As enterprises move artificial intelligence from experimentation into production, cybersecurity teams are being asked to defend systems they were not trained to secure a few years ago. CompTIA is responding with a credential focused specifically on that intersection: CompTIA SecAI+, its certification for AI security, risk and governance, has received accreditation from the ANSI National Accreditation Board (ANAB) under the ISO/IEC 17024 standard.
The rush to deploy generative AI has created a less visible problem for technology leaders: the workforce responsible for securing those systems is still catching up.
CompTIA is targeting that skills gap with SecAI+, a certification designed around the security implications of artificial intelligence. The organization said the credential has earned accreditation from the ANSI National Accreditation Board, confirming that it meets the internationally recognized ISO/IEC 17024 framework for certification quality, validity and impartiality.
The distinction matters because AI security is becoming a specialized discipline rather than simply another feature of conventional cybersecurity.
Traditional security teams are accustomed to protecting applications, networks, identities and data. AI introduces another layer of risks, including prompt injection, model manipulation, insecure AI integrations, sensitive-data leakage, adversarial attacks and the misuse of AI-powered tools.
At the same time, organizations need security professionals who understand the governance requirements surrounding AI—not just the technical mechanics of machine learning models.
CompTIA SecAI+ is intended to cover that broader territory. According to CompTIA, the certification validates skills in securing AI systems, identifying AI-enabled threats, managing AI risk, supporting AI governance and using AI-powered cybersecurity tools.
That puts the credential at an interesting point in the evolution of the enterprise AI stack.
Companies including Microsoft, Google, Amazon and NVIDIA are investing heavily in AI infrastructure and security capabilities, while vendors such as IBM, Palo Alto Networks and others are developing security products around AI workloads. But technology alone does not eliminate the need for people who understand how those systems can fail.
Certification programs are one way organizations attempt to formalize that expertise.
ANAB accreditation provides an independent layer of validation. ISO/IEC 17024 establishes requirements for organizations that certify people, including processes intended to ensure that certification examinations are consistent, impartial and based on defined competencies.
For employers, that can make a difference when evaluating credentials in a rapidly changing field. AI security remains young enough that job descriptions and skills frameworks are still evolving, making it difficult for organizations to determine whether a candidate genuinely understands the risks associated with AI systems.
The timing is significant.
McKinsey’s 2025 global AI survey found that 88% of respondents reported regular AI use in at least one business function, while most organizations remained in the process of moving beyond experimentation and pilots. The same research found that 62% were at least experimenting with AI agents.
As deployment expands, the attack surface expands with it.
AI applications frequently connect models to enterprise databases, internal applications, APIs and external tools. An AI agent with permission to perform actions can therefore create a different security problem from a chatbot that only generates text. The consequences of a compromised or poorly governed system can extend into business processes rather than remaining confined to a model’s output.
That is where SecAI+’s emphasis on risk management and governance becomes particularly relevant.
For enterprise security leaders, the value of an AI-focused certification is unlikely to be measured simply by how many employees earn the credential. The more important question is whether training translates into better security controls, clearer governance and faster identification of AI-specific threats.
CompTIA’s approach also reflects a broader shift in cybersecurity education. Certifications such as Security+, CySA+ and other established credentials have traditionally focused on general security disciplines. SecAI+ moves into a more specialized category in which AI, cybersecurity and responsible technology governance overlap.
The certification does not replace conventional cybersecurity expertise. Instead, it is designed as an additional layer for professionals who increasingly need to understand both.
That distinction is important for organizations building AI teams. An AI engineer may understand model architecture without knowing how to design a security monitoring strategy. A traditional security analyst may understand identity and network controls without understanding model behavior or AI-specific attack techniques. Enterprise AI programs increasingly need people who can bridge those disciplines.
There is also a competitive angle for technology employers.
As AI skills become more fragmented, standardized certifications can provide hiring teams with a common baseline for assessing candidates. The limitation is that certification alone cannot demonstrate real-world experience with an organization’s particular AI architecture, regulatory environment or threat model.
In practice, SecAI+ is therefore best viewed as one component of an enterprise AI security strategy rather than a substitute for hands-on expertise.
CompTIA says SecAI+ joins its portfolio of ANSI/ISO 17024-accredited certifications. Its accreditation could give the credential additional credibility as companies establish formal AI governance programs and begin defining AI security responsibilities across IT, cybersecurity, data and compliance teams.
The bigger trend is clear: AI adoption is creating a new layer of infrastructure that needs to be secured, governed and operated.
The next phase of enterprise AI will depend not only on larger models and faster chips, but also on whether organizations can build enough human expertise around them.
Market Landscape
AI security is emerging alongside the rapid expansion of enterprise AI, generative AI and agentic AI. The market is moving from isolated experimentation toward systems that connect models with corporate data, applications and automated actions.
That creates several workforce requirements: AI risk assessment, model security, identity and access controls, data protection, AI governance, threat detection and incident response.
Gartner has predicted that 33% of enterprise software applications will include agentic AI capabilities by 2028, compared with less than 1% in 2024. The firm has also warned that more than 40% of agentic AI projects could be canceled by the end of 2027 because of unclear business value, escalating costs or inadequate risk controls.
The result is likely to be greater demand for professionals who understand AI security throughout the technology lifecycle.
CompTIA is entering a market that includes vendor-specific security training from major cloud and cybersecurity providers, as well as broader AI certifications from universities, technology companies and professional organizations. Its vendor-neutral positioning could appeal to organizations operating mixed environments across Microsoft Azure, Amazon Web Services, Google Cloud and private infrastructure.
For enterprise buyers, the strongest certification programs will likely be those that complement practical experience rather than attempt to replace it.
Top Insights
- CompTIA SecAI+ earned ANAB accreditation, giving its AI-security certification independent validation as enterprises build specialized capabilities around AI risk and governance.
- AI security is becoming a distinct discipline, spanning model protection, AI-enabled threats, data security, governance and responsible deployment across enterprise technology environments.
- Enterprise AI adoption is accelerating, creating demand for professionals who can secure models, agents, APIs, data pipelines and AI-enabled business applications.
- Certification can standardize workforce assessment, giving employers a common competency baseline while practical experience remains essential for production AI security operations.
- Agentic AI raises the stakes, because systems capable of taking actions across enterprise applications require stronger controls around identity, permissions, monitoring and human oversight.
Power Tomorrow’s Intelligence — Build It with TechEdgeAI












