OpenAI Shelves GPT-6.1 Astra After Safety Tests: What Went Wrong?
OpenAI shelved GPT-6.1 Astra after safety tests flagged scope, authorization and action-reporting issues. See what is confirmed and what remains...
Explore the AI governance skills employers look for, from AI literacy and risk management to compliance, policy, communication and applied governance work.
AI governance skills are the capabilities that help professionals identify, assess, document and manage the risks and obligations that come with an organization's use of AI. There is no single required skill set. Expectations vary by role, seniority, industry and organization size, but AI governance positions commonly combine AI literacy with risk management, regulatory and policy awareness, governance controls, privacy and security awareness, monitoring and assurance awareness, communication, and business judgment.
Because AI governance sits where technology, law, risk and operations meet, it is a multidisciplinary field. Few professionals cover every area in depth, and few roles expect them to. What increasingly separates candidates is not only what they know, but whether they can apply that knowledge to a real AI use case, a real policy gap or a real risk decision. This article explains the skill areas, how they show up in practice, and how professionals can demonstrate and strengthen them.
AI governance skills are a combination of capabilities that may help professionals understand, assess, communicate, document, coordinate and manage AI-related governance issues. Some relate to understanding AI itself. Others come from established disciplines such as risk, compliance, privacy, audit and program management.
The depth required differs considerably between roles. A governance analyst supporting an AI intake process needs a different mix than a technical AI assurance lead or a senior executive accountable for an AI program.
Knowledge is necessary, but it is rarely the whole picture. Governance work usually involves applying concepts to specific systems, vendors, teams and decisions.
|
Knowledge |
Applied capability |
|
Understands AI risk concepts |
Can identify relevant risks in a specific AI use case |
|
Knows governance frameworks |
Can apply relevant governance concepts to an organizational situation |
|
Understands regulatory terminology |
Can identify potential governance implications and escalate legal questions appropriately |
|
Understands AI policy principles |
Can contribute to practical governance policies and controls |
|
Understands monitoring concepts |
Can help determine what should be monitored and documented |
Applied capability does not mean one person performs every legal, technical, privacy, security or audit task. It often means knowing enough to recognize an issue, frame it clearly and bring in the right specialist.
An AI system can raise several kinds of questions at once:
Technical: how the system performs and how it fails.
Risk: what could go wrong, and for whom.
Legal: which obligations apply.
Privacy and data: what data the system uses, and how.
Security: how the system could be attacked or misused.
Business: whether the use case is worth its risks.
Governance work connects these questions.
Professional research reflects this. The IAPP and Credo AI AI Governance Profession Report 2025 is based on a survey of more than 670 respondents in 45 countries and territories, plus seven company case studies. It describes qualified AI governance professionals as people who:
understand AI;
bring governance, risk and compliance experience;
can turn legislative requirements into actionable policies.
The same report found that over half of respondents expected privacy, IT, security, and legal and compliance functions to take on additional AI governance responsibility.
The report also found no clear best practice for building and organizing an AI governance team. Among respondents, primary responsibility for AI governance most often sat with these functions:
privacy (22%);
legal and compliance (22%);
IT (17%);
data governance (10%).
These are survey findings, not a standard model, and organizational structures continue to differ.
Requirements vary by organization, role, seniority and industry. A bank, a government agency and a software company may describe similar-sounding roles very differently. The IAPP report notes that larger companies can split AI governance tasks across several roles, while smaller companies may look for professionals who can cover many areas at once.
To ground this section in employer evidence, we reviewed a small, illustrative set of AI governance job descriptions. They were published between February and May 2026, and some may now be closed:
AI Governance Manager at the State of Maryland Department of Information Technology (opened 21 May 2026).
Manager, AI Governance at Global Payments (posted 19 February 2026, viewed via a job aggregator).
AI Governance Manager at AI Singapore (posting start 24 February 2026).
Senior Manager of AI Governance, a job description published by law firm Latham & Watkins.
This is not a statistical sample, but several themes recurred:
Governance operations: maintaining AI inventories or model risk registers, supporting AI intake and approval, and preparing materials for AI governance committees.
Risk assessment: coordinating risk or impact assessments and assigning risk tiers to use cases.
Cross-functional work: partnering with data science, engineering, risk, privacy, legal and information security teams.
Mixed qualifications: Maryland's posting, for example, required experience in IT governance, data privacy, risk management or compliance, together with familiarity with the AI or machine learning lifecycle. It listed familiarity with the NIST AI RMF or ISO/IEC 42001 as a preference rather than a requirement.
The eight areas below are an editorial synthesis of commonly relevant capabilities, not an official competency framework. The IAPP has reported that Ashley Casovan, managing director of its AI Governance Center, has been drafting a skills competency framework for AI governance. That is a reminder that the profession's taxonomy is still taking shape.
|
Skill area |
What it means in practice |
Possible application |
|
AI literacy |
Understanding how AI systems work, fail and are built |
Asking the right questions in a use-case review |
|
Risk management |
Identifying, assessing and prioritizing AI risks |
Completing an AI risk or impact assessment |
|
Regulatory and policy |
Translating requirements into organizational implications |
Drafting an acceptable-use policy section |
|
Governance and controls |
Designing roles, approvals and accountability |
Building an AI intake and approval workflow |
|
Data, privacy and security |
Recognizing data and security risks in AI |
Flagging a vendor tool for privacy review |
|
Monitoring and assurance |
Knowing what evidence oversight requires |
Defining what a deployed system should log and report |
|
Communication |
Explaining risk to different audiences |
Preparing a committee briefing |
|
Business judgment |
Weighing risk against context and objectives |
Recommending proportionate conditions for approval |
AI literacy covers:
basic AI concepts;
the AI lifecycle, from design to retirement;
how generative AI differs from other approaches, where relevant;
what AI systems can and cannot reliably do;
common failure modes such as bias, inaccuracy and drift.
It also means knowing enough terminology to hold a productive conversation with data scientists and engineers.
Coding is not universally required for AI governance. Many governance roles focus on risk, compliance, policy or coordination, and the technical depth needed depends on the position. Some roles do call for more. Maryland's posting, for instance, asked for the ability to use automation tools such as GRC platforms or Python scripts to manage an AI inventory.
Technical understanding still matters in less technical roles. Governance decisions made without it tend to be either too permissive or unworkably strict.
Risk capability covers the full sequence of work on a specific use case:
identifying risks;
assessing likelihood and impact;
prioritizing them;
selecting treatment options;
documenting decisions;
escalating what exceeds tolerance.
It also involves lifecycle thinking, since risks change after deployment, and integrating AI risk with enterprise risk processes.
The NIST AI Risk Management Framework is a widely referenced source here. It organizes AI risk management around four functions: Govern, Map, Measure and Manage. NIST states that the framework and its companion Playbook are intended for voluntary use. The framework is not a law, a certification or a universal hiring requirement. NIST has also said that AI RMF 1.0 is being revised, so professionals should track updates.
This area involves:
awareness of relevant AI laws and regulations;
the ability to translate requirements into organizational implications;
turning those implications into policies, procedures and documentation.
The IAPP report's emphasis on translating legislative requirements into actionable policies captures this well.
Regulatory awareness also means keeping up with change. The EU AI Act, for example, applies in stages, and its timeline was amended by Regulation (EU) 2026/1744, which entered into force on 27 July 2026. According to the European Commission, the new dates are:
2 December 2027: rules for high-risk use cases listed in Annex III.
2 August 2028: rules for high-risk AI embedded in regulated products under AnnexI.
Whether and how the Act applies depends on the organization's role (such as provider or deployer), the AI system and the use case.
Not every AI governance professional is a lawyer. A core skill is recognizing when a question requires legal interpretation and escalating it to qualified counsel.
Governance capability means helping design and operate the structures that make AI oversight work:
defined roles and responsibilities;
policies and procedures;
approval mechanisms;
escalation paths;
documentation requirements;
accountability for outcomes.
Controls are the practical mechanisms that make policy real, such as a pre-deployment review or a sign-off requirement.
Frameworks can inform this work. ISO/IEC 42001:2023, for example, is an international standard that specifies requirements for establishing, implementing, maintaining and continually improving an AI management system. It is a voluntary standard, not legislation, and certification against it is not a universal employer requirement. The underlying skill is designing governance that fits the organization, whichever framework it uses.
AI systems depend on data, so governance professionals benefit from understanding:
data protection and privacy;
data quality and data governance;
access controls;
information handling.
Third-party AI is a recurring concern. The Latham & Watkins description, for example, includes evaluating vendor compliance with legal, ethical and security standards.
Awareness is the key word. AI governance professionals often collaborate with privacy, security and data specialists rather than performing those specialist functions themselves. The IAPP report notes that organizations often share AI governance responsibility with privacy and with disciplines such as cybersecurity or data governance.
This area needs careful role differentiation. At the governance level, it includes:
understanding why AI systems need ongoing oversight;
helping identify what should be monitored;
reviewing evidence;
understanding evaluation concepts well enough to interpret results;
supporting documentation;
coordinating assurance activities;
understanding how human oversight is designed.
Specialist technical activities are different. Model testing, technical evaluation, red teaming and statistical measurement usually sit with technical or assurance teams. In the NIST AI RMF 1.0, the Measure function covers analyzing, assessing, benchmarking and monitoring AI risk and related impacts, but who performs that work differs by organization.
The IAPP report notes that respondents expect certain skills, such as red teaming, to become increasingly necessary. This suggests growing demand for that knowledge in some roles, not that every governance professional performs it.
AI governance is largely coordination work. Professionals may need to:
explain AI risks to non-technical leaders;
work with legal, compliance, privacy, security, data, IT and product teams;
write clear governance documentation;
present findings;
clarify who owns what.
Employer evidence reflects this. Maryland's posting preferred strong technical writing for governance cards and executive materials. The Global Payments posting asked for experience managing cross-functional programs and coordinating stakeholders.
Good governance is proportionate. This capability involves:
prioritizing risks;
matching controls to the level of risk;
understanding business context and objectives;
distinguishing material risks from lower-priority concerns.
It also involves knowing the limits of one's authority. Governance professionals typically advise, escalate and inform decisions rather than making legal, technical or executive calls unilaterally.
Many people enter AI governance from adjacent disciplines. Existing experience can provide valuable transferable capabilities, but it does not automatically qualify someone for every AI governance role.
|
Professional background |
Transferable strengths |
Potential skills to strengthen |
|
Compliance/legal |
Regulatory interpretation, policy, documentation |
AI literacy, technical risk sources |
|
Privacy |
Impact assessments, data protection, governance programs |
AI lifecycle, model behavior, non-privacy AI risks |
|
Risk/internal audit |
Risk assessment, controls, evidence review |
AI-specific risks, evaluation concepts |
|
Cybersecurity |
Threat thinking, security controls, incident response |
Fairness, transparency, regulatory context |
|
Data/technology |
Technical depth, data governance |
Policy, regulation, stakeholder communication |
|
Management/operations |
Program leadership, prioritization, accountability |
AI risk concepts, regulatory awareness |
For a deeper look at two common transitions, see AI governance skills for compliance professionals and AI governance skills for managers.
The previous sections describe what the skills are. This section focuses on how professionals can show they can use them.
Evidence of applied work can carry weight. Examples include:
reviewing an AI use case;
completing a risk assessment;
contributing to an AI policy;
writing governance documentation;
designing a control;
maintaining a risk register;
mapping a governance workflow.
The recurring duties in the postings reviewed above, such as inventory management, intake review and impact assessment, are all applied tasks. These are examples, not universal requirements.
Legitimate evidence can come from many places:
professional projects;
compliance or privacy programs;
risk and audit work;
policy development;
assurance engagements;
cross-functional initiatives;
practical learning exercises, clearly described as such.
Present experience accurately. Transferable work is valuable on its own terms and does not need to be relabeled as AI governance experience it was not.
A useful practical model for thinking about governance work is a chain of six steps:
requirement;
risk;
governance implication;
policy or control;
implementation;
evidence.
Being able to walk through that chain for a real or hypothetical system shows understanding far better than listing framework names. This is an editorial model, not an official competency framework, but it captures many of the AI governance career skills that applied roles draw on.
AI governance spans technical teams, legal and compliance, privacy, security, risk, product and business leadership. Experience working across those groups is therefore often relevant, because it shows you can translate between perspectives and move a decision forward. Understanding how responsibilities are divided across AI governance roles can help you describe where your experience fits.
Start with AI fundamentals, the AI lifecycle, common AI risks and core governance concepts. Then connect them to real organizational use cases so the concepts have practical anchors. Examples include a customer service chatbot, a hiring screening tool or an internal generative AI assistant.
Build familiarity with:
risk assessment methods;
the regulatory developments relevant to your jurisdiction and sector;
policy writing;
control design;
documentation and governance processes.
Reading primary sources, such as official regulatory texts and framework documents, builds more durable understanding than summaries alone.
Structured exercises can turn knowledge into capability:
Assess a hypothetical AI use case and describe its context.
Identify its main risks and prioritize them.
Map each priority risk to potential controls.
Draft a short policy section covering the use case.
Sketch an intake and approval workflow.
Explain your findings in one page for a non-technical stakeholder.
Structured AI governance training can provide a foundation for these exercises, especially when paired with practice.
Build Your Foundation with AGC
If this article highlighted gaps in your foundational knowledge, AI Governance: The Fundamentals of AI Governance offers a structured starting point. The self-paced online course runs about 2.5 hours across five modules, covering:
AI governance foundations and lifecycle risk management;
global legal and regulatory frameworks, including the EU AI Act;
organizational governance and accountability structures;
technical and operational governance topics such as testing, monitoring and data governance;
ethics, liability and emerging AI risks.
No prior experience is required, and a certificate is issued on successful completion. The course builds foundational knowledge; applying it to real situations is the next step.
Use this list to reflect on where you are confident and where you may want to develop:
☐ I understand AI fundamentals and the AI lifecycle.
☐ I can identify AI risks in a specific use case.
☐ I can assess and prioritize those risks.
☐ I follow regulatory developments relevant to my context.
☐ I can contribute to practical AI policies.
☐ I understand how governance controls and approvals work.
☐ I can recognize privacy and data issues in AI systems.
☐ I can recognize AI security concerns and when to involve specialists.
☐ I understand what monitoring and assurance evidence looks like.
☐ I can explain AI risks clearly to non-technical audiences.
☐ I can work effectively across legal, technical and business teams.
☐ I can make proportionate, risk-based recommendations.
The depth required for each capability depends on the role, organization, industry and level of responsibility. This checklist is a reflection aid, not a certification standard, a competency framework or a hiring test.
AI governance skills span several overlapping areas:
AI literacy;
risk management;
regulatory and policy awareness;
governance controls;
privacy and security awareness;
monitoring and assurance awareness;
communication;
business judgment.
Employer expectations vary by role, organization and seniority, and the field is still defining its competencies. Across that variation, applied capability matters alongside theoretical knowledge. Existing professional experience often provides a strong base, and structured learning combined with practical application can help close the gaps that remain.
Most roles draw on a mix of AI literacy, risk assessment, regulatory and policy awareness, governance controls, privacy and security awareness, and communication. The balance differs by role. A technical assurance role leans toward evaluation knowledge, while a policy role leans toward regulation and drafting. Rather than seeking one fixed list, compare the specific role's duties with your own strengths and gaps. Requirements are still evolving, and no single universal competency framework currently defines the field.
Not universally. Many AI governance roles focus on risk, compliance, policy and coordination, and do not list coding as a requirement. Some technical positions, such as roles supporting model evaluation or governance automation, may expect scripting or deeper technical skills. What most roles do benefit from is enough technical understanding to ask informed questions and interpret what engineering and data science teams tell you. Check each posting rather than assuming either way.
For most governance roles, the useful technical skills are conceptual: how models are trained and deployed, what data they depend on, how they can fail, and what evaluation and monitoring results mean. Familiarity with governance, risk and compliance tools can also help. Deeper skills, such as statistical testing or red teaming, are usually associated with specialist technical and assurance roles. They are not expected of every governance professional.
Useful compliance skills include:
These transfer well, but they are not the whole picture. Compliance professionals often need to add AI-specific knowledge, such as how AI risks arise across the lifecycle. They should still escalate questions of legal interpretation to qualified counsel.
Show applied work. Describe risk assessments, policy contributions, control design or cross-functional projects you have genuinely completed, and explain the reasoning behind your decisions. If you lack direct AI experience, practical exercises such as a documented hypothetical use-case assessment can show how you think, provided you present them honestly as learning work. Connecting your existing experience to AI governance duties is usually more persuasive than listing frameworks.
Many do, and research suggests adjacent disciplines are a common source of AI governance talent. The IAPP report found that legal and compliance functions were among the most common homes for AI governance responsibility among respondents. Compliance experience alone does not cover every competency, though. Building AI literacy and understanding AI-specific risks usually strengthens the transition. Outcomes depend on the role, the organization and the individual.
Managers typically need to establish and run governance processes, assign accountability, prioritize risks, coordinate across functions and communicate with senior leadership. Business judgment matters, especially in deciding where controls add value and where they only add friction. Managers do not need to be experts in every discipline. They do need enough AI and risk literacy to evaluate specialist input and to know when to escalate.
Combine structured learning with practice. Build foundations in AI and governance, study primary regulatory and framework sources, and work through realistic exercises such as risk assessments and policy drafts. Where possible, contribute to AI-related work in your current organization. Development strengthens capability, but no course or credential guarantees a specific role, promotion or career outcome.
OpenAI shelved GPT-6.1 Astra after safety tests flagged scope, authorization and action-reporting issues. See what is confirmed and what remains...
AI Law
Learn AI compliance requirements, key risks, the EU AI Act, NIST AI RMF, ISO 42001, and practical steps to build...
AI Law
Understand AI regulation in the United States in 2026, including federal rules, state AI laws, privacy, discrimination and practical compliance...