Image

The AI Security Certification that the market will ask for

EXIN's AI Security Professional (AISP) certification validates your ability to identify, test, and govern AI-specific security risks. Built on the OWASP AI Exchange, the open standard already shaping ISO and EU AI Act security guidance worldwide.

Sign up for early updates
OWASP AI ExchangeBody of knowledge
165+ practitionersBuilt by security experts
40+ pagesContributed to EU AI Act
ISO/IEC aligned27090 & 42001
September 2026Public launch date
Image

AI is already in production. The people securing it aren't ready.

The data is clear: AI deployment has outpaced the security profession's ability to assess it. And the gap is widening every quarter.

The problem

Your security team is skilled. But can they prove it?

Challenge 01

Conventional certifications have added AI. AISP is built around it.

CISSP, CISM, and CEH have added AI security topics to their curricula — because the market demanded it. But AI is still just one topic within much broader certifications. Security professionals learn about threats, while governance and compliance teams focus on policies and frameworks. Rarely do both perspectives come together in a single credential.

Challenge 02

Hiring alone won't close the gap

The market for skilled AI security practitioners is too small and too expensive. The SANS report's top recommendation isn't "hire more" — it's developing formal AI security capability in the professionals organizations already have. This means upskilling and being able to demonstrate the competency.

Challenge 03

Regulation is already requiring it

The EU AI Act, DORA, and NIS2 are pulling AI-specific security obligations into scope for regulated industries. Regulators will increasingly ask who on your team is formally qualified, not just who handles security generally.

The solution

Introducing EXIN AI Security Professional

Built from practice. Not a committee's interpretation of a regulation.

Built on the OWASP AI Exchange

The OWASP AI Exchange is an open, vendor-neutral body of knowledge for AI security, maintained by a global community of 165+ security practitioners, AI engineers, and governance professionals. With more than 200 pages of practical guidance, it goes far beyond a vendor framework or proprietary syllabus.

The Exchange has already contributed 40+ pages to the EU AI Act’s security guidance and continues to shape ISO/IEC standards. That means AISP teaches the same body of knowledge influencing the regulations and standards organizations are increasingly expected to follow.

Read full Body of Knowledge →
Your image description

Courseware designed by the global leading AI security practitioner

EXIN AISP's courseware was designed by Rob van der Veer. He is the Chief AI Officer at Software Improvement Group, founder of the OWASP AI Exchange, lead author of ISO/IEC 5338 (AI engineering), children’s book co-author on AI, and co-editor of the EU AI Act security standard, and has 34 years of experience in AI, security, and privacy.

This is not a certification built by a standards committee at a distance. It is built from experience with courseware designed by the person who wrote the standard it is based on. That’s real-world operational experience into every aspect.

Connect with Rob →
Career impact

AI Security Manager: A Career Path, Not Just a Certification

For professionals, this is more than a job, it’s a career trajectory. EXIN certifications are designed to connect into real-world job roles. This pathway brings together three certifications, with AISP as the final step, preparing professionals for one of the most in-demand roles in the market: AI Security Manager.

Step 01

EXIN AI Foundation

Core AI concepts, terminology, and real-world applications. The starting point for any professional working with AI systems.

+
Step 02

EXIN Information Security Foundation

Security fundamentals — risk management, access controls, threat landscapes, and organizational security practice.

+
New · Sep 2026
Step 03

EXIN AI Security Professional

Applied AI security — threat modeling, adversarial attacks, controls, red-teaming, and EU AI Act compliance.

=
Career outcome

EXIN AI Security Manager

One of the most sought-after roles in the marke. A certified, verifiable path to a career that didn't exist five years ago.

Salary data for AI security roles (2026)
AI Security Engineer
$185,930
avg / top earners: $287K+
AI Security Architect
$200K–$280K+
contract rates above this
LLM Security Specialist
$160K–$230K
fastest-growing role category
AI Red Teamer
$160K–$240K
demand projected +35% by 2028
AI Security Manager
$180K–$260K
avg across US, UK, EU markets
What you'll learn

Six domains. One credential that proves you can secure AI systems.

Every domain maps directly to real OWASP AI Exchange content — so what you learn for the exam is the same framework you'll reference on the job.

Domain 01

Organizing AI security in the enterprise

  • Apply the GUARD framework to structure AI security organizationally
  • Distinguish AI security risk from conventional cybersecurity risk
  • Map AI assets — training data, models, inputs, outputs — to their unique threats
Domain 02

Threat modeling and agentic AI risk

  • Run risk management steps purpose-built for AI threat modeling
  • Identify security risks specific to agentic AI systems
  • Apply structured, repeatable risk treatment and monitoring cycles
Domain 03

Recognizing input, development, and runtime threats

  • Classify evasion attacks by attacker knowledge level
  • Distinguish direct from indirect prompt injection; apply 7-layer defense
  • Identify data poisoning, model exfiltration, and sensitive data leakage
Domain 04

Implementing AI security controls

  • Apply governance controls across AI, security, and compliance programs
  • Limit sensitive data exposure to reduce your AI attack surface
  • Constrain model behavior through oversight, least-privilege, and explainability
Domain 05

Testing AI systems for security

  • Distinguish AI red-teaming from conventional security testing
  • Identify what to test in predictive AI versus generative AI
  • Run a systematic red-teaming process from scoping to validation of fixes
Domain 06

Privacy, compliance, and regulation

  • Apply AI-specific privacy principles to real-world scenarios
  • Map ISO/IEC 23894, 27005, 42001, and 5338 to compliance requirements
  • Navigate the EU AI Act, GDPR, and emerging AI copyright risk
Exam at a glance

What to expect on exam day.

The exam is scenario-based. Each question presents a real system and a real threat, asking you to make the right decision. It’s not about recalling definitions alone — it’s about applying knowledge with judgment. A true test of what you understand and how you use it.

40
Questions
90
Minutes
65%
Pass mark
Advanced
Level
English
Language

Accredited training available

EXIN's global network of accredited training partners delivers structured AISP preparation courses. Your employer can fund both training and exam through a single L&D budget request.

Study resources

The OWASP AI Exchange — your primary exam literature — is freely available at owaspai.org. A preparation guide and sample exam are available to download below.

Who is it for

Security experience or AI experience.
Either way, AISP is the certification for you.

Security

Security professionals

Analysts, architects, GRC specialists, penetration testers, and security leaders now responsible for AI systems they were never trained to assess.

AI / ML

AI and ML engineers

Engineers and data scientists building or deploying AI who need to understand the security implications of the systems they create.

Compliance

Risk, audit, and compliance

DPOs, compliance officers, and auditors responsible for AI governance, risk management, and regulatory readiness under the EU AI Act.

Leadership

Technology leaders

Architects, technical leads, and decision-makers responsible for evaluating, approving, and governing AI deployments across the organization.

Frequently asked questions

Honest answers to the questions candidates actually ask.

Do I need a cybersecurity or AI background to take the AISP exam? +
You do not need both a security background and an AI background, but you do need one. AISP is built for security professionals who need to understand AI-specific threats and controls, and for AI/ML engineers who need to understand the security implications of the systems they build. Most conventional security certifications were designed before AI became a dominant attack surface, which is why they cover fundamentals that are still relevant, but they do not cover AI-specific threats such as prompt injection, model exfiltration, adversarial evasion attacks, or training data poisoning, because those risks did not exist in their current form when those exams were built. AISP fills that specific gap.
Is the AISP exam multiple choice, or does it test practical skills? +
The exam is scenario-based, meaning questions present you with a real-world situation — for example, a system architecture, a threat, a set of constraints — and ask you to make the right judgment call, not retrieve a definition. This is deliberate. AI security decisions in practice are rarely clean. The evasion attacks on a fraud detection system carry different risk and mitigation logic than evasion attacks on a medical diagnosis device. The exam tests whether you understand that distinction and can reason through it, not whether you can recall a list of attack types.
Will AISP actually be recognized by employers, or is it too new to matter? +
This is the right question to ask about any certification launched in 2026, and we'd rather answer it directly. AISP is new. It does not yet have the decades of employer recognition that CISSP or CISM carry. But in AI security, the skillset is outrunning the credential. Organizations are not waiting for a certification to become famous before they hire for it — they are hiring right now for people who can actually do the work.

The OWASP AI Exchange — the body of knowledge AISP is built on — has directly contributed over 40 pages of content to the EU AI Act's own security guidance and is actively shaping ISO/IEC international standards. It is already the reference point regulators, auditors, and enterprise security teams reach for when assessing AI risk. The skills AISP validates are the skills those frameworks demand.

In practice: the moment you can speak fluently to prompt injection defenses, threat model an agentic AI system, or articulate the security obligations of a high-risk AI deployment under the EU AI Act, you are ahead of the vast majority of security professionals in any room you walk into. The certification makes that verifiable on a CV. Recognition of the credential will grow. The professionals who built the skills early will have already defined what good looks like.
I already hold CISSP / CISM / CEH. Why do I need another certification? +
You probably don't need it — you need the skills it validates. General security certifications were written before prompt injection, model exfiltration, adversarial evasion, and training data poisoning were real operational concerns. They cover the fundamentals that are still entirely relevant, but they don't cover the attack surface that opens up specifically when AI systems enter your environment. AISP is not a replacement for your existing credentials — it's the extension that makes them current. Think of it the way a network security specialist eventually added cloud security to their profile: not because networking stopped mattering, but because the environment they're securing changed.
What jobs does AISP help me qualify for or move into? +
The roles where AISP is most directly relevant are those where someone is now being asked to assess, secure, or govern AI systems as a core part of their job — not as a side interest. This includes AI security engineer, security architect with AI system scope, GRC analyst covering AI risk, technical compliance manager under EU AI Act obligations, and information security manager with AI governance responsibility. It's also increasingly relevant for penetration testers and red teamers expanding into AI-specific engagements, and for data scientists or ML engineers who want to formalize their understanding of the security implications of what they build.
Can AISP help my organization meet AI governance requirements? +
Yes. AISP addresses AI governance directly as one of its six core domains, covering how to organize AI security programs, implement governance controls, assign responsibility across AI security, secure development, compliance, and education programs, and demonstrate that AI risk is being actively managed — not just acknowledged. For organizations operating under frameworks like ISO/IEC 42001, DORA, NIS2, or the EU AI Act, AISP provides a credentialed, verifiable way to demonstrate that the people responsible for AI governance have the technical understanding to back it up.
How is AISP different from CompTIA SecAI+ or ISACA AAISM? +
These three certifications are not competing for the same candidate.

CompTIA SecAI+ has a dual focus: securing AI systems, but also using AI to improve security operations — threat detection, incident response automation, workflow tooling. AISP doesn't cover that second dimension and doesn't claim to. AISP is entirely focused on securing AI systems, built on the OWASP AI Exchange as its single canonical body of knowledge.

ISACA AAISM requires an active CISM or CISSP as a prerequisite. It's designed for senior security managers, not practitioners — it tests whether you can govern AI risk at the organizational level. AISP tests whether you can do the practitioner work: threat modeling, controls implementation, security testing, and compliance assessment on a specific AI system.

AAISM answers "can this leader govern AI risk?" SecAI+ answers "can this professional secure AI systems and use AI for security operations?" AISP answers "can this practitioner identify, test, and mitigate AI-specific threats using the standard the industry is converging on?" All three are complementary. None is a substitute for the others.

Be the FIRST certified before the market makes it mandatory.

Sign up today for updates before September launch!