

If you’ve been reading our quarterly Privacy Job Reports, you’ll know this isn’t a new observation, but the pace of change caught even us by surprise. In Q1 2026, 14% of privacy roles advertised across Seek and LinkedIn explicitly referenced artificial intelligence. By Q2 2026, that figure had jumped to 36%. In the space of three months, AI went from a notable trend to something employers now assume of a large share of the privacy workforce.
This isn’t confined to tech companies either. Over the past two quarters, we’ve seen AI-related privacy roles advertised by the Commonwealth Bank, ANZ, Optus, Woolworths Group, Canva, QBE, BHP, MUFG, HCF Australia and the Department of Defence. Banking, retail, mining, telecommunications, government, the demand is broad-based and growing.
When we dig into the job descriptions behind these numbers, a consistent picture emerges. Employers aren’t just looking for privacy professionals who are “AI-aware.” They’re looking for people who can operationalise AI governance inside a real organisation, from the foundations of a governance program through to the technical realities of building and deploying AI systems. The recurring themes we’re seeing include:
Understanding what AI is and the risks it poses. Roles increasingly expect candidates to go beyond the mechanics of traditional data collection and storage, and to understand how AI systems process personal information through automated decision-making, profiling and machine learning models, along with the broader risks AI poses to individuals and organisations, including bias, lack of transparency, and the potential for harm at scale.
Building and running a governance program, not just advising on one. We’re seeing employers ask for people who can define roles and responsibilities across a cross-functional AI governance program, deliver training and awareness across the business, and establish policies and procedures that hold up across the full AI lifecycle, not simply flag risk after the fact.
Familiarity with both existing law and AI-specific regulation. References to frameworks like the EU AI Act are now appearing alongside the usual GDPR, Privacy Act and APP citations, even in Australian-based roles. Employers want people who understand how existing data privacy, intellectual property, non-discrimination and consumer protection laws apply to AI, as well as the emerging risk-based frameworks specific to AI itself.
AI risk assessment capability, extended across the AI lifecycle. Several roles this year have specifically called for experience conducting AI risk assessments or algorithmic impact assessments, extending the logic of a Privacy Impact Assessment (PIA) into the design, training, testing, deployment and ongoing monitoring of AI systems, not just a one-off checkpoint before launch.
Cross-functional fluency with technical and vendor risk. AI governance roles sit at the intersection of privacy, legal, data science, cybersecurity and product teams. Employers are looking for practitioners who can speak the language of technical teams building AI systems, evaluate the terms and risks in AI vendor and licensing agreements, and govern AI systems long after they’ve gone live.
Responsible and ethical AI frameworks. Beyond legal compliance, employers are asking for people who can help build and embed organisational frameworks for responsible AI, covering fairness, transparency, explainability, human oversight and accountability.
Importantly, these expectations are showing up across seniority levels. It’s not just specialist AI governance leads, we’re seeing AI-related responsibilities appear in Privacy Officer roles, Privacy Manager roles, and even legal counsel positions. For the profession as a whole, this signals that AI governance capability is moving from a specialisation to a baseline expectation.
Here’s the challenge many organisations are facing: the demand for AI governance expertise is growing faster than the supply of people who genuinely have it. Traditional privacy training doesn’t cover AI-specific risk, and traditional AI or data science training doesn’t cover privacy and regulatory obligations. The result is a genuine skills gap, and it’s one that’s showing up clearly in the job market data.
For privacy leaders, this creates a decision point: hire externally for AI governance expertise (an increasingly expensive and competitive process, as our salary data shows), or invest in upskilling the privacy team you already have.
This is exactly the gap the IAPP Artificial Intelligence Governance Professional (AIGP) credential is designed to close, and it’s why Privacy 108 runs AIGP training for both organisations and the privacy professionals who work in them.
The AIGP is a comprehensive, practitioner-focused course covering:
For organisations, the case is straightforward. Rather than competing in an increasingly expensive and competitive market for external AI governance hires, AIGP training lets you build that capability inside a team that already understands your data, your risk appetite and your regulatory obligations. It’s a faster, more sustainable way to close the AI governance skills gap than waiting for the perfect external candidate to appear.
For individual practitioners, the case is just as compelling. The AIGP is a credential that speaks directly to what employers are now screening for, credibility that sits alongside privacy qualifications like the CIPM, in a job market where AI-related roles are growing far faster than the supply of qualified candidates. It’s a genuine opportunity to broaden your remit, position yourself for more senior and specialised roles, and future-proof your career as AI governance shifts from a niche skill to a baseline expectation across the profession.
Whether you’re a privacy leader looking to build AI governance capability across your team, or a practitioner looking to future-proof your own career, upskilling through AIGP training is one of the most valuable investments available in today’s market.
You can read more about the AIGP course here. Or contact us via the form below if you have any questions.
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.