Curriculum · Phase 7 · Module 7.2
The on-ramp to AI security: what actually goes wrong when AI ships to production in 2026, and the governance frameworks that now define the expectations. This module walks the AI attack surface — data, model, agent, and tools — with real incidents, then puts the three frameworks a GRC engineer is asked about side by side: NIST AI RMF (Govern/Map/Measure/Manage), ISO 42001 (the AI management system, the "ISO 27001 for AI"), and the EU AI Act with its risk tiers and obligations. You then classify eight AI use cases under the EU AI Act tiers — the exact judgement call that decides which controls a system must carry.
75 min
·
4 lessons
·
+50 pts