# Do AI certifications make sense when AI moves this fast? > A balanced look at what AI and AI-security certifications actually test, how fast the field under them changes, what public data says about their value, and the alternatives that exist alongside them. FireAI Security & Research Team (HisnLabs) · Published 2026-09-27 Canonical: https://hisnlabs.com/en/blog/are-ai-certifications-worth-it Within the same year, ISACA launched a new credential for managing AI security risk, GIAC published four new certifications covering AI security work, and CompTIA began revising its flagship entry-level exam to add AI content. That is not a coincidence; it is a certification industry visibly reacting to a field that keeps moving under it. This article looks at what these credentials actually test, what evidence exists about how quickly the knowledge behind them ages, what public data says about their value, and what people do instead or alongside them — without recommending for or against any specific paid product. ## Background The entry-level layer of cybersecurity certification predates the current wave of AI-specific credentials and still forms the baseline most of them build on. ISC2's entry-level credential (CC) assumes no prior work experience and covers five domains: security principles, security governance, identity and access management, networking and cloud security concepts, and security operations and incident response [[3]](https://www.isc2.org/certifications/cc). CompTIA's Security+ prepares candidates for roles such as security analyst, security engineer and systems administrator, and CompTIA has stated that its next version, Security+ V8, launching 17 November 2026, will add "expanded coverage of areas such as AI-related risks, security operations, and modern environments" to the existing exam [[4]](https://www.comptia.org/certifications/security). On top of that baseline, AI-specific credentials arrived quickly and from more than one direction. ISACA's Advanced in AI Security Management (AAISM), which it describes as the first AI-centric security management credential, requires candidates to already hold an active CISM or CISM-equivalent, or CISSP credential before registering, and tests three domains: AI Governance and Program Management, AI Risk Management, and AI Technologies and Controls, at a cost of $459 for members and $599 for non-members, plus a $50 application fee on passing [[1]](https://www.isaca.org/credentialing/aaism). GIAC, separately, added four AI-specific credentials to its catalogue: AI Security Automation Engineer (GASAE, tied to SANS course SEC598), AI Platform Security (GAIPS, tied to SEC545), Offensive AI Analyst (GOAA, tied to SEC535) and AI Penetration Tester (GAIPT, tied to SEC536), each tested with GIAC's CyberLive hands-on format rather than static recall [[2]](https://www.giac.org/certifications/). ## Evidence What these credentials test differs by design, and the difference matters for how they age. AAISM's three domains are process and governance work — program management, risk management, technology controls — the kind of structure that changes only when an organisation's overall approach to risk changes, not every time a new model ships [[1]](https://www.isaca.org/credentialing/aaism). GIAC's four AI credentials, by contrast, are tested hands-on against a live environment, and each is tied to a specific, named SANS course rather than a general body of knowledge, meaning the certifying body has coupled the credential's freshness to how often it revises that one course [[2]](https://www.giac.org/certifications/). There is direct evidence, from the standards bodies themselves, that the underlying material moves fast enough to force revision on a short cycle. NIST published its AI Risk Management Framework in January 2023, then found it necessary to add a Generative AI Profile in July 2024 and has a further Critical Infrastructure Profile scheduled for April 2026 — three distinct publications in roughly three years for a document meant to describe stable risk-management structure [[5]](https://www.nist.gov/itl/ai-risk-management-framework). MITRE ATLAS is not published as a fixed document at all: its content is versioned on a year-month-revision schedule, separate from the format version of the underlying data files, specifically because the catalogue of techniques and case studies keeps growing [[6]](https://atlas.mitre.org/). OWASP's Top 10 for LLM Applications is maintained the same way, as a living, versioned list — the current edition names ten categories, from prompt injection through unbounded consumption — rather than a document published once and left alone [[7]](https://genai.owasp.org/llm-top-10/). On what a credential is worth in pay, the only fetched source with concrete numbers is general rather than AI-specific: ISC2's 2024 global data put average salaries across its certification portfolio between $94,948 for the SSCP credential and $119,577 for CISSP, with no breakdown by AI specialisation [[10]](https://www.isc2.org/Insights/2024/05/ISC2-Reveals-Global-ISC2-Certification-Salaries). ISACA's State of Cybersecurity 2025 survey states, in the scope publicly visible on its report page, that it covers "a high demand for technical skills" alongside soft-skills gaps, and AI's effect on "attack vectors, defense strategies and policy development" among nearly 4,000 surveyed professionals; the full report sits behind a registration wall, so this article cites only that stated scope, not any finding about certifications specifically [[11]](https://www.isaca.org/resources/reports/state-of-cybersecurity-2025). ## Analysis Read together, the newest wave of AI-security credentials is not built the way a static, memorise-and-recall exam would be, and that looks like a direct response to the problem this article is asking about. AAISM tests a governance process that changes on the scale of years, not months, because organisational risk structure is more durable than any one model or tool [[1]](https://www.isaca.org/credentialing/aaism). GIAC's four AI credentials instead accept that the tooling changes constantly and test current, hands-on ability against a live environment rather than fixed facts, which keeps the credential meaningful at the moment of testing but pushes the ageing problem onto the certifying body, which must keep revising the underlying course to keep the exam current [[2]](https://www.giac.org/certifications/). Neither approach makes the knowledge stand still; each is a different, defensible way of coping with the fact that it will not. NIST's own need to bolt a Generative AI Profile onto its AI RMF within eighteen months of publishing it, and MITRE ATLAS's decision to version its content on a monthly-scale schedule rather than publish it once, are both, in effect, admissions by government and standards bodies that a fixed snapshot of this material goes stale quickly [[5]](https://www.nist.gov/itl/ai-risk-management-framework) [[6]](https://atlas.mitre.org/). That is the case for treating a certification as one input rather than the whole answer, and several alternatives exist alongside it, each with a real trade-off rather than a clean win. A portfolio or a record of open-source contributions demonstrates current, specific capability directly, but has no external verification and no standard format an employer can compare across candidates. Published write-ups and research carry the same trade-off in a sharper form: genuinely current, and open to anyone, with no gatekeeping at all, which is a strength for speed and a weakness for verification. Competitive practice sits between the two: Carnegie Mellon University's CyLab Security Academy runs picoCTF, a free platform whose scope now runs "from basic security fundamentals to advanced areas such as AI security," and CTFtime maintains a continuously updated archive of competitions and team rankings rather than a fixed exam date, so a CTF record is, by construction, closer to "what this person can do against today's challenges" than a credential earned at one point in time [[8]](https://picoctf.org/) [[9]](https://ctftime.org/). The trade-off is real: CTF participation favours people with time to compete outside work, its format suits offensive and technical roles far better than governance-track ones, and, unlike a credential, it maps onto no employer's formal hiring checklist. | Approach | What it verifies | How it ages | Best fit | | --- | --- | --- | --- | | Governance-focused credential (e.g. AAISM) | Process, policy and risk-management knowledge | Slowly — tied to organisational risk structure, not to a specific tool | Management and compliance track [[1]](https://www.isaca.org/credentialing/aaism) | | Hands-on, live-tested credential (e.g. GIAC's AI certifications) | Current ability against a live environment | As fast as the tooling — requires the issuer to revise the course | Practitioners specialising in one technical area [[2]](https://www.giac.org/certifications/) | | CTFs (picoCTF, CTFtime) | Demonstrated, current problem-solving ability | Continuously — the challenge set itself changes | Technical, offensive-leaning roles [[8]](https://picoctf.org/) [[9]](https://ctftime.org/) | | Portfolio / open-source contributions | Specific, inspectable work | As current as the last contribution | Anyone who can show, not just claim, recent work | *Compiled from the sources cited in this article.* ## Recommendations 1. New to the field: build shared vocabulary first, either through an entry-level credential such as ISC2's CC or CompTIA Security+, or through an equivalent free course such as FireAI University's [Foundations of cybersecurity](https://hisnlabs.com/en/university/cybersecurity-foundations); an AI specialisation sits on top of this, not instead of it [[3]](https://www.isc2.org/certifications/cc) [[4]](https://www.comptia.org/certifications/security). 2. Adding an AI specialisation as a practitioner: weigh a hands-on, live-tested credential against free, continuously updated practice — picoCTF's AI-security modules and an active CTFtime record — based on whether a specific employer needs the credential line or just the resulting skill [[2]](https://www.giac.org/certifications/) [[8]](https://picoctf.org/) [[9]](https://ctftime.org/). 3. Moving toward governance or management: a credential built on process, gated behind an existing CISM or CISSP, tends to age more slowly than a tool-specific one, because it tests a structure — NIST's Govern, Map, Measure and Manage functions — rather than a snapshot of current tooling; FireAI University's [Threat modelling and risk](https://hisnlabs.com/en/university/threat-modeling-and-risk) covers the same reasoning without an exam fee [[1]](https://www.isaca.org/credentialing/aaism) [[5]](https://www.nist.gov/itl/ai-risk-management-framework). 4. Evaluating any specific paid certification: check who issues it, what it requires as a prerequisite, whether it is tested hands-on against a live environment or by static recall, and how recently its content was last revised, before treating a marketing page's claims as the answer. 5. At every stage, track the field through material that updates continuously — MITRE ATLAS's case studies, OWASP's versioned Top 10, or a running research log such as the [FireAI Radar](https://hisnlabs.com/en/radar) — rather than treating one credential, once earned, as a finished answer [[6]](https://atlas.mitre.org/) [[7]](https://genai.owasp.org/llm-top-10/). > FireAI University publishes the governance, threat-modelling and offensive/defensive courses referenced in this article at no charge, and the FireAI Radar keeps a running, dated record of which AI tools and techniques the lab has actually tested. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Limitations ISACA's State of Cybersecurity 2025 report was not accessible without registering as a member; this article cites only the scope publicly stated on its report page, not its findings, and makes no claim about what it concludes regarding certifications specifically [[11]](https://www.isaca.org/resources/reports/state-of-cybersecurity-2025). ISC2's salary figures are from May 2024, span its whole certification portfolio, and are not specific to AI-security roles; no source consulted for this article gives AI-security-specific pay data [[10]](https://www.isc2.org/Insights/2024/05/ISC2-Reveals-Global-ISC2-Certification-Salaries). This article does not evaluate the difficulty, pass rate or exam quality of any credential named, since no fetched source provided that data. GIAC's four AI credentials are described here from the vendor's own catalogue page as newly available; this article did not sit any exam and cannot speak to how quickly their content will be revised going forward, only to the hands-on format they use today [[2]](https://www.giac.org/certifications/). Whether a specific credential is worth its cost for a given person depends on their employer, region and role, none of which any source cited here quantifies, and this article deliberately does not rank or recommend a specific paid certification. ## How FireAI and HisnLabs fit in Nothing here is an argument for or against any paid credential; FireAI is a firewall, not a training provider, and the honest way to keep pace with a field this fast is the same one this article recommends to everyone else: practice, published reference material, and a running record of what is actually changing. FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac. You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download). ## Sources - [ISACA: Advanced in AI Security Management (AAISM)](https://www.isaca.org/credentialing/aaism) - [GIAC: certifications catalogue (AI Security Automation Engineer, AI Platform Security, Offensive AI Analyst, AI Penetration Tester)](https://www.giac.org/certifications/) - [ISC2: Certified in Cybersecurity (CC)](https://www.isc2.org/certifications/cc) - [CompTIA: Security+ certification](https://www.comptia.org/certifications/security) - [NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) - [MITRE ATLAS: Adversarial Threat Landscape for AI Systems](https://atlas.mitre.org/) - [OWASP Gen AI Security Project: Top 10 for LLM Applications](https://genai.owasp.org/llm-top-10/) - [picoCTF, Carnegie Mellon University CyLab Security Academy](https://picoctf.org/) - [CTFtime: capture-the-flag event archive and rankings](https://ctftime.org/) - [ISC2: global certification salary data (2024)](https://www.isc2.org/Insights/2024/05/ISC2-Reveals-Global-ISC2-Certification-Salaries) - [ISACA: State of Cybersecurity 2025 (report scope)](https://www.isaca.org/resources/reports/state-of-cybersecurity-2025)