Knowledge in this field is uneven. Some countries have begun to name the meeting point of AI and cybersecurity. Others still teach the two apart.
That unevenness does not make the subject optional. Where AI is used with real weight — a country, a region, an organisation, a company — the knowledge around it cannot sit on the side. The subject is too delicate for approximation: data that is already good can be turned against those who hold it, and a model can be bent without anyone in the room quite seeing how.
The effort has to be made. Not later, and not only in the places that already have a course with a name. Wherever AI is treated as strategic, someone in the room needs to know how it can be defended.
What follows is not a catalogue and not an offer of mine. It is a map of public or widely recognised places I have come across — national agencies first, then a few universities and frameworks that travel across borders followed by major certifications.
The list will grow as I find sources that feel right.
Training
Europe
ENISA — good cybersecurity practices for AI
https://www.enisa.europa.eu/publications/multilayer-framework-for-good-cybersecurity-practices-for-ai
ENISA — Cybersecurity in the Frontier AI Era
https://www.enisa.europa.eu/publications/enisas-view-on-cybersecurity-in-the-frontier-ai-era
France
ANSSI — training catalogue (includes the short course Cybersecurity issues of Artificial Intelligence)
https://cyber.gouv.fr/le-catalogue-des-formations-proposees-par-lanssi
ANSSI — AI as a cyber issue
https://cyber.gouv.fr/enjeux-technologiques/intelligence-artificielle/
ANSSI — SecNumacadémie (general cyber MOOC; platform being rebuilt in 2026)
https://www.secnumacademie.gouv.fr/
Spain
INCIBE — national cybersecurity institute (training and talent programmes)
https://www.incibe.es/
DaSCI / University of Granada, funded by INCIBE — AI and cybersecurity programme
https://dasci.es/en/media-en/artificial-intelligence-and-cybersecurity-key-elements-of-the-new-training-programme-offered-by-dasci-and-incibe/
Germany
BSI — Federal Office for Information Security
https://www.bsi.bund.de/
Switzerland
NCSC — list of Swiss training courses on cyber-issues
https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/bildungsangebote.html
EPFL & ETH Zurich — joint Master in Cyber Security
https://www.epfl.ch/schools/ic/education/master/cyber-security/
Swiss Cyber Institute
AI Systems Security Training – Swiss Cyber Institute
United States / international frameworks
NIST — AI Risk Management Framework
https://www.nist.gov/itl/ai-risk-management-framework
CISA / NICCS — AI Security competency and listed courses
https://niccs.cisa.gov/tools/nice-framework/competency-area/artificial-intelligence-ai-security
SANS — AI Security Principles and Practices (GenAI and LLM defense)
https://www.sans.org/cyber-security-courses/ai-security-principles-practices
Certifications
Defense of AI systems ( GenAI / LLM )
GIAC AI Platform Security (GAIPS) — audit and secure GenAI apps and LLM pipelines (prompt injection, data leakage, model abuse). Prep: SANS SEC545.
https://www.giac.org/certifications/ai-security-platform-security-gaips
https://www.sans.org/cyber-security-courses/ai-security-principles-practices
GIAC AI Penetration Tester (GAIPT) — test AI systems for adversarial weaknesses. Prep: SANS SEC536.
https://www.sans.org/cyber-security-courses/ai-security-principles-practices
(liste GIAC AI : https://www.giac.org/focus-areas/artificial-intelligence)
Defense against AI-powered attacks (and how attackers use AI)
GIAC Offensive AI Analyst (GOAA) — offensive AI techniques so a defender can recognise them. Prep: SANS SEC535.
https://www.giac.org/certifications/offensive-ai-analyst-goaa
GIAC AI Security Automation Engineer (GASAE) — AI used across red / blue / purple operations. Prep: SANS SEC598.
https://www.sans.org/cyber-security-courses/ai-security-automation
Vendor-neutral, both sides
CompTIA SecAI+ (CY0-001) — launched 2026. Domains include securing AI systems and AI-assisted security (incident response, threat intel, testing).
https://www.comptia.org/
(annonce : https://www.prnewswire.com/news-releases/where-ai-and-cybersecurity-converge-introducing-comptia-secai-302689399.html)
SECO-Institute S-AISF (AI Security Foundation) — European entry level: AI-powered intrusions, adversarial risk, testing of AI systems.
https://www.dnv.com/training/ai-security-foundation-course/
Governance more than hands-on defense
ISACA AAISM (Advanced in AI Security Management) — enterprise programme, risk and control. Needs CISM or CISSP.
https://www.isaca.org/
ISC2 AI Security Certificate (course + certificate, not yet a full exam). A standalone ISC2 AI security certification is in preparation (beta expected 2027).
https://www.isc2.org/professional-development/certificates/build-ai-strategy
Frameworks to read even without a badge
MITRE ATLAS — adversary tactics against AI.
https://atlas.mitre.org/
OWASP Top 10 for LLM Applications.
https://owasp.org/www-project-top-10-for-large-language-model-applications/