AI All-in-One series · Offensive testing

AI Red Teaming & Offensive AI Security All-in-One by Kai London

Every AI system you have shipped is already being tested — by users, by researchers, and by people who will not tell you what they found. This is the professional handbook for testing it yourself first, with a method that produces findings an engineering team can fix and a risk committee can read.

Available on Amazon.

What is inside

Scoping and rules of engagement

Defining objectives, boundaries and safety constraints before a single test is run.

Prompt injection, direct and indirect

How untrusted content reaches the model, and the difference between a clever prompt and a real control failure.

RAG and data-layer attacks

Retrieval poisoning, embedding abuse and boundary violations in the knowledge layer.

Agent and MCP exploitation

Tool abuse, permission escalation and chaining an agent's own capabilities against its owner.

Model-level testing

Evasion, extraction and jailbreak methodology — run as structured assessment rather than anecdote.

Reporting that drives fixes

Severity, reproducibility, control mapping and retest, so findings close instead of accumulating.

Who it is for: red teamers and penetration testers moving into AI, security engineers running internal assurance, and the CISOs commissioning the work. Intended for authorised testing of systems you own or have written permission to assess.

NIST AI RMFOWASP Top 10 for LLMsMITRE ATLASEU AI ActISO/IEC 42001

Find it yourself, on your terms, with a report someone can act on. The alternative is a disclosure you did not schedule.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.