UprootSecurityUprootSecurity

Curriculum · Phase 7 · Module 7.2

AI Security Landscape + Governance Frameworks

The on-ramp to AI security: what actually goes wrong when AI ships to production in 2026, and the governance frameworks that now define the expectations. This module walks the AI attack surface — data, model, agent, and tools — with real incidents, then puts the three frameworks a GRC engineer is asked about side by side: NIST AI RMF (Govern/Map/Measure/Manage), ISO 42001 (the AI management system, the "ISO 27001 for AI"), and the EU AI Act with its risk tiers and obligations. You then classify eight AI use cases under the EU AI Act tiers — the exact judgement call that decides which controls a system must carry.

75 min

·

4 lessons

·

+50 pts

Article

AI Security in 2026: Why It Breaks Differently

20 min

+10 pts

Article

The Three AI Governance Frameworks: NIST AI RMF, ISO 42001, EU AI Act

25 min

+10 pts

Video

Watch: Classifying AI Systems Under the EU AI Act Tiers

10 min

+10 pts

Exercise

Classify 8 AI Use Cases Under the EU AI Act Tiers

20 min

+20 pts

AI Security Landscape + Governance Frameworks — UprootSecurity Bootcamp