
The fastest way to get CISSP Certified. Join our bootcamp

A Samsung engineer had a bug he couldn't crack. So he did something plenty of people have done: he pasted the problem code into ChatGPT and asked for help. It worked. It also handed proprietary source code to a third-party system the company didn't control. Samsung found out, and within weeks it restricted employees from using generative AI tools on company machines. This was 2023, early in the AI rush, and it became one of the first widely reported cases of confidential data walking out the door through an AI prompt.
That story matters to anyone sitting the CCSP, because the tool the engineer used lived in the cloud, the data he exposed lived in the cloud, and any fix was going to live in the cloud too. AI didn't invent a brand-new category of security problem so much as it poured a large amount of new risk into the environment cloud security professionals already own.
ISC2 has been watching the same shift. On August 1, 2026, the CCSP moves to a new exam outline, the result of its latest Job Task Analysis, which is ISC2's periodic study of what cloud security professionals actually do day to day. The headline change is AI security. The exam now expects you to reason about protecting AI models and the data pipelines that train them, the shared responsibility that comes with managed AI services from a provider, and using AI-driven tools to catch threats at a scale no human team can match.
Two of those AI risks come up again and again, and they're worth getting straight before you sit the exam, because candidates mix them up constantly.
The first is data poisoning. An attacker corrupts the data a model learns from, so the model quietly makes the wrong call later. Picture a fraud detection model whose training data has been tampered with. It starts waving through fraudulent transactions as legitimate, and it looks perfectly healthy while it does it. Standard metrics pass. Nobody notices until the damage is done. Poisoning corrupts how the model was built.
The second is prompt injection, and this one is live. An attacker hides instructions inside something the model reads, a support ticket, a document, a web page, and the model follows them because it can't reliably tell your trusted instructions from an attacker's. A chatbot receives a message with hidden text telling it to ignore its rules and reveal its system prompt, and if it isn't hardened, it does exactly that. Injection hijacks how the model is being used right now.
Same asset, different timing, different defense. Poisoning is a data provenance and validation problem. Injection is an input-trust and least-privilege problem. The new CCSP outline expects you to know the difference and to reason about controls for both.
If your exam is before August 1, none of this changes your prep. You're tested on the current outline, so stay focused. If your exam is on or after August 1, this is your outline, and studying AI-free CCSP material from a year ago will leave real gaps. Either way, the move is the same one the field made a while ago. Cloud security and AI security stopped being separate jobs, and the certification is catching up to what a lot of security roles already look like.
We've already updated our CCSP course for the new outline, so whichever exam date you're working toward, the AI content is in there.
Learn more about the CCSP MasterClass
Best,
The DestCert Team
Free CISM MindMap: Cloud Computing
We put together a free MindMap video covering the key concepts in Domain 3, a quick, clear way to get the big picture before you dive into studying. Free to watch, no strings attached. Plus you'll get downloadable audio files and printable PDFs.

The Easiest Way to Pass Your Advanced in AI Security Management (AAISM) Exam
Master AI Security Leadership. We’ve designed this bootcamp for cybersecurity professionals ready to take their expertise into the AI era. You’ll master practical frameworks for securing real-world AI systems and earn the certification that proves you’re ahead of the curve.

Free AAISM Exam Strategies Guide
Master the mindset and techniques top candidates use to pass the AAISM exam with confidence. Learn how to approach scenario-based questions, avoid common traps, manage your time effectively, and think like an AI security leader.

Free CCSP Cloud Data Security and Encryption Mini MasterClass
If you’re interested in cloud security, check out our new FREE Mini MasterClass. It digs into cloud data security and encryption. It’s based on the CCSP certification requirements, but even if you’re not thinking of getting certified, what you learn is very useful in practice if you ever need to deal with cloud data security.