Skip to content
Academy · Online Courses · intermediate

AI Security & Governance

Secure generative AI systems end-to-end — prompt injection, data exfiltration, model risk, and governance that holds in audits.

Duration

6 weeks · 6-8 hours/week

Level

Intermediate

Delivery

Online

Status

Open for enrollment

Introduction

Why this technology matters.

AI security and governance is the discipline of keeping LLM and agentic systems safe, compliant, and trustworthy — from prompt-injection defenses to data handling and audit trails. It matters now because AI systems touch sensitive data, call real tools, and generate authoritative-sounding output, which makes failures both more likely and more consequential.

It is used by product, security, and compliance teams to red-team models, enforce guardrails, and document decisions for review. It solves risk reduction and accountability for AI behavior, but it does not solve unclear product scope or poor evaluation — a policy document cannot substitute for measured quality, and guardrails cannot fix retrieval over data that should never have been connected.

By the end you will be able to build a threat model and red-team plan for an LLM feature, a guardrailed deployment with logging and review trails, and a governance packet documenting risks, controls, and escalation paths.

Why this course exists

The gap is between a demo with a safety disclaimer and a production AI system that withstands adversarial inputs, tool misuse, and auditor questions. The course teaches the arc from Model risks to Prompt and Context controls to Retrieval boundaries to Tool permissions to Agents oversight to Evaluation to Security and Production monitoring, so students ship AI that is both capable and defensible.

Overview

Know exactly what you're signing up for.

Who is this for

Security practitionersAI engineersML engineersTechnology leadersProduct managersEngineering managers

Prerequisites

  • Familiarity with LLM applications and APIs
  • Basic security concepts such as auth and data handling
  • Understanding of software delivery lifecycles

Technologies & tools

Prompt injection defensesRed-teaming toolkitsAccess controlsAudit loggingContent filteringModel provenancePolicy frameworks

Skills you'll gain

AI threat analysisAdversarial testingGuardrail designAudit readinessRisk assessmentSecure deployment practices
Curriculum

A 6 weeks arc, module by module.

  1. Module 01

    Week 1 — AI threat landscape and governance frames

  2. Module 02

    Week 2 — Prompt injection, jailbreaks, and extraction

  3. Module 03

    Week 3 — Data controls: PII, exfiltration, and provenance

  4. Module 04

    Week 4 — Red-teaming and evaluation

  5. Module 05

    Week 5 — Policy, audit, and reporting

  6. Module 06

    Week 6 — Capstone: a secured AI system with governance packet

Practical Training Flow

Learning → Guided Labs → Independent Practice → Industry Project → Capstone → Portfolio → Career Preparation. Practical hours are tracked alongside instructional hours and surfaced on the certificate.

Delivery as HIGAET Practical Training / Experiential Learning.

ai security courseai governance courseprompt injection defensehigaet academy
Outcomes

What you'll be able to do.

  • Map AI-specific attack surfaces: prompt injection, extraction, and abuse.
  • Design governance controls mapped to regulation and enterprise policy.
  • Implement red-team evaluations and continuous safety monitoring.
  • Produce a governance artifact that survives stakeholder and audit review.
Projects

You will build.

Every project ships as HIGAET Practical Training / Experiential Learning — portfolio-ready work, not exercises.

  1. Project 01

    Threat model for an LLM application

  2. Project 02

    Red-team exercise with mitigations

  3. Project 03

    Logging and audit trail for AI actions

  4. Capstone

    Secure AI deployment plan with governance controls

Key concepts

Speak the language first.

AI threat modeling
Identifies how attackers could abuse a model or its data flows, covering inputs, outputs, tools, and integrations.
Prompt injection
A technique where crafted inputs try to override a model's instructions, requiring input validation and output controls.
Data leakage prevention for LLMs
Practices that stop models from exposing sensitive training or retrieval data through careful scoping and redaction.
Model supply-chain risk
Risks from third-party models, datasets, and plugins, managed through provenance checks and version pinning.
Access control for AI systems
Restricts who can query, retrain, or configure models using roles, API keys, and audit logging.
Evaluation for harmful outputs
Tests model responses against safety criteria to catch disallowed or unsafe behavior before release.
Logging and traceability
Records prompts, retrieval context, and tool calls so AI decisions can be reviewed defensively after incidents.
Responsible disclosure process
A defined path for reporting and fixing AI vulnerabilities without exposing users to additional harm.
Governance controls mapping
Links AI safeguards to organizational policies so responsibilities for review and approval are clear.
Keep going

Fix, check, and go deeper.

Troubleshooting & common mistakes

Model echoes sensitive retrieved content to unauthorized users

Restrict retrieval scope by user role, add output filtering, and re-test with role-separated queries.

Prompt injection bypasses system instructions

Separate untrusted input from instructions, add validation and constrained tool permissions, then re-run adversarial tests.

Third-party model update changes behavior unexpectedly

Pin the model version, compare outputs against a saved evaluation set, and gate upgrades behind review.

Audit log missing prompt context for an incident

Enable structured logging of prompts, retrieval IDs, and tool calls, then verify coverage with a sample review.

Safety evaluation flags rising refusal errors on benign queries

Inspect the flagged cases for over-broad filters, refine categories, and re-run the evaluation suite.

Before you move on, you should be able to

  • Explain common attack paths against LLM-based systems
  • Design access controls for model APIs and tool integrations
  • Build logging that supports defensive incident review
  • Evaluate model outputs against defined safety criteria
  • Deploy version pinning for third-party models and datasets
  • Respond to reported AI vulnerabilities through a disclosure workflow
  • Assess AI features against organizational governance controls
Apply

Start your application.

Share a few details and a HIGAET advisor will reach out within one business day with next steps.

FAQ

Common questions

Ready to start AI Security & Governance?

A 6 weeks course — Online Courses.