Who should I follow to learn about AI Security?

    Updated September 13, 2026
    CONSENSUS
    Simon Willison

    Answer summary

    To learn about AI security, follow a mix of researchers, practitioners, and organizations pushing the boundaries of adversarial machine learning, LLM safety, and secure systems architecture, including experts like Dan Boneh, Nicholas Carlini, and Simon Willison, as well as organizations like OWASP and Google DeepMind.

    Your presence

    Sign in to check whether you are mentioned or cited in this prompt.

    Where each engine placed them

    #BrandChatGPTGemini logoGeminiAI ModeCopilot logoCopilotMention rateBrand Share of VoiceCiteRankCitabilitySentiment
    1SWSimon Willison - 6% -
    ChatGPTGeminiAI ModeCopilot
    Mention rate - Share of Voice 6%CiteRank - Citability Sentiment
    2SWSteve Wilson - 6% -
    ChatGPTGeminiAI ModeCopilot
    Mention rate - Share of Voice 6%CiteRank - Citability Sentiment
    3BSBruce Schneier - 6% -
    ChatGPTGeminiAI ModeCopilot
    Mention rate - Share of Voice 6%CiteRank - Citability Sentiment

    What the models searched first

    The sub-queries each engine actually searched before answering.

    Unlock the full picture

    The sub-queries each engine actually searched before answering.

    Your tracked entities

    Save a voice, brand or tool and see where it stands on this question.

    Full responses

    4 of 4 engines that answered. Full stored text as captured, with dashes shown as hyphens. Nothing is summarised.

    ChatGPT4,274 characters · September 13, 2026

    If you want to **actually learn AI Security**, rather than just follow generic “AI safety” news, I’d build your feed around a mix of **offensive security, LLM security, adversarial ML, agent security, and AI safety**. ### People I’d start with - **Simon Willison** - excellent for practical LLM security, prompt injection, data exfiltration, and understanding how AI systems fail in the real world. - **Brendan Dolan-Gavitt** - security researcher with a strong technical perspective on ML/AI security. - **Riley Goodside** - particularly useful for prompt injection and adversarial behavior in language models. - **Joseph Thacker** - practical application-security perspective on LLMs and AI applications. - **Gareth Edwards / AI Village** - useful for the offensive-security and red-team side of AI. - **Steve Wilson** - one of the people behind the OWASP LLM security work; especially worth following if you want security from an application/enterprise perspective. OWASP's current project covers LLM, agentic, data-security, and threat-intelligence initiatives. [Leadership & Contributors - OWASP Gen AI Security Project](https://genai.owasp.org/contributors/4/?utm_source=chatgpt.com) - **Ads Dawson** - particularly good if you're interested in **AI red teaming and offensive AI security**; he's the technical lead for OWASP's LLM security work. [Leadership & Contributors - OWASP Gen AI Security Project](https://genai.owasp.org/contributors/4/?utm_source=chatgpt.com) - **John Sotiropoulos** - worth following for **agentic AI security**, adversarial AI, and security standards. He co-leads OWASP's Agentic Security Initiative. [Leadership & Contributors - OWASP Gen AI Security Project](https://genai.owasp.org/contributors/2/?utm_source=chatgpt.com) - **Rachel James** - strong intersection of AI security engineering, governance, prompt injection, threat intelligence, and AI red teaming. [Leadership & Contributors - OWASP Gen AI Security Project](https://genai.owasp.org/contributors/2/?utm_source=chatgpt.com) - **Neel Nanda** - more on the AI-safety/interpretability side, but very useful for understanding *why* models behave the way they do. [People to follow in AI safety · AI Safety Guide](https://www.aisafetyguide.org/people?utm_source=chatgpt.com) ### Organizations/accounts I'd definitely follow - **OWASP GenAI Security Project** - probably the single best starting point for **practical LLM security**. - **MITRE ATLAS** - essential if you want to think like a security practitioner. It maps adversary tactics and techniques against AI systems, including generative and agentic AI. [MITRE ATLAS™](https://atlas.mitre.org/?utm_source=chatgpt.com) - **NIST** - for AI security standards, risk management, and adversarial-ML terminology. - **AI Village** - for offensive research and AI red teaming. - **Trail of Bits** - excellent security research, including AI/ML security. - **Google DeepMind Security / Research** - useful for research-level adversarial ML and model security. - **Anthropic's research/security teams** - particularly useful for frontier-model security and AI control, although I'd balance company-specific material with independent researchers. ### If your goal is cybersecurity specifically I'd prioritize these topics in roughly this order: 1. **Prompt injection** 2. **LLM application security** 3. **RAG security** 4. **Tool/agent security** 5. **Data poisoning & model poisoning** 6. **Adversarial machine learning** 7. **Model extraction / stealing** 8. **AI supply-chain security** 9. **AI red teaming** 10. **AI agents as an attack surface** MITRE ATLAS is particularly good for turning that list into an actual threat-modeling framework; its current matrix covers 178 techniques, 37 mitigations, and 68 case studies. [MITRE ATLAS™](https://atlas.mitre.org/?utm_source=chatgpt.com) **My “just give me 10 follows” list:** Simon Willison, Brendan Dolan-Gavitt, Riley Goodside, Joseph Thacker, Steve Wilson, Ads Dawson, John Sotiropoulos, Rachel James, Neel Nanda, and **MITRE ATLAS/OWASP GenAI Security**. If you tell me whether you're coming from **cybersecurity, software engineering, or AI/ML**, I can give you a much more targeted **AI Security learning path (people → courses → GitHub repos → labs → books)**.

    Copilot4,744 characters · September 13, 2026

    **To learn about AI Security, follow a mix of technical researchers, cybersecurity leaders, and governance experts - this ensures you get both practical defenses and long-term safety perspectives.** ## 🔑 Key Experts in AI Security Category| Who to Follow| Why They Matter ---|---|--- **Core AI Safety & Alignment**| **Paul Christiano (Alignment Research Center)**| Leading voice on AI alignment and long-term safety risks.[AI Security Speakers | Concise AC](https://infosec-conferences.com/thought-leaders-speakers/) | **Sheila McIlraith (University of Toronto / Vector Institute)**| Researches interpretability, planning, and trustworthy AI.[AI Security Speakers | Concise AC](https://infosec-conferences.com/thought-leaders-speakers/) | **Jeff Clune (UBC, ex-OpenAI)**| Focuses on AI robustness and interpretability.[AI Security Speakers | Concise AC](https://infosec-conferences.com/thought-leaders-speakers/) | **David Duvenaud (Vector Institute)**| Works on probabilistic modeling and AI safety.[AI Security Speakers | Concise AC](https://infosec-conferences.com/thought-leaders-speakers/) | **Gillian Hadfield (AI Governance)**| Bridges law, policy, and AI governance.[AI Security Speakers | Concise AC](https://infosec-conferences.com/thought-leaders-speakers/) **AI Security, Robustness & Privacy**| **Nicolas Papernot (Google Brain / Vector Institute)**| Known for adversarial robustness and privacy-preserving ML.[AI Security Speakers | Concise AC](https://infosec-conferences.com/thought-leaders-speakers/) | **Luka & Marin Ivezic (ISF, Applied Quantum AI)**| Focus on secure AI deployment in critical infrastructure.[AI Security Speakers | Concise AC](https://infosec-conferences.com/thought-leaders-speakers/) **Cybersecurity Leaders (AI \+ Security)**| **Bruce Schneier (Harvard, EFF)**| Cryptographer and public intellectual shaping AI \+ security debates.[Top Cybersecurity Leaders of 2026 | The Industry Leaders](https://www.theindustryleaders.org/leaders/top-25-cybersecurity-leaders-2026) | **Katie Moussouris (Luta Security)**| Pioneer in vulnerability disclosure and bug bounty programs.[Top Cybersecurity Leaders of 2026 | The Industry Leaders](https://www.theindustryleaders.org/leaders/top-25-cybersecurity-leaders-2026) | **Alex Stamos (Stanford, ex-Facebook CISO)**| Practical insights on AI-driven threats and enterprise defense.[Top Cybersecurity Leaders of 2026 | The Industry Leaders](https://www.theindustryleaders.org/leaders/top-25-cybersecurity-leaders-2026) **Influencers & Analysts**| **Keren Elazari (Tel Aviv University)**| Advocates ethical hacking as a defense against AI-driven threats.[Top 10: Cybersecurity Influencers | Cyber Magazine](https://cybermagazine.com/top10/top-10-cybersecurity-influencers) | **Matthew Rosenquist (Cybersecurity Insights)**| Translates AI-related risks into business strategy.[Top 10: Cybersecurity Influencers | Cyber Magazine](https://cybermagazine.com/top10/top-10-cybersecurity-influencers) | **Ross Haleliuk (Venture in Security)**| Analyzes AI security market trends and investment flows.[12 IT and security voices shaping the conversation in 2026](https://www.iru.com/blog/2026-it-security-voices) ## 📌 How to Build Your Feed * **On X (Twitter) & LinkedIn:** Follow researchers like Nicolas Papernot, Sheila McIlraith, and Paul Christiano for technical updates. * **For policy & governance:** Track Gillian Hadfield and Bruce Schneier for perspectives on regulation and systemic safety. * **For practical defenses:** Engage with Katie Moussouris, Alex Stamos, and Luka/Marin Ivezic for applied security strategies. * **For broader industry context:** Add voices like Keren Elazari and Ross Haleliuk, who connect technical risks to business and society. ## ⚠️ Risks & Considerations * **AI-generated attacks are evolving fast** (e.g., phishing at scale, adversarial inputs). Following robustness researchers like Papernot helps you stay ahead.[Top Cybersecurity Leaders of 2026 | The Industry Leaders](https://www.theindustryleaders.org/leaders/top-25-cybersecurity-leaders-2026) * **Governance is fragmented** - different countries are setting divergent AI security standards. Thought leaders like Gillian Hadfield and Bruce Schneier highlight these gaps.[AI Security Speakers | Concise AC](https://infosec-conferences.com/thought-leaders-speakers/) * **Hype vs. reality:** Many influencers oversimplify AI risks. Prioritize researchers with peer-reviewed work and practitioners with real-world deployment experience. 👉 Would you like me to create a **curated “starter list” with direct X and LinkedIn profiles** so you can follow them immediately? That way, you’ll have a ready-made feed of AI security voices.

    Gemini3,273 characters · September 13, 2026

    Learning AI security effectively means following researchers, practitioners, and organizations pushing the boundaries of adversarial machine learning, LLM safety, and secure systems architecture. The top experts, researchers, and organizations to follow span academia, industry research, and hands-on offensive/defensive security: ### Leading Researchers & Practitioners * **Dan Boneh:** Co-director of the Stanford Computer Security Lab and a pioneer in applied cryptography and AI security. His work and courses cover the core intersections of system security and machine learning vulnerabilities. [AI Security Course | Stanford Online](https://online.stanford.edu/courses/xacs134-ai-security#:~:text=Professor%20Boneh%20heads%20the%20applied%20cryptography%20group,the%202013%20Godel%20prize.%20In%202011%20Dr.) * **Nicholas Carlini:** A research scientist at Google DeepMind whose work focuses extensively on machine learning security, privacy, and adversarial examples (such as membership inference attacks and data extraction). * **Simon Willison:** An independent developer and researcher who is exceptionally vocal and thorough about tracking prompt injection, LLM security flaws, and agentic workflows in real time. His blog and social feeds are premier resources for practical day-to-day AI vulnerability tracking. * **Gadi Evron & The Secjuice / AI Security Community:** Excellent voices tracking enterprise risks and the changing threat landscape of operational AI. * **Harish Ramadoss:** Known for practical AI security implementations (building, breaking, and defending LLM pipelines, RAG systems, and MCP servers) and presenting research at major security conferences like Black Hat and DEF CON. [Best AI Security Certification Courses In 2026](https://www.modernsecurity.io/pages/blog?p=best-ai-security-certification-courses#:~:text=The%20instructor%2C%20Harish%20Ramadoss%2C%20has%20presented%20AI,Certification.%20Check%20Out%20AI%20Security%20Course%20Overview.) ### Key Organizations & Standards Groups * **OWASP (Open Worldwide Application Security Project) Top 10 for LLMs:** Follow the contributors and maintainers behind the OWASP LLM project. It is the gold standard baseline for understanding common vulnerabilities like prompt injection, insecure output handling, and training data poisoning. * **MITRE ATLAS:** Follow the team and updates around MITRE's Adversarial Threat Landscape for Artificial-Intelligence Systems. It serves as a living knowledge base of adversary tactics and techniques mapped to real-world AI systems. * **The Center for AI Safety (CAIS):** Focused on technical safety research, catastrophic risks, and systemic evaluations of frontier AI models. ### Platforms & Labs for Hands-On Learning If you want to transition from following thought leaders to actively practicing AI security, platforms like **TryHackMe** (which features dedicated AI security pathways), specialized programs from **Practical DevSecOps (CAISP)** , and academic tracks from institutions like **Stanford Online** provide structured labs covering prompt injection, model extraction, and RAG pipeline hardening. Who are you hoping to focus on - high-level policy and governance, or hands-on hacking and engineering defense?

    Google AI Mode2,741 characters · September 13, 2026

    Learning about **AI Security** requires looking at a mix of traditional cybersecurity veterans who focus on machine learning, applied researchers dealing with LLM vulnerabilities, and policy/safety organizations. The top experts, projects, and organizations to follow are categorized below by their focus area: 1\. Practical AppSec & LLM Vulnerabilities * * ** _Steve Wilson_ :** Leads the [OWASP Top 10 for Large Language Model Applications](https://owasp.org/www-project-top-10-for-large-language-model-applications) project. Following his work and the OWASP GenAI Security project gives you the definitive shared vocabulary for prompt injection, data poisoning, and agentic risks. [OWASP Top 10 for Large Language Model Applications](https://owasp.org/www-project-top-10-for-large-language-model-applications)[A Guide to Key Thinkers in AI Security - HRExaminer](https://www.hrexaminer.com/p/a-guide-to-key-thinkers-in-ai-security) * **HiddenLayer Research Team:** An enterprise AI protection firm whose security team regularly publishes real-world findings on adversarial machine learning, model theft, and runtime attacks against enterprise deployments. * 2\. Cybersecurity & Threat Landscape Realists * * * ** _Bruce Schneier_ :** A legendary cryptographer and security technologist who writes extensively on the intersection of AI, governance, and systemic digital risk via his blog, [_Schneier on Security_](https://www.schneier.com/). * * * **_Mikko Hyppönen_ :** Chief Research Officer at WithSecure, frequently shares pragmatic insights on how cybercriminals are weaponizing generative AI versus how defenders are adapting. * * * **_Graham Cluley_ :** Co-host of the award-winning _Smashing Security_ and _The AI Fix_ podcasts, excellent at breaking down real-world AI-driven scams and enterprise threats without heavy jargon. 3\. Frontier AI Labs & Alignment/Safety Research * * ** _Demis Hassabis_ & Google DeepMind:** DeepMind is widely regarded as a leader in frontier infrastructure security and biosecurity research. Following DeepMind’s safety publications offers a look at how top-tier labs manage dual-use risks. * **Anthropic & OpenAI Research Feeds:** Following core safety researchers and official lab communications from [Anthropic](https://www.anthropic.com/research) and [OpenAI](https://openai.com/research) provides direct access to the latest frontier model vulnerabilities, alignment breakthroughs, and red-teaming disclosures. * Would you prefer to focus more on **practical application security (securing code/APIs for LLMs)** or the **macro-level policy and existential risk** side of AI? Let me know and I can narrow down specific whitepapers or newsletters to start with.