# AI Red Teaming and Assurance

Canonical URL: <https://www.nobledesktop.com/classes/ai-red-teaming-and-assurance>

## Overview

This capstone of the applied AI security path closes the gap between testing an AI system and defending the decision to run it. It separates two things organizations routinely conflate: red teaming, deliberately trying to break, mislead, or misuse a system, and assurance, the documented evidence that a system is trustworthy enough for its purpose. Participants run the engagement lifecycle end to end, scoping testing to the system's risk classification, setting objectives, writing rules of engagement that separate an exercise from an incident, and managing team composition and deconfliction, then match technique to attack surface, weighing manual testing against automated approaches.

Two things make this course unique. The first is agentic AI, where the attack surface expands from what a system says to what a system does. The second is assurance itself: rather than stopping at finding problems, the course builds the assurance case as claim, argument, and evidence an oversight body can audit, alongside TEV&V records, model and system cards, and how it all feeds a risk-acceptance decision. It also teaches the hard judgment calls, and by design uses scenario-based practice activities instead of a lab, so procurement and oversight staff can take it alongside the testers. It tops a path that runs from [AI Security Fundamentals for the Cyber Workforce](https://www.nobledesktop.com/classes/ai-security-fundamentals-for-the-cyber-workforce) through [Securing AI/ML Systems: Protecting the Intelligent Attack Surface](https://www.nobledesktop.com/classes/securing-ai-ml-systems) and [AI Security Monitoring and Incident Response](https://www.nobledesktop.com/classes/ai-security-monitoring-and-incident-response).

## What you'll learn

- Distinguish red teaming from adjacent assurance activities, and place it correctly in the AI assurance lifecycle
- Run a red-team engagement lifecycle from planning through reporting
- Scope testing to a system's risk classification, and set objectives that produce usable results
- Write rules of engagement, and handle team composition and deconfliction
- Match adversarial testing techniques to the attack surface they actually address
- Weigh manual expert-driven testing against automated and tool-assisted approaches
- Apply probing techniques to generative AI systems
- Tell a genuine red-team finding apart from an ordinary software bug
- Build Test, Evaluation, Verification and Validation records that support a risk decision
- Construct an assurance case as claim, argument and evidence
- Interpret model cards and system cards, and judge independent evaluation results
- Structure a findings report and prioritize by impact rather than technical complexity
- Manage remediation and retesting, and apply human oversight as a mitigation
- Recognize when a finding becomes an incident
- Extend testing and assurance to foundation models and to agentic, tool-using systems

## Prerequisites

This is an advanced capstone course. Participants should already understand AI and machine learning security fundamentals and be familiar with adversarial testing or assurance work.

## Curriculum

#### Module 1

- Foundations: What Is AI Red Teaming, and Where Does It Fit in AI Assurance?
- What red teaming is and is not
- Where it sits in the AI assurance lifecycle
- The range of assurance activities
- The guidance the course draws on
- Who is involved

#### Module 2

- Planning and Scoping a Red-Team Engagement
- The engagement lifecycle
- Scoping to risk classification
- Setting red-team objectives
- Rules of engagement
- Team composition and deconfliction

#### Module 3

- Adversarial Testing Techniques for Machine Learning and Generative AI
- Matching technique to attack surface
- Manual versus automated and tool-assisted red teaming
- Generative AI probing techniques
- A preview of testing agentic and tool-using systems
- Telling red-team findings apart from ordinary bugs

#### Module 4

- AI Assurance Frameworks: TEVV, Assurance Cases, and Documentation
- Test, Evaluation, Verification and Validation
- The assurance case as claim, argument and evidence
- Model cards and system cards
- Independent evaluation and measurement science
- From assurance documentation to a risk-acceptance decision

#### Module 5

- From Findings to Fixes: Reporting, Remediation, and Human Oversight
- Structuring a findings report
- Prioritizing by impact rather than technical complexity
- Remediation and retesting
- Human oversight as a mitigation category
- When a finding becomes an incident

#### Module 6

- Red Teaming and Assurance for Generative and Agentic AI; Capstone Scenario
- Foundation models and misuse-risk testing
- Agentic AI and the expansion of the attack surface from output to action
- Why red teaming and assurance are recurring rather than one-time
- A capstone scenario

## Schedule
- Jan 6, 2027 – Jan 7, 2027 — Live Online
- Feb 1, 2027 – Feb 2, 2027 — Live Online
- Mar 19, 2027 – Mar 22, 2027 — Live Online
- Apr 5, 2027 – Apr 6, 2027 — Live Online
- May 26, 2027 – May 27, 2027 — Live Online
- May 26, 2027 – May 27, 2027 — Live Online
- Jun 21, 2027 – Jun 22, 2027 — Live Online
- Jul 6, 2027 – Jul 7, 2027 — Live Online
- Aug 4, 2027 – Aug 5, 2027 — Live Online

## Pricing

**Tuition:** $1049
