Share this article

AI anxiety is showing up on the org chart
Accelerating security solutions for small businesses Tagore offers strategic services to small businesses. | A partnership that can scale Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. | Standing out from competitors Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market. |
Cybersecurity org charts have morphed significantly in response to AI concerns—with companies now hiring several security titles that didn’t even exist three years ago.
In this latest Trust Signals drop, we analyzed Salesforce records and HRIS integrations and found a 26x rise in "AI Security" related job titles since 2023. Functions like Head of AI Security. AI Governance Lead, and AI Security Architect are the industry's answer to a problem that’s already inside the house: Shadow AI and the rise in security alerts tied to it.
New roles in the org chart
Vanta’s data shows that AI Security Engineers and Architects have already tripled YTD in 2026 versus all of 2025 combined. These titles represent the technical wing of this new profession, pulled from ML engineering, security engineering, and MLOps to govern AI use and deployment across the tech stack.
AI Governance managers, specialists, and leads weren’t appearing in Vanta’s data before 2024 (though traditional GRC and data governance roles have always existed). Now, governance roles with that specific AI qualifier have grown 10x in the last two years, staffed largely by people with legal, privacy, risk, or compliance backgrounds who've had to become fluent in how models, agents, and AI platforms actually work.
A familiar pattern: technology outpacing job titles
This isn't the first time technology has outpaced the job titles built to manage it. In the mid-1990s, the first "Chief Information Security Officer" role emerged as an evolution of Chief Security Officer in response to a series of cybersecurity attacks. It took almost 15 years—and an onslaught of data breaches—for it to become a standard in the C-suite.
In 2018, GDPR did something similar in months rather than years with the "Data Protection Officer" role, where it forced companies to formalize privacy as its own discipline within a defined runway.
Both times, the underlying risk grew faster than any existing function could absorb it, and the market responded. The same pattern is repeating now, at a much faster pace.
The split even mirrors the last two cycles. Information security eventually separated into technical and governance tracks, and privacy split into legal and operational functions. Now, AI oversight is dividing in the same way: engineers governing the pipeline, and compliance-minded generalists governing the policy.
What security leaders should do now
If the CISO and DPO analogy holds, "AI Security Architect" and "AI Governance Lead" are early indicators of the next standard lines on an org chart. But this time, companies have to act even faster.
With CISO and DPO hires, the companies that adapted fastest didn't wait for a perfectly-titled hire to show up. They started with an inventory of what was already running, often assigning the work to whoever on the existing team was closest to it, and formalized the role around that person once the scope became clear.
The same move applies here. Before writing a job description, most security leaders already have someone doing a version of this job under a different title—like an engineer tracking which AI tools touch production or a compliance lead fielding questions about vendor AI use. Finding that person and giving them the mandate is faster than waiting for the market to produce a purpose-built hire. Nobody majored in AI Governance and is coming in with the perfect pedigree for a role like this—yet.
Technology can also accelerate impact as roles and responsibilities evolve internally. Vanta’s TPRM solution provides organizations with visibility to close the Shadow IT and AI gap, and our AI Governance solution (early access now available) specifically drills into agent oversight—cataloguing agents that exist within an environment and what those agents access, then enforcing guardrails to mitigate risk.
Either way, there’s an opening for companies to build the function now and design it on their own terms, determining who owns model monitoring, vendor reviews, and agent oversight.
Companies can be proactive before an incident forces the decision, but it won’t stay that way indefinitely.
Methodology
The data used in this analysis is drawn from two independent sources: Vanta's Salesforce CRM contacts database (2.2M+ records) and employee records from HRIS integrations (BambooHR, Rippling, etc.) connected through Vanta's product (deduplicated to most-recent state per employee). AI Risk/Security/Governance roles are identified via case-insensitive keyword matching on the job title field against nine patterns: "AI Risk," "AI Security," "AI Governance," "AI Compliance," "AI Safety," "AI Ethics," "Artificial Intelligence Risk," "Artificial Intelligence Security," and "Artificial Intelligence Governance." This approach intentionally excludes general "Risk" or "Security" titles without the "AI" qualifier, likely undercounting practitioners working under broader titles. Salesforce contacts are limited to non-deleted records with a valid creation date; HRIS employees are deduplicated to a single current record per person. Company breadth is measured using distinct account identifiers (Salesforce) and distinct customer domains (HRIS). Normalized share is computed as AI-titled records divided by total new records created in the same quarter, controlling for overall growth in both data pools. Year-over-year growth rates use full calendar years; 2026 figures are partial-year (through approximately July 2026) and noted as YTD throughout.





FEATURED VANTA RESOURCE
The ultimate guide to scaling your compliance program
Learn how to scale, manage, and optimize alongside your business goals.















.png)

