Live online training - EXIN certification included

EXIN
AI Security Professional

based on the OWASP AI Exchange

Every AI system your organisation deploys widens your attack surface, and most security teams have not been trained for the new threats: prompt injection, data poisoning, model theft, agents with too much access. This course prepares you for the EXIN AI Security Professional exam in four live half-days, built on the OWASP AI Exchange, the open body of knowledge written by 165+ security experts and reflected in ISO/IEC 27090 and the EU AI Act.

You train with an accredited trainer, work through cases from a private company and a public agency, take two full mock exams, and sit the official exam with the voucher included. No prior certification is required. It's designed for security and IT professionals, and for the managers and project leads who have to decide what "secure enough" means for AI.
Format
Live online, English
(ClickMeeting, course hub)
Duration
4 x 3.5 hours live
14 hours in total, plus optional self-paced prep module
Cohort size
8 to 12 students*
*Minimum 8 required to start the cohort

Early bird cohort min. 6

Certification included
Official EXIN exam and one retake included, web-proctored, voucher valid 12 months

AI series

Price
€ 1,595 incl. VAT*
Cohort 1 early bird:
 € 1,295 until 17 Oct.
*2026 launch pricing. Tax depends on the VAT rate in your EU country of residence; your total stays the same. EU companies: €1,275 ex VAT (early bird €1,035) by invoice; contact us first.
Write your awesome label here.

The attack surface that "just appeared"

Your organisation is already running AI. Someone in marketing has a chatbot on the website, the developers pull open-source models from a hub, a vendor ships an "AI agent" that reads mailboxes and books meetings. Each one is an IT system, so everything you know about security still applies. But each one also has assets that did not exist before: training data that can be poisoned, a model that can be stolen through its own API, an input channel that takes instructions from strangers, and output that other systems trust without checking.

The people who could have raised the alarm mostly haven't been trained for it. AI security has been an expert niche with scattered papers and vendor slides. The OWASP AI Exchange changed that: one open, structured body of knowledge on AI threats and controls, maintained by the security community and feeding the ISO standards and the EU AI Act. EXIN built a certification on it. This course gets you through that certification, and, more importantly, makes you the person in the room who can say what to do.
AI security is not a new discipline. It's your existing discipline with new assets to protect. Learn where they are.

From "we should look at that" to a plan

Four half-days, in order of how you would actually work: organise, then understand the threats, then choose controls, then test, then make it hold up under privacy law and the AI Act. Every session pairs the OWASP AI Exchange material with cases from two fictive organisations you will get to know well: Splork Inc., a mid-size software company, and the Latverian Agency for National Infrastructure (LANI), a public body with critical systems. You decide what they should do; then we look at what the body of knowledge says.

Session 1: AI security in the organisation. Why AI security is an extension of your security programme, the AI-specific assets, the G.U.A.R.D. cycle, threat modelling for AI, and the particular risks of agentic AI.

Session 2: Input and development-time threats. Evasion attacks by attacker knowledge, direct and indirect prompt injection and the seven layers of protection, disclosure of sensitive data, model exfiltration, resource exhaustion, data and model poisoning, supply-chain risk.

Session 3: Runtime threats and controls. Conventional attacks with AI consequences, augmentation data and RAG as an asset, the three control families: governance, limiting sensitive data, limiting unwanted behaviour. Shared responsibility with model providers.

Session 4: Testing, privacy and compliance. AI security testing and red teaming, the general testing approach, privacy principles applied to AI, ISO/IEC 23894, 27005, 42001 and 5338, the EU AI Act and GDPR, copyright risk.
Four sessions. Five exam domains.
One plan you can defend on Monday.

Built for the people who will be asked

This course is for the people who get asked "is this safe?" about AI systems and need a better answer than a shrug:
  • Security professionals and architects who need to extend what they already do to AI systems.
  • Developers, DevSecOps and risk managers who own the controls, also when the model comes from a third party.
  • IT and project leads rolling out AI in a private company or a public agency.
  • Managers with a technical background who sign off on AI vendors and want to know which questions to put in the contract.
You do not need to be a machine-learning engineer, and no prior certification is required. You do need to be comfortable with basic IT security concepts and willing to learn the AI vocabulary. If that worries you, the optional self-paced prep module "AI security foundations" covers the terminology before the first session.
If you use AI tools in your daily work and want to use them safely, our AI Foundation or AI Essentials courses are the better fit. This course is for the people who have to secure the systems behind those tools, and to show that they did.

About the exam

40 scenario-based multiple-choice questions, 90 minutes, closed book, pass mark 65% (26 correct). Online, web-proctored through EXIN Anywhere, at a time you choose. No prerequisites. The certification tests at Bloom levels 2 and 3, which means you must apply the knowledge to a scenario, which is exactly what the mini-cases and mock exams train.

A second attempt, if you need one, is included: one free retake if you attended all four sessions and completed both mock exams, within the 12-month voucher validity.
The systems are already running. The question is whether anyone in your organisation can say what could go wrong and what to do about it. Make that person you.

 Key outcomes

  • Organise AI security in your organisation. Use the G.U.A.R.D. cycle: Govern, Understand, Adapt, Reduce, Demonstrate.
  • Recognise the AI-specific threats. From evasion and prompt injection to poisoning, model theft and agentic risks, and recognise at which point in the lifecycle each one strikes.
  • Choose controls that hold. Limit sensitive data, limit unwanted model behaviour, and define who owns each control when the model comes from a third party.
  • Scope AI security testing. Plan red teaming and testing that goes beyond a conventional pentest.
  • Make it hold up under the law. Apply privacy principles, the four supporting ISO standards and the EU AI Act risk classes to a concrete system.
  • Pass the EXIN AI Security Professional exam. The training, two full mock exams and five mini-cases train what the scenario questions test.

What's included

Four live half-day sessions (14 hours)
  • With the trainer, 09:30 to 13:00 CET, via ClickMeeting. Recorded for anyone who misses one.
Official EXIN exam voucher
  • Web-proctored, taken at a time of your choosing. The voucher is valid 12 months from enrolment.
Course hub on our learning platform
  • Pre-work for each session, supplementary content, session recordings and downloadable slides, in one place.
"AI security foundations" prep module
  • Self-paced, for anyone who need to establish or brush up on the AI vocabulary before day one.
Five mini-cases with per-option feedback
One per exam domain, set at Splork Inc., a mid-size software company, and the Latverian Agency for National Infrastructure, a public body with critical systems. You decide what they should do; then we check the body of knowledge.
Two full mock exams
  • 40 questions each, in the official format, open from day one.
Interactive study tools
  • The threat taxonomy map, the standards ladder and the threat-to-control navigator.
EXIN preparation guide, sample exam and glossary
  • Plus the OWASP AI Exchange as your core reading, free at owaspai.org.
Free retake
  • One free retake if you attended all four sessions and completed both mock exams, within the 12-month voucher validity. You keep access to the mock exams and cases.
Trainer support between sessions
  • Ask your questions in the course hub between sessions. Typical response time is max. 24 hours.

Practical details

Format:
Live online, English, via ClickMeeting. Course hub on the Academy platform (LearnWorlds).
Dates:
Four half-days, 09:30 to 13:00 CET.
  • Cohort 1: 20, 22, 27 and 29 October 2026.
  • Cohort 2: 10, 12, 17 and 19 November.
  • Cohort 3: 1, 3, 8 and 10 December.


2027 dates to follow
Access:
All student content, including session recordings, is available for one year after purchase.
Price:
2026 launch pricing: €1,595 including VAT. Cohort 1 early bird discount €1,295 until 17 October. The VAT portion depends on your EU country of residence; the total you see is the total you pay.
EU business purchase:
EU companies pay €1,275 ex VAT (early bird €1,035) by reverse-charge invoice. Please contact us before ordering, and we'll arrange it.
Requirements:
A modern PC, a headset and a stable internet connection. For the exam you must use a computer that you can install and run downloaded software on.
What's not needed:
Prior certification, machine-learning skills, attack tooling.

Pricing and VAT

Price includes 25% VAT. EU companies pay €1,275 ex VAT (early bird €1,035) by reverse-charge invoice; please contact us directly before placing an order. Cohort 1 (October 2026) has an early-bird price of €1,295 until 17 October; Cohorts 2 and 3 are €1,595.

Exam information

The exam is offered as an online, web-proctored exam through the EXIN Anywhere service, live or recorded, at a time you choose.
Exam type: 
Multiple-choice, scenario-based. Closed book.
Questions:
40
Delivery:
Web-based, proctored through EXIN Anywhere. 90 minutes.
Pass mark:
65% - 26 correct answers out of 40.
Cost: 
First attempt included in course price. One free retake if you attended all four sessions and completed both mock exams. Voucher valid 12 months from enrolment (we are not able to extend vouchers).
Requirements: 
No prerequisites. Basic IT security literacy is recommended; the prep module covers the AI vocabulary.

Course Content

What you will learn

Five modules follow the five domains of the EXIN AI Security Professional exam. Each module combines live teaching, a mini-case from Splork Inc. or the Latverian Agency, and pre-work in the course hub. The percentages show the weight of each domain in the exam.

Module 115% of the exam

AI security in the organisation

Where AI security sits in your organisation, how it differs from conventional security, and how to run the first threat model.

  • The five G.U.A.R.D. steps: Govern, Understand, Adapt, Reduce, Demonstrate
  • AI-specific assets and the key threats against them
  • Risk management steps for threat modelling
  • Risks of agentic AI
Module 237.5% of the exam

AI security threats

The full threat map: what the attacker touches, and when. Input threats, development-time threats and runtime threats, with the countermeasures for each.

  • Evasion, prompt injection (direct and indirect), sensitive data disclosure
  • Model exfiltration and resource exhaustion
  • Data poisoning, model poisoning and supply chain risks during development
  • Runtime threats: model leaks, injection through AI output, augmentation data manipulation
Module 327.5% of the exam

AI security controls

The controls that hold, and who owns each one when the model comes from a third party.

  • General governance controls and their coverage
  • Control split between your organisation and your AI vendor
  • Limiting sensitive data in training, prompts and outputs
  • Limiting unwanted model behaviour, and why it pays off
Module 47.5% of the exam

AI security testing

How to test an AI system beyond conventional penetration testing, and how to scope it.

  • Why AI security testing is needed, and what it covers
  • Threats to test that conventional testing misses
  • Testing strategies, from red teaming to model evaluation
Module 512.5% of the exam

Privacy and compliance

Privacy principles applied to AI, the standards ladder, and the EU rules your AI systems must meet.

  • Privacy concerns in AI systems and how to apply the principles to a case
  • ISO/IEC 23894, 27005, 42001 and 5338 as the AI editions of standards you know
  • Compliance challenges, the EU AI Act, and copyright risk mitigation
Exam preparationIncluded

Two mock exams and the official exam

Two full 40-question mock exams in the official format, open from day one. Your EXIN exam voucher is included; you book your own slot after session 4.

  • Mock exam 1 after session 2, mock exam 2 after session 4
  • Interactive study tools: threat taxonomy map, standards ladder
  • EXIN preparation guide, sample exam and glossary

Live sessions: four half-days of 3.5 hours, 09:30 to 13:00 CET. The detailed agenda per session is published in the course hub before your cohort starts.

 In-house training at your location is also available

Bring the course to your company team anywhere in the EU. The same four sessions, delivered on site over two days, with physical workshop sessions.
  • Team of up to 8: €9,900 ex VAT. Team of up to 14: €15,900 ex VAT.
  • EXIN exam and one retake included for every participant.
  • You provide the venue, catering and equipment.
  • Invoiced with reverse-charge VAT to EU companies and public bodies.

Refund policy

Courses can be refunded before they start according to EU rules. Missed classes will not be refunded, but recordings will be available for streaming.

Customer support

We are always available for customer support via email. Typical response time is max. 24 hours.

1 year access

All student content, including session recordings, is available for one year after the course purchase.

Frequently asked questions - this course

Do I need a technical background?

Basic IT security literacy, yes. Machine learning, no. The prep module covers the AI vocabulary.

How long do I have access?

All student content, including the session recordings, is available for one year after the course purchase. The exam voucher is valid 12 months from enrolment. Please see the full terms for vocuhers, we are anot able to renew them for you, if they expire. 

Can I cancel?

Within 14 days of purchase, yes, if you are a consumer in the EU/EEA and the course has not started. After the first session, no. You can transfer your seat to a colleague before the course starts. Full terms: corprevac.com/terms.

VAT calculation for EU citizens

All prices shown include VAT. If you live in the EU, the VAT portion is calculated at checkout based on your country of residence, but your total will remain the amount displayed on this page.

Is the course accredited by EXIN?

Yes. Corporate Revolutionary Academy is an EXIN accredited training organisation, and the trainer is accredited by EXIN for the EXIN AI Security Professional certification.

Is the exam included?

Yes, the official EXIN exam voucher for an online proctored examis part of the price. You book your own slot with EXIN after the course.

How much preparation is expected?

EXIN recommends around 84 study hours in total for this certification. The 14 live hours, the mini-cases, the mock exams and the OWASP AI Exchange reading cover it; plan two to three hours between sessions.

Can my company pay by invoice?

Yes. EU companies pay €1,275 ex VAT (early bird €1,035) by reverse-charge invoice with your EU VAT number; contact us before ordering. Consumers receive a receipt by email at enrolment and can find it under Payment History.

What if the cohort does not fill?

Each cohort needs a minimum of 8 participants to run (6 for the early-bird cohort). If a cohort does not reach the minimum, we tell you at least one week before the first session, and you choose between a full refund and a seat on the next cohort.

What if I fail the exam?

You get one free retake if you attended all four sessions and completed both mock exams, within the 12-month voucher validity. You keep access to the mock exams and cases.

Additional questions? Please see the general FAQ

Christian Triantafillou Schade

Agile Leadership Consultant, writer and trainer. Scrum Master, Release Train Engineer (RTE). EXIN accredited AI trainer.
About your trainer
Christian has advised Danish public agencies and private companies on digital and organisational change since 1996, as an agile coach, Release Train Engineer and trainer, and co-founded the Corporate Revolutionary Academy, an EXIN accredited training organisation. His AI work sits at the intersection of security, governance and EU regulation.

He teaches the way he consults: starting from what goes wrong and working toward what holds up. He holds the EXIN AI Security Professional certification and is accredited by EXIN to deliver this training.

Customer feedback for our academy