Why This Course?
AI coding agents like Claude Code can read your codebase, run commands, and ship changes in minutes. For development teams this is a massive productivity gain. In regulated sectors such as healthcare, finance, and government, it also introduces a new category of risk: an agent that touches real data, real credentials, and real systems, in environments where the rules have teeth.
Most teams are already experimenting with AI-assisted development. This training shows how to do it in a way that keeps privacy, security, and compliance requirements intact, and how to demonstrate to auditors and regulators that they hold.
The approach is realistic and hands-on. You will see exactly what leaves your machine when an agent runs, where things go wrong in practice (data leakage, malicious dependencies, prompt injection), and how to build guardrails in three layers: advisory guidance the AI usually follows, good defaults committed to the repository, and machine-level rules that apply to everyone. The central idea of the day is to replace blind trust with verification and demonstrability.
The course is built by practitioners: a cybersecurity specialist with a background in hacking, incident response, and threat intelligence for multinationals and government organizations, and a former Meta Staff Engineer who led security and privacy initiatives affecting billions of users. Claude Code is used as the working example throughout, and the principles transfer directly to other AI coding agents.
The training can be delivered as an open course or as an in-company session, tuned to your sector’s regulatory context and, where possible, to your team’s actual codebase and workflows.
What You Will Learn
- What AI coding agents actually are, and what leaves your machine when they run
- Which account types and contractual terms determine what happens to your data (consumer vs. commercial terms, DPA, Zero Data Retention)
- How the permission model works, why the bypass flag is dangerous, and what a safer middle ground looks like
- The building blocks of modern coding agents (skills, subagents, MCP servers, and hooks) and which of them you can rely on for security
- How real incidents happen: data leakage from local files, hallucinated and typo-squatted dependencies, and indirect prompt injection through external content
- How to classify data before it enters an agent’s context
- The three boundaries to defend: ingestion, execution, and verification
- How regulations such as the GDPR and NIS2, and sector standards like NEN 7510/7513 for Dutch healthcare, apply to AI-assisted development
- Seven security principles your team can hold in their heads
- How to implement and verify layered guardrails, and how to answer the regulator’s question: “How do you verify that AI-assisted development is safe for sensitive data?”
Hands-on Practice
Participants are shown how to work with skills, subagents and hooks on their own setup. They are encouraged to actively look for misconfigurations around account types, stray .env files, database seeds and dumps, connected MCP servers, and risky habits. They classify real data from their own work, and leave with a concrete, committed baseline of guardrails, a verification checklist, and a 30/60/90-day roadmap to embed safe AI-assisted development in the organization.
Who Is This For?
Software engineers and development teams that use or plan to adopt AI coding agents in regulated sectors such as healthcare, finance, and government. The training is equally valuable for security teams, privacy officers, engineering managers, CTOs, and compliance and risk professionals who need to set policy for AI-assisted development.
No prior experience with AI coding agents or security is required.
For in-company sessions, the training can be adapted for mixed audiences including management, with a stronger focus on governance, accountability, and demonstrability toward regulators.
Certification
Certificate of Completion: Secure Software Development with AI in Regulated Environments, issued by Black Swan Training Center.
Requirements
- No prior experience with AI coding agents required
- Laptop with a modern browser; for hands-on editions, the ability to run a terminal application
- Basic familiarity with software development is useful, but not mandatory
- Technical curiosity
Looking for an in-company training? Get in touch
Course Features
- Duration 1 day
- Skill level All levels
- Language English (also available in Dutch)
- Certification No








