Module
Module 1 of 6Lesson 1 of 1~3 min

Course overview

Lesson 1 of the module "Overview" in the course "Secure an AI product: prompt injection, guardrails and the AI Act".

Lesson objective

By the end of this overview, you will know what you are going to produce (your product's five-piece AI security and compliance dossier: risk register, specified guardrails, operations plan, AI Act analysis, transparency and GDPR) and in what order the five modules get you there.

Where it fits

Overview

What will I produce in this course, and in what order?

Lessons in this module

  1. Course overview (this lesson)

What you will learn in the course

This lesson is part of the course Secure an AI product: prompt injection, guardrails and the AI Act

  • Map the attack surface of an AI product and its risks with the OWASP Top 10 for LLM Applications 2025, in a prioritized risk register.
  • Analyze a product's direct and indirect prompt injection paths, system prompt leakage and data exfiltration (lethal trifecta).
  • Specify layered guardrails (input, output, rights, human approval, isolation, limits) with testable criteria and their cost.
  • Plan red teaming, abuse monitoring and incident response for an AI feature.
  • Qualify a product under the AI Act (role, risk level, prohibited practices, transparency, timeline) and connect this analysis with the GDPR.