Beyond AI Security: Learning How to Assess AI Systems

Beyond AI Security: Learning How to Assess AI Systems

in

Beyond AI Security: Learning How to Assess AI Systems

My Experience with INE’s AI Systems Security Specialist (eAIS) Learning Path

When I started exploring AI security, one of the first things I realized was that understanding the attacks was only the beginning.

In my previous article, I shared my experience completing TryHackMe’s AI Security learning path and how it changed the way I viewed artificial intelligence from a cybersecurity perspective. That experience introduced me to concepts such as Large Language Models (LLMs), prompt injection, AI-specific attack surfaces, threat modelling and AI forensics.

While continuing that learning journey, I became interested in a different question:

How do security professionals actually assess AI systems?

Understanding that an AI application can be vulnerable is one thing. Being able to analyze the architecture behind it, identify where risks exist, evaluate security controls and communicate findings is a different skill set.

That curiosity led me to the INE AI Systems Security Specialist (eAIS) learning path.

As someone transitioning into cybersecurity after more than thirteen years working in digital design roles, my goal is to develop the practical and analytical skills needed for entry-level security roles, particularly Security Operations.

I do not expect AI security to be my first responsibility as a junior analyst, but I do expect AI-enabled applications to become increasingly common in the environments security teams protect. For that reason, developing AI security awareness feels less like learning a niche topic and more like preparing for the future of cybersecurity.


Understanding AI Systems Before Securing Them

One of the aspects I appreciated most about this learning path was that it did not immediately jump into attacks; before discussing how AI systems can fail, it first builds an understanding of how they work.

This is important because modern AI applications are not simply a model receiving a question and generating an answer. They are ecosystems made of multiple interconnected components: applications, APIs, models, retrieval systems, vector databases, external tools and orchestration layers.

Every component introduces potential risks.

Every connection creates another opportunity for data to move, permissions can be misconfigured or trust can be misplaced.

This way of thinking felt very familiar from traditional cybersecurity. The technology may be new, but many of the principles remain the same: understand the architecture, identify trust boundaries, analyze data flows and determine where security controls are required.

The course gradually introduces concepts such as tokens, embeddings, context windows, inference, Retrieval-Augmented Generation (RAG), AI agents and model endpoints.

Although this foundational section is theory-heavy, I found that building this knowledge first made the later security concepts much easier to understand.

It is difficult to assess an AI system if you do not understand what you are assessing.

This was probably one of the most valuable lessons from the entire experience:

AI security is not only about finding ways to manipulate a chatbot. It is about understanding the complete system around the model and identifying where security problems can emerge.


Moving From Learning Vulnerabilities to Performing Assessments

One of the biggest differences I noticed between exploring AI security concepts and studying this learning path was the focus on methodology.

Many security topics are introduced through individual vulnerabilities: a weakness exists, an attacker exploits it, and a defender applies a mitigation.

However, real security work usually requires a much broader approach: a professional assessment does not begin with an attack, it begins with understanding the environment.

The eAIS learning path places a strong emphasis on concepts such as threat modelling, identifying attack surfaces, analyzing trust boundaries, planning security tests, documenting findings and validating remediation.

The module that stood out most to me was AI Security Testing & Validation because it connected many separate concepts into a complete security workflow.

Instead of simply learning individual AI attacks, the focus shifted towards questions such as:

  • How should an AI security assessment be planned?
  • What components should be reviewed?
  • How should risks be prioritized?
  • How should findings be communicated?
  • How can we confirm that a security improvement actually works?

This approach is what made the learning valuable from a professional perspective.

A security analyst is not only someone who can identify vulnerabilities, they also need to understand context, explain risk and provide useful information that helps an organization improve its security posture.

That mindset applies whether the technology being assessed is a traditional web application, cloud environment or an AI-enabled system.


Learning Through Practical Application

Although the course contains a significant amount of theory, the practical exercises helped connect those concepts to real scenarios.

One learning method I particularly liked was the combination of instructor-led demonstrations followed by hands-on practice using detailed walkthroughs.

Seeing the workflow first and then reproducing it myself helped me understand not only which commands or techniques were being used, but also why they were relevant.

During my first pass through the practical material, some of the technical details felt challenging, especially around large code, APIs and AI application components.

However, revisiting the labs later with a stronger foundation changed the experience completely.

Instead of simply following instructions, I started focusing on what each step revealed about the system being tested.

That second iteration was where the learning became much more meaningful.


Areas Where the Experience Could Improve

No training platform is perfect, and I think there are areas where this learning path could become even stronger.

The biggest opportunity is the balance between theoretical explanations and visual learning.

The instructor explains complex topics clearly, but many sections rely heavily on text-based slides.

Additional diagrams, architecture illustrations and more visual examples would make some concepts easier to absorb, especially during the longer foundational sections.

I also would have enjoyed more repetition through practical scenarios.

The existing labs are useful, but cybersecurity skills become much stronger when learners repeatedly apply the same concepts in different situations.

For someone preparing for a security role, repeated practice is what transforms theoretical knowledge into confidence.

These are improvements to the learning experience rather than criticisms of the content itself.

The course provides a broad and valuable perspective on AI security, especially because it considers both offensive and defensive aspects rather than focusing only on exploiting AI systems.


The Certification Experience and What It Taught Me

Bridging the Gap Between Theory and Practice

The certification exam itself was one of the most challenging parts of the journey, shifting towards complex hypothetical scenarios while placing much greater emphasis on practical red teaming techniques and DevOps-related concepts.

The biggest lesson I learned was that understanding the theory behind AI security is not the same as being technically prepared for every aspect of an assessment.

The training develops a strong conceptual foundation and teaches security methodology, but the exam places greater emphasis on practical technical analysis, including API interaction, Python code understanding and implementation details.

Coming from a defensive security background rather than software development or offensive security, I underestimated how much time I needed to spend strengthening those areas, especially becasue I was told during the training “I didn’t need to understand everything” or “it was fine to just have basic python knowledge”.

Learning From My First Attempt

My first attempt showed me exactly where my gaps were.

Instead of simply reviewing the course material again, I changed my preparation strategy. I went back through the practical labs, studied the code more carefully, practised API endpoint enumeration, reviewed JSON responses and focused on understanding the technical details behind the exercises.

That process was valuable because it reinforced an important lesson about cybersecurity learning: Finding gaps in your knowledge is not a failure. It is information about where to focus your next effort.

An Unexpected Ending

My second attempt went much better and I felt much more confident going through the technical technical assignments.

This time, I genuinely felt I had a realistic chance of passing, but it ended in an unexpected way. After spending almost the entire allocated time completing the exam, I reached the time limit before manually clicking the final Submit button.

Under INE’s current exam policy, attempts must be submitted before the timer expires; otherwise, the attempt is automatically forfeited and cannot be graded. I contacted support to ask whether my recorded answers could still be reviewed, but they confirmed that this follows their current certification process.

Beyond the Result

Although this was a frustrating experience, it also highlighted something important about professional growth: unexpected obstacles are part of learning. The value I gained from the preparation process went beyond the final exam result.


Final Thoughts

Completing the eAIS learning path expanded my understanding of how modern AI systems are built, where their security risks emerge and how security professionals can approach assessing them.

The biggest takeaway was not learning a collection of AI attacks. It was learning to look at AI systems through a security mindset.

When I now think about an AI-enabled application, I do not only see the model. I see the surrounding architecture, the data flows, the trust boundaries, the integrations and the security controls that need to be evaluated.

That way of thinking connects directly with the skills I continue developing for a future SOC role: understanding systems, investigating behavior, identifying risks and communicating findings clearly.

Even though AI security is a specialized area, learning to analyze complex systems methodically is a skill that transfers well to security operations.

Alongside building my homelab, practicing security investigations, developing SIEM skills and documenting my cybersecurity journey through technical articles, this learning experience has been another step towards becoming a more capable security professional.