Secure an AI product: prompt injection, guardrails and the AI Act
An AI risk register with OWASP, testable layered guardrails, red teaming and incidents, and an AI Act analysis after the Digital Omnibus.
Own the security and compliance of a product that embeds AI, together with the engineering team, security and legal: map threats with the OWASP Top 10 for LLM Applications, analyze prompt injection and data exfiltration paths, specify layered guardrails with testable criteria, organize red teaming, abuse monitoring and incident response, then qualify your product under the EU AI Act (role, risk level, Article 50 transparency, timeline after the Digital Omnibus) and the GDPR. You leave with your product's five-piece AI security and compliance dossier: risk register, specified guardrails, operations plan, dated AI Act analysis, transparency and GDPR, ready to review with security and a lawyer. This course is not legal advice.
What you will be able to do
- Map the attack surface of an AI product and its risks with the OWASP Top 10 for LLM Applications 2025, in a prioritized risk register.
- Analyze a product's direct and indirect prompt injection paths, system prompt leakage and data exfiltration (lethal trifecta).
- Specify layered guardrails (input, output, rights, human approval, isolation, limits) with testable criteria and their cost.
- Plan red teaming, abuse monitoring and incident response for an AI feature.
- Qualify a product under the AI Act (role, risk level, prohibited practices, transparency, timeline) and connect this analysis with the GDPR.
Prerequisites
- Have an AI feature in production or in the works (assistant, text generation, agent, extraction)
- Know what a system prompt, a tool call and a RAG system are, at the "I know what it is" level
- Recommended course: Build an AI assistant for your product (its lesson on guardrails goes deeper here).
- Recommended course: Design reliable agents and tool calling (injection through an agent's tool outputs).
- This course replaces neither a security audit nor a lawyer's advice: it prepares you to run them and review them.
Syllabus
What will I produce in this course, and in what order?
- Course overview2 steps
Objective · By the end of this overview, you will know what you are going to produce (your product's five-piece AI security and compliance dossier: risk register, specified guardrails, operations plan, AI Act analysis, transparency and GDPR) and in what order the five modules get you there.
Where can an AI product be attacked, and how do you prioritize what you protect?
Objective · By the end of this lesson, you will be able to map the attack surface of an AI feature, run it through the ten categories of the OWASP Top 10 for LLM Applications 2025, and derive a risk register prioritized by likelihood and impact.
Objective · By the end of this lesson, you will be able to tell direct injection, indirect injection and jailbreaks apart, list every injection entry point in your product, and decide what may or may not go into a system prompt.
How does an attack get data out or trigger actions, and where do you cut it off?
Objective · By the end of this lesson, you will be able to spot the channels through which an injection can get data out (tools, requests, images, links, RAG index), to say whether your product combines the lethal trifecta and to choose the element to remove.
Objective · By the end of this lesson, you will be able to match each model output with its consumer and the control that makes it safe, reduce the functionality, rights and autonomy of an AI feature to what is needed, and specify the limits that bound its consumption.
Which guardrails do you specify, how do you know they hold, and what do you do on incident day?
Objective · By the end of this lesson, you will be able to choose, for each risk in the register, guardrails in several layers (input, context, actions, output, operations), to tell those that bound the risk from those that reduce it, and to specify them with a testable criterion and a cost.
Objective · By the end of this lesson, you will be able to plan a red teaming campaign and the adversarial test set that comes out of it, choose the abuse monitoring signals in production, and write the incident runbook of an AI feature, kill switch and notifications included.
What does the AI Act require of my product, from when, and how does it fit with the GDPR?
Objective · By the end of this lesson, you will be able to qualify each AI feature of your product under the AI Act - AI system or not, your company's role, risk level, obligations and application dates after the Digital Omnibus - and to record this analysis, dated, to review with a lawyer.
Objective · By the end of this lesson, you will be able to determine which obligations of Article 50 of the AI Act apply to your features, write their notices and product requirements, and list the GDPR points to check with your DPO (roles, legal basis, information, minimization, processors, impact assessment).
Do your product's register, guardrails and AI Act analysis hold up in review?
Objective · By the end of this lesson, you will be able to assemble your product's AI security and compliance dossier (risk register, specified guardrails, operations plan, AI Act analysis and GDPR points), self-assess it with the kit's checklist and plan its application over 7 and 30 days.