What One Year in AI Security and Governance Changed About How I See AI
After a year in AI security and governance, the author shifted from seeing AI as purely technical to recognizing it as a socio-technical system requiring robust governance and risk management.
Background
- The author spent a year working in **AI security and governance** (the policies, risk assessments, and technical guardrails that organizations put in place to safely deploy AI systems). This is a post reflecting on how that experience shifted their perspective.
- **AI governance** is a fast-growing field concerned with making AI systems transparent, accountable, and aligned with legal/ethical requirements (e.g., the EU AI Act, U.S. Executive Orders on AI). It sits at the intersection of engineering, legal, and compliance teams.
- The article's likely audience is tech workers who are either new to AI safety/security or skeptical that AI poses real risks. The author argues that hands-on governance work reveals subtleties that abstract debates miss.
- Prior context: In 2023–2024, major AI companies (OpenAI, Google, Anthropic) began creating dedicated governance teams, and "responsible AI" shifted from a niche concern to a mainstream corporate function. This post adds a practitioner's viewpoint to that conversation.