Assemble the risk register, the guardrails and the AI Act analysis
Lesson 1 of the module "Your register, your guardrails, your analysis" in the course "Secure an AI product: prompt injection, guardrails and the AI Act".
Lesson objective
By the end of this lesson, you will be able to assemble your product's AI security and compliance dossier (risk register, specified guardrails, operations plan, AI Act analysis and GDPR points), self-assess it with the kit's checklist and plan its application over 7 and 30 days.
Where it fits
Your register, your guardrails, your analysis
Do your product's register, guardrails and AI Act analysis hold up in review?
Lessons in this module
- Assemble the risk register, the guardrails and the AI Act analysis (this lesson)
What you will learn in the course
This lesson is part of the course Secure an AI product: prompt injection, guardrails and the AI Act
- Map the attack surface of an AI product and its risks with the OWASP Top 10 for LLM Applications 2025, in a prioritized risk register.
- Analyze a product's direct and indirect prompt injection paths, system prompt leakage and data exfiltration (lethal trifecta).
- Specify layered guardrails (input, output, rights, human approval, isolation, limits) with testable criteria and their cost.
- Plan red teaming, abuse monitoring and incident response for an AI feature.
- Qualify a product under the AI Act (role, risk level, prohibited practices, transparency, timeline) and connect this analysis with the GDPR.
Related courses
- Build an AI assistant for your productAdvanced · ~3 hr
- Design a RAG architecture that fits your productAdvanced · ~3 hr 30 min
- Evaluate an AI feature: test sets, metrics and LLM judgesAdvanced · ~3 hr