AI-300: Offensive Security for AI Systems - on the way to OSAI.
AI-300 (OSAI) covers attacks against AI systems: prompt injection, manipulating agents and tool calls, attacks on data pipelines and model supply chain, and hardening LLM applications.

- Certification
- OSAI - OffSec AI Security Specialist
- Level
- Advanced
- Discipline
- Attack
- Audience
- Teams and individuals
Who this course is for
Pentesters, AI engineers and security teams that have to secure LLM applications, agents and ML pipelines in production.
Not the right course yet if
- -You have no web or API testing experience yet - start with WEB-200
- →Systematically attack and assess LLM applications and agents
- →Demonstrate prompt injection and tool abuse paths
- →Name and mitigate risks in the data and model supply chain
- ·Pentest or application security experience
- ·Basic understanding of LLMs, APIs and Python
Not sure whether you meet them? We run a short placement conversation before you buy.
What AI-300 covers.
- Direct and indirect prompt injection
- Agents, tools and permission boundaries
- RAG and data pipeline attacks
Course content, labs and the OSAI exam are provided by OffSec. Precedence always sits with the official course description. This page reviewed: 2026-08-12.
Labs and format
Labs with vulnerable LLM applications, agent setups and data pipelines.
Exam and credential
Practical exam against AI applications, with a report. Passing awards the OSAI certification.
The packages that include AI-300.
Prices in EUR, net, plus statutory VAT. Invoiced through a German entity. Your course is pre-selected at checkout.
You have a focused block of time and want to sit the exam soon.
- ▸ 90 days of course access including labs
- ▸ 1 exam attempt
- ▸ Exactly this course
Study alongside a job, without lab time pressure.
- ▸ 365 days of course access including labs
- ▸ 2 exam attempts
- ▸ Proving Grounds Practice, KLCP and OSWP included
Several people in a team, with evidenced progression.
- ▸ The full OffSec catalogue
- ▸ Learning paths and reporting
- ▸ Reassignable from 5 seats
- +Application to your own LLM product as part of our AI security programme
- +Mapping into EU AI Act and ISMS evidence
For security teams
Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.
See Learn EnterpriseTeam capability development
Badges, learning paths and evidence across attack, defend, build and govern.
See the capability mapOther hackers also bought ... ;)
No. It enables your team but does not replace an independent assessment before release.
It provides technical assessment capability and evidence. The regulatory judgement stays with your compliance function.
Not sure whether AI-300 is the right course?
We run a short placement conversation: background, study time, goal. Then we recommend a course and package - even when it is the cheaper one.