So, there I was, start of the new year of 2026, fresh off of a win earning OSEP in November; next thing I know in late January something happens. Something that stops my OSCE3 progress in its tracks. Did you see it? How could you not?? The announcement was… everywhere! OffSec drops a new course like a fresh album, says, “pre-registration coming in March”…
Sooo….What to do? Do I try to power through my last 2 certs first? Or do I take on a side quest, with OffSec’s new offering? I should stay on course, right? It’s not like the course is going anywhere. AI is here to stay it seems, so, no issues there.

As I thought about this, I kept coming back to the fact that the AI era is such a new landscape. Not just in cyber, but in tech altogether. I haven’t been able to dive into something like this while it’s still new, and got that new smell, like the early days of Active Directory, cloud, containers, and all that. The decision was clear.
Welcome to OSAI! Where you learn to hack AI, and with the recommendation of bringing along your own agent, you’re not alone on the journey!
This is my (Aromak) post-OSAI-Hexxed-BitHeadz-blog… post. Where we’re still keeping things human… for now…!

Ahhhh, there it is… OSAI with my name on it.
Let’s get in it.
The following is, of course, just my opinion. The reviews are pouring in, and there are several blogs, posts etc. to read through, I would suggest checking out as many as you can to really get a sense of OffSec’s latest challenge.
Prerequisites
What should one have before tackling this course? Well, experience of course goes above and beyond. At MINIMUM, I would look at getting certs like OSCP and OSEP. Let’s not play, OSAI is a level 300 course, and still requires that hacker mindset.
Pros and cons of the course
Depending on your perspective, this section could be good, or not so good. Take a solid look at the syllabus>>> AI Cybersecurity Course & Certification | OffSec.
Understand what topics are here, for example, attack surfaces include cloud, modern AI technologies, etc. this means this is not just, point you directly at AI and hack away, it’s teaching how AI is used in the real world, and you still need to conquer that foundation before getting to the new content.
That was the pros, what about the cons? I believe any con to this course can be offset by realistic expectations.
- The course is too hard!
- Yes, it’s a level 300 course, probably a good idea to have some XP before dropping into this one.
- There’s too much fluff around the AI content!
- Yes, AI is being shoved into everything these days, and you just never know in what capacity you’ll come across it in the wild.
- The labs are BROKEN!
- OK, as someone who was in there day one, I agree it was a rocky start, but I applaud OffSec for getting it fixed for us. Were we Beta testers there for a bit? Yes, but the course was much better 30-60 days in.
- There’s only 4 challenge labs!
- True, it’s a new course, they’ll add more over time. In fact, they dropped a 5th lab while my course was active.
Now on the big one. The one big issue I had, was just learning about allowed AI usage for the exam fairly late in the game. This was a really hard concept for me to grasp. From the same vendor who will not allow sqlmap on OSCP, allows you to AI ninja this course.
This didn’t sit well with me… I mean, at first. Why would you have to feel like you require a subscription to AI services, or feel like you need a rock’n set up at home to get through the exam? But eventually, I realized that by having to use AI, meant having to test how to use it in an offensive capacity.
At the beginning of the course, I was creating my own tools and scripts, testing those in the labs, but uncertain how they would hold up on the exam. As the course got more advanced, I was feeling concerned that my tools could not keep up. To my surprise, this is actually where the journey got even better.
I have a 3090 GPU, which give me 24GB of VRAM. I started really putting to the test to build custom agents, specializing in specific areas of offensive security. While the deep dive was cool, I just wasn’t confident at the time it would have gotten me through the exam.
I opted to use Claude instead. Looking back on it now though, I think I would have been ok, however using Claude correctly and deploying some hardcore agents to do the dirty work for you was super beneficial.
The exam
The first rule of OffSec exam is that you dont talk about the OffSec exam! At least, the details at least. So here is a high level of how mine went…
This was a hard exam for me. Because it requires a manipulation of the hacker mindset. Meaning, passing off a lot of the steps that I would do to get intimately familiar with the target system, those are now in the hands of blazing fast agent. Not just on the exam, but for the whole course in general. Remember FFUFing parameters? Dirbusting endpoints? Encoding your own wordlists for SQLi or LFI testing? I love those steps! When I could truly see the charms and flaws of a target environment. Now, it’s different. I had to understand that I am the captain on the ship, and the agents are there doing the grunt work… much faster than I ever did lol.
At first, progress was good. Paced appropriately, I would call it. Eventually, 12 hours in, I’m at seventy points. SEVENTY POINTS! and this exam requires SEVENTY-FIVE points to pass. This means I am literally ONE flag away from having the required points to pass this bad boy!
But… I’m 12 hours in. I’m tired. Exhausted even. I bet some of you reading this know this exact feeling. So close to just, getting the points, just got for it, get that flag, go sleep, come back with a fresh mind, figure out if you’re going for those last points, or get a nice head start on your write up…
I should rest. I should rest, right? Do I step away? Try to Get some sleep? Could I sleep? Knowing my mind and being here before, I doubt I’d pass out anytime soon… so I decided to press on. And this exactly where my progress comes to a screeching halt.

The ol’ OffSec wall boss, blocking me from any progress. SIGH. Hours pass. I begin going in circles. The fatigue kicks in hard. “Just one more flag, and you can go sleep” is what my mind keeps telling me. More hours pass, nothing. A storm rolls through, I can hear the thunder and see lightning as rain starts hammering the windows, and I’m nervous about losing power. I take moment to laugh at my situation and pray to the weather gods to like, just chill. I can’t lose power right now! I guess it worked, the storm passed, I didn’t lose power.
FINALLY, with just only a few hours left on the exam timer, a breakthrough! This! This is what I needed! Sure enough, I jolly my way around the keyboard to the next flag, took a quick second to think about it.. Go FoR mOrE fLaGz?! hm, no. Rest. Must. Get. Rest! I end my exam, go rest, and wrap up the report.
Then comes the waiting game. I submitted my report on 8/23 and got my results on 8/30. I have seen others mention it taking shorter or longer, so, results may vary.

Thanks to OffSec for putting together another solid course! My favorite part of OSAI was the parts that were never even in the course material, which has been a repeating experience with these courses. The individual journey and research I went down to better understand the advantages and limitations of current Artificial Intelligence.
This is the new landscape; and we’re hacking at the speed of AI. Hexxed BitHeadz is looking to continue using AI in offensive security work and research. That’s it for now! Thanks for stopping by!

Until next time!
