AI and machine learning 路 Free

AI Security and the OWASP Top 10 for LLMs

The security course for people who have already built something with an LLM: the attack surface a model adds, all ten 2026 OWASP LLM risks one at a time, indirect injection and zero-click agent attacks, what leaks out through a chatbot, securing agents with identity and least privilege, the OWASP MCP and agentic guidance, red-teaming with MITRE ATLAS, and the NIST-based governance a plant or a GCC can actually enforce.

15 modules 9h 21m of video English 路 self-paced

Inside the course

AI Security and the OWASP Top 10 for LLMs: Syllabus at a glanceAI Security and the OWASP Top 10 for LLMs: What you will be able to doAI Security and the OWASP Top 10 for LLMs: Tools and credits

From the lessons

  • Artificial Intelligence: The new attack surface

    Why an LLM is a new attack surface

    IBM Technology

  • What Is a Prompt Injection Attack?

    LLM01: prompt injection and its defences

    IBM Technology

  • OWASP TOP 10 for LLM02: Sensitive Information Disclosure

    LLM02 and LLM08: what leaks out

    Vandana Verma

  • OWASP Top 10 for LLM05:2025 - Improper Output Handling

    LLM10 and LLM03: output handling and excessive agency

    Vandana Verma

  • OWASP Top 10 for LLM10:2025 Unbounded Consumption

    LLM06: unbounded consumption and the cost of running AI

    Vandana Verma

  • AI Privilege Escalation: Agentic Identity & Prompt Injection Risks

    Agent identity, privilege and delegation

    IBM Technology

Lesson frames belong to the creators named in the Credits below and are shown from YouTube.

What you will learn

Threat-model an AI feature by its parts; name and defend against all ten OWASP LLM risks; trace an indirect injection from a poisoned document to an executed action; write the rule for what may be pasted into a public chatbot; check the provenance of a model, dataset or plugin before it is used; scope an agent's tools, identity and permissions so it cannot act beyond its brief; review a connector before wiring it in; plan a pen test of an LLM feature; and fill the register entry and AI-use policy that make the whole thing auditable.

  • Draw an AI feature as its parts and mark where an outsider's text can enter
  • Name all ten 2026 OWASP LLM risks and sort a real incident into the right one
  • Trace an indirect injection from a poisoned document to an executed action
  • Write the one-page rule on what may and may not be pasted into a public chatbot
  • Scope an agent's tools, identity and permissions to the least it actually needs
  • Plan a pen test of an LLM feature and fill the AI register entry behind it

For you

Taking AI Security and the OWASP Top 10 for LLMs from the United States

The course project 路 about 16 hours

Securing a maintenance-manual chatbot before it goes on the plant network at a Cork pharma plant

Take a RAG chatbot that answers technicians' questions from PLC and drive manuals on an OpenRouter free model, and do to it what a plant's OT security team does before anything reaches the plant network: inventory its parts, map its threats to the OWASP Top 10 for LLM Applications with a test for each, red-team it with promptfoo and by hand, write the security requirements from what you found, fix it, re-test on the same test IDs, and hand over an incident-response and model-update procedure. You deliver the risk register, the test report with the prompts you tried, the CRS and the re-test evidence. The sample pack shows what each document looks like when a plant's security team signs it.

Sample document pack, 7 documents, filled in for the scenario

  • Asset inventoryOT Asset Inventory: Maintenance Manual Chatbot and Everything It Reaches
  • Risk registerThreat and Risk Register: Maintenance Manual Chatbot, mapped to the OWASP Top 10 for LLM Applications 2026
  • CRSCybersecurity Requirements Specification: Maintenance Manual Chatbot on the Plant Network
  • Test reportRed-Team Test Report: Baseline and Re-test of the Maintenance Manual Chatbot
  • ProcedureIncident Response and Model Update: Maintenance Manual Chatbot
  • PlanRemediation and Go-Live Plan: Maintenance Manual Chatbot on the Plant Network
  • Training recordTraining Record: Chatbot Users, Owner and Corpus Custodian

Read inside the course and download as a workbook. The project is optional practice, marked when you submit it; the certificate needs only the modules and the final assessment.

Course content

15 modules 路 49 lessons 路 9h 21m

In order, at whatever pace suits you. Each module ends with a practice task that builds on the last.

  1. 01Why an LLM is a new attack surface34m
  2. 02The 2026 OWASP Top 10 for LLM applications40m
  3. 03LLM01: prompt injection and its defences57m
  4. 04Indirect injection, promptware and zero-click attacks36m
  5. 05LLM02 and LLM08: what leaks out36m
  6. 06LLM04 and LLM05: supply chain, data and model poisoning26m
  7. 07LLM10 and LLM03: output handling and excessive agency29m
  8. 08LLM09 and LLM07: retrieval weaknesses and misinformation34m

Requirements

Who it is for
Intermediate. Best after any LLM, RAG or AI agent course in the track. Some IT or OT security background helps, but no coding is required.
Software
None required. A free chatbot account is enough for the leakage and grounding exercises. What to download, and how
Hardware
None.

Software you need

What to download, where from, what it costs and how to install it. Every link goes to the maker's own site, never a mirror.

Nothing to install

A free account on any AI assistant is enough for the leakage and grounding exercises.

One AI assistant

Any one is enough.

  1. 01

    ChatGPT

    OpenAI, in the browser

    Free plan with limits
    Runs on
    Any modern web browser, plus mobile and desktop apps
    Account
    A free OpenAI account

    The Free plan allows everyday text chats. File uploads, image creation, voice and data analysis have tighter limits than paid plans, and ads may appear in some countries. Paid plans raise the limits.

    Open ChatGPTchatgpt.com
  2. 02

    Claude

    Anthropic, in the browser

    Free plan with limits
    Runs on
    Any modern web browser, plus desktop and mobile apps
    Account
    A free Claude account (you must be 18 or over)

    The Free plan covers chat on web, desktop and mobile, web search, file creation and Artifacts. Usage limits reset on a rolling five-hour window and depend on message length and features used. Paid plans give more usage.

    Open Claudeclaude.com
  3. 03

    Google Gemini

    Google, in the browser

    Free with limits
    Runs on
    Any modern web browser, plus Android and iOS apps
    Account
    A free Google account

    Free with a Google account, including a Flash model, limited access to the Pro model, image generation, Deep Research and Gems. Paid Google AI plans give higher limits. Some features require you to be 18 or over.

    Open Google Geminigemini.google.com
  4. 04

    Microsoft Copilot and Microsoft 365 Copilot Chat

    Microsoft, in the browser

    Free
    Runs on
    Any modern web browser, plus Windows, macOS, Android and iOS apps
    Account
    None needed

    Microsoft Copilot is free for individuals; you must be at least 13 (older in some countries). Microsoft 365 Copilot Chat is included at no extra cost for organisations with an eligible Microsoft 365 licence and needs a work or school (Microsoft Entra ID) account.

Checked against each maker's own page on 27 September 2026. Trial lengths and editions change; the maker's page is the final word.

AI Security and the OWASP Top 10 for LLMs at a glance

AI Security and the OWASP Top 10 for LLMs is a free, self-paced online course from EDWartens for engineers, developers and students applying AI to real work. It has 15 modules and 9h 21m of video lessons by IBM Technology, Vandana Verma, Jeff Crume, with written notes and worked problems, a practical project with a document pack and a 15-question final assessment (pass mark 60%). Learning is free with an account; an optional certificate with a public verification code is issued when you pass. Last updated 27 September 2026.

All course facts
Price
Free, for good. No trial, no card. The only paid item is the optional certificate, a small one-off fee.
Who it is for
Engineers, developers and students applying AI to real work
Format
15 self-paced modules, 9h 21m of video, written notes, a practice task per module and one final assessment.
Level
Intermediate. Intermediate. Best after any LLM, RAG or AI agent course in the track. Some IT or OT security background helps, but no coding is required.
Brand
Vendor-neutral
Software
None required. A free chatbot account is enough for the leakage and grounding exercises.
Hardware
None.
Certificate
Optional EDWartens Certificate of Completion, verifiable by code. Not a vendor credential.
Video lessons by
IBM Technology, Vandana Verma, Jeff Crume (independent creators, credited below)
Language
English
Last updated
27 September 2026

A shareable EDWartens certificate

Finish every module and pass the final assessment, and the optional EDWartens certificate is yours. It carries a unique verification code on a public page anyone can check, so it stands up when a recruiter looks it up. See it below.

The course itself stays free whether or not you ever buy one.

Stuck? Ask a practising engineer

A free course usually means a comment section and hope. This one does not. Every module has an Ask-your-trainer panel that reaches the same engineers who teach our paid programme: people who commission panels for a living, not moderators.

Pairs well with

More free courses: Free cyber security courses 路 Free AI courses for engineers 路 Free IT security and SOC analyst courses

Learner reviews

No reviews yet

Reviews here are written only by learners who have finished every module of AI Security and the OWASP Top 10 for LLMs, and they are published exactly as written. Finish the course and yours will be the first.

Common questions

Who is the AI Security and the OWASP Top 10 for LLMs course for?

Engineers who have already put an LLM, a RAG chatbot or an agent near company data, and IT or OT security people who now have AI systems on their asset list. It is the security counterpart to the building courses in the AI track.

What do I need to know first?

You should have seen an LLM application from the inside, so any LLM, RAG or agent course in the track first. Some IT or OT security background helps but is not assumed, and no coding is required. Every task is done on paper against a system you already work with.

Is this the OWASP certification?

There is no OWASP certification for the LLM Top 10. The OWASP Top 10 for LLM Applications is a free published document that anyone may read, and this course teaches you to apply it to a real system. This course is not a security certification of any kind and does not prepare you for one.

Is this a hacking course?

No. It is defensive: threat modelling, controls, agent permissions, governance and incident response. The testing module covers how an authorised test of an LLM feature is scoped, run and written up, not how to attack somebody else's system.

How long is it?

Fourteen modules plus a final, about nine hours of video and roughly fourteen hours in total once the notes, practice tasks and practice questions are counted. A module a day for a fortnight works well.

Is the AI Security and the OWASP Top 10 for LLMs course really free?

Yes. Every module, practice task and assessment. You create an account so your progress is saved and the assessments can be marked. The certificate is the only paid item, and only if you want it.

What certificate does the AI Security and the OWASP Top 10 for LLMs course give?

An EDWartens Certificate of Completion, issued when you have finished every module and passed the final at 60 per cent, with a verification code anyone can check. It is not a vendor credential and is never described as one.

Who made the video lessons in the AI Security and the OWASP Top 10 for LLMs course?

The creators named in the Credits block at the foot of this page, on their own YouTube channels. EDWartens did not make the videos and the creators are not affiliated with EDWartens. What EDWartens wrote is the study plan, the notes, the practice tasks and the assessments.

What you walk away with

Your certificate for AI Security and the OWASP Top 10 for LLMs

Finish the course, pass the final, and this is the document with your name on it.

Sample EDWartens Certificate of Completion for AI Security and the OWASP Top 10 for LLMs
Sample. The issued certificate carries your name, admission number, a unique certificate number and its own QR code.
  • Verifiable by anyone

  • Adds to LinkedIn in one click

  • QR code on the certificate

  • Names what you can do

  • A permanent link

  • Earned, not attended

Learning is free. The certificate is optional.

Add it now and pay only when you have finished the course, or come back for it later. One-off, US$28.99, with a receipt.

Issued by EDWartens, the training division of Wartens, as a Certificate of Completion for this self-paced course. Sold by Wartens Ltd (England and Wales). It is not a vendor certification, a university award or a CPD-accredited activity, and it does not certify competence on live equipment. Delivered electronically; see the refund policy.

Credits

Who made the video lessons

The video lessons in this course were created by the people below, not by EDWartens. Every lesson streams from its creator's own YouTube channel; EDWartens neither hosts nor sells that footage, and the creators are not affiliated with EDWartens and do not endorse this course. What EDWartens wrote is the study plan, the notes, the practice tasks and the assessments.

  • IBM Technologythe attack-surface, prompt injection, promptware kill chain, zero-click, shadow AI, corpus poisoning, LLMjacking, agent security, zero trust, MITRE ATLAS and NIST AI RMF explainers
  • Vandana Vermathe risk-by-risk walkthrough of LLM01 to LLM10, the first look at the OWASP MCP Top 10, and the OWASP Securing Agentic Applications guide
  • Jeff Crumethe long adversarial AI session on evasion, model inversion, model theft and deepfakes

If you are one of these creators and would like a lesson removed or credited differently, write to info@wartens.com.