When it comes to understanding how artificial intelligence (AI) is changing cybersecurity, those discussions tend to focus on the technical skills that cybersecurity professionals have or must acquire to compete. In today’s job market, professionals with proven AI skills are increasingly sought after as enterprises look to better utilize these platforms. As AI interest grows, however, there is also a significant need for cybersecurity professionals and others to help address knowledge gaps when it comes to a wide range of security-related issues beyond the technical aspects. These include governance, risk assessment, data protection, data privacy, government compliance and regulatory issues. This is where the field of governance, risk and compliance – GRC for short – is having its moment. A term coined in 2002, this field encompasses traditional IT and cybersecurity teams as well as other parts of the organization, from legal to finance to HR to the executive boardroom. One definition of GRC is an organization-wide strategy to “manage governance and risks while maintaining compliance with industry and government regulations,” according to IBM. By creating this type of framework – one that encompasses various parts of an enterprise – an organization is then able to establish policies and procedures that address risk. One reason GRC is gaining more attention now is that the growing use of AI is creating fresh risk concerns for organizations, from how internal data is used with these virtual chatbots and platforms to the responsibility of managing large language models. These challenges require enterprise-wide rules and procedures to ensure security. “First, AI itself now requires governance. Organizations must develop policies around model risk, data handling, prompt injection, bias, explainability and regulatory compliance. AI introduces new oversight obligations at both the technical and board level,” said Shane Barney, CISO at Keeper Security. “Second, regulatory expansion tied