SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Most organizations think of shadow AI as simply employees pasting sensitive data into a chatbot or using a personal subscription in place of a corporate one. However, that is the least dangerous version of shadow AI. The more pressing issue is agentic: copilots, autonomous agents, and the skills, plugins, hooks, and extensions that power them. They are often deployed by well-meaning teams, invisible to security, and given access to organizational knowledge that nobody explicitly scoped.
Nearly every piece of that footprint is a third-party component, making shadow AI a supply chain problem as well. Unvetted code and models can execute with an agent’s permissions, while adversaries are increasingly using AI to find and exploit these gaps. We are told that agentic AI is the solution—but is it also part of the problem?
Matt Bromiley is a Lead Solutions Engineer at LimaCharlie and SANS Certified Instructor. He serves as a GIAC Advisory Board member, a SME for the SANS Security Awareness, and a technical writer for the SANS Analyst Program.
Learn more

Sounil Yu is the Founder and CTO of Knostic, and a leading voice in AI cybersecurity innovation. He is the creator of the Cyber Defense Matrix and the DIE Resiliency Framework.
Learn more