ProSentinel Academy / AI

AI Security and Risk Management

Protect information, processes and decisions, from everyday AI use to system-level assessment.

Who it is for

AI users, security and cybersecurity teams, IT, data owners and risk professionals.

In practice

Recognise risks arising from data, integrations and model actions. Connect technical safeguards with organisational accountability. This defensive programme does not extend the service offer to penetration testing.

Entry requirements

Basic computer skills and an understanding of how AI is used at work. Level I does not require a technical specialism.

Levels II and III require the preceding level’s competencies or verified equivalent experience. Preparation is agreed before enrolment. Higher levels introduce technical elements; tool requirements are confirmed in advance.

Three development levels

Level I / Foundation

Aware and Secure AI Use

Basic computer skills and an understanding of how AI is used at work. Level I does not require a technical specialism.

After this level, you can

  • Recognise situations that could expose information.
  • Choose an independent way to verify a request or material.
  • Distinguish suspicion from a confirmed incident and know when to escalate.
Competency scope
  • Unapproved use of private AI tools, known as shadow AI, and reporting AI use within an organisation.
  • Information disclosed to models, confidential and sensitive data, and leakage.
  • AI-assisted phishing and social engineering; independently confirming unusual requests.
  • Synthetic images and recordings, or deepfakes, voice cloning and fabricated documents.
  • Disinformation, incorrect answers and recommendations, and limits to automated forgery detection.
  • Basic material verification, safe working practices and escalation to the responsible person.

Competency assessment

A knowledge test and a short task assessing risk and selecting a safe next action.

Credential after successful assessment

ProSentinel — Certified AI Security Practitioner — Foundation

NEXT RECOMMENDED COMPETENCY

A recommendation suggests a development direction. It does not waive the destination programme’s entry requirements.

Level II / Professional

AI System Threats and Protection

Competence at the preceding level of this track or equivalent experience, confirmed before participation.

After this level, you can

  • Connect a threat scenario with a process and a business consequence.
  • Identify trust boundaries and appropriate data and tool safeguards.
  • Explain access controls and how their effectiveness should be assessed.
Competency scope
  • Prompt injection, including malicious instructions embedded in documents or web pages, and system instruction leakage.
  • Data poisoning: introducing harmful material into system datasets, and manipulation of model behaviour.
  • Unsafe tool use, excessive agent permissions and improper handling of outputs by other systems.
  • Security of retrieval-augmented generation (RAG), integrations and the technology supply chain.
  • Identity and access management, credential protection and action logging.
  • Secure architecture foundations using risks documented by the OWASP GenAI Security Project.

Competency assessment

A test, case analysis and practical assessment of safeguards in a prepared solution. No unauthorised activity on production systems.

Credential after successful assessment

ProSentinel — Certified AI Security Practitioner — Professional

NEXT RECOMMENDED COMPETENCY

A recommendation suggests a development direction. It does not waive the destination programme’s entry requirements.

Level III / Advanced

Managing AI Security and Risk

Competence at the preceding level of this track or equivalent experience, confirmed before participation.

After this level, you can

  • Produce a reasoned risk assessment across a solution’s lifecycle.
  • Assign risk owners, safeguards and monitoring measures.
  • Design an incident response and criteria for safe recovery.
Competency scope
  • Threat modelling, risk analysis and the attack surface: points through which a system can be affected.
  • Model lifecycle, suppliers, architecture, knowledge bases and agent security.
  • Permissions, monitoring and event logging.
  • Incident response, containment and recovery.
  • Risk registers, control selection, auditable records and continuous monitoring.
  • Reference frameworks: OWASP GenAI, NIST AI RMF and the Generative AI Profile, ISO/IEC 23894 and ISO/IEC 42001.

Competency assessment

A knowledge check, advanced case and AI risk management project, followed by a defence of priorities and safeguards.

Credential after successful assessment

ProSentinel — Certified AI Security Practitioner — Advanced

NEXT RECOMMENDED COMPETENCY

A recommendation suggests a development direction. It does not waive the destination programme’s entry requirements.

Certification rules

ProSentinel — AI Security Specialist

Specialist certification requires successful assessments at all three levels of the track and a current Level III credential. Passing a higher level does not automatically award lower-level credentials.

The knowledge test requires at least 80%. Practical assessment requires all specified competencies; breaches of safety or independent-work rules prevent a pass. Attendance alone does not confer certification.

Certification is valid for 36 months. Renew a level through a current assessment of its competencies; renew a specialisation through a Level III assessment covering the whole track. Academy rules on retakes, appeals and an independent certification decision apply.

This is ProSentinel Academy’s own competency certification system. It is not a state or regulated qualification, an academic degree or an ISO certificate.

Related Academy competencies

Reference frameworks

These materials inform the programme. Referencing them does not imply partnership, accreditation or certification by their authors.

Explore AI programmes