PIONEERING INDEPENDENT AI Security CREDENTIALS
The AI security certification the market will ask for
EXIN AI Security Professional (AISP) validates your ability to identify, test, and govern AI-specific security risks — built on the OWASP AI Exchange, the open standard already shaping ISO and EU AI Act security guidance.

OWASP AI Exchange
Body of knowledge
165+ practitioners
Built by security experts
40+ pages
Contributed to EU AI Act
ISO/IEC aligned
27090 & 42001
The problem
Your security team is skilled. But can they prove it?
AI deployment has outpaced the security profession’s ability to assess it — and the gap is widening every quarter.
01
Conventional certifications have added AI. AISP is built around it.
CISSP, CISM, and CEH have added AI security topics because the market demanded it — but AI is still one topic within a much broader certification. Security professionals learn about threats; governance and compliance teams focus on policy. Rarely do both come together in one credential.
02
Hiring alone won’t close the gap
The market for skilled AI security practitioners is too small and too expensive. The top recommendation isn’t “hire more” — it’s developing formal AI security capability in the people you already have, and being able to demonstrate that competency.
03
Regulation is already requiring it
The EU AI Act, DORA, and NIS2 are pulling AI-specific security obligations into scope for regulated industries. Regulators will increasingly ask who on your team is formally qualified — not just who handles security generally.
The regulatory reality
Article 4 of the EU AI Act is not coming. It is here.
“Providers and deployers of AI systems shall take measures to ensure … a sufficient level of AI literacy of their staff … dealing with the operation and use of AI systems on their behalf.”
— EU AI Act, Article 4
Active
Feb 2, 2025
Article 4 AI-literacy obligation in force; unacceptable-risk AI banned
Active
Aug 2, 2025
Obligations for general-purpose AI providers took effect
Imminent
Aug 2, 2026
Transparency obligations enforced
Upcoming
Dec 2027 / Aug 2028
High-risk system requirements follow
Penalties for non-compliance: up to €15 million or 3% of annual global turnover — rising to €35 million or 7% for the most serious violations. This applies to every EU organization using AI.
Purpose-built for AI-specific security threats and governance
Built on the OWASP AI Exchange — the open, practitioner-led standard directly shaping ISO/IEC 27090 and the EU AI Act. AISP certifies professionals who can identify, test, mitigate, and govern AI security risks in the real world.
6
Domains
40
Questions
90
Minutes
65%
Pass mark
Advanced
Level
No prerequisites
Unlike ISACA AAISM
Why AISP
Built by the experts who wrote the standards your auditors use.
Rooted in the OWASP AI Exchange
The living standard built by 165+ security experts, reflected in ISO/IEC 27090 and the EU AI Act. Courseware designed by its founder, Rob van der Veer.
Aligned with CEN and ISO standards
The e-Competence Framework (EN 16234-1), the EU AI Act Security Standard (prEN 18282), the AI Professional Role Profiles (CWA 18398:2026) EXIN helped develop, and ISO/IEC 27090.
Developed with the Software Improvement Group
Jointly developed with SIG, a Leader in the 2026 Gartner Magic Quadrant for Technical Debt Management Tools. Real-world attack intelligence, built in.
40+ years of certifications and trust
EXIN has certified 3 million+ professionals in 165 countries since 1984. Trusted by enterprises, governments, and 450+ accredited training organizations.
The EXIN AI portfolio
AISP is part of a complete AI certification path
From foundational literacy to specialist security practice, EXIN’s AI portfolio lets every role build verifiable, standards-based AI competence.

AI Foundation
Entry level

AI Essentials
Entry level

Generative AI Award
Specialist award

AI Compliance Professional
Professional

AI Security Professional
This certification
What you’ll learn
Six domains. One credential that proves you can secure AI systems.
Every domain maps directly to real OWASP AI Exchange content — what you learn for the exam is the same framework you’ll reference on the job.
Domain 01
Organizing AI security in the enterprise
Apply the GUARD framework to structure AI security organizationally
Distinguish AI security risk from conventional cybersecurity risk
Map AI assets — training data, models, inputs, outputs — to their unique threats
Domain 02
Threat modeling and agentic AI risk
Run risk management steps purpose-built for AI threat modeling
Identify security risks specific to agentic AI systems
Apply structured, repeatable risk treatment and monitoring cycles
Domain 03
Recognizing input, development, and runtime threats
Classify evasion attacks by attacker knowledge level
Distinguish direct from indirect prompt injection; apply 7-layer defense
Identify data poisoning, model exfiltration, and sensitive data leakage
Domain 04
Implementing AI security controls
Apply governance controls across AI, security, and compliance programs
Limit sensitive data exposure to reduce your AI attack surface
Constrain model behavior through oversight, least-privilege, and explainability
Domain 05
Testing AI systems for security
Distinguish AI red-teaming from conventional security testing
Identify what to test in predictive AI versus generative AI
Run a systematic red-teaming process from scoping to validation of fixes
Domain 06
Privacy, compliance, and regulation
Apply AI-specific privacy principles to real-world scenarios
Map ISO/IEC 23894, 27005, 42001, and 5338 to compliance requirements
Navigate the EU AI Act, GDPR, and emerging AI copyright risk
Career impact
AI Security Manager: a career path, not just a certification
EXIN certifications connect into real-world job roles. This pathway brings together three certifications, with AISP as the final step, preparing professionals for one of the most in-demand roles in the market.
01
EXIN AI Foundation
Core AI concepts, terminology, and real-world applications
02
EXIN Information Security Foundation
Risk management, access controls, threat landscapes
03
EXIN AI Security Professional
Applied AI security — threat modeling, adversarial attacks, controls, red-teaming, EU AI Act compliance
EXIN AI Security Manager
One of the most sought-after roles in the market
AI Security Engineer
$185,930 avg / $287K+ top
Glassdoor, May 2026
AI Security Architect
$200K–$280K+
Practical DevSecOps 2026
LLM Security Specialist
$160K–$230K
Practical DevSecOps 2026
AI Red Teamer
$160K–$240K, +35% demand by 2028
Practical DevSecOps 2026
AI Security Manager
$180K–$260K
Glassdoor 2026
Market comparison
How AISP compares to other AI security certifications
Dimension
ISACA AAISM
CAISP
CompTIA SecAI+
EXIN AISP
Content focus
Security mgmt overlay
Hands-on LLM/AppSec
Generic security + AI
AI security + governance, integrated
EU AI Act aligned
Partial — governance only
No
No
Yes — co-editor of the Act’s security standard
Prerequisite
CISM or CISSP (barrier)
None
CISSP / CISM
None — broadly accessible
Standards pedigree
ISACA frameworks
OWASP LLM Top 10
ISC²/ISACA
ISO 27090 · 5338 · OWASP · EU AI Act
Target audience
Experienced managers
AppSec engineers
Senior security roles
Security, GRC, compliance, architects — broad
Technical + governance
Governance only
Technical only
General
Both, in one credential
AISP is for every professional who needs to demonstrate certified AI security competence — regardless of prior certification.
Security experience or AI experience. Either way, AISP is for you.
Security professionals
Analysts, architects, GRC specialists, penetration testers, and security leaders now responsible for AI systems they were never trained to assess.
AI and ML engineers
Engineers and data scientists building or deploying AI who need to understand the security implications of the systems they create.
Risk, audit, and compliance
DPOs, compliance officers, and auditors responsible for AI governance, risk management, and regulatory readiness under the EU AI Act.
Technology leaders
Architects, technical leads, and decision-makers responsible for evaluating, approving, and governing AI deployments across the organization.
What to expect on exam day
The exam is scenario-based. Each question presents a real system and a real threat, asking you to make the right decision — not recall a definition.
40 Questions · 90 Minutes · 65% Pass mark · Advanced Level · English
Accredited training available
EXIN’s global network of accredited training partners delivers structured AISP preparation. Training and exam can be funded through a single L&D budget request.
Study resources
The OWASP AI Exchange, the primary exam literature, is free at owaspai.org. Download the preparation guide and sample exam below.
Frequently asked questions
Do I need a cybersecurity or AI background to take the AISP exam?
Is the AISP exam multiple choice, or does it test practical skills?
Will AISP actually be recognized by employers, or is it too new to matter?
I already hold CISSP / CISM / CEH. Why do I need another certification?
What jobs does AISP help me qualify for or move into?
Can AISP help my organization meet AI governance requirements?
How is AISP different from CompTIA SecAI+ or ISACA AAISM?
Bringing AISP into your organization
For corporateS
Certifying your team?
Three routes into your organization — an accredited partner, your internal training academy, or direct exam for experienced professionals. Every route includes the exam.
Book a 30-minute team certification consultation
For training partners
Delivering AISP training?
Only EXIN-Accredited Partners deliver AISP at launch. Existing partners sign a short addendum; new partners follow fast onboarding. Everything is built for you: editable courseware, train-the-trainer, sample exams, candidate portal.
Start an accreditation conversation
Be the first certified before the market makes it mandatory.
AISP is the only AI security certification mapped to the European CEN standard for AI professional role profiles — for organizations serious about securing AI, complying with the AI Act, and willing to prove it.
Chat with our team
450+ partners
40 years of experience
Nearly 3 million certified
ISO 27001 certified