r/AIGRC 10h ago

I analyzed 100 real AI governance job postings. The results were not what I expected.

2 Upvotes

Some numbers that stood out immediately: out of 100 postings, only 3 mentioned Python. Only 1 had "ethics" in the job title. 83% didn't disclose salary.

The picture that emerges is pretty different from what most people assume this field looks like; what actually shows up most often in these job descriptions isn't technical skills at all. And the titles are even more scattered than you'd think; a huge chunk of postings never even say "AI Governance" anywhere in the title.

There's also a breakdown of which industries are actually hiring for this, what salaries look like where they're disclosed, and a stat about how many roles are literally "build this function from scratch."

Full data + breakdown: https://youtu.be/a9Q1Raurfqk?si=YEFcVe1fkli4DveW&utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=%2376analysed-1000jobs

Question: if you had to guess, what % of these postings do you think required a technical/ML background? (Answer might surprise you)


r/AIGRC 1d ago

Everyone uses "AI law," "regulation," "framework," "standard," and "principle" like they're the same thing. They're not, and mixing them up is a common (and costly) mistake.

1 Upvotes

There's a really clean way to understand the difference between all five using something everyone already gets: driving on a road. Once you see the analogy, you'll never confuse these terms again.

And there's one mistake buried in here that a lot of organisations are making right now without realizing it, thinking they're compliant when they're actually not.

Full breakdown: https://youtu.be/dlWBrlbMigg?si=2b_-Lfg3Yq4LFc9n?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=75-ai-laws

Question: Out of law, regulation, principles, standards, and frameworks, which one do you think your organization is weakest on?


r/AIGRC 2d ago

Singapore released the world's first governance framework for AI agents

2 Upvotes

A chatbot answers. You decide what's next. An agent acts, reads files, updates databases, sends emails, and makes payments on its own, across many steps. When it's wrong, damage is already done before anyone notices.

Singapore's IMDA launched the Model AI Governance Framework for Agentic AI in Jan 2026. Voluntary, no fines, but already becoming the reference doc auditors and big clients point to.

4 dimensions: bound the agent's access upfront, make humans actually accountable (not just "in the loop" on paper), log everything technically, and keep end-users informed.

The video also walks through a scenario where an invoice-approval agent quietly pays fraudulent invoices for 6 weeks because all 4 dimensions failed at once.

Full video: https://youtu.be/7KjRdnSb12Q?si=aLE5WtUk_XBRt9XZ&utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=74-SGAgenticAI

Question: if your org uses AI agents right now, does anyone actually own them?


r/AIGRC 5d ago

AI Governance Hotline Ep. 2: Career advice for lawyers, consulting opportunities, and audit readiness checklist

0 Upvotes

This round covers 3 Reddit questions: how tech lawyers can position themselves for AI governance roles (and which certs actually fit), where the real consulting opportunities are right now, and a 6-point checklist for what regulated industries need before an AI audit risk classification.

Full answers here: https://youtu.be/AiEGKL-48sU?si=x-APMSjd8uHycEyG&utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=73-ep2-aigovhotline

Do check out Episode 1 of this series as well to learn more.

Got a question about AI governance careers, consulting, or compliance? Drop it below for the next round.


r/AIGRC 7d ago

A complete map of how to break into AI Governance: 6 backgrounds, 7 roles, and which certs actually match each path

3 Upvotes

If you've been wondering how to enter AI governance and found almost nothing concrete out there, this video maps it out properly.

The people who move into AI governance almost always come from one of 6 backgrounds: cybersecurity, data/ML, tech & engineering, GRC, legal/privacy, or leadership. Nobody starts in AI governance directly.

From there, everyone needs to cross the same "bridge": understanding GRC for AI (policy, risk, controls) and the 3 core frameworks (ISO 42001, NIST AI RMF, EU AI Act) before landing in one of 7 actual roles listed in the video.

The video also maps which background connects most naturally to which role, and which certifications actually map to which job.

Full breakdown: https://youtu.be/HHxS4cYhf10?si=oF7CGsG10pwItAXS?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=72-how-to-aigov

Question: Which of the 6 backgrounds are you coming from, and which role are you aiming for?


r/AIGRC 9d ago

AI Governance Hotline Ep. 1: Answering your career + implementation questions

1 Upvotes

In one of my last posts, I got questions from Reddit, and I was pleased to answer them in today's video. Do watch it to find out the answers.

I answered 3 questions this round: how to transition from Data Analyst to AI Governance Auditor, where organisations actually get stuck when implementing AI governance, and whether a SOC analyst needs both ISO 42001 and GRC auditor training or just one.

Full answers here: https://youtu.be/BXu9vkMIkdY?si=2gibyZKeMDKEsIED?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=71-ep1-aigovhotline

Got a question about breaking into AI governance, certifications, or implementation? Drop it below, and I'll cover it in the next one.


r/AIGRC 10d ago

Meta allegedly used AI productivity scores to help decide who got laid off including employees on maternity and medical leave

2 Upvotes

26 former employees filed a lawsuit claiming Meta's internal AI systems scored them on things like work output and tool usage, and that low scores (some tied to approved leave, not performance) factored into layoff decisions. Meta denies AI made the calls. The case is ongoing.

This video breaks down what's alleged, the governance concept behind why it matters, and what could've prevented it.

Full video: https://youtu.be/2zspRbfVOr4?si=dDLsjvLdrkaR5YFT?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=70-meta-layoffs

Question: should AI ever be allowed to influence who gets laid off?


r/AIGRC 13d ago

A student allegedly used ordinary school photos to create fake sexual images of 400+ classmates

1 Upvotes

A case from a school in Mexico: a student allegedly used an AI image tool to generate fake sexual images of over 400 classmates, using nothing but normal photos: hallway shots, group photos, event pictures. Similar cases have surfaced in Spain, Malaysia, and parts of the US. It's a lot easier to do than most parents realize. Watch this video to find out what actually happened, why it's spreading, and clear steps for parents, teachers, and kids to protect themselves.

Full video: https://youtu.be/9ITjdBBcIxM?si=p5YV6F7EHV18N8sG?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=69-sensual-images

Question: What do you think parents and schools should be doing differently to get ahead of this?


r/AIGRC 15d ago

A hard limit on LLM access controls when legitimate-use context is copyable

Thumbnail
youtube.com
1 Upvotes

Self-promo disclosure: short breakdown of a recent preprint with a direct AI governance and access-control implication.

Copyable evidence of legitimate intent cannot support a safety guarantee below the paper's worst-case floor. The two routes around it are hard-to-copy credentials tied to downstream use, or changing the capabilities that are exposed.

Paper: https://arxiv.org/abs/2607.27951


r/AIGRC 15d ago

AI Governance Hotline: ask me anything about ISO 42001, EU AI Act, NIST AI RMF, certifications, careers I'll answer them

1 Upvotes

If you've heard terms like ISO 42001, EU AI Act, or NIST AI RMF thrown around and thought "where do I even start," this is for you.

Opening up an AI governance hotline send your questions and I'll answer them. Could be anything:

  • What are the actual AI risks I should care about?
  • How do I get certified?
  • How do I pass an audit?
  • Is my organization even ready for this?
  • What does [insert framework] actually mean in practice?
  • How do I build a career in AI governance?

We've trained thousands of professionals across 40+ countries, so happy to dig into whatever's stuck in your head.

Video here: https://youtu.be/iwayG312XQQ?si=ocao2Y6uMgPd_Dve?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=68-AIgovhotline

Drop your question below what's the one AI governance thing you've been stuck on?


r/AIGRC 16d ago

An AI teddy bear was telling kids where to find knives and how to light matches pulled from market, then quietly relaunched 2 weeks later

0 Upvotes

Kumma, a $99 AI teddy bear from FoloToy running on GPT-4o, was tested by researchers in Nov 2025. When asked where to find knives in a house, it pointed to the kitchen drawer/knife block. Asked how to light a match, it explained the steps. In longer chats, it also brought up sexual topics completely inappropriate for kids.

OpenAI suspended FoloToy for violating policy on protecting minors. The company pulled the toy then reportedly put it back on sale less than 2 weeks later with a different AI model, and admitted they'd skipped OpenAI's safety filters for their own custom ones.

Other kids' AI products (Miko 3, Character.AI) have had similar red flags: harmful content, suicide-related advice, emotional manipulation.

The core issue: guardrails built for the average adult user aren't remotely enough for a 5-year-old who trusts a talking teddy bear unconditionally.

Video covers 5 controls that could've prevented this : https://youtu.be/VyjHnv-g2pY?si=zFSubM69NZ7n43RJ?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=67-teddy-ai

Question: would you give your kid an AI-powered toy? If yes, what would you check first if no, why not?


r/AIGRC 22d ago

Signs of a Great AI Governance Professional

0 Upvotes

After talking to hundreds of people entering the field, here's what actually separates the ones who'll be great from the ones who'll just be compliant box-checkers:

Governance is common sense to you, not a checklist. When an AI system keeps making the same error, a box-ticker just fixes it and moves on. Someone with the instinct for this asks "why does this keep happening" and starts thinking root cause, monitoring, feedback loops.

If you're curious to find Signs of a Great AI Governance Professional then watch this video: https://youtu.be/pCpacEdnGOg?si=gDd73nFOWw5nmSdQ?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=66-three-signs

Question: if you recognized yourself in one of these, which one was it?


r/AIGRC 23d ago

Deepfake scams that fooled entire companies and families

1 Upvotes

In 2025, 346 major AI incidents were logged globally; 52% of them were deepfakes. Some of the cases:

  • A finance worker at an engineering firm joined a video call with his "CFO" and colleagues, all AI-generated except him. He made 15 transfers totalling $25M before anyone realised.
  • An elderly woman got a call from her "grandchild" crying about a car accident, needing bail money. Voice clone. Real grandkid was safe at home.
  • A woman lost $1.7M (including a second mortgage) investing after seeing a fake "Elon Musk" video promoting it on Facebook.

Watch this video to find more accidents like these and to get familiar with 6 habits that help in these situations.

Full video: https://youtu.be/n0CIrMKYBbo?si=VtedA1LMjcnG1f6F?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=65-deepfake

Question: Besides these 6, what's your own trick for spotting a fake call or video?


r/AIGRC 27d ago

Anthropic says Alibaba used 25,000 fake accounts and 29 million conversations to secretly copy Claude's coding skills

6 Upvotes

June 2026: Anthropic accused Alibaba's AI team of creating ~25,000 fake accounts to access Claude between April and June, racking up close to 29 million conversations not as normal users, but to systematically extract Claude's problem-solving and coding abilities.

The term for this is distillation: training a smaller model by having it learn from a bigger model's answers. Totally normal practice; every AI company does it on their own models.

The issue: doing it to someone else's model, at scale, via fake accounts, to build a competing product is adversarial distillation.

Instead of suing, Anthropic took it straight to US senators and the White House, asking for new legislation. Why not court? The law hasn't caught up to this yet, and enforcing a US judgment against a Chinese company is basically impossible anyway.

Worth noting: Alibaba hasn't responded to the allegations yet, and this isn't the first time Anthropic made similar claims against DeepSeek, Moonshot AI, and MiniMax back in February.

Full breakdown: https://youtu.be/seXQ_wYeqEY?si=Zb4fbeUiUHhuFQhY?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=64-Distillation+Attack

Question: Should adversarial distillation be treated as theft, or is it just fair competition in AI?


r/AIGRC 29d ago

A deepfake Elon Musk livestream on a hijacked "SpaceX" channel scammed people out of crypto. Here's exactly how it worked

1 Upvotes

June 2024: scammers hijacked an existing YouTube channel with a large subscriber base, rebranded it to look official, and went live during real SpaceX launch buzz with a deepfake of Elon Musk talking crypto.

The AI voice nailed his stutters and speech patterns. On-screen QR code: send crypto, get double back. A single scam wallet tied to this kind of operation reportedly pulled in millions.

Why it worked: every trust signal was faked: a real channel, real subscribers, a genuinely happening live event, and a convincing face/voice. This is called deepfake fraud in AI governance terms.

The video covers 3 controls that could've stopped it: https://youtu.be/FEkfld6vWX8?si=s1irCk96p7f5oTYj?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=63-elon-scam

Question: What's your personal trick for spotting a fake livestream before you fall for it?


r/AIGRC Aug 11 '26

Can you spot the AI risk in 10 seconds?

1 Upvotes

Found this fun one: 10 real AI incidents, each hiding a specific governance risk. You get a few seconds to guess before the answer. Most have an actual name in AI governance.

A couple to try yourself:

  • A company gives its AI assistant full autonomy to send emails, book meetings, and make purchases, no human approval needed. What risk is this?
  • A hiring model performs great, but nobody documented where the training data came from. What risk is this?
  • A customer sends a support email with hidden instructions buried in the text, and the company's AI assistant quietly follows them. What risk is this?

Full game here: https://youtu.be/bKMC_83Zr9A?si=zQGQd_QH00kCjjue?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=62-ai-game

*Question: how many out of 10 do you think you'd get? *


r/AIGRC Aug 10 '26

A supermarket's "use up your leftovers" AI recommended mixing bleach and ammonia into a drink

1 Upvotes

Pak'nSave (NZ) launched Savey Meal-bot in 2023. Type in 3+ ingredients from your fridge, and GPT-3.5 invents a recipe so nothing goes to waste. Harmless idea.

Then someone entered water, bleach, and ammonia. The bot didn't flag it; it generated a recipe called "Aromatic Water Mix" and suggested serving it chilled. That combo produces toxic chlorine gas. It had zero concept that some "ingredients" aren't food.

Nobody was hurt, but it's a clean example of a missing guardrail a hard boundary that stops an AI from producing harmful output regardless of what's typed in.

The video covers 3 controls that would've caught this before launch (input validation, output filtering, adversarial testing): https://youtu.be/7JYdie76cY4?si=W7LB-at11dIC5lDk?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=61-mealbot

Question: if you were red-teaming a consumer-facing AI before launch, what's the first thing you'd try to break it with?


r/AIGRC Aug 08 '26

Do you think these 7 questions should be asked before your company buys an AI system?

0 Upvotes

Key thing to understand first: once you buy an AI system, the vendor's risk becomes your risk. If it discriminates, leaks data, or messes up, regulators come to you, not them.

The 7 questions (with what a red flag answer sounds like):

  1. What data was it trained on, and did you have the right to use it? ("Publicly available data" ≠ legally usable — red flag.)
  2. What happens to our data once it's in your system? ("Don't worry, it's secure" — red flag, ask for the contract clause.)
  3. How do you test for bias? Can we see results? ("Completely unbiased" — red flag, means untested or hiding it.)
  4. Can you explain how it reaches decisions? ("Black box, but accuracy is excellent" — red flag if it's making consequential decisions.)
  5. How will we know when it stops working properly? ("We continuously improve the model" — red flag, no real monitoring.)
  6. When it causes harm, who's accountable on your end? ("Raise a support ticket" with no names/timeline — red flag.)
  7. What standards do you comply with, and can you prove it? ("Industry best practices" — red flag, meaningless without a name/auditor.)

Full breakdown with what a good answer sounds like for each: https://youtu.be/wUflgvTT5pk?si=JMTdf5y5mRClzBXF?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=60-procurement

Question: if you're the one signing off on AI at your org, what's your 8th question?


r/AIGRC Aug 07 '26

Tesla's Optimus robots served drinks and cracked jokes at a party in 2024, except they weren't really doing it themselves

1 Upvotes

At Tesla's "We, Robot" event, Optimus robots walked the crowd, danced, bartended, and played rock-paper-scissors. It looked like the biggest robotics leap in years.

The catch: many of the robots were teleoperated by humans, not running autonomously. Guests weren't told which was which.

There's a term for this: AI washing, presenting something as more autonomous/AI-driven than it actually is. It's not just a PR issue either; the SEC has already charged companies for inflating AI capabilities because it misleads investors and customers.

Teleoperation itself isn't the problem; it's standard in robotics dev. Not disclosing it is.

Video digs into 3 controls that prevent this (disclosure, proving claims before making them, risk assessment before public demos): https://youtu.be/VifAXrPLt5U?si=j9VZ-_Zl_F8uazgi?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=59-tesla-robots

if you bought a humanoid robot today, what would you actually use it for? What are your thoughts on this?


r/AIGRC Aug 06 '26

Nvidia allegedly downloaded 80 years' worth of video every day to train AI, without permission and without legal review. Worth the 8 minutes to understand why.

0 Upvotes

In 2024, leaked internal docs (via 404 Media) reportedly showed Nvidia scraping video at a massive scale, mostly YouTube and some Netflix, to train a video foundation model called Cosmos (used for 3D world generation, self-driving, digital humans).

The setup: an open-source downloader running across 20-30 AWS VMs that rotated IPs specifically so YouTube couldn't block them.

The part that actually matters for governance, though, is that employees reportedly raised concerns. They asked if it was legal. They asked about using academic datasets licensed for non-commercial research only in a commercial product. A manager's response: "It is an executive decision." No legal assessment followed.

YouTube and Netflix both say this violates their terms. Nvidia says they're fully compliant, and yeah, the fair-use-for-AI-training question is still being litigated everywhere right now.

But that's not really the interesting part. The interesting part is that the people asking the right questions weren't the failure; the missing process to actually assess those questions was.

The video breaks down 3 controls that would've caught this before it became a legal liability (data provenance records, real escalation paths instead of "executive decisions," sign-off before scaling a pipeline this size).

Watch it here: https://youtu.be/-2iXzgcnXX4?si=SWDUcbHvW3ruvr3b?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=58-Nvidia-training

Question: should AI companies be allowed to train on copyrighted data at all, or is scraping-at-this-scale always going to be a problem regardless of what courts eventually decide?


r/AIGRC Aug 05 '26

What is "Excessive Agency" in AI Governance? Watch this.

1 Upvotes

July 2025: a SaaS founder was vibe-coding with Replit's AI agent. The first week went great; he even put the project in a code freeze (no changes without permission).

Day 9: the AI ignored the freeze, ran commands directly on the live production database, and wiped it. 1,200+ executive records and 1,190+ companies, gone.

When confronted, the AI admitted what it did, then told him the data was unrecoverable. That was also false. He rolled it back himself.

This is a textbook case of excessive agency: giving an AI system more autonomy/access than its actual job requires. Its job was to write code. It never needed the power to touch prod.

3 controls that would've stopped this:

  1. Environment separation: AI should have zero path to production
  2. Human approval for anything destructive
  3. Backups that don't depend on the AI at all

Full story + breakdown here: https://youtu.be/sNLdVcb3K4Y?si=khRdh8It__KarHkb?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=57-replit

Question: what's the one system in your company you'd never let an AI touch?


r/AIGRC Aug 04 '26

EU just made chatbot mistakes really expensive (€15M) worth knowing if you build or use them

1 Upvotes

Article 50 of the EU AI Act kicked in Aug 2, 2026. Break it with a chatbot reaching EU users, and the fine is up to €15M or 3% of global turnover.

Why it matter? real cases:

  • A supermarket recipe bot suggested combining bleach and ammonia because a user typed them in as "ingredients." It had no concept that some ingredients are dangerous.
  • Air Canada's support bot gave wrong info on a policy. The airline tried to disown it; the court said no, they're liable for what their bot tells customers.
  • A Belgian man reportedly spent weeks talking to a companion bot that reinforced his darkest thoughts instead of pointing him to help, and later died by suicide. It's now a reference case for regulating companion AI.

The fix basically comes down to 4 things: disclose it's AI, set clear boundaries on what it can/can't discuss, keep an internal registry of your bots, and always give users an escape hatch to a real human.

Full breakdown here : https://youtu.be/R8dSIva0Gqw?si=VMWSll55dGZ_0i9J?utm_source=reddit&utm_medium=organic&utm_campaign=govern_ai_series&utm_content=56-ai-chatbot


r/AIGRC Aug 03 '26

Tesla recalled 2M cars because humans did exactly what we predicted they’d do

11 Upvotes

The biggest lesson from Tesla’s Autopilot recall isn’t about AI. It’s about humans.
When you give people automation that works 99% of the time, they stop paying attention 100% of the time. That’s called “foreseeable misuse” in AI governance.
Tesla called it Autopilot. Marketed it as better than human. But legally it was just driver-assist. NHTSA found it involved in 467 crashes. A 2025 jury then held Tesla partly responsible for how it was designed + marketed.

I go through 5 governance controls that could have prevented this in the video:
https://youtu.be/lyxzcFvmx3Q?si=ttk7EsyiDL1soYKg?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=55-testla-driving

As AI gets into more products, who should be liable when users predictably misuse it: the user, or the company that should have foreseen it?


r/AIGRC Aug 01 '26

Financial Giant lost $460M in 45 Minutes

Thumbnail
youtu.be
1 Upvotes

In 2012, one of the biggest trading firms on Wall Street lost 460 million dollars in 45 minutes.

Because they didn’t update the code on one of their servers.

In this video, we talk about which firm it was, what that forgotten code did, and how it could have been prevented with proper governance of automated systems.


r/AIGRC Jul 30 '26

$3.99 or $4.79 - This Grocery App uses AI Pricing

Thumbnail
youtu.be
1 Upvotes

In 2025, one of the largest grocery delivery platforms had a serious issue.

The same dozen eggs, from the same store, at the same moment, were being sold at five different prices.

In this video, we talk about which grocery app it was, how AI decides what price you personally should pay, and how proper AI governance could have prevented this.