AI governance is becoming an operating profession rather than a policy-writing side activity. A dated review of 100 current, publicly readable vacancies found that employers are building a function around ownership, lifecycle decisions, risk, controls, evidence, monitoring and oversight. The roles do not sit in one department. They connect business teams, technology, data, risk, compliance, privacy, security, legal and independent assurance.
The largest primary role family in the sample was enterprise AI governance and Responsible AI operations, with 43 vacancies. The remaining 57 were divided across AI or model-risk governance, compliance and GRC operations, independent assurance and controls testing, and governance platforms that translate policy into traceable workflows. The practical conclusion is important: an AI Governance Manager needs to make a governance system work across organizational boundaries, not simply explain principles.
Research question
This study asked: What organizational role families, seniority levels and operating interfaces are visible in a dated sample of 100 current public AI-governance vacancies?
The question deliberately avoids estimating worldwide demand. Public vacancy data are volatile, unevenly distributed and shaped by what can be read without authentication. The objective was to identify the operating shape of the profession and the boundaries that professional learning should respect.
Method and screening
The unit of observation was one current, unique vacancy with material responsibility for enterprise AI governance, AI or model risk, AI compliance or GRC, independent AI assurance, or governance-platform operations where control evidence was central.
The complete research archive - the 12-page report, structured evidence workbook and accepted-vacancy dataset - is openly available at Zenodo DOI 10.5281/zenodo.22016868.
The final corpus contained 100 vacancies retrieved on 19 August 2026. Every accepted record retained an employer, title, location, region, public URL, retrieval date, seniority stratum and one mutually exclusive primary role-family code. Full vacancy bodies were not copied. Internal validation retained only a short evidence excerpt for eligibility review; the public data package contains derived metadata and URLs.
The recorded screening disposition was:
| Disposition | Records |
|---|---|
| Accepted current vacancies | 100 |
| Closed, expired, removed or unavailable by explicit status | 17 |
| Inaccessible or not independently verifiable | 23 |
| Total recorded records considered | 140 |
The 140 records are not a worldwide sampling frame. They are the recorded candidates reviewed for this research. Closed and inaccessible records were excluded rather than inferred.
Duplicate employer-title-jurisdiction-requisition combinations were removed. A multi-location requisition counted once. Employer or employer applicant-tracking pages were preferred where readable; current specialist or public job-board pages were retained when they exposed a distinct live vacancy and public application path.
The 100 accepted records represented 95 distinct employer-name strings. This count was not normalized to ultimate corporate groups.
Composition of the evidence base
The sample was geographically broad but North-America-weighted:
| Region | Vacancies | Share |
|---|---|---|
| North America | 67 | 67% |
| Continental Europe | 9 | 9% |
| UK and Ireland | 6 | 6% |
| APAC | 10 | 10% |
| Africa and MENA | 4 | 4% |
| Latin America | 4 | 4% |
Source concentration is another limitation:
| Source family | Vacancies | Share |
|---|---|---|
| Specialist job board | 56 | 56% |
| Employer or employer ATS | 31 | 31% |
| General public job board | 10 | 10% |
| Recruiter | 3 | 3% |
These distributions make the study useful for occupational discovery, but not for comparing regional market size or source-platform market share.
Finding 1: direct governance operations form the largest role family
Each accepted vacancy received one primary role-family code so that totals would reconcile to 100:
| Code | Primary role family | Vacancies | Share |
|---|---|---|---|
| G1 | Enterprise AI governance and Responsible AI operations | 43 | 43% |
| G2 | AI risk and model governance | 13 | 13% |
| G3 | AI compliance, legal and GRC operations | 16 | 16% |
| G4 | Independent assurance, audit and controls testing | 14 | 14% |
| G5 | Governance platforms and policy-to-control evidence | 14 | 14% |
G1 roles were the largest single family. Their public evidence described governance operating models, accountable ownership, policies, use-case intake, inventories, risk routing, lifecycle oversight, committees, monitoring and reporting. This is the centre of the profession: maintaining the process through which an organization decides what AI may be used, under what conditions, with which evidence and who remains accountable.
Yet G1 was not a majority of the whole sample. That matters because governance managers rarely own every substantive decision. They coordinate a system in which other functions retain distinct authority.
Finding 2: 57% of the sample sits at governance interfaces
The other 57 vacancies were not weaker versions of the same job. They represented four interfaces that an AI Governance Manager must understand without absorbing their professional mandates.
AI and model-risk roles emphasize challenge, classification, validation expectations, monitoring and risk reporting. Compliance, legal and GRC roles translate obligations and policies into review processes, documentation and escalation. Independent assurance roles test whether controls and evidence are credible. Governance-platform roles configure workflows, access, integrations, guardrails and traceability.
This division supports a federated operating model. Business and product owners define the intended outcome and remain accountable for use. Technical teams build or integrate systems. Data owners provide provenance, quality and permitted-use evidence. Risk, privacy, security, compliance and legal teams provide specialist review. Independent assurance tests claims. The governance function connects decisions and evidence without pretending to replace those owners.
Finding 3: the profession has several entry and ownership levels
The seniority mix was:
| Seniority stratum | Vacancies | Share |
|---|---|---|
| Executive | 23 | 23% |
| Manager, lead or principal | 41 | 41% |
| Specialist, analyst, consultant or engineer | 36 | 36% |
The manager, lead and principal stratum was the largest. This aligns with the coordinating nature of the function: the work requires enough authority to convene owners, challenge incomplete evidence, operate decision forums and escalate exceptions.
At the same time, 36 specialist and practitioner roles show viable contribution paths. These professionals may maintain inventories, run intake, document assessments, configure workflows, monitor controls, support assurance or prepare governance reporting. Twenty-three executive roles show that the function can also own enterprise standards, oversight and board-level accountability.
The role-family and seniority cross-tab reinforces the pattern:
| Family | Executive | Manager/lead/principal | Specialist/analyst/consultant/engineer | Total |
|---|---|---|---|---|
| G1 | 13 | 20 | 10 | 43 |
| G2 | 5 | 5 | 3 | 13 |
| G3 | 3 | 4 | 9 | 16 |
| G4 | 1 | 6 | 7 | 14 |
| G5 | 1 | 6 | 7 | 14 |
Direct governance operations appear at every level but are concentrated in management and executive strata. Compliance, assurance and platform families contain more practitioner roles in this sample. These are descriptive counts, not claims about career progression probabilities.
Finding 4: governance work must connect policy to evidence
The selected short evidence excerpts repeatedly referenced controls, risk, evidence, compliance, standards, monitoring, assurance, lifecycle work, documentation and reporting. Because each vacancy contributes only one short excerpt, those words cannot be converted into percentages of employers requiring a skill. They are discovery signals, not prevalence estimates.
The signals nevertheless point to a coherent operating challenge. A policy says what an organization expects. A control defines how that expectation affects a decision or activity. Evidence shows whether the control was performed, by whom, on what information and with what result. Oversight uses that evidence to decide whether a system can proceed, needs conditions, requires remediation or must stop.
A mature governance workflow therefore needs clear states: discovered, registered, scoped, classified, reviewed, approved with conditions, deployed, monitored, changed, suspended, retired and archived. The names may vary, but ambiguous status is a control failure because nobody can tell which evidence is current or which decision applies.
Finding 5: governance technology is part of the profession
Fourteen vacancies were primarily coded as governance-platform or policy-to-control roles. They described configured workflows, evidence capture, integrations, permissions, automation and technical guardrails.
This does not turn an AI Governance Manager into an AI engineer. It means the manager must understand how governance decisions are represented in systems. A workflow should preserve who submitted a use case, which version was reviewed, which owner approved it, what conditions apply, when monitoring is due and how exceptions are escalated.
Automation can reduce administrative effort, but it must not automate accountability. A risk-tier suggestion may help route a case, yet the accountable reviewer must see the basis, correct errors and record the final decision. A monitoring alert may prioritize investigation, but it cannot silently change an approved purpose or close an incident.
Finding 6: assurance is different from first-line operation
Fourteen vacancies were primarily assurance, audit or controls-testing roles, while another 13 focused on AI or model risk. Their presence protects an important boundary.
The team that operates a governance process can provide evidence that a review occurred. It cannot independently prove that its own controls are sufficient and effective. Risk functions may challenge classifications and monitoring thresholds. Validation teams may test models. Internal audit or external assurance may examine design and operation. Legal advisers may determine the meaning of a rule for a real organization.
Professional learning should therefore teach learners to prepare reviewable evidence and respond to challenge, not to declare their own system certified, compliant or audit-ready.
Finding 7: the operating model is cross-jurisdictional but law is not
The vacancies span several regions, industries and organizational contexts. That supports organization-neutral processes such as inventory, ownership, intake, decision rights, monitoring, incident handling and evidence management.
It does not support one universal legal checklist. Duties depend on jurisdiction, actor role, sector, system purpose and date. A governance record should therefore preserve applicability fields: jurisdiction, entity, system or use case, actor role, source, status, checked date, responsible reviewer and unresolved question.
The course that follows this research will provide general professional education. It will not classify a real system under law, reproduce protected standards or guarantee compliance, employment, certification or regulator acceptance.
Implications for professional learning
The evidence supports an applied operating-system outcome rather than a memory test. Learners should practice building distinct artifacts that connect across the AI lifecycle:
- governance charter and decision-rights map;
- AI-system inventory and ownership record;
- use-case intake and evidence request;
- risk-tiering and review-routing method;
- lifecycle decision-gate record;
- policy-to-control and evidence map;
- third-party AI due-diligence record;
- human-oversight and authority plan;
- monitoring, exception and incident workflow;
- assurance evidence pack and management dashboard.
The artifacts should culminate in an AI Governance Operations & Evidence Manual for a fictional or sanitized organization. Legal, technical, data, privacy, security, risk and assurance owners remain responsible for their specialist conclusions.
Limitations
This is a purposive, dated snapshot rather than a probability sample or worldwide census. North America represents 67% of accepted records. A specialist job board supplied 56%. Publicly inaccessible vacancies are absent, and vacancy status can change after retrieval.
One primary code simplifies multidisciplinary roles. Small regional cells are descriptive only. Employer-name counts were not normalized to corporate groups. The data contain no valid salary, market-size, growth-rate or causal evidence. Absence of a duty from the selected short excerpt does not establish that the employer omitted it.
The study identifies operating patterns. It does not provide legal advice, determine compliance, confer accreditation or guarantee employment.
Conclusion
The evidence shows AI governance taking shape as a cross-functional operating profession. The largest family owns enterprise governance processes, while risk, compliance, assurance and governance technology provide essential interfaces. Managerial roles are prominent, but specialist and executive pathways are both visible.
The practical task is to connect policy to decisions, controls, evidence, monitoring and accountable oversight across the AI lifecycle. Organizations need a governance system whose state can be understood and challenged, not a collection of principles that cannot be traced to action.