PIONEERING INDEPENDENT AI Security CREDENTIALS

The AI security certification the market will ask for

EXIN AI Security Professional (AISP) validates your ability to identify, test, and govern AI-specific security risks - built on the OWASP AI Exchange, the open standard already shaping ISO and EU AI Act security guidance.

OWASP AI Exchange

Body of knowledge

165+ practitioners

Built by security experts

40+ pages

Contributed to EU AI Act

ISO/IEC aligned

27090 & 42001

The problem

Your security team is skilled. But can they prove it?

AI deployment has outpaced the security profession’s ability to assess it - and the gap is widening every quarter.

01

Conventional certifications have added AI. AISP is built around it.

CISSP, CISM, and CEH have added AI security topics because the market demanded it - but AI is still one topic within a much broader certification. Security professionals learn about threats; governance and compliance teams focus on policy. Rarely do both come together in one credential.

02

Hiring alone won’t close the gap

The market for skilled AI security practitioners is too small and too expensive. The top recommendation isn’t “hire more” - it’s developing formal AI security capability in the people you already have, and being able to demonstrate that competency.

03

Regulation is already requiring it

The EU AI Act, DORA, and NIS2 are pulling AI-specific security obligations into scope for regulated industries. Regulators will increasingly ask who on your team is formally qualified - not just who handles security generally.

The regulatory reality

Article 4 of the EU AI Act is not coming. It is here.

“Providers and deployers of AI systems shall take measures to ensure … a sufficient level of AI literacy of their staff … dealing with the operation and use of AI systems on their behalf.”

- EU AI Act, Article 4

Active

Feb 2, 2025

Article 4 AI-literacy obligation in force; unacceptable-risk AI banned

Active

Aug 2, 2025

Obligations for general-purpose AI providers took effect

Imminent

Aug 2, 2026

Transparency obligations enforced

Upcoming

Dec 2027 / Aug 2028

High-risk system requirements follow

Penalties for non-compliance: up to €15 million or 3% of annual global turnover - rising to €35 million or 7% for the most serious violations. This applies to every EU organization using AI.

Purpose-built for AI-specific security threats and governance

Built on the OWASP AI Exchange - the open, practitioner-led standard directly shaping ISO/IEC 27090 and the EU AI Act. AISP certifies professionals who can identify, test, mitigate, and govern AI security risks in the real world.

6

Domains

40

Questions

90

Minutes

65%

Pass mark

Advanced

Level

No prerequisites

Unlike ISACA AAISM

Why AISP

Built by the experts who wrote the standards your auditors use.

Rooted in the OWASP AI Exchange

The living standard built by 165+ security experts, reflected in ISO/IEC 27090 and the EU AI Act. Courseware designed by its founder, Rob van der Veer.

Aligned with CEN and ISO standards

The e-Competence Framework (EN 16234-1), the EU AI Act Security Standard (prEN 18282), the AI Professional Role Profiles (CWA 18398:2026) EXIN helped develop, and ISO/IEC 27090.

Developed with the Software Improvement Group

Jointly developed with SIG, a Leader in the 2026 Gartner Magic Quadrant for Technical Debt Management Tools. Real-world attack intelligence, built in.

40+ years of certifications and trust

EXIN has certified 3 million+ professionals in 165 countries since 1984. Trusted by enterprises, governments, and 450+ accredited training organizations.

The EXIN AI portfolio

AISP is part of a complete AI certification path

From foundational literacy to specialist security practice, EXIN’s AI portfolio lets every role build verifiable, standards-based AI competence.

AI Foundation

Entry level

AI Essentials

Entry level

Generative AI Award

Specialist award

AI Compliance Professional

Professional

AI Security Professional

This certification

What you’ll learn

Six domains. One credential that proves you can secure AI systems.

Every domain maps directly to real OWASP AI Exchange content - what you learn for the exam is the same framework you’ll reference on the job.

Domain 01

Organizing AI security in the enterprise

Apply the GUARD framework to structure AI security organizationally

Distinguish AI security risk from conventional cybersecurity risk

Map AI assets - training data, models, inputs, outputs - to their unique threats

Domain 02

Threat modeling and agentic AI risk

Run risk management steps purpose-built for AI threat modeling

Identify security risks specific to agentic AI systems

Apply structured, repeatable risk treatment and monitoring cycles

Domain 03

Recognizing input, development, and runtime threats

Classify evasion attacks by attacker knowledge level

Distinguish direct from indirect prompt injection; apply 7-layer defense

Identify data poisoning, model exfiltration, and sensitive data leakage

Domain 04

Implementing AI security controls

Apply governance controls across AI, security, and compliance programs

Limit sensitive data exposure to reduce your AI attack surface

Constrain model behavior through oversight, least-privilege, and explainability

Domain 05

Testing AI systems for security

Distinguish AI red-teaming from conventional security testing

Identify what to test in predictive AI versus generative AI

Run a systematic red-teaming process from scoping to validation of fixes

Domain 06

Privacy, compliance, and regulation

Apply AI-specific privacy principles to real-world scenarios

Map ISO/IEC 23894, 27005, 42001, and 5338 to compliance requirements

Navigate the EU AI Act, GDPR, and emerging AI copyright risk

Career impact

AI Security Manager: a career path, not just a certification

EXIN certifications connect into real-world job roles. This pathway brings together three certifications, with AISP as the final step, preparing professionals for one of the most in-demand roles in the market.

01

EXIN AI Foundation

Core AI concepts, terminology, and real-world applications

02

EXIN Information Security Foundation

Risk management, access controls, threat landscapes

03

EXIN AI Security Professional

Applied AI security - threat modeling, adversarial attacks, controls, red-teaming, EU AI Act compliance

EXIN AI Security Manager

One of the most sought-after roles in the market

AI Security Engineer

$185,930 avg / $287K+ top

Glassdoor, May 2026

AI Security Architect

$200K–$280K+

Practical DevSecOps 2026

LLM Security Specialist

$160K–$230K

Practical DevSecOps 2026

AI Red Teamer

$160K–$240K, +35% demand by 2028

Practical DevSecOps 2026

AI Security Manager

$180K–$260K

Glassdoor 2026

Market comparison

How AISP compares to other AI security certifications

Dimension

ISACA AAISM

CAISP

CompTIA SecAI+

EXIN AISP

Content focus

Security mgmt overlay

Hands-on LLM/AppSec

Generic security + AI

AI security + governance, integrated

EU AI Act aligned

Partial - governance only

No

No

Yes - co-editor of the Act’s security standard

Prerequisite

CISM or CISSP (barrier)

None

CISSP / CISM

None - broadly accessible

Standards pedigree

ISACA frameworks

OWASP LLM Top 10

ISC²/ISACA

ISO 27090 · 5338 · OWASP · EU AI Act

Target audience

Experienced managers

AppSec engineers

Senior security roles

Security, GRC, compliance, architects - broad

Technical + governance

Governance only

Technical only

General

Both, in one credential

AISP is for every professional who needs to demonstrate certified AI security competence - regardless of prior certification.

Security experience or AI experience. Either way, AISP is for you.

Security professionals

Analysts, architects, GRC specialists, penetration testers, and security leaders now responsible for AI systems they were never trained to assess.

AI and ML engineers

Engineers and data scientists building or deploying AI who need to understand the security implications of the systems they create.

Risk, audit, and compliance

DPOs, compliance officers, and auditors responsible for AI governance, risk management, and regulatory readiness under the EU AI Act.

Technology leaders

Architects, technical leads, and decision-makers responsible for evaluating, approving, and governing AI deployments across the organization.

What to expect on exam day

The exam is scenario-based. Each question presents a real system and a real threat, asking you to make the right decision - not recall a definition.

40 Questions · 90 Minutes · 65% Pass mark · Advanced Level · English

Accredited training available

EXIN’s global network of accredited training partners delivers structured AISP preparation. Training and exam can be funded through a single L&D budget request.

Study resources

The OWASP AI Exchange, the primary exam literature, is free at owaspai.org. Download the preparation guide and sample exam below.

Frequently asked questions

Do I need a cybersecurity or AI background to take the AISP exam?

Is the AISP exam multiple choice, or does it test practical skills?

Will AISP actually be recognized by employers, or is it too new to matter?

I already hold CISSP / CISM / CEH. Why do I need another certification?

What jobs does AISP help me qualify for or move into?

Can AISP help my organization meet AI governance requirements?

How is AISP different from CompTIA SecAI+ or ISACA AAISM?

Bringing AISP into your organization

For Corporate Partners

Certifying your team?

Three routes into your organization - an accredited partner, your internal training academy, or direct exam for experienced professionals. Every route includes the exam.

Book a 30-minute team certification consultation

For Training Partners

Delivering AISP training?

EXIN-Accredited Partners can deliver AISP. Existing partners sign a short addendum; new partners follow fast onboarding. Everything is built for you: editable courseware, train-the-trainer, sample exams, candidate portal.

Start an accreditation conversation

Be the first certified before the market makes it mandatory.

AISP is the only AI security certification mapped to the European CEN standard for AI professional role profiles - for organizations serious about securing AI, complying with the AI Act, and willing to prove it.

Chat with our team

450+ partners

40 years of experience

Nearly 3 million certified

ISO 27001 certified