D831

D831 Introduction to AI and Security help

The short answer

D831 Introduction to AI and Security is listed under banner number ITAS 2143 and is worth 2 competency units. It covers artificial intelligence terminology, its history and its limitations, the ethical questions it raises, and the practices for securing AI systems in professional environments. D831 and ITAS 2143 are one requirement. It is a short course with a demanding standard: precision about what these systems actually do, in a subject where imprecise language is everywhere.

D831 grading scale at WGU, how the work is graded, from WGU Tutors
How WGU grades D831, visualized by WGU Tutors.

Limitations are the content, not a caveat

The course description names limitations explicitly, and that is the signal for how to study it. Understanding what an AI system cannot do is more valuable than being able to describe what it can, because every security question that follows depends on it. A model trained on historical data reproduces what was in that data, including its gaps and its biases. A system that predicts does not explain. A system that appears confident is not thereby correct. Those three facts generate most of the risks the course examines.

Terminology needs the same precision it needs in every security subject. Artificial intelligence is a broad field, machine learning is a set of approaches within it, and a specific model architecture is narrower still. Using the broad term when you mean the narrow one makes an answer vague in a way evaluators notice, and it makes risk claims imprecise, because the risks attached to a statistical classifier are not identical to those attached to a generative system.

Securing AI has two directions and confusing them is a common error. One direction is using AI to improve security, such as anomaly detection over volumes no analyst could read. The other is securing the AI itself: protecting training data, preventing manipulation of inputs, controlling who can query a model and what they can extract from it, and managing what staff paste into external services. When a scenario mentions employees using an external assistant, that is the second direction.

Ethics is graded seriously here rather than treated as commentary. Automated decisions affect people, and questions about transparency, contestability, fairness across groups and human oversight are the substance rather than the framing. An answer that names a specific person who is affected and a specific harm is worth far more than a general statement about responsible use.

Work here returns Competent or Not Competent, since WGU issues no letter grades and holds no ordinary grade point average, while the 2 competency units simply size the course inside a flat-priced six month term. Two competency units make this a small course inside a flat-priced six month term, which makes it a good candidate for closing early while a larger course runs alongside.

Turning a short rubric into a dense plan

If your version of D831 uses a performance assessment, expect a compact rubric where each aspect carries proportionally more weight. WGU requires a score of 2 in each aspect for a task to pass and scores each aspect alone, so on a four or five aspect rubric a single thin answer is a large share of your exposure.

Budget carefully. Take a rubric with four scored aspects and a target near 1,300 words. Reserve 110 words for the organization and the AI use in question, and 90 for the close, leaving 1,100 across four aspects, or 275 each. Weight by demand: an aspect asking you to analyse risks and recommend practices deserves 370, an aspect asking for an ethical analysis deserves 330, and the two remaining descriptive aspects take 200 each. That totals 1,100.

On a short document, headings matter more than usual. Give every aspect its own heading even in a three page paper, because there is no room for an evaluator to hunt and no length for a buried answer to hide in.

Name the specific AI use before analysing anything. "The organization uses a machine learning model to flag unusual login behaviour" is a starting point that makes every later paragraph concrete. "The organization uses AI" is not, and everything written after it will be general.

Shape for an AI risk and practice analysis

D831 deliverables usually examine an AI use case and its security implications. These proportions fit a short document.

SectionContentShare
Use caseThe specific system, what it decides or produces, and who relies on its output.14 percent
Capability and limitsWhat the approach genuinely does and where it fails, stated concretely for this use.18 percent
Security risksRisks to the system and risks created by it, kept clearly separate from one another.22 percent
Data handlingWhat data trains or feeds it, where that data goes, and what leaves the organization.16 percent
Ethical analysisWho is affected, what harm is possible, and what oversight or recourse exists.17 percent
PracticesSpecific measures for this use, with the risk each one addresses.13 percent

Sourcing a field that moves faster than its literature

This is the hardest sourcing environment in the security curriculum, because the volume of commentary is enormous and much of it is promotional or already out of date. Prefer published guidance from standards bodies and national agencies on securing AI systems, which exists and is more specific than general commentary. Prefer primary documentation of a model or service for capability claims, dated, over articles describing it.

Treat vendor claims about capability as marketing until corroborated. A provider describing its own system as accurate or safe is making a commercial statement, and using it as evidence weakens an otherwise sound analysis. Where independent evaluation exists, cite that instead and note its method.

Currency is not optional here. Give the date of every source about a model, a service or a technique, because the field's practical facts change within months. A statement about what a system can or cannot do is a claim about a version at a moment, and writing it that way is accuracy rather than hedging.

There is one more discipline worth naming in a course about AI. If you use an AI tool while studying, it is a study aid, not a source, and its output is not evidence. Anything it tells you needs verification against a real source before it enters your submission, and work you cannot explain in your own words will not survive an explanatory aspect regardless of where it came from.

Apply whichever citation style the task specifies and cite at the point of claim. Where you make a risk claim, tie it to a mechanism rather than to a general worry, since a named mechanism is checkable and a general worry is not.

Competent analysis and returned work

Competent submissions are specific. A named use case, a concrete limitation, risks separated into risks to the system and risks from it, real data flows including what leaves the organization, and an ethical analysis with an actual affected person in it.

Returns follow four shapes. The document discusses AI in general and never names a system or a decision. Limitations are listed as generic caveats rather than applied. The two risk directions are mixed, so it is unclear whether a control protects the model or protects people from it. Or the ethical section is a paragraph asserting the importance of responsible use.

A quick test: count how many sentences in your draft would still be true if the organization changed industry entirely. If most of them would, the submission is a general essay and the applied aspects will score it accordingly.

Nothing is deducted when performance assessment work goes back for revision, so send it in the moment each aspect is genuinely addressed, rather than holding it back for another pass. If your section carries an objective assessment, WGU objective assessments are proctored and our boundary is absolute: preparation only, with terminology drills, practice questions and a candid read on your preassessment result. Sitting an assessment for you is not something we do, give no help from the moment it starts, and portal credentials are never requested or handled.

Writing about AI in general?

Send the D831 rubric and your scenario. We anchor it to one named use case and build risk, data and ethics sections with word targets.

Eight mistakes that cost time in D831

  • Never naming the use case. One specific system, one specific decision. Everything else follows from that sentence.
  • Using AI as a catch-all term. Say which approach you mean, because the risks differ between them.
  • Mixing the two risk directions. Risks to the system and risks created by the system need separate treatment.
  • Generic limitations. Apply the limitation to this use. A model that cannot explain its output matters differently in fraud flagging than in spam filtering.
  • Ignoring what leaves the organization. Data pasted into an external service has left. That is a data handling fact, not a theoretical one.
  • Vendor claims as evidence. Provider statements about their own accuracy or safety are commercial, not evaluative.
  • Undated sources. In this field a source without a date is a claim about an unknown version.
  • Ethics as a slogan. Name the affected person and the possible harm, then say what oversight exists.

Three questions students ask about D831

Do I need to build or train a model?
Not at this level. The course is oriented toward understanding what these systems do, where they fail and how to handle them responsibly. Your rubric is the authority on the exact deliverable, and technical model building belongs to dedicated courses elsewhere in the catalog.
Is 2 CUs enough time to cover a subject this big?
The course is deliberately introductory, and its scope is bounded to terminology, limitations, ethics and security practice. What makes it feel large is the volume of external commentary. Working from the course materials and published guidance rather than from general reading keeps it to its intended size.
What does ITAS 2143 refer to?
It is the banner number recorded for the course listed as D831 Introduction to AI and Security. There is one course and one requirement behind the two identifiers, both of which turn up in WGU records and in study groups.

Where D831 sits in WGU's programs

The July 2026 catalog places this code in 1 current WGU program. Open a program page for the complete standard path and term positions. The live Degree Plan remains authoritative after transfer credit, substitutions, and mentor planning.

The assessments, one by one

The public catalog does not publish this course's PA/OA identity or task count. WGU Tutors publishes at most one PA manual per course and only from a WGU-controlled public rubric. Until that source exists, PA help begins from the student's real Course of Study and OA support remains preparation only.

Keep going

Online now