Explore the intricacies of AI security through a comprehensive examination of strategies, risk management frameworks, and governance structures. This course equips participants with the tools to implement Explainable AI for security auditing, develop effective AI Acceptable Use Policies, and establish an AI Incident Response Playbook. Engage in practical lessons on NIST AI RMF and MITRE ATLAS for threat modeling and dive into regulatory compliance under the EU AI Act. Participants will also learn to assess third-party AI vendors, manage data privacy, and create metrics dashboards, culminating in a project focused on AI governance for a real-world launch scenario.
Overview
Syllabus
- Welcome
- Preview the shift from building AI systems to governing them, confirm the Python and spreadsheet prerequisites, and tour the browser-based workspaces where every exercise runs.
- Explainable AI (XAI) for Security Auditing
- Learn how explainable AI (XAI) and SHAP enable security auditors to detect bias, assess model risk, and create defensible audit findings for black-box models.
- Implementing Explainable AI (XAI) for Security Auditing
- Audit AI for security using SHAP: investigate model decisions, detect proxy biases, perform counterfactuals, and draft clear audit memos for stakeholders.
- AI Risk Framework Implementation (NIST AI RMF)
- Learn to implement the NIST AI Risk Management Framework's Govern, Map, Measure, Manage loop to identify, track, and mitigate AI-specific risks in dynamic environments.
- Implementing AI Risk Framework (NIST AI RMF)
- Apply the NIST AI Risk Management Framework to assess, score, and visualize AI risks, build risk registers, and create executive reports for responsible AI deployment.
- AI Threat Modeling (MITRE ATLAS)
- Learn how to use MITRE ATLAS to identify adversary tactics against AI systems, assess techniques like data poisoning and prompt injection, and anticipate threats that traditional security tools miss.
- Implementing AI Threat Modeling (MITRE ATLAS)
- Build an AI threat model with MITRE ATLAS: map attack surfaces, score technique likelihood and impact, and prioritize mitigations for a production ML pipeline.
- Regulatory Compliance for AI / EU AI Act
- Learn how the EU AI Act's risk-based tiers classify AI systems, and identify the data governance, transparency, human oversight, and robustness duties that attach to high-risk deployments.
- Implementing Regulatory Compliance for AI (EU AI Act)
- Apply the EU AI Act to classify AI systems by risk tier, build a compliance matrix, map obligations to controls, and produce an auditable compliance plan.
- Developing an AI Acceptable Use Policy
- Learn how an AI Acceptable Use Policy fits the wider policy stack, and identify the approved-tool lists, data classification rules, and prohibitions that make a policy enforceable.
- Drafting an AI Acceptable Use Policy
- Draft an enforceable AI Acceptable Use Policy: define prohibited uses, map policy clauses to technical controls, and design an exception procedure with clear approval authority.
- Understanding AI Incident Management
- Understand unique AI incident types, detection strategies, response frameworks, severity levels, blameless learning, and emerging regulatory requirements for effective AI incident management.
- Building an AI Incident Response Playbook and Detection Pipeline
- Build an AI incident response playbook: classify incident severity, implement automated detection against metric baselines, and define escalation paths for AI-specific failure modes.
- AI Security Metrics and Dashboarding
- Learn what separates a genuine key risk indicator from a vanity metric, and how to select, band, and threshold AI security KRIs for executive dashboards.
- Building an AI Security KRI Dashboard
- Build an AI security KRI dashboard in code: compute refusal-rate and fairness indicators, apply green-amber-red bands, and surface portfolio-level risk for governance review.
- Understanding Third-Party AI Vendor Risks
- Learn to identify, categorize, and mitigate the unique risks of third-party AI vendors, including data, bias, drift, lock-in, and security with robust governance and contracts.
- Conducting a Third-Party AI Vendor Assessment
- Assess third-party AI vendors: score risk across weighted criteria, evaluate SLA compliance, tier vendors by exposure, and produce evidence-backed procurement recommendations.
- Documenting Security in a Model Card
- Learn how a model card documents security posture, what belongs in its Security Considerations section, and how it anchors a transparency stack that regulators can audit.
- Authoring an AI Security Model Card
- Author a security-focused model card: document adversarial vulnerabilities and subgroup performance, then crosswalk each section to EU AI Act Article 11 technical documentation duties.
- AI Governance for Bias and Fairness Auditing
- Learn to audit AI for disparate outcomes using core fairness metrics, understand why they cannot all be satisfied at once, and govern fairness across the model lifecycle.
- Running a Fairness Audit and Making a Launch Decision
- Run a fairness audit end to end: measure subgroup disparities, test threshold adjustments against a policy card, and defend a launch, hold, or remediate decision.
- Understanding Data Retention and Privacy for AI
- Explore AI's data retention paradox, deletion challenges post-training, regulatory conflicts, key data types, and privacy-preserving techniques for responsible AI governance.
- Building an AI Data Retention and Deletion Pipeline
- Build an AI data retention and deletion pipeline: apply retention schedules, select deletion methods under legal holds, and trace deletion impact through model lineage.
- Understanding the AI Governance Operating Model
- Learn what distinguishes a governance operating model from a framework: decision rights, an AI Review Board charter, RACI accountability, and the failure modes that break most designs.
- Designing an AI Governance Operating Model
- Design an AI governance operating model: draft a review board charter, assign RACI accountability, set reporting cadences, and stress-test the design against common failure modes.
- Project: HealthGuard Launch Review: AI Governance Portfolio
- Run a pre-launch GRC review of a clinical AI model: classify it under the EU AI Act, audit fairness and explainability, and defend a Go or No Go launch recommendation.
Taught by
Sohbet Dovranov