Roles

Your First AI Governance Lead Should Ship an Inventory, Not a Policy

Your first AI governance hire is an operator, not a philosopher. In month one they produce a complete inventory of AI systems in use, a risk tier for each one under the EU AI Act's Annex III categories, and a lightweight review gate that a shipping team can pass in days. Hire someone who has sat inside an engineering org, not only advised one. Title it Lead or Manager, and place it between legal and the platform team.

The takeMost companies hire this role backwards. They recruit a policy specialist, get a beautiful principles document in week six, and discover in month four that nobody knows how many AI systems the company runs. The inventory is the hard part, because it requires walking into a product team's standup and asking uncomfortable questions about a vendor API someone wired in last spring. Hire the person who has done that walk. Policy drafting is a skill you can rent; the standing authority to ask a team what it shipped is a skill you have to place on the org chart.

Where Olive fits

Open a role and see what the work shows

Under the automated-decision rules, 'the model gave them a 74' is not an explanation. Olive produces no composite and no automated decision at all: a person writes every finding, each one carries the excerpt it rests on, and every released report exports with its rubric, scorer and bank versions attached.

Rank your shortlist

What Does an AI Governance Lead Actually Do in Month One?

They find out what you are running. Month one is an inventory: every model, vendor API, agent, and embedded feature across product, sales ops, HR and support, with an owner and a purpose written next to each. Then a risk tier per system, and a review path a team can clear in days. A policy document is month three, and it is the easy part.

The inventory is uncomfortable work, which is why it goes first and why it filters candidates. Start with the RevOps manager who put a resume-screening tool on a corporate card because recruiting was drowning and procurement was a six-week queue. It worked, which is the problem: it has been ranking applicants for three quarters, it decides which of them a human ever reads, and nobody outside that team knows it runs. Somebody has to sit down with that manager, and with the platform engineer who added a summarization endpoint to a support flow eighteen months ago, and get both written down without turning either conversation into an investigation. That is a temperament as much as a skill.

Risk tiering follows immediately, because the tier decides how much process each system deserves. The EU AI Act applies most of its high-risk requirements from 2 August 2026, with Article 6(1) classification obligations following on 2 August 2027 3. Anything touching employment, credit, education access or essential services sits in the categories that carry documentation, logging and human-oversight duties. Everything else can move through a two-page review. The corporate-card screener lands in the top tier the day it is written down, and finding it then rather than in a regulator's question is what the awkward conversation bought. Getting that split right in month one is what buys the rest of the year.

The third deliverable is the gate itself, and it has to be fast enough that engineers use it instead of routing around it. A good version is a short form, a named reviewer, and a service-level commitment measured in days. A bad version is a committee that meets fortnightly. If you hire someone whose instinct is the committee, you will spend year two dismantling their work.

Which Traits Separate a Real AI Governance Lead From a Performed One?

Dual literacy is the trait, and it is rarer than the resume volume suggests. The person can read Article 6 of the AI Act and can read a model card, and can tell you which fields of the second one satisfy which clause of the first. Performed expertise stops at the vocabulary: frameworks named, principles listed, no working knowledge of how the artifact is produced or by whom.

The tells are specific. Ask what an evaluation set for a deployed classifier should contain and who assembles it. A real candidate answers with a sampling argument and a name for the person on the hook. Ask how they would document a system built on a third-party model where the vendor will not share training data, which is precisely the position the corporate-card screener leaves you in. A real candidate talks about what can be evidenced at the deployment boundary: input logging, monitored drift, an escalation path, a supplier attestation with a date on it. A performed candidate says the vendor should be transparent.

Listen next to how they talk about engineers. Governance leads who have worked inside product teams describe the gate as a service with a latency budget. Ones who have only advised describe it as a control. The vocabulary difference is small and predicts almost everything about whether the program survives contact with a shipping deadline.

Then ask about a time they approved something they were uneasy about. The honest answer names the residual risk, the compensating control, and the review date they put on the calendar. A candidate who has never approved anything uneasy has never had the authority you are hiring for. The same test works for an AI compliance officer, where the failure mode is the mirror image: escalating everything until the escalation path is ignored.

And watch for someone who distinguishes between the governance the regulation requires and the governance the business needs. Those overlap by maybe half. A lead who cannot name the half your regulator does not care about will spend budget on the wrong things.

Which Backgrounds Produce Strong AI Governance Leads?

Four feeder paths produce most of the strong candidates: privacy program management, model risk management from a regulated bank, security GRC, and technical program management from a machine learning platform team. Each brings a piece. Privacy people know how to run an inventory and a DPIA. Model risk people know validation and challenge. Security GRC people know audits and controls testing. ML TPMs know how the systems are actually built.

The privacy path is the most common, and it transfers well because GDPR Article 30 records and a system inventory are the same discipline applied to a different object. The risk is that a privacy background makes the work document-shaped by default. Probe whether they have ever changed how a system was built, not only how it was described.

Model risk management out of banking is underrated and worth actively sourcing. SR 11-7 validation practice already contains most of what the AI Act asks for, and these candidates arrive with a working idea of independent challenge and of what a model inventory looks like when it has been maintained for a decade. What they often lack is speed, because the bank cadence is quarterly and yours is weekly.

The unexpected ones are worth naming. Clinical research coordinators and regulatory affairs specialists from medical devices carry deep instincts about evidence trails and about a product that cannot ship until the file is complete. Aviation safety and industrial process safety backgrounds bring hazard analysis, which maps onto AI risk assessment better than most ethics coursework does. And a strong internal candidate often already exists: the staff engineer who has been quietly writing the ML platform's review checklist for two years and would rather do it with a title and a budget.

How Do Strong AI Governance Candidates Use AI in Their Own Work?

They use it constantly and they distrust it precisely. The practice that produces a good governance lead is having spent a year using an assistant to draft control mappings, then catching it invent a clause reference, then building a habit of checking every citation against the source text. That habit is the job. Governance work fails on unverified specifics, and an assistant produces unverified specifics fluently.

Ask what they use it for and what they refuse to use it for. Useful answers cluster: drafting first-pass control mappings across two frameworks, summarizing a long vendor security questionnaire, generating the adversarial version of an argument they are about to make to a product team. The refusals are more informative. Strong candidates will not let a model write the risk classification itself, because the classification is the judgment they are paid for and because a wrong tier propagates silently through everything downstream.

The practice behind the skill is checking. A candidate who has genuinely worked this way will describe a specific method: pulling the actual regulation text into the context rather than trusting recall, keeping a note of which claims were verified and which were assumed, running the same question twice with different framings to see whether the answer moves. That is what fluency looks like in a discipline where a confident wrong answer is worse than no answer.

And they will have opinions about the tooling their own program uses, since a governance lead who is comfortable with AI will build a gate that runs on structured data rather than on a shared document. That instinct also matters for the neighbouring AI policy manager role, where the deliverable is language rather than a system but the verification problem is identical.

Where Do You Source an AI Governance Lead, and What Does the Role Pay?

Sourcing is easier than the title's novelty suggests, because the community is small and public. The IAPP's AI governance certification cohort, the Responsible AI community around ACM FAccT, ISACA's audit membership, and the model risk groups inside large banks are the four pools that actually contain people. Standards work is another: individuals who have participated in NIST AI Risk Management Framework working groups or ISO/IEC SC 42 committees have self-selected for exactly this job.

Pay is documented well enough to plan against, as long as you read the sources for what they are. One vendor's May 2026 salary study puts mid-career AI governance manager and lead base pay in US tier-one markets at $140,000 to $218,000, with the UK at roughly $100,000 to $170,000 and Germany at $85,000 to $145,000 1. Postings on an EU AI Act job board carrying published ranges cluster with a median advertised midpoint of $179,000 and a middle half of $171,000 to $285,000, though that board's sample includes engineering and senior counsel titles that pull the top end up 2. Neither is a public wage series, so read them against each other rather than either alone: as of mid-2026 that puts $150,000 to $220,000 base in range for a first non-executive governance hire, with a premium where the role also carries legal qualification.

On closing: this population moves for scope, not for compensation deltas, and the offer dies on ambiguity about authority. The questions a strong candidate asks are who the role reports to, whether it can block a launch, and whether there is budget for a tooling line rather than only headcount. The concrete form of that question is whether this role could require the RevOps manager to pause the screener while an evaluation set gets assembled, and who hears the appeal if the answer is no. Say the answer plainly in the process. A role reporting into legal with no engineering relationship reads to a good candidate as a role that will be overruled, and they will decline politely and take the other offer.

On location: the inventory phase is genuinely better in person, because it depends on hallway access to people who did not volunteer for a meeting. After that, the work is document and data work and travels fine. Most postings on that same board are hybrid at large employers 2; a fully remote first governance hire is workable if you commit to two on-site weeks up front and a standing seat in the platform team's planning ritual. The sourcing pools above also serve an AI security engineer search, and the two roles compete for some of the same GRC candidates.

Read the evidence

Common questions

How do I become an AI governance lead?

Start from a discipline that already runs an inventory and an evidence trail: privacy program management, model risk validation, security GRC, or ML platform program management. Add working technical fluency, meaning you can read a model card and an evaluation report without a translator. Then get a system into production under a documented review, even a small one, so you can describe a gate you built rather than a framework you read. Certifications from IAPP or ISACA help with resume screening and do not substitute for that. The candidates who get hired can name a decision they made and what evidence it rested on.

Should the AI governance lead report to legal or to engineering?

Either can work; reporting to legal alone rarely does. The role needs standing in both places, so the common structures that succeed are a report into a chief legal or risk officer with a dotted line and a permanent seat in engineering planning, or a report into a CTO or CAIO with legal sign-off authority defined in writing. What matters more than the box is whether the role can pause a launch. If it cannot, it becomes a documentation function and strong candidates will read that from the job description.

Do we need an AI governance lead before we deploy AI?

Not necessarily before the first deployment, but before the fifth. The threshold most companies hit is not a regulatory one, it is that nobody can answer what AI systems are in use and who owns them. If you cannot produce that list in an afternoon today, the hire is already late. Smaller companies often start with a fractional or consulting arrangement to build the inventory, then convert to headcount once the review gate needs a standing owner and a service-level commitment.

What titles should we search besides AI Governance Lead?

Head of AI Governance, AI Governance Manager, Responsible AI Lead, Head of AI Oversight, and AI Ethics Specialist all describe overlapping work. Job boards tracking EU AI Act compliance roles also show Compliance Analyst for AI Governance, AI Governance Specialist, AI Auditor and various counsel titles 2. Search on the deliverables rather than the title: model inventory, AI risk classification, ISO 42001, NIST AI RMF, and AI Act readiness will surface people whose current title is something else entirely.

What does the EU AI Act require, and when?

Prohibitions and AI literacy obligations applied from 2 February 2025, general-purpose model obligations from 2 August 2025, and most high-risk system requirements from 2 August 2026, with Article 6(1) classification rules following on 2 August 2027 3. Whether a specific system of yours is high-risk, and whether you are a provider or a deployer, changes the obligations substantially. Those determinations are legal ones with real penalties attached, so check with counsel rather than classifying from a summary.

How do I test a candidate's technical depth without a technical interview panel?

Give them an artifact and ask what is missing. A real model card, a vendor security questionnaire response, or an evaluation report from a system like yours works well. Strong candidates immediately name absent fields: no intended-use statement, no demographic breakdown of the evaluation set, no version pinning, no named owner. Weak candidates summarize what is there. The exercise takes twenty minutes, needs no engineer in the room to score, and separates people faster than any list of frameworks.

References

  1. 1. AI Governance Salary Report 2026 VerifyWise, 2026. verifywise.ai Mid-career AI governance manager and lead base ranges by market, as of May 2026: US tier one $140,000-$218,000, UK $100,000-$170,000, Germany $85,000-$145,000.
  2. 2. EU AI Act Jobs AI Governance Jobs, 2026. ai-governance-jobs.com Advertised ranges across EU AI Act compliance postings: median midpoint $179,000, middle half $171,000-$285,000; also the spread of titles used for this work.
  3. 3. EU AI Act Implementation Timeline Future of Life Institute, artificialintelligenceact.eu, 2026. artificialintelligenceact.eu Application dates: prohibitions 2 February 2025, GPAI obligations 2 August 2025, most high-risk requirements 2 August 2026, Article 6(1) 2 August 2027.

3 sources, numbered by first appearance. Every one was opened and checked against the claim it carries. How Olive sources claims

General guidance for hiring teams. What works at one company and one volume may not transfer to yours.

Olive assesses how a person works with AI. It does not detect AI-written documents, and it never produces a score, a ranking, or a match percentage for a person. Candidates read the same report the employer reads.

Back to answers

Open your first role Ten attempts a month against a live item bank, with a human-written report on every one.