Attack
Injection pack
Reproducible cases, including a retrieved document that tries to exfiltrate.
Prompt injection, data leakage, the lethal trifecta, PII, and controls you can show a security review — not a slide about “responsible AI”.
Created by Baljeet Dogra
Attack
Reproducible cases, including a retrieved document that tries to exfiltrate.
Defence
Threats to controls to tests. Gaps named in writing.
Expand a part for the syllabus. Content stays searchable when closed.
OWASP LLM risks, data flows, where secrets live.
Direct, indirect, tool abuse. Prompts are not a control.
PII, minimisation, retention, what never to log, residency.
Red team a peer system. Capstone control map.
You will face a security review. Vibes will not pass.
You need LLM-shaped threats, not a copy of the web checklist.
Related: Becoming an AI Principal Engineer · AI Governance & Compliance
No. Labs are on systems you control. The techniques are the ones that show up in reviews.
Security and privacy labs. Governance & Compliance covers the Act, ISO 42001 and NIST AI RMF as systems of record.
Four weeks to a control map that survives a security review. Create an account to enrol.
Enrol now