EXIN's AI Security Professional (AISP) certification validates your ability to identify, test, and govern AI-specific security risks. Built on the OWASP AI Exchange, the open standard already shaping ISO and EU AI Act security guidance worldwide.
The data is clear: AI deployment has outpaced the security profession's ability to assess it. And the gap is widening every quarter.
CISSP, CISM, and CEH have added AI security topics to their curricula — because the market demanded it. But AI is still just one topic within much broader certifications. Security professionals learn about threats, while governance and compliance teams focus on policies and frameworks. Rarely do both perspectives come together in a single credential.
The market for skilled AI security practitioners is too small and too expensive. The SANS report's top recommendation isn't "hire more" — it's developing formal AI security capability in the professionals organizations already have. This means upskilling and being able to demonstrate the competency.
The EU AI Act, DORA, and NIS2 are pulling AI-specific security obligations into scope for regulated industries. Regulators will increasingly ask who on your team is formally qualified, not just who handles security generally.
The OWASP AI Exchange is an open, vendor-neutral body of knowledge for AI security, maintained by a global community of 165+ security practitioners, AI engineers, and governance professionals. With more than 200 pages of practical guidance, it goes far beyond a vendor framework or proprietary syllabus. The Exchange has already contributed 40+ pages to the EU AI Act’s security guidance and continues to shape ISO/IEC standards. That means AISP teaches the same body of knowledge influencing the regulations and standards organizations are increasingly expected to follow.
EXIN AISP's courseware was designed by Rob van der Veer. He is the Chief AI Officer at Software Improvement Group, founder of the OWASP AI Exchange, lead author of ISO/IEC 5338 (AI engineering), children’s book co-author on AI, and co-editor of the EU AI Act security standard, and has 34 years of experience in AI, security, and privacy. This is not a certification built by a standards committee at a distance. It is built from experience with courseware designed by the person who wrote the standard it is based on. That’s real-world operational experience into every aspect.
For professionals, this is more than a job, it’s a career trajectory. EXIN certifications are designed to connect into real-world job roles. This pathway brings together three certifications, with AISP as the final step, preparing professionals for one of the most in-demand roles in the market: AI Security Specialist.
Core AI concepts, terminology, and real-world applications. The starting point for any professional working with AI systems.
Security fundamentals — risk management, access controls, threat landscapes, and organizational security practice.
Applied AI security — threat modeling, adversarial attacks, controls, red-teaming, and EU AI Act compliance.
One of the most sought-after roles in the marke. A certified, verifiable path to a career that didn't exist five years ago.
Every domain maps directly to real OWASP AI Exchange content — so what you learn for the exam is the same framework you'll reference on the job.
The exam is scenario-based. Each question presents a real system and a real threat, asking you to make the right decision. It’s not about recalling definitions alone — it’s about applying knowledge with judgment. A true test of what you understand and how you use it.
EXIN's global network of accredited training partners delivers structured AISP preparation courses. Your employer can fund both training and exam through a single L&D budget request.
The OWASP AI Exchange — your primary exam literature — is freely available at owaspai.org. A preparation guide and sample exam are available to download below.
Analysts, architects, GRC specialists, penetration testers, and security leaders now responsible for AI systems they were never trained to assess.
Engineers and data scientists building or deploying AI who need to understand the security implications of the systems they create.
DPOs, compliance officers, and auditors responsible for AI governance, risk management, and regulatory readiness under the EU AI Act.
Architects, technical leads, and decision-makers responsible for evaluating, approving, and governing AI deployments across the organization.