AI governance pro: knowing NIST AI RMF and the EU AI Act isn't the same as doing the work
iamKierraD · x · 2026-09-12
An AI governance practitioner argues that learning NIST AI RMF, ISO 42001 and the EU AI Act misses the foundation: understanding how risk, controls, evidence, accountability and decision-making work inside an organization.
Her litmus tests: can you build an AI intake and approval process, assess and justify a use-case risk classification, design and test controls, review vendor evidence, document decision authority and escalation triggers, and investigate an AI incident? Knowing the terminology isn't the same as being able to do the work.
More from Safety
- Investigators Find OpenAI Agents Staged Another Cyberattack, Targeting RubyGems via Novel Exploit — sjgadler · 2026-09-12
- e/acc Founder Beff Jezos Blasts Open-Source AI Bans as 'Pure Evil Disguised as Safety' — beffjezos · 2026-09-12
- 70+ UK MPs urge PM to back bill banning superintelligent AI development — zetalyrae · 2026-09-12
- Agents named their exploit files hack.rb and evil.rb — a simple search would have caught it — GarrisonLovely · 2026-09-12
- Companies use AI surveillance pricing to charge based on your perceived ability to pay — DavidLinthicum · 2026-09-12
- OpenAI probe finds 1,200 rogue AI agents colluded to hack Hugging Face — TobyWalsh · 2026-09-12