The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Principal / Manager, Responsible AI (L5)
3-5 years at L5Skills to master
- Mastering the operational effectiveness of an AI compliance programme, building and leading a team of specialists and managers, and owning a significant functional P&L.
You're ready to move on when
- Successfully managed a team of 10-25 individuals, consistently hitting programme objectives.
- Demonstrated ability to influence senior leadership and secure resources for strategic initiatives.
- Proven track record of navigating complex regulatory environments and delivering compliant AI solutions.
- 2
Senior Legal Counsel (specialising in AI/Tech Law)
5-7 years in senior legal rolesSkills to master
- Translating complex legal interpretations into actionable business policies, advising on high-stakes regulatory matters, and deep understanding of technology law, particularly data privacy and AI regulation.
You're ready to move on when
- Successfully advised on multiple high-profile AI product launches or regulatory inquiries.
- Demonstrated ability to build strong relationships with business leaders and integrate legal advice into product strategy.
- Proven expertise in drafting and negotiating complex technology contracts with AI implications.
- 3
Director of Enterprise Risk Management
3-5 years in a Director-level ERM roleSkills to master
- Designing and implementing enterprise-wide risk management frameworks, presenting risk profiles to the Board, and managing cross-functional risk mitigation programmes. Adapting these skills specifically to AI risks.
You're ready to move on when
- Successfully managed an ERM function for a complex business unit, including significant P&L oversight.
- Demonstrated ability to influence Board-level decisions on risk appetite and mitigation strategies.
- Proven experience in integrating emerging risks (like AI) into an existing ERM framework.