Skip to main content

AI Governance Engineer: an open body of knowledge mapping EU AI Act, ISO 42001 and NIST AI RMF to the artefacts that satisfy each obligation

0
Medium
Published: 09/22/2026 (09/22/2026, 09:27:40 UTC)
Source: Reddit Cybersecurity

Description

AI Governance Engineer is an open, versioned body of knowledge that maps AI governance frameworks such as the EU AI Act, ISO 42001, and NIST AI RMF to concrete artefacts satisfying each obligation. It provides a structured approach to AI governance engineering, emphasizing continuous, machine-readable evidence over point-in-time attestations. The resource includes chapters, a maturity model, reusable patterns, and data exports to support implementation and auditability of AI governance obligations.

Reddit Discussion

r/cybersecurity·posted by u/losanchos2
00

What it is: a free, open, versioned body of knowledge on AI governance engineering: eleven chapters, a five-level maturity model, seventeen reusable patterns, and a crosswalk that maps each obligation to the concrete artefact that satisfies or supports it. CC BY 4.0, source on GitHub, versioned releases with a changelog and a DOI so it can be cited. Nothing to sign up for and nothing behind a paywall.

Why I wrote it: frameworks tell you what must be true, and very little tells you what has to exist in the build for it to be true. Framework coverage proves you read the framework, not that any risk fell. So the crosswalk runs the other way — from the obligation to the artefact, and to the layer that owns it.

The reference material is exported as data, not only as web pages:

- crosswalk (CSV and JSON): one governance topic per row, across the instruments that bind it

- obligations (CSV and JSON): obligation, artefact, owning layer

- glossary (JSON), cross-referenced to the chapter that defines each term

https://aigovernanceengineer.com/

Two things I would like this sub to push back on:

- The mappings are my reading, and readings differ. If a row looks wrong, tell me which one and why, or send a pull request.

- I argue that continuous, machine-readable evidence beats a point-in-time attestation. If you have sat on either side of an audit or a certification, does that hold in practice, or do assessors still want the static pack?

Wrong mappings are the thing I most want caught before anyone relies on them.

Links cited in this discussion

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/22/2026, 09:47:42 UTC

Technical Analysis

This resource defines AI governance engineering as the application of engineering practices—systems thinking, product thinking, and code—to AI system governance. It maps legal and regulatory obligations from frameworks like the EU AI Act Art. 9 (risk management) to specific artefacts and layers within an AI governance stack. The stack consists of five layers: policy-as-code, inventory and transparency, evals and red teaming as evidence, runtime controls and observability, and assurance and continuous compliance. The approach prioritizes executable policies that block unsafe deployments, continuous runtime evidence, and machine-readable audit data. It aims to replace static documentation with live, queryable assurance and integrates governance ownership with engineering workflows.

Potential Impact

This body of knowledge supports organizations in implementing AI governance obligations with engineering rigor, potentially improving compliance and risk management for AI systems. It does not describe a vulnerability or exploit but provides a framework to reduce governance risks by ensuring continuous compliance and evidence generation. There is no direct security threat or vulnerability described.

Defensive Guidance

Not applicable as this is not a vulnerability or threat. Organizations interested in AI governance can adopt the practices and artefacts described to enhance their governance posture. No patches or fixes are relevant.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6ab24ebaf7a7c54106fed078

Added to database: 09/22/2026, 09:47:38 UTC

Last enriched: 09/22/2026, 09:47:42 UTC

Last updated: 09/22/2026, 16:47:42 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses