AI compliance roles with no authority

Had two interviews this week where “AI compliance” was in the title, but the team had no risk register, no DPIA process, and assumed the EU AI Act won’t hit them until 2026. If you’ve been hired to stand up governance, what scope and budget did you secure up front so you weren’t the lone ethics person expected to bless models without process?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​‌‌‍‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‍​⁠​​​⁠​⁠​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍⁠​‌‌‍‍‌⁠​⁠​⁠​‌‌‍⁠​‌​‌⁠‌‌‍‍​‍⁠‌​⁠‌⁠‌‌‍‌​⁠‌‌‌‌‌‍‌⁠‌⁠‌​‍‍‌‌⁠⁠‌⁠​⁠​‍​‍‌⁠⁠‌

It’s tough to build a governance framework when you’ve got no risk register or DPIA in place. From my experience, securing budget for training and tools upfront helps back your efforts. Maybe consider reaching out to EU compliance experts early on; their insights could really strengthen your position.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​‌‌‍‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​‌​⁠‍​​⁠​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‍​⁠​​​⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌​⁠‌​‌‍‌‍‌‌‌‌‍​‌​‍​‌​⁠‍‌‌​​‌‍‌‍‌​⁠‌‌‍‌⁠​⁠​‍‌‍​⁠‌‌‍​​⁠‌‌​⁠‌‌‌​‌⁠​‍​‍‌⁠⁠‌