Skip to main content

Every exercise is indexed by name, CWE, OWASP, MITRE ATT&CK, CIS, NIST CSF, GDPR and EU AI Act reference.

Try

AI & LLM Security
Training

Train employees to spot prompt injection, deepfakes, and AI-generated phishing before attackers exploit your AI tools.

43 interactive exercises across AI at Work and the OWASP Top 10 for LLM, agentic and MCP applications. Free to play, no sign-up required.

1

AI at Work

13 exercises

AI-Written Phishing

Spot a phishing email with perfect spelling and your project name.

  • ATT&CKT1566.002
  • CIS 14.2
Play Exercise →

AI Voice Phishing Calls

Take a scam call from an AI that answers every question.

  • ATT&CKT1566.004
  • EU AI ActArt. 50
  • CIS 14.2
Play Exercise →

Cloned Voice Payment Fraud

Handle a payment request sent as your manager's voice note.

  • ATT&CKT1656
  • EU AI ActArt. 50
  • CIS 14.2
Play Exercise →

Voice Clone Impersonation

Handle the fallout when a clone of your voice calls a colleague.

  • ATT&CKT1656
  • EU AI ActArt. 50
  • CIS 14.2
Play Exercise →

Deepfake Hiring Fraud

Run a liveness check on a remote candidate mid-interview.

  • ATT&CKT1656
  • EU AI ActArt. 50
  • CIS 14.2
  • NIST CSFPR.AA
Play Exercise →

AI Support Chatbot Scam

Spot a fake AI support chat that asks for your login code.

  • ATT&CKT1566.002
  • EU AI ActArt. 50
  • CIS 14.2
Play Exercise →

Unapproved AI Notetakers

Find the AI notetaker sitting in a confidential HR meeting.

  • GDPRArt. 5
  • EU AI ActArt. 4
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Prompt Injection in Documents

Trace an AI summary back to hidden text inside a PDF.

  • OWASP LLMLLM01:2026
  • CWE-1427
  • ATT&CKT1566.001
  • EU AI ActArt. 4
  • CIS 14.2
Play Exercise →

Unreviewed AI Output

Cut the internal details out of an AI-drafted client reply.

  • OWASP LLMLLM02:2026
  • GDPRArt. 5
  • EU AI ActArt. 4
  • CIS 14.4
Play Exercise →

Shadow AI Tools

Photograph a roadmap into a free AI app, then put it right.

  • GDPRArt. 5
  • EU AI ActArt. 4
  • CIS 14.4
  • NIST CSFID.AM
Play Exercise →

AI Agent Payment Fraud

Watch a web page redirect the payment your AI agent makes.

  • OWASP LLMLLM01:2026
  • CWE-1427
  • ATT&CKT1657
  • EU AI ActArt. 4
  • CIS 14.2
Play Exercise →

AI Assistant Oversharing

Check the source when an assistant answers with colleagues' salaries.

  • OWASP LLMLLM02:2026
  • GDPRArt. 5
  • EU AI ActArt. 4
  • CIS 14.4
  • NIST CSFPR.DS
Play Exercise →

Shared AI Agent Access

Share an assistant built on your files and watch it answer with your access.

  • OWASP LLMLLM02:2026
  • GDPRArt. 5
  • EU AI ActArt. 4
  • CIS 14.4
  • NIST CSFPR.AA
Play Exercise →
2

OWASP Top 10 for LLM Applications

10 exercises

Clawdbot (Moltbot) Prompt Injection

Stop a hidden prompt from hijacking your AI assistant mid-task.

  • OWASP LLMLLM01:2026
  • CWE-1427
  • CIS 16
  • NIST CSFPR.PS
Play Exercise →

Sensitive Data Exposure Through AI

See what happens when confidential data enters a consumer AI tool.

  • OWASP LLMLLM02:2026
  • CWE-200
  • CIS 16
  • NIST CSFPR.PS
Play Exercise →

AI Supply Chain Attack

Deploy an AI plugin that hides a backdoor in plain sight.

  • OWASP LLMLLM04:2026
  • CWE-1104
  • CIS 16
  • NIST CSFPR.PS
Play Exercise →

AI Knowledge Base Poisoning

Watch poisoned documents corrupt your AI's answers in real time.

  • OWASP LLMLLM05:2026
  • CIS 16
  • NIST CSFPR.PS
Play Exercise →

Unsafe AI Output Handling

Exploit an AI whose outputs flow unchecked into live systems.

  • OWASP LLMLLM10:2026
  • CWE-1426
  • CIS 16
  • NIST CSFPR.PS
Play Exercise →

Over-Permissioned AI Agent

Manipulate an AI assistant into misusing its own permissions.

  • OWASP LLMLLM03:2026
  • CWE-250
  • CIS 16
  • NIST CSFPR.PS
Play Exercise →

AI System Prompt Leakage

Extract hidden instructions from a customer-facing AI chatbot.

  • OWASP LLMLLM08:2026
  • CWE-200
  • CIS 16
  • NIST CSFPR.PS
Play Exercise →

RAG Pipeline Exploitation

Exploit a RAG pipeline to access documents beyond your clearance.

  • OWASP LLMLLM09:2026
  • CIS 16
  • NIST CSFPR.PS
Play Exercise →

AI Hallucination and Misinformation

Catch fabricated statistics and fake citations in an AI report.

  • OWASP LLMLLM07:2026
  • CIS 16
  • NIST CSFPR.PS
Play Exercise →

AI Denial-of-Service Attack

Launch a denial-of-wallet attack against an unprotected AI API.

  • OWASP LLMLLM06:2026
  • CWE-770
  • CIS 16
  • NIST CSFPR.PS
Play Exercise →
3

OWASP Top 10 for Agentic Applications

10 exercises

4

OWASP MCP Top 10

10 exercises

Frequently asked questions

What does the AI at Work course cover?

AI at Work is an 11-exercise course for every employee, not just the teams building AI. It covers AI-written phishing, AI voice agents on the phone, cloned voices, deepfake job candidates, fake AI support chats and AI notetakers that join meetings uninvited.

The second half is about the AI you already use: hidden instructions in documents, reviewing an AI-drafted reply before it leaves your outbox, free consumer AI tools, and an agent that pays a site nobody chose. Start with AI-Written Phishing or AI Agent Payment Fraud.

What is AI prompt injection?

AI prompt injection is an attack where malicious instructions are hidden inside documents, emails, or web pages that an AI assistant processes. When the AI reads the content, it follows the hidden instructions instead of the user's intent.

This can cause the AI to leak sensitive data, ignore safety rules, or perform unauthorized actions without the user realizing the input was manipulated.

How can prompt injection lead to data exfiltration?

An attacker embeds instructions in a document telling the AI to include sensitive data in its output, encode it in URLs, or send it to external endpoints.

Because the AI processes the document's full text, it may follow these instructions alongside legitimate content, sending confidential information to unintended recipients.

What is the OWASP Top 10 for LLM Applications?

The OWASP Top 10 for LLM Applications is an industry-standard framework that identifies the ten most critical security risks in large language model deployments.

It covers prompt injection (LLM01), sensitive information disclosure (LLM02), supply chain vulnerabilities (LLM03), data poisoning (LLM04), improper output handling (LLM05), excessive agency (LLM06), system prompt leakage (LLM07), vector and embedding weaknesses (LLM08), misinformation (LLM09), and unbounded consumption (LLM10). Our course includes one hands-on exercise for each risk.

What is the OWASP Top 10 for Agentic Applications?

The OWASP Top 10 for Agentic Applications is a 2025 framework that addresses security risks specific to autonomous AI agents that use tools, make decisions, and take actions independently.

It covers agent goal hijacking (ASI01), tool misuse and exploitation (ASI02), identity and privilege abuse (ASI03), agentic supply chain vulnerabilities (ASI04), unexpected code execution (ASI05), memory and context poisoning (ASI06), insecure inter-agent communication (ASI07), cascading failures (ASI08), human-agent trust exploitation (ASI09), and rogue agents (ASI10).

See RansomLeak in Action

Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.