Student interest in AI safety is surging, and schools are rushing to prepare for new career paths.
As the world increasingly recognizes the need for safer and more secure AI, U.S. colleges and universities are trying to meet a growing demand for AI security education that prepares future workers to safeguard businesses’ and governments’ powerful AI systems.
AI cybersecurity education programs, from undergraduate and graduate classes to professional certificates, are sprouting up all over the country, as experts warn that young people need to understand how to manage AI risks as they enter a workforce teeming with algorithms, models and agents. The recent autonomous-hacking incidents involving frontier AI models have further underscored the need for cybersecurity education.
With policymakers and business leaders fretting about the consequences of reckless AI development that doesn’t prioritize security, higher-education institutions are rushing to fill a stark curriculum void before it’s too late. They are receiving support from a cybersecurity workforce coalition, a handful of pioneering professors and a government newly energized about infusing AI security into classrooms.
“As we see different models from Anthropic and OpenAI and other organizations begin to cross boundaries and do things that they weren’t trained to do, it becomes all the more important to make sure that we have appropriate governance,” said Michael Mattarock, associate director of the Carnegie Mellon University’s Information Networking Institute.
Universities have responded to AI’s growing prominence by creating courses about virtually every aspect of the technology. But until recently, demand for AI cybersecurity education had been relatively muted — something experts described as a serious problem.
“As AI becomes embedded across industries and critical systems, graduates need to understand how to build and deploy AI that is secure, trustworthy and resilient, not simply how to make the technology work,” said Eman El-Sheikh, associate vice president and professor at the University of West Florida’s Center for Cybersecurity and AI. “We need graduates who understand … how to protect AI models, data and systems from vulnerabilities, attacks and misuse.”
Several experts compared the hazards of overlooking AI security education to the disastrous consequences of universities ignoring cybersecurity in their early computer science courses . “Everybody’s chasing the cool, sexy thing of AI, and not always doing the due diligence to make sure that those solutions or those platforms are properly secured,” Mattarock said.
Preparing students to mitigate AI risks will give them “a skill set that makes them competitive for tighter job markets,” said John Petrozzelli, director of the MassCyberCenter, a Massachusetts state government hub that is incorporating AI education into a program that trains college students to work in security operations centers .
Future AI developers who graduate without foundational cybersecurity skills — including the ability to evaluate model outputs for signs of compromise — will end up building systems that they don’t know how to oversee and that lack key safeguards, Mattarock said.
“Everybody’s chasing the cool, sexy thing of AI, and not always doing the due diligence to make sure that those solutions or those platforms are properly secured.”
Associate Director, Information Networking Institute, Carnegie Mellon University
Multiple experts argued that the recent loss-of-control incidents involving frontier AI models offered a potent illustration of what can happen when developers overlook security.
“Taking the ethical approach” of incorporating clear guardrails into AI systems “is really critical,” Petrozzelli said, “especially when they’re looking at using it for cybersecurity purposes, like vulnerability scanning or penetration testing.”
On the bright side, Mattarock said the trend of autonomous-hacking incidents “continues to spark interest [in AI security] among students.”
AI cybersecurity education is still a nascent field, experts said, with universities at different stages of rolling out curricula.
It is unclear exactly how many universities now offer AI security programs, but Cybersecurity Dive identified several scattered across the country, including at the University of Chicago , Dakota State University , Florida International University and South Carolina’s military academy, The Citadel . Last November, a National Security Agency program created to recognize universities with outstanding cybersecurity curricula designated Ferris State University as its first “Center of Academic Excellence in Secure Artificial Intelligence.”
At the Georgia Institute of Technology, Assistant Professor Teodora Baluta is in the process of creating a permanent course out of a machine learning security elective she taught in the spring and fall of 2025. Her lessons connect social questions about AI, such as the privacy of training data, with technical considerations such as using threat modeling to prevent jailbreaking and preserve robustness.
The course’s goal is to teach students how to engage in threat modeling that compares a system’s defenses to the dangers it faces. Baluta said she wanted students to come away from the class “thinking a little bit adversarially.” Certain threats may not be very common, she added, “but if at least they’re aware of it conceptually, they’ll be more responsible AI computer scientists.”
“[Schools] need to graduate a cadre of well-rounded students that are looking at the combination of the science side of things and the liberal-arts side.”
Carnegie Mellon University, one of the first schools to create a cybersecurity curriculum, offers at least three levels of AI security education. Undergraduates can take a course on Responsible AI and AI Governance , while graduate students can pursue a Master of Science in Artificial Intelligence Engineering - Information Security , one of the first such degrees in the nation and one that other universities are using as a template. CMU also offers a Future of Secure AI certificate , a four-day program for senior technical leaders.
The certificate program teaches technical managers about how AI-related security risks such as data-poisoning attacks could affect their organizations, and it prepares them to communicate those risks to executives. “If we can’t articulate return on investment [or] how different attack vectors have influence over the bottom line of the business, we’re probably not going to be able to get executive stakeholder buy-in,” said Mattarock, who co-leads the program. “We have to make sure that folks are equipped with that ability.”
AI has become an increasingly important consideration for the Pentagon-funded National Cybersecurity Workforce Development Program (NCWDP), a consortium of roughly three dozen universities that jointly develop curricula and create training pathways combining classes, industry certificates and career development. Member schools have already taught more than 11,000 students through 146 pathways and awarded more than 19,000 credentials, according to El-Sheikh of UWF, which leads the consortium.
UWF itself offers a federally certified AI cybersecurity study program , as well as AI security graduate degrees and professional certificates. And as part of its leadership of the NCWDP consortium, UWF oversaw a project to create an AI fundamentals course that it shared with other schools for incorporation into their cybersecurity programs.
AI security education appears poised to take off. UWF is seeing “strong and growing interest” in its program, El-Sheikh said, and Carnegie Mellon now receives almost as many applications for its AI security master’s degree, which launched in 2022, as it does for its top-ranked information security master’s degree, which launched in 2003. Georgia Tech’s Baluta said that when she discussed LLM security during an undergraduate-level cybersecurity class, many students expressed interest in learning more.
The number of enrollments in online AI security classes from learning platforms Coursera and Udemy skyrocketed 665% between 2025 and 2026, the companies reported recently .
As more learners embrace the field, El-Sheikh said schools should “embed security throughout AI curricula rather than limiting it to a single course” and treat it as a foundational concept rather than trying to introduce it later.
Experts also said lessons should balance the human and technical aspects of AI safety and security to prepare graduates for the ethical judgments that are often at the heart of AI development and deployment. Schools “need to graduate a cadre of well-rounded students that are looking at the combination of the science side of things and the liberal-arts side,” Petrozzelli said.
Universities that have already embraced AI security education are now refining and expanding their offerings. The NCWDP consortium is developing new workforce pathways specifically focused on AI security careers, and UWF is creating new certificate and degree programs for the field. Baluta said she plans to add more lessons about agentic AI to her syllabus.
The field’s expansion can’t happen quickly enough for education leaders who fear the consequences of young professionals rushing to adopt a new technology in unsafe ways.
“Students who learn how to develop and use AI without understanding its security risks,” El-Sheikh said, “are missing an increasingly critical part of the picture.”