Two months · Red team and blue team · Live labs
An intensive two-month programme that turns cybersecurity professionals into AI security specialists — teaching the attacks first, because a defence you have never had to get past is not a defence you can trust.


Eight components structure the programme, from threat modelling across the ML lifecycle through hands-on adversarial attacks and the defences that stop them.


Tech AI Magazine has recognized the Heisenberg Institute for AI and Quantum Computing in its Best Places to Study AI listing.
What the Institute puts behind every candidate it admits.
People who attack and defend these systems for a living — adversarial machine learning on one side, red teaming on the other. Select a name to read their profile.
Beyond the programme team, a global faculty of practitioners, researchers and technology enablers teaches across the Institute, and every cohort also meets visiting CEOs, CAIOs and AI researchers. All of them are named in the Faculty Directory 2026.
Every offensive technique is executed in a lab against a working model, and every defensive module is measured against the attacks from the phase before it. Nothing is taught as theory that can be demonstrated as practice.


The order is the argument: you cannot harden a system you have never taken apart.

Seven groups of tooling — the offensive toolkit, the defensive one, and the monitoring stack that tells you which is winning.

Successful completion confers the Certified Professional in AI Security credential from the Heisenberg Institute.

Graduates of the CAIS programme on what changed for them.
I come from cybersecurity, so I initially thought AI security would be fairly straightforward to pick up. It wasn’t. I started watching videos about prompt injection, adversarial attacks and model security, but everything felt very fragmented. CAIS helped me understand how these risks fit into the bigger AI system. I finally had a framework instead of a list of attacks.
I had a good understanding of traditional application security but very little practical experience securing AI systems. That was becoming a problem because more of the systems I was working with were starting to include AI. CAIS helped me understand the differences and, importantly, gave me practical ways to think about securing these systems.
My issue was that most of the AI security material I found was either very academic or just a quick demo of an attack. CAIS was different because we looked at the attack and then had to think about how to defend against it. That made the concepts stick much better for me.
I had probably watched too many videos on LLM security before joining. Every video had a new vulnerability and after a while it was difficult to tell what was actually important. CAIS gave me a structured view of the AI attack surface. It helped me stop thinking about individual vulnerabilities and start thinking about the whole system.
I joined because AI was increasingly coming into conversations with our security team and I didn’t want to be the person who only understood the traditional security side. CAIS gave me enough technical depth to understand how AI systems can fail and how the security approach needs to change. That has already been useful in my work.
I had done quite a bit of self-learning before CAIS, but there was no real sequence to it. I would learn about one attack, then another, then read something about model security and go down another rabbit hole. The program gave me the structure I was missing. It also made me much more comfortable discussing AI security with engineering teams.
The biggest thing I took away from CAIS was the attacker mindset. I was used to looking at systems from a defensive perspective. Learning to think about how someone would actually try to manipulate or attack an AI system changed the way I look at these architectures. It made AI security feel much more tangible.
The programme admits a cohort every month. Applying early is the surest way to secure the cohort you want.

Flexible payment options and corporate sponsorship support are available — contact the admissions team for details.
You've taken the first step toward mastering applied AI and intelligent systems.
Review the program details carefully — our cohorts are selective, and designed for committed builders and leaders who can shape the future of AI.
When you are ready, we encourage you to apply early to secure your place.
By submitting this form you agree to our Terms and Conditions and our Privacy Policy.
When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.
These cookies enable the website to provide enhanced functionality and personalisation. They may be set by us or by third party providers whose services we have added to our pages. If you do not allow these cookies then some or all of these services may not function properly.
These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work.
These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous.
These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device.