The AI Security Gap Nobody’s Trained For
If you’ve spent any time in a SOC over the last two years, you’ve probably noticed the tools around you have quietly changed. Detection engines flag anomalies using machine learning models instead of static signatures. Analysts run prompts against internal copilots to triage alerts faster. And somewhere in the org chart, someone is now asking whether the AI vendor your company just signed with actually protects the data you feed it. That last question is the one most security teams aren’t fully equipped to answer yet, and it’s exactly the gap CompTIA built SecAI+ to close.
What Is CompTIA SecAI+ (CY0-001)?
SecAI+, exam code CY0-001, is CompTIA’s first certification built specifically for the intersection of artificial intelligence and cybersecurity. It launched in February 2026, and it isn’t asking you to become a data scientist. It’s asking you to do something more specific: understand how AI systems get attacked, how to defend them, and how to use AI defensively without introducing new risk in the process.
Why AI Security Skills Are in High Demand Right Now
Let’s start with why this matters right now. Recent industry research puts the number at 85% of enterprises that have already experienced some form of AI related security incident, whether that’s a data leak through a generative AI tool, a model manipulated through adversarial input, or sensitive data exposed somewhere in a training pipeline. At the same time, LinkedIn Workforce Insights data shows AI and machine learning security job postings grew 112% between 2022 and 2025, more than double the growth rate of cloud security and nearly four times the growth rate of SOC analyst roles. Governance and risk roles with an AI component grew 67% over the same stretch. The market isn’t waiting for certifications to catch up. It’s already hiring for skills most security professionals haven’t formally validated yet.
SecAI+ Exam Format and Domain Breakdown
The exam itself is a single test, up to 60 questions in 60 minutes, scored on the familiar 100-900 CompTIA scale with a 600 needed to pass. It’s organized into four domains, and the weighting tells you where to spend your study time. Basic AI Concepts Related to Cybersecurity covers about 17% of the exam and lays the conceptual foundation, model types, training methods, and the AI lifecycle. Securing AI Systems is the heaviest domain by far at 40%, covering threat modeling, adversarial attacks, guardrails, defensive architecture, and monitoring. AI Assisted Security makes up 24% and looks at how AI shows up inside the SOC itself, in threat hunting, automated pentesting, and fraud detection, along with how attackers are weaponizing the same tools. The remaining 19% is AI Governance, Risk, and Compliance, covering frameworks like the NIST AI RMF and the EU AI Act.
SecAI+ Prerequisites and Recommended Experience
There’s no hard prerequisite, but CompTIA recommends two plus years of hands-on security experience and familiarity with AI and machine learning concepts. If you’ve already got Security+ or an equivalent under your belt, you have the foundation this course builds on directly.
Who Should Get SecAI+ Certified?
Who is this actually for? If you’re a security analyst, SecAI+ gives you a framework for understanding how AI changes your threat landscape. If you’re an AI or ML engineer, it hands you the adversarial mindset and security vocabulary to build systems that don’t introduce new attack surfaces. SOC analysts get a way to evaluate the AI powered tools already showing up in their daily workflow, and risk and compliance professionals get the regulatory grounding they’re increasingly being asked to apply. It also maps to DoD 8570 and 8140 requirements, which matters if you’re anywhere near government or defense contracting.
Career Paths and Salary Impact After SecAI+
As for where it leads, SecAI+ slots naturally after Security+ in a career path, and it opens the door to more specialized roles: AI security architect, MLSecOps engineer, AI risk analyst, or AI governance specialist, several of which are currently commanding a 15 to 30% salary premium over comparable traditional security roles. From there, the next step for people moving into governance is often ISACA’s AAISM, and for senior leadership, CISSP and CISM are both folding AI specific content into their own bodies of knowledge.
Should You Get SecAI+ Certified Now?
None of this means every security professional needs to drop what they’re doing and specialize in AI tomorrow. But the data is telling a pretty clear story, the security professionals who understand AI, both as an attack surface and as a defensive tool, are going to be the ones organizations are actively searching for. Getting certified now doesn’t just validate what you know, it puts you ahead of a curve that’s moving faster than most of the industry expected.
Talk to you next week.

