Two new certifications. One mission. The question is which one deserves your time — or whether the answer is both.
1. WHY THIS MATTERS RIGHT NOW
The timing couldn’t be louder. In the same week that Anthropic accidentally leaked 500,000 lines of Claude Code’s source — exposing safety bypass flags, permission classifiers named “YOLO,” and an anti-distillation system that poisons competitor training data — two of the most respected names in offensive security have independently launched certifications dedicated to breaking AI systems.
The Fortinet 2025 Skills Gap Report found that while 97% of organisations are deploying or planning AI-enabled security tools, nearly half say their teams lack the hands-on AI expertise to use those tools effectively. OffSec In a recent AI red teaming CTF run by Hack The Box and HackerOne, only 43% of registrants managed to complete even a single challenge Channel Insider — evidence of a skills gap that’s widening faster than the industry can fill it.
AI systems are no longer experimental add-ons. They’re production infrastructure making real decisions about access, triage, and response. And they’re being deployed far faster than they’re being secured. Prompt injection currently holds the number-one spot on the OWASP Top 10 for LLM Applications 2025, with supply chain vulnerabilities at number three. OffSec
The attackers aren’t waiting for the defenders to catch up. Neither should you.
2. THE CONTENDERS
OffSec OSAI+ (AI-300) — Advanced AI Red Teaming
OffSec needs no introduction. The company behind OSCP — arguably the most respected offensive security certification in the world — has brought its “Try Harder” philosophy to AI. AI-300 is a hands-on course designed to teach security professionals how to assess and exploit modern AI systems, including generative AI, LLMs, and multi-agent environments. OffSec
The course launched on March 31, 2026 OffSec Support, available via Course & Cert Bundle, Learn One, and Learn Enterprise subscriptions. The earliest exam date opened is July 15, 2026. OffSec Support
Key details:
- Learners interact with enterprise-style AI architectures including LLMs, vector databases, multi-agent systems, model orchestration frameworks, and cloud environments supporting AI infrastructure. OffSec
- The exam is a rigorous 24-hour practical red team engagement where learners must compromise a realistic AI-enabled enterprise environment. OffSec
- The exam is fully proctored OffSec Support and open-book (except AI chatbots).
- The OSAI certification does not expire. The OSAI+ designation expires after three years but can be maintained through continuing education paths. OffSec Support
- The transition from OSCP typically requires 50 to 100 hours of study, with most professionals completing it in 6 to 12 weeks. OffSec
- OffSec’s prerequisite LLM Red Teaming learning path covers roughly 30 hours across six modules on LLM fundamentals, prompt injection, jailbreaking, and supply chain attacks. OffSec
Hack The Box COAE — Certified Offensive AI Expert
HTB has taken a different but complementary approach. The AI Red Teamer Job Role Path was developed in collaboration with Google, aligned with Google’s Secure AI Framework (SAIF). HTB Academy The certification — HTB COAE — is now available on HTB Academy and HTB Enterprise plans, serving as the final assessment for the AI Red Teamer path. Hackthebox
Key details:
- The exam is a rigorous 7-day practical engagement where candidates are dropped into a simulated corporate environment and tasked with performing a full-scale AI offensive assessment. Hack The Box
- The curriculum covers real-world adversarial attacks: adversarial ML, data poisoning, evasion attacks, LLM output exploitation, and AI privacy breaches. Hack The Box
- The exam evaluates proficiency in adversarial ML, LLM output exploitation, and AI system security, with a commercial-grade technical report required for completion. Hackthebox
- The learning path covers prompt injection, model privacy attacks, adversarial AI, supply chain risks, and deployment threats, combining theory with hands-on exercises. HTB Academy
- Modules span AI foundations, gradient-based adversarial attacks, sparsity-constrained attacks, privacy attacks against ML models, LLM prompt injection, LLM output vulnerabilities, and AI defence.
- Access is through HTB Academy’s Silver Annual subscription or Enterprise plans.
3. HEAD-TO-HEAD COMPARISON
| OffSec OSAI+ (AI-300) | HTB COAE | |
|---|---|---|
| Provider Pedigree | The OSCP people. Gold standard in offensive certs since 2006. | The platform that gamified hacking. Partnered with Google for this one. |
| Launch Date | March 31, 2026 | April 2, 2026 |
| Exam Format | 24-hour proctored practical engagement | 7-day practical engagement |
| Exam Focus | Recon, exploitation, post-exploitation across AI-enabled enterprise environments | Full-scale AI offensive assessment: adversarial ML, LLM exploitation, privacy attacks |
| Report Required | Yes — professional pentest report | Yes — commercial-grade technical report |
| Framework Alignment | OffSec’s own offensive methodology (OSCP DNA) | Google’s Secure AI Framework (SAIF) |
| Prerequisite Path | LLM Red Teaming learning path (~30hrs) + AI-300 course | AI Red Teamer Job Role Path (multiple modules, built with Google) |
| Cert Expiry | OSAI: never. OSAI+: 3 years (renewable) | Not specified |
| Proctored | Yes | Not specified |
| Scope | Heavy on LLMs, multi-agent systems, AI infrastructure, cloud environments | Broader ML coverage: gradient attacks, evasion, data poisoning, privacy + LLM exploitation |
| Ideal Candidate | Pentesters / red teamers pivoting into AI. OSCP holders. | Security professionals wanting full-spectrum AI/ML offensive + defensive coverage. |
| Access Model | Course & Cert Bundle / Learn One / Learn Enterprise | Silver Annual (Academy) / Grow & Scale (Enterprise) |
4. WHERE THEY DIFFER — AND WHY IT MATTERS
Philosophical Approach
OffSec brings its battle-tested “methodology over memorisation” approach. OSAI is built for the operator, not the auditor — the 24-hour exam isn’t testing recall or framework memorisation, it’s testing whether you can sustain an offensive engagement against novel AI attack surfaces and adapt when things don’t work as expected. OffSec If you’ve done the OSCP, you know the feeling: sleep-deprived, staring at a stubborn shell, forcing yourself to think laterally. OSAI brings that same pressure to AI systems.
HTB takes a broader, more academic-offensive hybrid approach. The Google partnership gives it SAIF alignment, which matters for enterprise credibility and compliance. COAE goes beyond prompt injection tricks — it validates AI security knowledge across the full attack surface: adversarial ML, data poisoning, LLM exploitation, AI application and system security, privacy, and defence, all in one credential. Hack The Box The 7-day exam window trades intensity for depth — you’re expected to conduct a thorough, methodical assessment rather than a sprint.
Scope of Coverage
This is where the real difference sits. OffSec OSAI+ leans heavily into the infrastructure and LLM exploitation side — how AI systems sit within enterprise environments, how agents orchestrate, how vector databases and model pipelines can be compromised. It’s the pentest perspective applied to AI.
HTB COAE casts a wider net into classical ML adversarial techniques — gradient-based attacks, evasion, data poisoning, membership inference, privacy attacks against trained models. If you want to understand how to manipulate a neural network at the mathematical level as well as prompt-inject an LLM, COAE covers more ground.
Exam Endurance
24 hours (OffSec) vs 7 days (HTB). Both are practical, both require a professional report, and neither is multiple-choice. The OffSec format rewards the high-pressure sprint operator. The HTB format rewards the methodical researcher who produces enterprise-grade documentation.
5. THE CASE FOR DOING BOTH
Here’s the thing: these certifications aren’t competing. They’re complementary.
OSAI+ gives you the OffSec brand, the OSCP-lineage credibility, and the ability to pressure-test AI-enabled enterprise environments under time constraints. It proves you can perform under fire.
COAE gives you the Google SAIF alignment, the deeper ML adversarial toolkit, and a 7-day engagement format that mirrors how real AI red team assessments actually get scoped in enterprise contracts. It proves you can go deep.
Together, they tell an employer or a client: “I can break your LLM chatbot, poison your training pipeline, exfiltrate data through your RAG system, pivot through your multi-agent orchestration, and write you a report that your CISO can take to the board.”
In a world where state-backed attackers are reportedly using highly autonomous AI models at up to 90% autonomy SecurityBrief, having one certification is good. Having both is a signal that you’re not just keeping up — you’re staying ahead.
6. THE BIGGER PICTURE: CONTINUOUS LEARNING ISN’T OPTIONAL ANYMORE
The Claude Code leak didn’t just expose Anthropic’s source code. It exposed exactly how fast the AI attack surface is evolving. Hidden feature flags for autonomous agents that “dream” overnight. Anti-distillation systems. Safety bypass modes. Permission classifiers making risk decisions in real time. Multi-agent swarm architectures. These aren’t theoretical threats in a textbook — they’re production code that was running last week.
The rate of change in AI means that a certification you earn today needs to be the starting point, not the destination. Both OffSec and HTB seem to understand this — OffSec’s OSAI+ requires continuing education every three years to maintain the designation OffSec Support, and HTB’s path is already evolving with new defensive and privacy modules added in January 2026.
The professionals who will thrive in this landscape are the ones who treat AI security as a discipline, not a one-off badge. Earn the certs. Do the labs. But also: read the leaked source code, study the CVEs as they drop, follow the researchers who find the prompt injection bypasses, and build your own adversarial tooling. The certs give you the foundation. The continuous work gives you the edge.
The bad guys aren’t taking a study break. Neither should you.
7. WHAT’S NEXT
I’ll be enrolling in both OSAI+ and COAE over the coming weeks. Expect follow-up posts with hands-on reviews covering the course material quality, lab environments, exam experience, and whether these certifications deliver on the promise of producing real-world AI red teamers. Stay tuned.
[AIL3]
