Straight answers

Questions we get every week

AI governance is the internal system that decides how AI gets built and shipped — who approves a model, what testing it has to survive, who is accountable when it misbehaves. AI compliance is the narrower job of proving that system satisfies an external rule: a state statute, a customer contract, an auditor's request.

Governance is the machine. Compliance is the receipt. Companies routinely hire for the second when the problem is the first, which is how you end up with a compliance manager who has no authority to stop a launch.

It's the umbrella term for independent testing, attestation and ongoing verification of an AI system — proving it does what it should and does not do what it shouldn't, on a continuing basis rather than a one-time sign-off. It sits across governance, risk, compliance and security rather than belonging to any one of them alone.

Almost nobody in the US hires under that title yet. The work gets done by auditors, compliance managers, risk analysts and security engineers, each holding one slice of it — which is the gap this practice is built to translate.

Director-level scope generally runs $190K–$250K base, with executive scope reaching $250K–$400K and above. Median across the wider function sits near $169K.

One correction worth making early: the technical roles — ML security engineer, LLM security architect, red teamer — price against security engineering, not against compliance. Companies that band them as compliance roles do not get callbacks, and usually cannot work out why.

It depends entirely on why the role was created. Compliance-triggered hires normally sit under Legal, Risk, or the Chief Privacy Officer. Security-triggered hires sit under the CISO.

At AI vendors it is often neither — if the role exists to clear customer security reviews and unblock revenue, it belongs in go-to-market, and treating it as a compliance seat will cost you the candidates who are good at it.

Yes, for one specific reason: its extraterritorial reach. Any US company selling into or operating in the EU needs staff who understand its high-risk-system obligations, regardless of where that company is headquartered — a real driver of US-based compliance hiring, not a European issue happening somewhere else.

It is not, however, the primary driver in the US market. That is the state patchwork — Texas, California, Colorado — layered under enforcement from the FTC, SEC, DOJ, EEOC and FCC. A company with no EU exposure at all still faces real hiring pressure for this work.

You can. The constraint is reach: a post reaches the market segment that is actively looking. We take a different approach with focused engagement to professionals who are employed, stable, and not reading job posts in any given week. Building relationships with this audience is a different motion.

Another challenge is knowing what to post — whether you want a governance director, a privacy engineer or a red teamer, and whether the people doing this work call it the same thing.

Fair question, and we pressure-tested it before committing. Posting volume has held flat at roughly 71 net-new US roles a week through the first seven months of 2026 — no seasonal collapse, which is the pattern hype markets show first.

There is also a direct precedent. GDPR created the Data Protection Officer, which turned into a durable specialist recruiting niche that still exists eight years later. Regulatory-created roles do not tend to evaporate; they get absorbed into the org chart.