AI governance pro: knowing NIST AI RMF and the EU AI Act isn't the same as doing the work

iamKierraD · x · 2026-09-12

An AI governance practitioner argues that learning NIST AI RMF, ISO 42001 and the EU AI Act misses the foundation: understanding how risk, controls, evidence, accountability and decision-making work inside an organization.

Her litmus tests: can you build an AI intake and approval process, assess and justify a use-case risk classification, design and test controls, review vendor evidence, document decision authority and escalation triggers, and investigate an AI incident? Knowing the terminology isn't the same as being able to do the work.

Original post →

More from Safety

Safety channel →