The AI Learning Hub Journal
◆ Free course · 4 modules · 25 lessons

Securing AI Systems

Threat-model, test, harden and respond — defending AI and agentic systems in practice

Read it in the library →
Module 1 · 6 lessons

Threat Modelling for AI Systems

Where classic threat models break on AI, how to inventory the real attack surface of a feature you own, drawing trust boundaries when the model itself consumes untrusted input, data-flow diagramming an LLM feature, enumerating techniques with MITRE ATLAS, and writing down the risks you have decided not to defend against.

  1. Why Classic Threat Models Miss AI
  2. Mapping the Attack Surface
  3. Trust Boundaries When the Model Is Untrusted
  4. Data-Flow Diagramming an LLM Feature
  5. Enumerating Techniques with MITRE ATLAS
  6. Deciding What You Will Not Defend
Module 2 · 7 lessons

The Attack Surface in Depth

Prompt injection at engineering depth and why filtering alone cannot hold, indirect injection through every ingestion channel, the lethal trifecta used as a design test, tool poisoning and the MCP supply chain, memory and context contamination, excessive agency, and the full inventory of exfiltration paths.

  1. Prompt Injection at Engineering Depth
  2. Indirect Injection and the Ingestion Inventory
  3. The Lethal Trifecta as a Design Test
  4. Tool Poisoning and the MCP Supply Chain
  5. Memory and Context Contamination
  6. Excessive Agency and Exfiltration Paths
  7. A Jailbreak Taxonomy
Module 3 · 6 lessons

Hardening and Controls

Least privilege for agents and scoped tool access, sandboxing and egress control, approval gates on irreversible actions, structured output and constrained decoding, guardrail models and their false-positive cost, agent identity and full-trace audit logging, and defence in depth with an honest account of what no single control can hold.

  1. Least Privilege for Agents
  2. Sandboxing and Egress Control
  3. Approval Gates on Irreversible Actions
  4. Structured Output and Constrained Decoding
  5. Guardrail Models and Their False-Positive Cost
  6. Identity, Audit Trails, and Defence in Depth
Module 4 · 6 lessons

Testing, Response, and Governance

Running an authorised adversarial exercise end to end, turning findings into security regression tests in CI, using automated adversarial testing without overstating it, detecting an AI incident in production, responding when the failing component is a model rather than a host, and closing the loop through post-incident review and governance.

  1. Running an Authorised Exercise
  2. Security Regression Tests in CI
  3. Automated Adversarial Testing and Its Limits
  4. Detecting an AI Incident in Production
  5. Response When the Failure Is a Model
  6. Post-Incident Review and Governance

Every lesson is free, with no sign-up. Reading happens in the library, where your progress is saved on your device.