Moving from privacy into AI governance
What carries over from a privacy career, what you will need to learn, and how to show an employer you can do the job before you have held the title.
Most people working in AI governance today started somewhere else, and privacy is the most common starting point. The two disciplines share a method: understand what a system does, work out who it could affect, decide what is proportionate and keep a record. If you have run impact assessments and advised product teams, you already do a version of the job.
This guide sets out what transfers, where the gaps usually are, and how to close them without leaving your current role.
What carries over
- Risk assessment. A data protection impact assessment and an AI impact assessment ask similar questions and suffer from the same failure, which is being completed too late to change anything.
- Working with engineers. Knowing how to get an accurate description of a system from the people who built it is the scarcest skill in both fields.
- Regulatory reading. You are used to principles-based law, regulator guidance and the judgement calls between them.
- Records and accountability. Inventories, registers and evidence of decisions are as central to AI governance as they are to privacy.
Where the gaps usually are
How models are built and tested
You do not need to train models, but you do need to follow a conversation about training data, evaluation sets, drift and error rates. Without that, it is hard to tell a real control from a reassuring sentence. A short applied machine learning course, plus time spent reading your own organisation’s model documentation, is enough to start.
Harms beyond personal data
Privacy trains you to look for effects on identifiable individuals. AI governance also covers systems that use no personal data at all, and harms such as unsafe output, unreliable performance for particular groups, or over-reliance by the people using the tool. Practise widening the question from “is this lawful processing?” to “what happens when this is wrong, and to whom?”
The frameworks
Employers most often name three: the EU AI Act, ISO/IEC 42001 and the NIST AI Risk Management Framework. You should be able to explain what each is for and how they differ. Our guide to responsible AI frameworks covers them in more detail.
Building evidence in your current role
Hiring managers consistently say they would rather see one real piece of work than a list of courses. Useful things to volunteer for:
- Add AI-specific questions to your existing impact assessment template and pilot them on a live project.
- Offer to build or tidy the inventory of AI systems. Most organisations do not have a complete one.
- Join, or help set up, the group that reviews new AI use cases.
- Write the staff guidance on using generative AI tools, and handle the questions that follow.
Each of these gives you something specific to describe at interview: what the problem was, what you did and what changed.
Is a certificate worth it?
The IAPP’s AIGP is the certificate you will see most often in job adverts, usually as desirable. It is a reasonable way to structure your learning and signals intent. It will not substitute for experience, and for a first move, a worked example from your own organisation carries more weight.
What the first role looks like
Entry points tend to be analyst and manager roles in a governance, risk or privacy team with AI added to the remit. Titles are inconsistent, so search by responsibility as well as by name. Combined privacy and AI governance roles are common and are often the easiest step, because you bring full competence in half of the job from the first day.
Looking for a first move? Browse current AI governance roles, or set up an alert to hear when new ones are posted.