoritative-sounding output, which makes failures both more likely and more consequential.
It is used by product, security, and compliance teams to red-team models, enforce guardrails, and document decisions for review. It solves risk reduction and accountability for AI behavior, but it does not solve unclear product scope or poor evaluation — a policy document cannot substitute for measured quality, and guardrails cannot fix retrieval over data that should never have been connected.
By the end you will be able to build a threat model and red-team plan for an LLM feature, a guardrailed deployment with logging and review trails, and a governance packet documenting risks, controls, and escalation paths.
Why this course exists
The gap is between a demo with a safety disclaimer and a production AI system that withstands adversarial inputs, tool misuse, and auditor questions. The course teaches the arc from Model risks to Prompt and Context controls to Retrieval boundaries to Tool permissions to Agents oversight to Evaluation to Security and Production monitoring, so students ship AI that is both capable and defensible.
Know exactly what you're signing up for.
Who is this for
Prerequisites
- Familiarity with LLM applications and APIs
- Basic security concepts such as auth and data handling
- Understanding of software delivery lifecycles
Technologies & tools
Skills you'll gain
A 6 weeks arc, module by module.
- Module 01
Week 1 — AI threat landscape and governance frames
- Module 02
Week 2 — Prompt injection, jailbreaks, and extraction
- Module 03
Week 3 — Data controls: PII, exfiltration, and provenance
- Module 04
Week 4 — Red-teaming and evaluation
- Module 05
Week 5 — Policy, audit, and reporting
- Module 06
Week 6 — Capstone: a secured AI system with governance packet
Practical Training Flow
Learning → Guided Labs → Independent Practice → Industry Project → Capstone → Portfolio → Career Preparation. Practical hours are tracked alongside instructional hours and surfaced on the certificate.
Delivery as HIGAET Practical Training / Experiential Learning.
What you'll be able to do.
- Map AI-specific attack surfaces: prompt injection, extraction, and abuse.
- Design governance controls mapped to regulation and enterprise policy.
- Implement red-team evaluations and continuous safety monitoring.
- Produce a governance artifact that survives stakeholder and audit review.
You will build.
Every project ships as HIGAET Practical Training / Experiential Learning — portfolio-ready work, not exercises.
- Project 01
Threat model for an LLM application
- Project 02
Red-team exercise with mitigations
- Project 03
Logging and audit trail for AI actions
- Capstone
Secure AI deployment plan with governance controls
Speak the language first.
- AI threat modeling
- Identifies how attackers could abuse a model or its data flows, covering inputs, outputs, tools, and integrations.
- Prompt injection
- A technique where crafted inputs try to override a model's instructions, requiring input validation and output controls.
- Data leakage prevention for LLMs
- Practices that stop models from exposing sensitive training or retrieval data through careful scoping and redaction.
- Model supply-chain risk
- Risks from third-party models, datasets, and plugins, managed through provenance checks and version pinning.
- Access control for AI systems
- Restricts who can query, retrain, or configure models using roles, API keys, and audit logging.
- Evaluation for harmful outputs
- Tests model responses against safety criteria to catch disallowed or unsafe behavior before release.
- Logging and traceability
- Records prompts, retrieval context, and tool calls so AI decisions can be reviewed defensively after incidents.
- Responsible disclosure process
- A defined path for reporting and fixing AI vulnerabilities without exposing users to additional harm.
- Governance controls mapping
- Links AI safeguards to organizational policies so responsibilities for review and approval are clear.
Fix, check, and go deeper.
Troubleshooting & common mistakes
Model echoes sensitive retrieved content to unauthorized users
Restrict retrieval scope by user role, add output filtering, and re-test with role-separated queries.
Prompt injection bypasses system instructions
Separate untrusted input from instructions, add validation and constrained tool permissions, then re-run adversarial tests.
Third-party model update changes behavior unexpectedly
Pin the model version, compare outputs against a saved evaluation set, and gate upgrades behind review.
Audit log missing prompt context for an incident
Enable structured logging of prompts, retrieval IDs, and tool calls, then verify coverage with a sample review.
Safety evaluation flags rising refusal errors on benign queries
Inspect the flagged cases for over-broad filters, refine categories, and re-run the evaluation suite.
Before you move on, you should be able to
- Explain common attack paths against LLM-based systems
- Design access controls for model APIs and tool integrations
- Build logging that supports defensive incident review
- Evaluate model outputs against defined safety criteria
- Deploy version pinning for third-party models and datasets
- Respond to reported AI vulnerabilities through a disclosure workflow
- Assess AI features against organizational governance controls
Start your application.
Share a few details and a HIGAET advisor will reach out within one business day with next steps.
Common questions
Continue in Online Courses.
Generative AI Foundations
Build a rigorous mental model of modern Generative AI — from tokens and embeddings to transformers, fine-tuning, and evaluation.
View CourseApplied LLM Engineering
Move from prompt experiments to production: orchestration, evals, observability, and cost control for LLM systems.
View CourseRetrieval-Augmented Generation Systems
Design and ship RAG pipelines that are accurate, observable, and cheap to operate at scale.
View CourseWhat should you learn next?
Ready to start AI Security & Governance?
A 6 weeks course — Online Courses.