$ GRC FOR AI

Understand → build → secure. This is stage three.

There is a gap in compliance right now, and AI is widening it. The frameworks exist — NIST AI RMF, ISO 42001, NIST 800-30 — but almost nobody shows the part that actually matters: what you do to satisfy a control on a real system, the evidence an auditor would accept, and whether it works. Most governance writing stops at “this control maps to that control.”

GRC for AI is where I close that gap from the builder’s side. I build the AI systems — RAG pipelines, knowledge bases, agent workflows — and then I audit my own builds against the frameworks: a real risk assessment, a per-tool vulnerability check, the honest gaps, and what I’d do about them. Build and security are not opposites. The audit is the build log.

This is the last of three tracks: Foundations to understand, Infrastructure to build, and this one to secure what you built. If you came for the systems, Infrastructure is the build; this track is how I prove it holds up.