"AI certification" is a single phrase covering four unrelated things, which is why searching for it returns lists that agree on nothing. Before any of them is useful, it is worth separating what you are actually asking.
| What you mean | Where to go |
|---|---|
| "What exists, and which is for me?" | This page. |
| "Is any of this worth the money?" | Do AI certifications matter? — written against our own commercial interest. |
| "My organisation needs to govern AI." | AI governance and who owns AI risk. This is usually a process problem, not a credential problem. |
| "My staff need to use AI safely." | Training, not certification. See the last section. |
Our position, before anything else
AI Coalition Network sells AI certifications. That makes this page the one we would most like you to read as a funnel, so it is built not to be one: our programmes appear in the table below in the family they actually belong to, described in the same terms as everyone else's, and two of the other families outrank them for the purposes most people arrive with.
The four families
Every AI credential on the market sits in one of these. The differences that matter are who issues it and what happens if you misuse it — not the syllabus.
| Family | Examples | What it actually signals | Can it be revoked? | |
|---|---|---|---|---|
| A | Independent professional body | IAPP AIGP; ISACA AAIA, AAISM, AAIR | You passed an exam set by an organisation that did not train you, and you maintain it | Yes — membership and conduct rules apply |
| B | Platform vendor | AWS, Microsoft, Google Cloud | You can build on that company's stack | Yes, but rarely relevant |
| C | University | Postgraduate certificates, executive programmes | You completed assessed academic work | Effectively no |
| D | Seller-issued programme certificate | Training companies, online platforms, and us | You completed that seller's course | No |
Family D is the largest by volume and the weakest by signal, because the organisation setting the standard is the organisation taking the payment. Ours are family D. They are issued by us, no external body has endorsed them, and they carry no standing in any regulated profession. We say the same on the programme pages.
The thing the roundups leave out: the best ones are not entry points
This is the single most useful fact on this page, and it is missing from almost every "top AI certifications" list, because it disqualifies most readers from most of the list.
ISACA's AI credentials are stacked on credentials you must already hold.
- AAISM (Advanced in AI Security Management) requires an active CISM or CISSP.
- AAIA (Advanced in AI Audit) requires a CISA, or one of a defined set of audit and accountancy designations — CIA, US CPA, ACCA or FCCA, Canadian CPA, Australian CPA or FCPA, or the Japanese CPA designation — held in an IT audit or IT advisory role.
So if you are new to the field, these are not available to you, and no amount of study changes that this year. The prerequisite is the point: ISACA is certifying that an already-credentialled auditor or security manager has extended their practice to AI. The AI part is the smaller half.
The IAPP AIGP is the significant standalone exception. It has no prerequisite credential, which makes it the realistic entry point for governance work. It is a 100-question multiple-choice exam including case studies, the certification runs for two years, and renewal requires credits of further professional education plus a maintenance fee. That renewal requirement is worth noticing — a credential that expires is one whose issuer expects the field to move, which is a mark in its favour.
Start from the role
Read down the first column to yours. The third column is the honest answer, and for several roles it is "none".
| Role | What you actually need to be able to do | Credential worth considering |
|---|---|---|
| Executive or board member | Ask the questions that surface an unmanaged risk; know what you are accountable for and what you have delegated | None. Read who owns AI risk and hold one review meeting. A certificate would not help you. |
| Governance, risk or compliance lead | Run an inventory, an impact assessment and a review cycle; map obligations to controls | IAPP AIGP (family A, no prerequisite). The strongest single option for this role. |
| Internal auditor | Test whether stated AI controls are operating; evidence it | ISACA AAIA — if you already hold CISA or a listed accountancy designation. Otherwise get that first. |
| Security engineer or CISO | Threat-model model-specific attacks; control data flow into and out of AI systems | ISACA AAISM — if you hold CISM or CISSP. Start with prompt injection, which is the failure mode most teams meet first. |
| Data scientist or ML engineer | Build, evaluate and monitor models; know what your evaluation does not cover | Vendor track (family B) if you work on one platform. Otherwise published work beats any certificate. |
| Software engineer integrating AI | Handle non-determinism, cost, latency and failure; treat model output as untrusted input | Vendor track, narrowly. Most of this is learned by shipping. |
| Procurement or vendor manager | Tell a substantiated vendor claim from an unsubstantiated one; get the right terms in the contract | None specific. Use the vendor risk assessment — a checklist beats a certificate here. |
| Legal or privacy counsel | Track obligations across jurisdictions; advise on defensible process | IAPP AIGP, which sits naturally alongside privacy practice. |
| Everyone else using AI at work | Know what not to paste into it, and when to check its output | None. This is a training and policy problem. See below. |
What certification does not do
Three limits, all of which hold regardless of which family you buy from.
It does not satisfy a legal obligation. No AI statute we are aware of requires a named individual to hold a credential. Obligations attach to processes, documentation, notice and review. Texas frames an affirmative defence around discovering a violation through an internal review process substantially complying with NIST's Generative AI Profile — a free framework, pointed at a process rather than a person. If you are buying a certificate to reduce legal exposure, you are buying the wrong thing; see NIST AI RMF vs ISO/IEC 42001.
It does not demonstrate capability. Nearly all of these assess knowledge recall. The professions with genuinely load-bearing credentials add assessed work, supervised practice and an independent licensing body; AI has none of that infrastructure yet. This is covered properly in the honest assessment, including what it means for ours.
It does not make an organisation compliant. A certified individual inside an organisation with no inventory, no owner and no review cycle changes nothing measurable. The order that works is: know what systems you have, name who owns the risk, then decide whether that person needs a credential.
If what you actually need is staff training
A common and expensive confusion: an organisation decides it needs "AI certification" when the real need is that four hundred people are using chat tools with no guidance about client data.
Certification is a poor instrument for that. It is individually purchased, exam-shaped and optional, and the goal is uniform competent behaviour across everyone. What works instead is a short written policy stating what may and may not be put into which tools, a named person to ask, and one worked example per department. Human oversight that is more than a rubber stamp covers the review side of the same problem.
Buy certification for the individual who will own the governance work. Buy training for everyone else.
Where our own programmes fit
Family D, stated plainly. Our profession-specific programmes are structured courses ending in a certificate we issue ourselves. They are built for practitioners in a named profession who want the AI material organised in the order it matters for that profession, rather than a general syllabus they have to translate.
That is a real thing to want and a reasonable thing to buy. It is not a licence, not recognition by any external body, and not a substitute for the family A credentials above if your role is on that list. The test we would apply to any seller including ourselves: would you take the course if it issued no certificate at all? If yes, you are buying structured learning and that is a defensible purchase. If no, look harder at what the certificate signals.
What to do next
- Name the role. Not "we need AI skills" — which person, doing what.
- Check whether a credential exists for it at all. For four of the nine roles above, the answer is no.
- Check the prerequisites before the price. The two strongest AI credentials are closed to you unless you already hold a CISM, CISSP, CISA or an accountancy designation.
- Ask what happens if the holder is incompetent. If nothing, you are buying learning rather than assurance. Buy it for that.