Course overview
Lesson 1 of the module "Overview" in the course "Secure an AI product: prompt injection, guardrails and the AI Act".
Lesson objective
By the end of this overview, you will know what you are going to produce (your product's five-piece AI security and compliance dossier: risk register, specified guardrails, operations plan, AI Act analysis, transparency and GDPR) and in what order the five modules get you there.
Where it fits
Overview
What will I produce in this course, and in what order?
Lessons in this module
- Course overview (this lesson)
What you will learn in the course
This lesson is part of the course Secure an AI product: prompt injection, guardrails and the AI Act
- Map the attack surface of an AI product and its risks with the OWASP Top 10 for LLM Applications 2025, in a prioritized risk register.
- Analyze a product's direct and indirect prompt injection paths, system prompt leakage and data exfiltration (lethal trifecta).
- Specify layered guardrails (input, output, rights, human approval, isolation, limits) with testable criteria and their cost.
- Plan red teaming, abuse monitoring and incident response for an AI feature.
- Qualify a product under the AI Act (role, risk level, prohibited practices, transparency, timeline) and connect this analysis with the GDPR.
Related courses
- Build an AI assistant for your productAdvanced · ~3 hr
- Design a RAG architecture that fits your productAdvanced · ~3 hr 30 min
- Evaluate an AI feature: test sets, metrics and LLM judgesAdvanced · ~3 hr