Module
Module 4 of 6Lesson 1 of 2~22 min

Specify layered, testable and costed guardrails

Lesson 1 of the module "Guardrails and security operations" in the course "Secure an AI product: prompt injection, guardrails and the AI Act".

Lesson objective

By the end of this lesson, you will be able to choose, for each risk in the register, guardrails in several layers (input, context, actions, output, operations), to tell those that bound the risk from those that reduce it, and to specify them with a testable criterion and a cost.

Where it fits

Guardrails and security operations

Which guardrails do you specify, how do you know they hold, and what do you do on incident day?

Lessons in this module

  1. Specify layered, testable and costed guardrails (this lesson)
  2. Red teaming, abuse monitoring and incident response

What you will learn in the course

This lesson is part of the course Secure an AI product: prompt injection, guardrails and the AI Act

  • Map the attack surface of an AI product and its risks with the OWASP Top 10 for LLM Applications 2025, in a prioritized risk register.
  • Analyze a product's direct and indirect prompt injection paths, system prompt leakage and data exfiltration (lethal trifecta).
  • Specify layered guardrails (input, output, rights, human approval, isolation, limits) with testable criteria and their cost.
  • Plan red teaming, abuse monitoring and incident response for an AI feature.
  • Qualify a product under the AI Act (role, risk level, prohibited practices, transparency, timeline) and connect this analysis with the GDPR.