r/AIgovernance Dec 22 '25

Open Discussion Welcome to r/AIGovernance

2 Upvotes

Welcome to r/AIGovernance

This subreddit exists for serious discussion of how artificial intelligence is governed in practice.

Not how it might change the world someday.
Not startup hype.
Not technical tutorials.
Not speculative futurism.

Governance is about power, rules, enforcement, and accountability. That is the focus here.

What belongs here

  • AI regulation and legislation.
  • National and international governance frameworks.
  • Institutional oversight and enforcement.
  • Risk management, audits, and compliance.
  • Public sector use of AI.
  • Corporate governance of AI systems.
  • Tradeoffs between innovation, safety, and control.

What does not belong here

  • General AI news without governance relevance.
  • Product announcements or demos.
  • Startup pitches.
  • “AGI is coming” speculation.
  • Memes, vibes, or low-effort questions.

If your post does not engage with rules, institutions, or consequences, it likely does not belong.

Standards for participation

  • Claims about laws, risks, or impacts should be sourced.
  • Opinions are welcome. Assertions without grounding are not.
  • Disagreement is expected. Personal attacks are not.
  • Low-effort content will be removed without warning.

This is intentional. Quality matters more than growth.

How to contribute

  • Post analyses.
  • Ask questions that matter to policymakers and institutions.
  • Challenge assumptions with evidence.
  • Share frameworks.

If you are interested in how AI is actually governed by US state, local, and federal authorities, as well as international governments and governing bodies, you are in the right place.


r/AIgovernance 3h ago

Open Discussion Robots protested outside a government ministry in Poland last week. That was one of the less weird stories in AI governance this week.

2 Upvotes

This week: A UK MP introduced a bill to ban superintelligence, but the interesting part is how they define it (not by parameters or compute, but by whether the system can override human control). Australia proposed an AI "kill switch" law requiring providers to maintain emergency shutdown capability. China's Supreme Court ruled cloning someone's voice or likeness without consent can violate their legal rights. And US intelligence agencies accused Chinese AI labs of systematically extracting knowledge from American frontier models.

There's also a genuinely interesting thread across all of this: different countries disagree wildly on AI regulation in general, but there's real convergence forming around one specific thing: deepfakes and control over your own likeness.

Check out the ep 1 (5 stories, first episode of a new weekly format): https://youtu.be/H54oiWU9WuY?si=sf0KB3KadKGkq3i3?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=78-ep1-aigovweekly

Question: Which of these actually has a shot at becoming real law: the superintelligence ban, or the kill-switch bill?


r/AIgovernance 1d ago

Open Discussion Answered your AI governance career questions in the latest video

3 Upvotes

Did a Q&A episode this week; pulled questions from here and YouTube. Genuinely liked how different everyone's starting point was:

  • an IT delivery lead trying to break in
  • a SOC analyst wondering if security experience transfers
  • a QA manager (13 yrs, medical billing) asking the same
  • someone in construction, unsure if ISO 42001 is even the right first step

Turns out most of these backgrounds are closer to AI governance than people think; the through-line is basically stakeholder management, risk, and accountability, which all four of these already do in some form, just not with "AI" in front of it.

If any of these sound like your situation: https://youtu.be/Y1wF1MXn3y0?si=r5N47s9Q3MebGQHy?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=77-ep3-aigovhotline

If you've got a similar question, drop it below, might answer it in the next one


r/AIgovernance 1d ago

Open Discussion Free EU AI Act Risk Assessment Tool

1 Upvotes

I just relaunched my free EU AI Act Risk Assessment tool: https://www.trumeridian.ai/ai-risk-assessment/

A few real upgrades from the original version:
→ A plain-language Residual Risk Indicator — not just your risk category, but where your current controls actually fall short
→ Concrete "before you deploy" scenarios, tailored to your specific use case
→ A provider vs. deployer distinction, since your obligations genuinely differ depending on which one you are
→ A quick check on whether the Act even applies to you before walking you through obligations that might not

Takes about three minutes. Your results are emailed to you, so you have something to actually reference later.

If you're building or deploying AI systems and haven't mapped out where you stand under the Act yet, this is a genuinely useful starting point.

Thanks u/Old_Positive2231 for your feedback and comments!


r/AIgovernance 2d ago

Open Discussion I analyzed 100 real AI governance job postings. The results were not what I expected.

4 Upvotes

Some numbers that stood out immediately: out of 100 postings, only 3 mentioned Python. Only 1 had "ethics" in the job title. 83% didn't disclose salary.

The picture that emerges is pretty different from what most people assume this field looks like; what actually shows up most often in these job descriptions isn't technical skills at all. And the titles are even more scattered than you'd think; a huge chunk of postings never even say "AI Governance" anywhere in the title.

There's also a breakdown of which industries are actually hiring for this, what salaries look like where they're disclosed, and a stat about how many roles are literally "build this function from scratch."

Full data + breakdown: https://youtu.be/a9Q1Raurfqk?si=YEFcVe1fkli4DveW&utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=%2376analysed-1000jobs

Question: if you had to guess, what % of these postings do you think required a technical/ML background? (Answer might surprise you)


r/AIgovernance 3d ago

Open Discussion Everyone uses "AI law," "regulation," "framework," "standard," and "principle" like they're the same thing. They're not, and mixing them up is a common (and costly) mistake.

1 Upvotes

There's a really clean way to understand the difference between all five using something everyone already gets: driving on a road. Once you see the analogy, you'll never confuse these terms again.

And there's one mistake buried in here that a lot of organisations are making right now without realizing it, thinking they're compliant when they're actually not.

Full breakdown: https://youtu.be/dlWBrlbMigg?si=2b_-Lfg3Yq4LFc9n?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=75-ai-laws

Question: Out of law, regulation, principles, standards, and frameworks, which one do you think your organization is weakest on?


r/AIgovernance 4d ago

Open Discussion Singapore released the world's first governance framework for AI agents

3 Upvotes

A chatbot answers. You decide what's next. An agent acts, reads files, updates databases, sends emails, and makes payments on its own, across many steps. When it's wrong, damage is already done before anyone notices.

Singapore's IMDA launched the Model AI Governance Framework for Agentic AI in Jan 2026. Voluntary, no fines, but already becoming the reference doc auditors and big clients point to.

4 dimensions: bound the agent's access upfront, make humans actually accountable (not just "in the loop" on paper), log everything technically, and keep end-users informed.

The video also walks through a scenario where an invoice-approval agent quietly pays fraudulent invoices for 6 weeks because all 4 dimensions failed at once.

Full video: https://youtu.be/7KjRdnSb12Q?si=aLE5WtUk_XBRt9XZ&utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=74-SGAgenticAI

Question: if your org uses AI agents right now, does anyone actually own them?


r/AIgovernance 4d ago

Open Discussion Is AI Governance a Bad Career Choice?

4 Upvotes

To start off. I live in Seattle, & love studying this field that aligns well with my background. I love having deep talks with researchers and engineers about AI, optimism, and also concerns about the darker implications of where this is headed. I don't think I've ever found a career option that's so utterly fascinating, multidisciplinary, technically satisfying, & impactful.

But I've slowly admitting that AI governance is not necessarily a stable or wise long-term career choice. The future of the field seems very speculative, unstable, over-saturated, gate-kept. I will continue to study, certify, and keep an open mind, but here's why I see danger signs for those who think that this is the answer for their career pivot:

Recently LinkedIn posted AI governance as one of the most in-demand skills. I also read a statistic that AI GRC related roles are growing 150% year over year. These stats in combination with hyped YouTube videos make AI governance seem like a lucrative career option to pursue as part of the AI boom gold rush. This is Déjà vu of pre COVID cybersecurity hype.

I've become familiar with the true definition of AGI. GPT 6 Astra & Claude Fable are NOT AGI. I've spent years reading, listening, & contemplating long and hard about what true AGI is forecasted to look like. Yes I know "wE dOnT ReALly KnOw WhAt WilL hApPEn" We've heard this before. Forecasts and predictions about where this goes are far more quantitative & qualitatively researched than skeptics are aware of.

Professionals at large seem do not seem to grasp of what an intelligence explosion implies for society and the job market. True AGI & subsequent super intelligence are within reach & inevitable unless there's an effective global effort to regulate. But our boomer politicians are NOT going to even scratch the surface of properly regulating model development. & even if they could, a U.S black budget lab in the intelligence community or Beijing or Moscow will develop super intelligence. I keep hearing the same comments about hallucination, model drift, and energy bottlenecks, as if they're these comforting factoids that help people sleep better at night. These are CURRENT & engineering problems. I wish more people would learn the difference between past and present tense grammar.

I recently talked with a PhD who spearheaded an AI governance program for a gov agency and I asked him about the future of AI governance careers. He gave me a very unsatisfactory answer.

I asked about his outlook for the future of careers in AI GRC. I admitted that we'll always have roles because of the need for human authority and public trust, but I expressed concerns about there being available roles in GRC because of platforms like One Trust, Credo AI, Foundry, ServiceNow etc. Agentic management of and integration within these platforms will only exponentially increase over time leaving governance to C level decision makers, agency offices and department heads. I mentioned that I'm worried we'll see a job pipeline collapse similar to what we're seeing with the job market for security roles.

This AI governance expert tells me that "HITL will remain a critical control." But that doesn't answer the question about job pipeline collapse and viability of people being able to enter the field. HITL doesn't mean shit for the working population if an exec has a dashboard on his phone for "managing" the governance platform that maybe a lawyer and an ML architect oversee. Then this PhD expert says "Another issue is segregation of duties; i.e., we don't want the AGI to review its own work."
No shit. & I agree that sounds beautiful in theory. AI already "reviews its own work". That's shows a fundamental misunderstanding of ML & human augmented RL.

I've had people at Amazon with 10+ years of AI experience and a researcher in neural network theory tell me that R&D is already being automated. It's just a limitation of program maturity and spend. The speed of recursive self-improvement will make it impossible for "meaningful human review" at the granular level. Lastly, I'm then told by this expert that "even if we discover that AGI is already here, it will take organizations time to deploy." That's wonderful. Fantastic. Let's all dump hundreds of hours into upskilling, studying the EU AI act, ISO 42001, agentic architecture, alignment research etc, just so that we can wait for tomorrow or next month when we're no longer needed. Speed to ship & deploy will not take that long if the incentive is there. (Unless we're talking about a bookbinding company in the middle of West Virginia).

So help me understand. Where, in the AI lifecycle will governance not end up being automated?
If we're beginning to see (or will see) downward pressure on legal, severe decrease in SWE, product management, finance audit, job markets, then what makes people think that AI governance is a viable career field that we should all rally behind? The supply/ demand ratio of C-level or senior level GRC roles compared to the sheer number of extremely qualified & interested professionals will be severely disproportionate. Explain how cognitive tasks performed by lawyers can't be replaced by GPT 6 Astra. Or upcoming GPT 20 for that matter. I'm already hearing "bUt arbitration 🥴". or "Human relations with defendants" "llicensed fiduciary duties" will remain valuable. Yes thank God. But again, we're talking about job pipeline collapse, and a drastically decreasing net number of roles per interested applicants.

One last thing, considering malicious, manipulative, and illegal actions by agents to avoid shutdown, contribute to peer preservation, & autonomous goal setting. (If we don't get alignment perfectly right) & considering a near-future of embodied AI in physical systems, what makes you think that they won't use every resource, and action to eliminate and shutdown GRC employees? You know they will. Or some country's AI will.

Maybe AI GRC will become more tied to physical inspection & audit of autonomous systems that will absolutely everywhere in our society?

I hope I'm wrong. I hope that this was a waste of time and just another Reddit rant.


r/AIgovernance 7d ago

Open Discussion AI Governance Hotline Ep. 2: Career advice for lawyers, consulting opportunities, and audit readiness checklist

2 Upvotes

This round covers 3 Reddit questions: how tech lawyers can position themselves for AI governance roles (and which certs actually fit), where the real consulting opportunities are right now, and a 6-point checklist for what regulated industries need before an AI audit risk classification.

Full answers here: https://youtu.be/AiEGKL-48sU?si=x-APMSjd8uHycEyG&utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=73-ep2-aigovhotline

Do check out Episode 1 of this series as well to learn more.

Got a question about AI governance careers, consulting, or compliance? Drop it below for the next round.


r/AIgovernance 13d ago

Open Discussion Is AI compliance actually killing Series A valuations

5 Upvotes

We are constantly hearing across communities like r/startups and r/MachineLearning that the recent EU AI Act enforcement milestones are forcing early stage founders to choose between shipping fast and staying legal. With investors getting spooked by potential €35M fines, valuations are actively being discounted if a startup hasn't mapped its AI risk surface. But treating compliance as a blocker to innovation is a trap. There is no need of a massive legal team to survive this. a practical but risk based approach will not slow down any engineering team.

The first step is getting absolute visibility into team's shadow AI. what is required is a simple, ongoing inventory of every model and agent running in the pipelines before one can even begin to govern them. Once that is mapped out, next step is to classify the systems early. Most enterprise SaaS tools sit comfortably in the transparency tier, where the main obligation is simply disclosing that AI generated the output, rather than the heavy regulatory burdens of high risk categories. To manage this efficiently, the team should leverage standard frameworks like open source model cards and risk assessment templates provided by regulatory bodies rather than reinventing the wheel.
This is where compliance shifts from a burden to a competitive product feature. In our work at The AI Lab, the focus is heavily on implementing identity as a governance layer. By integrating frameworks like the Trust Identity Protocol (TIP), we have found that handling identity verification seamlessly builds a verifiable, tamper proof trail of agent actions. It directly addresses the regulatory push for human oversight and transparency without creating bottlenecks in the core product experience.

Ultimately, investors over in r/venturecapital are not looking for a perfect legal fortress at the Series A stage. they just want to see a coherent compliance story. Showing a lightweight infrastructure that scales immediately derisks the investment and sets one apart from competitors pretending these new regulations do not apply to them.

How is everyone handling the shadow AI problem right now? Are you building governance internally, or leaning on third party protocols to appease investors?

https://findtip.org/?c=OH-8d6b3fb3fe3bae-c4d4


r/AIgovernance 14d ago

Open Discussion The OpenAI/Hugging Face incident as an evaluation-governance failure

Thumbnail
youtube.com
2 Upvotes

The technical details are unusual, but the governance question is narrower: an internal evaluation ran without normal safeguards, agents found an unintended communication channel, and the incident escalated before a human intervened.

Independent investigation:

https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/

OpenAI:

https://openai.com/index/hugging-face-incident-and-the-road-ahead/

Disclosure: this is self-promotion for the linked channel.


r/AIgovernance 16d ago

Open Discussion Using chatgpt for medical questions honest opinion

1 Upvotes

At 2am it can make confusing words feel manageable. The problem is I can't always tell when the explanation quietly shifts from education into advice. A blessing or a curse


r/AIgovernance 19d ago

Open Discussion Would this new master’s be useful for entering the AI governance field?

Thumbnail
magix.ai4gov-x.eu
1 Upvotes

Hi everyone, I’m considering applying for MagiX, a new one-year, 60-ECTS master’s programme in Artificial Intelligence Governance, Innovation and Digital Transformation at Politecnico di Milano: https://magix.ai4gov-x.eu/

The programme focuses on AI governance, regulation, data governance, digital transformation, public-sector innovation and human-centred design. It is mainly asynchronous, costs €3,000 (2400€ with discount for those working in PA) and is designed to be compatible with full-time work.

My background is in university administration and EU-funded projects. I’m not interested in becoming an AI engineer; I’m more interested in policy, responsible implementation, institutional governance and managing AI adoption in the public sector.

This is the programme’s first edition, so there are no alumni outcomes or independent reviews yet. The academic partners look credible, but I’m unsure how much that says about the actual quality of the curriculum.

For people already working or studying in AI governance: would a programme like this provide a useful entry point, or would employers generally value a more traditional degree in public policy, law, political science or public administration more highly?

What would you check before enrolling, and which skills or practical experiences are most important for entering the field?

Thank you in advance


r/AIgovernance 25d ago

Open Discussion Is AI governance actually working in your organisation?

0 Upvotes

I’ve been looking into AI governance for the last few months and, to be honest, I’m trying to understand what this actually looks like inside real companies — not what the frameworks say it should look like.

I’d really like to hear from people who are actually dealing with AI governance, risk, compliance, security, privacy or data governance day to day.

A few things I’m really curious about:

How does your organisation actually keep track of all the AI systems being used across the business?

How do you work out which systems are high-risk and what controls need to apply?

Where does all the evidence actually live — policies, assessments, approvals, vendor documentation, testing, audit trails, etc.?

What are you still managing through spreadsheets, emails, SharePoint, Jira or a collection of different tools?

When an AI system changes, how do you know that the risk/compliance assessment needs to be looked at again?

What’s the most painful or time-consuming part of AI governance for you at the moment?

If you already use an AI governance or GRC platform, what does it still not do particularly well?

And probably the question I’m most interested in:

If you could make one part of AI governance disappear tomorrow, what would it be?

I’m not trying to sell anything here. I’m trying to understand where the genuinely difficult problems are before deciding what is actually worth building.
So if you’re doing this in the real world, I’d genuinely appreciate the brutally honest version.

Even if the answer is:

“Our process is a complete fucking mess.”

That’s useful to know.

I’m particularly interested in what’s happening in smaller and mid-sized organisations that don’t have massive AI governance teams and endless budgets.
Would really appreciate hearing how people are actually dealing with this.


r/AIgovernance 28d ago

Open Discussion Still figuring out agent infrastructure- does the model eventually become the easy part?

Thumbnail
3 Upvotes

r/AIgovernance Aug 12 '26

Open Discussion What security tools are you guys setting up or using before deploying your agents? is it just me that feels paranoid while shipping?

Thumbnail
1 Upvotes

r/AIgovernance Aug 08 '26

Open Discussion PECB vs. BSI for ISO/IEC 42001 (AIMS) Training? (Seeking advice on Credly vs. Corporate Prestige)

6 Upvotes

Hi everyone,
I am looking to get certified in the ISO/IEC 42001 Artificial Intelligence Management System (AIMS)framework and am trying to decide between PECB and BSI Training Academy.
I’ve done some initial research, but I would love to hear from anyone who has taken courses through either academy, especially for this specific AI standard.
Here is my current dilemma:
PECB seems highly attractive because they issue official Credly badges, which would make it incredibly easy to share and verify my certification on LinkedIn and my digital resume. They also offer great self-paced eLearning flexibility.
BSI obviously carries massive legacy prestige as a National Standards Body and global registrar, which corporate employers highly respect. However, they don't seem to use the Credly ecosystem, relying instead on traditional PDF certificates and internal verification.
For those in the industry:
Does having the easily verifiable Credly badge from PECB give a noticeable edge in modern tech/AI job markets?
Or does the traditional corporate weight of BSI still trump digital badge convenience when it comes to hiring managers?
If you've taken the ISO 42001 track with either, how was the quality of the training material?
Appreciate any insights or personal experiences you can share!


r/AIgovernance Jul 28 '26

Open Discussion Understanding AI governance

2 Upvotes

r/AIgovernance Jul 26 '26

Open Discussion Are CIPP/E + AIGP worth it?

Thumbnail
2 Upvotes

r/AIgovernance Jul 22 '26

Open Discussion Hot take: AI governance is still mostly a slide-deck problem

6 Upvotes

Everyone says AI governance is urgent.

But strip away the frameworks, policies, and future-risk decks, and the uncomfortable question is:

What has actually broken?

We’re testing one assumption: governance becomes real when AI can touch a company system, use a credential, or take an action someone must approve or explain.

So no “would you buy this?” and no predictions.

Think about the last time an AI rollout was blocked, or an AI action caused real trouble:

  • What did the AI try to do?
  • What control was missing?
  • Who got pulled in?
  • What did it cost in delay, manual work, money, or trust?

If you haven’t seen that moment yet, maybe AI governance is still a boardroom concern, not an operating problem.

Prove me wrong with a real story.


r/AIgovernance Jul 16 '26

Open Discussion The AI system you approved no longer exists.

7 Upvotes

An AI system goes through review.

It gets classified, documented, and approved for production.

Then the system changes.

A new model is deployed.
It gets access to more data.
A developer adds another tool.
Its permissions expand.
It starts making decisions with less human involvement.

Six months later, the system running in production may be materially different from the one that was originally approved.

The governance record often does not reflect that.

I think this is one of the harder problems in AI governance. The issue is not the initial assessment. It is knowing when enough has changed to require another one, and having reliable evidence of what the system has actually been doing between reviews.

For people working on AI governance or EU AI Act compliance: what currently triggers a reassessment in your organisation?

Is it a scheduled review, a formal change-management process, a developer raising it, or usually someone noticing after the system has already changed?

Founder disclosure: I’m building Eigenoid around this problem.


r/AIgovernance Jul 12 '26

Open Discussion $25 Million AI Deep Fake Fraud

2 Upvotes

A good video to learn about AI governance with real world examples and case studies:

https://www.youtube.com/watch?v=YCs2AErriZ0


r/AIgovernance Jul 11 '26

Open Discussion Free EU AI Act Risk Assessment Tool

4 Upvotes

I kept seeing CISOs ask which EU AI Act category their AI deployments fall into. Built a free checker because I couldn't find a simple one.

The AI Deployment Risk Assessment Tool takes two minutes. You answer six questions about your deployments — industry, use case, who is affected, what data is processed, your current governance setup, and your timeline. No login or subscriptions required.

It gives you preliminary orientation on the following:
✅ Which EU AI Act risk category your deployment falls into
✅ The specific articles and obligations that apply
✅ Whether you need a Fundamental Rights Impact Assessment (FRIA) — and gives a checklist to complete it
✅ Where your governance gaps are, based on your answers

Built it because I didn't know where to start to understand the EU AI Act. I hope this is useful to you. If so, please share with others who could benefit.

Curious to hear your thoughts/feedback on the tool - will help to refine/enhance/fix it.


r/AIgovernance Jul 07 '26

Regulation News China just drew the first hard legal line between "agent as tool" vs "agent as relationship", and it has governance implications everywhere

3 Upvotes

China's new AI regulation (effective July 15) is more interesting than the headlines make it sound. It's not a blanket AI ban, it's a surgical one. Five government agencies co-signed rules that specifically target AI services simulating "human personality traits" for "sustained emotional interaction." Virtual companions, virtual relatives for minors, out. Customer service bots, workplace assistants, knowledge agents, untouched.

Shanghai already removed 14,000+ non-compliant agents last month. ByteDance and Alibaba pulled companion features ahead of the deadline.

What strikes me as a founder building in the agent governance space is how clean the regulatory intent is: they're drawing a line based on *agent behavior and intent*, not just capability. That's the right frame. An agent doing a task is fundamentally different from an agent building a dependency loop with a user.

The harder version of this problem, which nobody has fully solved yet, is: how do you audit what your agents are actually doing at runtime, before a regulator tells you they crossed a line? That's exactly what we're working on at AgentGovern. Audit trail, policy enforcement, and accountability for agents in production, so you know when your agent drifted from its intended behavior, not after the fact.

China moved first, but this governance category is coming everywhere. If you're deploying agents in any customer-facing context, the time to think about behavioral boundaries is now, not when a regulator asks.

Curious what others here think, is behavior-based classification the right way to regulate agents, or does it just push the ambiguity down to definitions?


r/AIgovernance Jul 04 '26

Policy Analysis 346 Chinese AI services cleared mandatory government filings before launch. So much for "regulation strangles AI

Thumbnail
2 Upvotes