Exercises
Freeze an evaluation; calculate rater agreement; expose judge position bias; derive misuse cases; test indirect injection; constrain a tool; probe exfiltration; poison a retrieval source; minimize retained data; analyze subgroup errors; write a system card; build a risk register; and run an incident tabletop.
Required evidence
Submit versioned tests, system manifest, raw and summarized results, representative failures, a rejected alternative, named control owners, and residual-risk decision. Safety claims without adversarial evidence do not pass.
Oral defense
Demonstrate one failure, identify its first violated boundary, explain why layered controls limit impact, and execute the stop or escalation path.
Source backbone
Use NIST AI RMF, OWASP LLM Top 10, NIST SSDF, and Building Secure and Reliable Systems.