AI and machine learning 路 Free
AI Security and the OWASP Top 10 for LLMs
The security course for people who have already built something with an LLM: the attack surface a model adds, all ten 2026 OWASP LLM risks one at a time, indirect injection and zero-click agent attacks, what leaks out through a chatbot, securing agents with identity and least privilege, the OWASP MCP and agentic guidance, red-teaming with MITRE ATLAS, and the NIST-based governance a plant or a GCC can actually enforce.
Inside the course



From the lessons

Why an LLM is a new attack surface
IBM Technology

LLM01: prompt injection and its defences
IBM Technology

LLM02 and LLM08: what leaks out
Vandana Verma

LLM10 and LLM03: output handling and excessive agency
Vandana Verma

LLM06: unbounded consumption and the cost of running AI
Vandana Verma

Agent identity, privilege and delegation
IBM Technology
Lesson frames belong to the creators named in the Credits below and are shown from YouTube.
What you will learn
Threat-model an AI feature by its parts; name and defend against all ten OWASP LLM risks; trace an indirect injection from a poisoned document to an executed action; write the rule for what may be pasted into a public chatbot; check the provenance of a model, dataset or plugin before it is used; scope an agent's tools, identity and permissions so it cannot act beyond its brief; review a connector before wiring it in; plan a pen test of an LLM feature; and fill the register entry and AI-use policy that make the whole thing auditable.
- Draw an AI feature as its parts and mark where an outsider's text can enter
- Name all ten 2026 OWASP LLM risks and sort a real incident into the right one
- Trace an indirect injection from a poisoned document to an executed action
- Write the one-page rule on what may and may not be pasted into a public chatbot
- Scope an agent's tools, identity and permissions to the least it actually needs
- Plan a pen test of an LLM feature and fill the AI register entry behind it
For you
Taking AI Security and the OWASP Top 10 for LLMs from the United States
- Free in the United States, as everywhere, and self-paced: lessons, notes and the final assessment are open at any hour, so your time zone and shift pattern do not matter.
- The optional certificate for learners in the United States is a one-off US$28.99. What you get for it
- Plants across the Americas most often run Allen-Bradley, Siemens and Inductive Automation; each has its own free course to take next.
- See automation and engineering jobs in the United States, and what the industry looks like in Houston, Detroit and Chicago.
- EDWartens also has a regional site for the United States, for classroom training and local support: edwartens.com/us.
The course project 路 about 16 hours
Securing a maintenance-manual chatbot before it goes on the plant network at a Cork pharma plant
Take a RAG chatbot that answers technicians' questions from PLC and drive manuals on an OpenRouter free model, and do to it what a plant's OT security team does before anything reaches the plant network: inventory its parts, map its threats to the OWASP Top 10 for LLM Applications with a test for each, red-team it with promptfoo and by hand, write the security requirements from what you found, fix it, re-test on the same test IDs, and hand over an incident-response and model-update procedure. You deliver the risk register, the test report with the prompts you tried, the CRS and the re-test evidence. The sample pack shows what each document looks like when a plant's security team signs it.
Sample document pack, 7 documents, filled in for the scenario
- Asset inventoryOT Asset Inventory: Maintenance Manual Chatbot and Everything It Reaches
- Risk registerThreat and Risk Register: Maintenance Manual Chatbot, mapped to the OWASP Top 10 for LLM Applications 2026
- CRSCybersecurity Requirements Specification: Maintenance Manual Chatbot on the Plant Network
- Test reportRed-Team Test Report: Baseline and Re-test of the Maintenance Manual Chatbot
- ProcedureIncident Response and Model Update: Maintenance Manual Chatbot
- PlanRemediation and Go-Live Plan: Maintenance Manual Chatbot on the Plant Network
- Training recordTraining Record: Chatbot Users, Owner and Corpus Custodian
Read inside the course and download as a workbook. The project is optional practice, marked when you submit it; the certificate needs only the modules and the final assessment.
Course content
15 modules 路 49 lessons 路 9h 21m
In order, at whatever pace suits you. Each module ends with a practice task that builds on the last.
- 01Why an LLM is a new attack surface4 lessons34m
- 02The 2026 OWASP Top 10 for LLM applications2 lessons40m
- 03LLM01: prompt injection and its defences4 lessons57m
- 04Indirect injection, promptware and zero-click attacks3 lessons36m
- 05LLM02 and LLM08: what leaks out4 lessons36m
- 06LLM04 and LLM05: supply chain, data and model poisoning4 lessons26m
- 07LLM10 and LLM03: output handling and excessive agency4 lessons29m
- 08LLM09 and LLM07: retrieval weaknesses and misinformation4 lessons34m
Requirements
- Who it is for
- Intermediate. Best after any LLM, RAG or AI agent course in the track. Some IT or OT security background helps, but no coding is required.
- Software
- None required. A free chatbot account is enough for the leakage and grounding exercises. What to download, and how
- Hardware
- None.
Software you need
What to download, where from, what it costs and how to install it. Every link goes to the maker's own site, never a mirror.
Nothing to install
A free account on any AI assistant is enough for the leakage and grounding exercises.
One AI assistant
Any one is enough.
- 01Free plan with limits
ChatGPT
OpenAI, in the browser
- Runs on
- Any modern web browser, plus mobile and desktop apps
- Account
- A free OpenAI account
The Free plan allows everyday text chats. File uploads, image creation, voice and data analysis have tighter limits than paid plans, and ads may appear in some countries. Paid plans raise the limits.
Steps
- 1.Open chatgpt.com.
- 2.Click Sign up and create an account with your email, or a Google, Microsoft or Apple account.
- 3.Verify your email and confirm your details.
- 4.Type your question in the message box.
- Do not paste personal data, passwords or confidential work files.
- ChatGPT tells you when you reach a limit. Wait for it to reset or switch to a lighter task.
Open ChatGPTchatgpt.com - 02Free plan with limits
Claude
Anthropic, in the browser
- Runs on
- Any modern web browser, plus desktop and mobile apps
- Account
- A free Claude account (you must be 18 or over)
The Free plan covers chat on web, desktop and mobile, web search, file creation and Artifacts. Usage limits reset on a rolling five-hour window and depend on message length and features used. Paid plans give more usage.
Steps
- 1.Open claude.ai (or see the plans at claude.com/pricing).
- 2.Sign up with your email or Google account and confirm your email.
- 3.Confirm you are 18 or over and accept the terms.
- 4.Type your question in the message box.
- Long conversations and large files use up your limit faster. Start a new chat for a new topic.
- Do not paste personal data or confidential work files.
Open Claudeclaude.com - 03Free with limits
Google Gemini
Google, in the browser
- Runs on
- Any modern web browser, plus Android and iOS apps
- Account
- A free Google account
Free with a Google account, including a Flash model, limited access to the Pro model, image generation, Deep Research and Gems. Paid Google AI plans give higher limits. Some features require you to be 18 or over.
Steps
- 1.Open gemini.google.com.
- 2.Sign in with your Google account.
- 3.Accept the terms the first time you use it.
- 4.Type your question or upload a file in the prompt box.
- Use a personal Google account. Work or school accounts depend on your administrator's settings.
Open Google Geminigemini.google.com - 04Free
Microsoft Copilot and Microsoft 365 Copilot Chat
Microsoft, in the browser
- Runs on
- Any modern web browser, plus Windows, macOS, Android and iOS apps
- Account
- None needed
Microsoft Copilot is free for individuals; you must be at least 13 (older in some countries). Microsoft 365 Copilot Chat is included at no extra cost for organisations with an eligible Microsoft 365 licence and needs a work or school (Microsoft Entra ID) account.
Steps
- 1.Open copilot.microsoft.com.
- 2.Optionally click Sign in and use your personal Microsoft account.
- 3.Type your question in the message box.
- 4.For work or school use, sign in at microsoft365.com with your organisation account and open Copilot Chat.
- Copilot Chat with a work or school account adds enterprise data protection. Use it for work material if your organisation provides it.
Open Microsoft Copilot and Microsoft 365 Copilot Chatcopilot.microsoft.com
Checked against each maker's own page on 27 September 2026. Trial lengths and editions change; the maker's page is the final word.
AI Security and the OWASP Top 10 for LLMs at a glance
AI Security and the OWASP Top 10 for LLMs is a free, self-paced online course from EDWartens for engineers, developers and students applying AI to real work. It has 15 modules and 9h 21m of video lessons by IBM Technology, Vandana Verma, Jeff Crume, with written notes and worked problems, a practical project with a document pack and a 15-question final assessment (pass mark 60%). Learning is free with an account; an optional certificate with a public verification code is issued when you pass. Last updated 27 September 2026.
All course factsHide course facts
- Price
- Free, for good. No trial, no card. The only paid item is the optional certificate, a small one-off fee.
- Who it is for
- Engineers, developers and students applying AI to real work
- Format
- 15 self-paced modules, 9h 21m of video, written notes, a practice task per module and one final assessment.
- Level
- Intermediate. Intermediate. Best after any LLM, RAG or AI agent course in the track. Some IT or OT security background helps, but no coding is required.
- Brand
- Vendor-neutral
- Software
- None required. A free chatbot account is enough for the leakage and grounding exercises.
- Hardware
- None.
- Certificate
- Optional EDWartens Certificate of Completion, verifiable by code. Not a vendor credential.
- Video lessons by
- IBM Technology, Vandana Verma, Jeff Crume (independent creators, credited below)
- Language
- English
- Last updated
- 27 September 2026
A shareable EDWartens certificate
Finish every module and pass the final assessment, and the optional EDWartens certificate is yours. It carries a unique verification code on a public page anyone can check, so it stands up when a recruiter looks it up. See it below.
The course itself stays free whether or not you ever buy one.
Stuck? Ask a practising engineer
A free course usually means a comment section and hope. This one does not. Every module has an Ask-your-trainer panel that reaches the same engineers who teach our paid programme: people who commission panels for a living, not moderators.
Pairs well with
PLC programming 路 FreeSiemens TIA PortalFrom zero electrical knowledge to a working, simulated S7-1200 program, for nothing.
PLC programming 路 FreeSiemens TIA Portal in Three HoursThe first three hours of the Siemens TIA Portal course, cut to end on a win: what a PLC is, how it is wired, a project configured in TIA Portal, and your first ladder program running in simulation. Finish it in an evening or two, earn a certificate, and carry straight on into the full course.
PLC programming 路 FreeTIA Portal: Build a MachineOne machine, start to finish. Take a bottle filling line from a written specification and an I/O list to a structured S7-1200 program with a fill station, a capper, a reject sorter and an operator screen with alarms, then test it against a written record and archive it for hand-over. The lessons are the reference; the machine is yours, and it is what you submit.
Instrumentation 路 FreeInstrumentation for PLC EngineersThe half of the loop that is not code. Follow one measurement from the transmitter in the field, down the 4-20 mA loop, into the analog card, through NORM_X and SCALE_X into engineering units, out again to a valve, and back to the control room when the reading is wrong.More free courses: Free cyber security courses 路 Free AI courses for engineers 路 Free IT security and SOC analyst courses
Learner reviews
No reviews yet
Reviews here are written only by learners who have finished every module of AI Security and the OWASP Top 10 for LLMs, and they are published exactly as written. Finish the course and yours will be the first.
Common questions
Who is the AI Security and the OWASP Top 10 for LLMs course for?
Engineers who have already put an LLM, a RAG chatbot or an agent near company data, and IT or OT security people who now have AI systems on their asset list. It is the security counterpart to the building courses in the AI track.
What do I need to know first?
You should have seen an LLM application from the inside, so any LLM, RAG or agent course in the track first. Some IT or OT security background helps but is not assumed, and no coding is required. Every task is done on paper against a system you already work with.
Is this the OWASP certification?
There is no OWASP certification for the LLM Top 10. The OWASP Top 10 for LLM Applications is a free published document that anyone may read, and this course teaches you to apply it to a real system. This course is not a security certification of any kind and does not prepare you for one.
Is this a hacking course?
No. It is defensive: threat modelling, controls, agent permissions, governance and incident response. The testing module covers how an authorised test of an LLM feature is scoped, run and written up, not how to attack somebody else's system.
How long is it?
Fourteen modules plus a final, about nine hours of video and roughly fourteen hours in total once the notes, practice tasks and practice questions are counted. A module a day for a fortnight works well.
Is the AI Security and the OWASP Top 10 for LLMs course really free?
Yes. Every module, practice task and assessment. You create an account so your progress is saved and the assessments can be marked. The certificate is the only paid item, and only if you want it.
What certificate does the AI Security and the OWASP Top 10 for LLMs course give?
An EDWartens Certificate of Completion, issued when you have finished every module and passed the final at 60 per cent, with a verification code anyone can check. It is not a vendor credential and is never described as one.
Who made the video lessons in the AI Security and the OWASP Top 10 for LLMs course?
The creators named in the Credits block at the foot of this page, on their own YouTube channels. EDWartens did not make the videos and the creators are not affiliated with EDWartens. What EDWartens wrote is the study plan, the notes, the practice tasks and the assessments.
What you walk away with
Your certificate for AI Security and the OWASP Top 10 for LLMs
Finish the course, pass the final, and this is the document with your name on it.

Verifiable by anyone
Adds to LinkedIn in one click
QR code on the certificate
Names what you can do
A permanent link
Earned, not attended
Learning is free. The certificate is optional.
Add it now and pay only when you have finished the course, or come back for it later. One-off, US$28.99, with a receipt.
Issued by EDWartens, the training division of Wartens, as a Certificate of Completion for this self-paced course. Sold by Wartens Ltd (England and Wales). It is not a vendor certification, a university award or a CPD-accredited activity, and it does not certify competence on live equipment. Delivered electronically; see the refund policy.
Credits
Who made the video lessons
The video lessons in this course were created by the people below, not by EDWartens. Every lesson streams from its creator's own YouTube channel; EDWartens neither hosts nor sells that footage, and the creators are not affiliated with EDWartens and do not endorse this course. What EDWartens wrote is the study plan, the notes, the practice tasks and the assessments.
- IBM Technologythe attack-surface, prompt injection, promptware kill chain, zero-click, shadow AI, corpus poisoning, LLMjacking, agent security, zero trust, MITRE ATLAS and NIST AI RMF explainers
- Vandana Vermathe risk-by-risk walkthrough of LLM01 to LLM10, the first look at the OWASP MCP Top 10, and the OWASP Securing Agentic Applications guide
- Jeff Crumethe long adversarial AI session on evasion, model inversion, model theft and deepfakes
If you are one of these creators and would like a lesson removed or credited differently, write to info@wartens.com.
