Forge University
AI Security & Governance

The AI Governance Skills Gap Is Now a Budget Decision, Not a Future One

August 24, 2026

Randy Hall, CEO— AI-assisted and reviewed prior to publication.

Server hall split between orderly, gated pathways and chaotic tangled light trails, symbolizing governed versus ungoverned

AI adoption inside most organizations has already outrun the governance program meant to control it, and the certifications meant to staff that program are only now catching up. Recent research from ISACA shows AI use accelerating well ahead of formal policy, tested incident response, and measurable oversight. That gap is why training budgets built around general security certifications no longer satisfy a board asking who can actually govern the AI systems already running in production.

Why did AI governance suddenly become a budget line item?

Because the exposure stopped being theoretical. ISACA's research found that nearly three out of four European IT and cybersecurity professionals say staff are already using generative AI at work, up ten points in a year, but just under a third of organizations have put formal policies in place. That is not a training gap leadership can defer to next fiscal year. It is unmanaged operational risk sitting in production right now.

The numbers get sharper once you ask about incident response instead of policy. In a separate ISACA survey of digital trust professionals across Europe, 59% said they did not know how quickly their organization could halt an AI system during a security incident, and only 21% said their organization could do so within half an hour. A board that would never accept "we don't know how fast we can isolate a compromised server" is currently accepting the same answer for AI. That inconsistency is what turns AI governance from a nice-to-have into a line item a CFO actually reads.

The workforce data confirms leadership already feels this. ISACA's polling found that 42% of respondents believe they will need to increase their skills and knowledge in AI within the next six months in order to retain their job or advance their career, and separately, 47% of cyber teams are now involved in AI governance, up notably from the prior year. Governance work is landing on existing security staff whether or not those staff were trained for it.

Which certifications actually close this gap right now?

Two credentials launched specifically to answer this, and they are not interchangeable. ISACA's Advanced in AI Security Management (AAISM) is built for people who already hold a CISM or CISSP and need to extend that management authority into AI-specific risk. ISACA describes it as the first AI-centric security management certification, created because AI tools are being adopted faster than organizational policies can keep up, giving security professionals a way to demonstrate they can implement enterprise AI solutions while identifying, assessing, monitoring, and mitigating the risks that come with them.

The credential is organized around three domains that map directly to what a governance program actually needs someone to own: AI Governance and Program Management, AI Risk Management, and AI Technologies and Controls, covering everything from designing AI governance models aligned to business objectives to identifying AI-specific vulnerabilities, managing third-party risk, and embedding AI into secure architectures. If your organization already has a CISM or CISSP on staff wondering what comes next, the AAISM certification prep track is built for exactly that transition, not a rebuild from zero.

CompTIA took a different route with SecAI+, aimed lower in the org chart at practitioners who secure and operate systems day to day. CompTIA's own framing is direct: "As AI expands into core business processes, the ability to secure AI systems, manage AI-related risk and support responsible AI governance has become a defining capability for modern cyber security job roles." Unlike AAISM, SecAI+ does not require a prerequisite credential. It is designed as a complement to existing experience and certifications including Security+, CySA+ and PenTest+, which makes it the more practical first purchase for a team that has security fundamentals but no AI-specific coverage yet.

The demand signal behind both launches is consistent across vendors. ISC2's most recent workforce research found AI was the most pressing skill needed for cybersecurity teams, cited by 41% of respondents, and 69% said their teams had already integrated AI tools, were actively testing them, or were in early evaluation. That is not a niche specialization anymore. It is close to a baseline expectation for anyone managing security operations.

What framework should a training decision actually be built around?

Almost every one of these certifications, and almost every governance program worth building, now maps to the same skeleton: the NIST AI Risk Management Framework. NIST's own documentation describes it as a framework that provides outcomes and actions enabling dialogue, understanding, and activities to manage AI risks and develop trustworthy AI systems, operationalized through four functions: Govern, Map, Measure, and Manage.

That structure matters for a buying decision because it gives you a shared vocabulary to evaluate vendors and training providers against. If a certification's curriculum cannot tell you where its content sits inside Govern, Map, Measure, or Manage, it probably has not been built with enterprise deployment in mind. AAISM's domain structure and SecAI+'s objectives both trace back to this same core, which is part of why pairing a management-track credential with a practitioner-track one produces coverage instead of overlap. If your team needs a plain-language walkthrough of how the domains break down before committing budget, the certification resources hub covers exam objectives and curriculum overviews across ISACA and CompTIA tracks side by side.

How should you actually structure the budget decision?

Treat it the way you would any other control gap, not as generic upskilling. Before approving spend, a buying committee should get straight answers to a short list of questions:

  • Who on the team is currently accountable for AI incident response, and can they document it the way they would for any other system?
  • Does at least one person hold a credential that maps to a recognized governance framework, or is oversight running on improvised judgment?
  • Is the certification prerequisite realistic for the person you want to hold it, given CISM and CISSP are required for AAISM specifically?
  • What is the cost of one ungoverned AI incident against the cost of certifying the people already doing this work informally?

That last question is the one that gets budget approved. Certifying the analyst or manager already fielding AI questions is cheaper than discovering during an incident that nobody can produce evidence of who approved the system, what data it touches, or how to shut it off. If you want a study plan built around one of these tracks specifically, you can start training whenever your team is ready to move past ad hoc AI policy.

Which credential fits which role?

The honest answer depends on where the person sits in your organization, not which certification has the newer launch date.

RoleBest-fit credentialPrerequisite
Security manager or CISO-track leader owning AI policy and program designAAISMActive CISM or CISSP
Security analyst or engineer securing AI systems and using AI in daily operationsSecAI+Security+, CySA+, or PenTest+ recommended
Auditor validating AI governance and controlsAAIAActive CISA or equivalent audit credential

None of these replace the foundational certification underneath them. AAISM is explicitly described as a credential that supplements the globally validated best practices of CISM and CISSP with AI-centric domain expertise, and SecAI+ is positioned the same way relative to Security+ and CySA+. Buying one without the foundation underneath it produces a credential without the operational judgment it assumes the holder already has.

What changes operationally once the team is certified

The practical shift is accountability, not just knowledge. A certified team can name who owns AI incident response, point to a documented halt procedure, and show which framework their controls map to when a regulator or board member asks. Given that most organizations currently cannot answer the simple question of how fast they could stop a misbehaving AI system, that alone is a meaningful competitive difference, not a compliance formality.

The organizations treating this as a 2027 problem are the ones already behind. AI adoption did not wait for a governance program to get built around it, and the certifications that validate governance skill did not exist in a form buyers could purchase against until the past year. That window has now closed. What is left is a straightforward staffing decision: certify the people already doing this work, or keep gambling that the next AI incident happens on a system someone remembered to document.

Further Reading

Start training free at Forge University