Back to AI Roadmap
🛡️
LAYER 09

09. AI Safety / Security / Governance / Observability

Benchmark Companies:
LakeraLakeraNeMo GuardrailsNeMo GuardrailsCisco (Robust Intelligence)Cisco (Robust Intelligence)Protect AIProtect AIHiddenLayerHiddenLayerPalo Alto NetworksPalo Alto NetworksPromptfooPromptfooAzure Content SafetyAzure Content SafetyCredo AICredo AIOneTrustOneTrustwatsonx.governancewatsonx.governanceLangfuseLangfuseBraintrustBraintrustArize PhoenixArize PhoenixDatadogDatadogDynatraceDynatraceWhyLabsWhyLabsOpenAIOpenAIAnthropicAnthropicGoogle CloudGoogle CloudArize AIArize AIHugging FaceHugging FaceBigIDBigIDDatabricksDatabricksMicrosoftMicrosoft

Cross-cutting defenses across the AI lifecycle: direct/indirect prompt injection defense, guardrails, red teaming, regulatory governance, and distributed tracing.

📊Layer View Mode:
🌐3D CROSS-CORRELATION MATRIX

09. AI Safety / Security / Governance / Observability · Cross-Correlation Ecosystem

Click any company, tech category, or career role to illuminate all cross-associations and dim unrelated entities.

🔍
🏢

Benchmark Enterprises

25
LakeraLakera
1
NeMo GuardrailsNeMo Guardrails
1
Cisco (Robust Intelligence)Cisco (Robust Intelligence)
2
Protect AIProtect AI
2
HiddenLayerHiddenLayer
1
Palo Alto NetworksPalo Alto Networks
1
PromptfooPromptfoo
1
Azure Content SafetyAzure Content Safety
2
Credo AICredo AI
2
OneTrustOneTrust
2
watsonx.governancewatsonx.governance
1
LangfuseLangfuse
2
BraintrustBraintrust
1
Arize PhoenixArize Phoenix
3
DatadogDatadog
2
DynatraceDynatrace
2
WhyLabsWhyLabs
1
OpenAIOpenAI
2
AnthropicAnthropic
2
Google CloudGoogle Cloud
2
Arize AIArize AI
3
Hugging FaceHugging Face
1
BigIDBigID
1
DatabricksDatabricks
1
MicrosoftMicrosoft
2
🛠️

Tech Stack Categories & Atomic Nodes

4 Tracks
9.1

9.1 AI Application Security & Adversarial Testing

Direct/indirect prompt injection defense, instruction hierarchy, jailbreak testing, NeMo Guardrails, tool privilege escalation prevention, and safe deserialization.
Sub-Page
Prompt Injection Defense, Jailbreak Interception & NeMo Guardrails
💰 $210K - $450K / year (AI Security & Prompt Defense) | ¥600K - ¥1.4M / year
Strict instruction hierarchy control (System > Tool > User), perplexity anomaly filters, delimiter tag hardening, NVIDIA NeMo Guardrails (Colang 2.0), and OWASP Top 10 for LLM v2.0 vulnerability mitigations.
Benchmark:LakeraLakeraNeMo GuardrailsNeMo GuardrailsCisco (Robust Intelligence)Cisco (Robust Intelligence)PromptfooPromptfooProtect AIProtect AI
Prompt InjectionJailbreak DefenseInstruction HierarchyNeMo GuardrailsColangOWASP Top 10 for LLMLakera
Tool Privilege Scoping, DLP Egress & Supply Chain Security
💰 $205K - $440K / year (Tool Scoping & AI Supply Chain Security) | ¥580K - ¥1.35M / year
Dynamic least-privilege tool token scoping, streaming PII redaction (Presidio), sandbox egress network policies, and model weight malicious deserialization defenses (Safetensors / ModelScan).
Benchmark:Protect AIProtect AIHiddenLayerHiddenLayerCisco (Robust Intelligence)Cisco (Robust Intelligence)Palo Alto NetworksPalo Alto Networks
Tool AbuseData Exfiltration (DLP)PII RedactionEgress FilteringSafetensorsModelScanSupply Chain Security
9.2

9.2 Responsible AI, Safety & Model Risk

14 harm taxonomies, fairness and bias metrics, human-in-the-loop escalation, Model & System Cards transparency, and security incident response.
Sub-Page
Harm Taxonomy, Fairness/Bias Auditing & Human Oversight
💰 $200K - $430K / year (Responsible AI & Alignment) | ¥550K - ¥1.3M / year
Multi-modal content moderation across 14 harm categories (hate/self-harm/harassment/CBRN), demographic parity and equalized odds fairness auditing, and human-in-the-loop escalation controls.
Benchmark:Azure Content SafetyAzure Content SafetyOpenAIOpenAIAnthropicAnthropicGoogle CloudGoogle CloudArize AIArize AI
Harm TaxonomyBias AuditingDemographic ParityEqualized OddsHuman OversightAzure Content SafetyConstitutional AI
Model Cards, System Cards Transparency & Incident Response
💰 $190K - $410K / year (Model Risk & Transparency Governance) | ¥520K - ¥1.22M / year
Standardized Model & System Cards transparency reporting, intended use and out-of-scope boundary definitions, MITRE ATLAS threat mapping, and Coordinated Vulnerability Disclosure (CVD).
Benchmark:Hugging FaceHugging FaceOpenAIOpenAIAnthropicAnthropicGoogle CloudGoogle Cloud
Model CardsSystem CardsMITRE ATLASVulnerability DisclosureIncident ResponseHugging Face
9.3

9.3 AI Governance, Compliance & Audit Evidence

GDPR/CCPA privacy compliance, Zero Data Retention (ZDR), policy-as-code (Rego), NIST AI RMF 1.0, EU AI Act conformity, and automated audit evidence bundles.
Sub-Page
Privacy Compliance, Zero Data Retention & Policy-as-Code
💰 $195K - $420K / year (AI Privacy & Policy-as-Code) | ¥540K - ¥1.28M / year
GDPR/CCPA compliance, Zero Data Retention (ZDR) enforcement, user consent ledgers, Open Policy Agent (OPA/Rego) declarative policy gates, and automated access control reviews.
Benchmark:OneTrustOneTrustBigIDBigIDDatabricksDatabricksCredo AICredo AI
Data PrivacyZero Data Retention (ZDR)Policy-as-CodeOPA / RegoConsent LedgerOneTrustBigID
NIST AI RMF Mapping, Third-Party Model Vetting & Audit Evidence
💰 $200K - $435K / year (AI Governance & Regulatory Audit) | ¥560K - ¥1.32M / year
NIST AI RMF 1.0, ISO/IEC 42001, and EU AI Act regulatory mappings, third-party model vendor vetting, tamper-proof automated audit evidence bundles, and exception management.
Benchmark:Credo AICredo AIwatsonx.governancewatsonx.governanceOneTrustOneTrustMicrosoftMicrosoft
NIST AI RMFISO 42001EU AI ActAudit EvidenceThird-Party VettingCredo AIIBM watsonx
9.4

9.4 AI Observability, Quality & Incident Response

OpenTelemetry GenAI semantic conventions, end-to-end span distributed tracing, embedding drift (MMD/Wasserstein), online quality probes, and error budget burn rate alerts.
Sub-Page
End-to-End Distributed Tracing & OpenTelemetry GenAI
💰 $195K - $410K / year (Distributed Tracing & GenAI APM) | ¥520K - ¥1.22M / year
Standardized OpenTelemetry GenAI semantic conventions, nested agent/tool/RAG span cascaded tracing, TTFT and TPOT latency breakdowns, real-time payload inspection, and interactive visualization.
Benchmark:LangfuseLangfuseArize PhoenixArize PhoenixDatadogDatadogDynatraceDynatraceBraintrustBraintrust
Distributed TracingOpenTelemetry GenAISpan CascadeTTFT / TPOTLangfuseArize PhoenixDatadog
Quality Drift Monitoring, Embedding Drift & Incident Response
💰 $190K - $400K / year (AI Quality Drift & SRE Reliability) | ¥500K - ¥1.18M / year
High-dimensional embedding drift detection via MMD & PSI, online quality and feedback probes, SLO error budget burn rate alerting, and cross-layer security incident response runbooks.
Benchmark:Arize AIArize AILangfuseLangfuseWhyLabsWhyLabsDatadogDatadogDynatraceDynatrace
Embedding DriftMMDPSIQuality ProbesError Budget Burn RateIncident ResponseWhyLabsArize AI
💼

Career Track Roles

18
💼AI Security Engineer
2
💼AI Red Team Engineer
1
💼AI Safety Engineer
2
💼Responsible AI Engineer
2
💼AI Governance Specialist
2
💼Observability Engineer
2
💼Privacy Engineer
1
💼SRE
1
💼Application Security Engineer
1
💼AI Systems Engineer
1
💼Threat Researcher
1
💼Safety Researcher
1
💼Model Risk Manager
1
💼Compliance Engineer
2
💼AI Risk Consultant
1
💼LLMOps Engineer
1
💼AI Platform Engineer
1
💼Evaluation Engineer
1
🔄Sub-Domain Sequential Path (4 stages):
9.1

9.1 AI Application Security & Adversarial Testing

Open Sub-Page

Direct/indirect prompt injection defense, instruction hierarchy, jailbreak testing, NeMo Guardrails, tool privilege escalation prevention, and safe deserialization.

Prompt Injection Defense, Jailbreak Interception & NeMo Guardrails

Strict instruction hierarchy control (System > Tool > User), perplexity anomaly filters, delimiter tag hardening, NVIDIA NeMo Guardrails (Colang 2.0), and OWASP Top 10 for LLM v2.0 vulnerability mitigations.

🏢 Companies
LakeraLakeraNeMo GuardrailsNeMo GuardrailsCisco (Robust Intelligence)Cisco (Robust Intelligence)PromptfooPromptfooProtect AIProtect AI
🛠️ Tech Stack
Prompt InjectionJailbreak DefenseInstruction HierarchyNeMo GuardrailsColangOWASP Top 10 for LLMLakera
💼 Roles & Salary
AI Security Engineer、AI Red Team Engineer、Application Security Engineer
💰 $210K - $450K / year (AI Security & Prompt Defense) | ¥600K - ¥1.4M / year

Tool Privilege Scoping, DLP Egress & Supply Chain Security

Dynamic least-privilege tool token scoping, streaming PII redaction (Presidio), sandbox egress network policies, and model weight malicious deserialization defenses (Safetensors / ModelScan).

🏢 Companies
Protect AIProtect AIHiddenLayerHiddenLayerCisco (Robust Intelligence)Cisco (Robust Intelligence)Palo Alto NetworksPalo Alto Networks
🛠️ Tech Stack
Tool AbuseData Exfiltration (DLP)PII RedactionEgress FilteringSafetensorsModelScanSupply Chain Security
💼 Roles & Salary
AI Security Engineer、AI Systems Engineer、Threat Researcher
💰 $205K - $440K / year (Tool Scoping & AI Supply Chain Security) | ¥580K - ¥1.35M / year
9.2

9.2 Responsible AI, Safety & Model Risk

Open Sub-Page

14 harm taxonomies, fairness and bias metrics, human-in-the-loop escalation, Model & System Cards transparency, and security incident response.

Harm Taxonomy, Fairness/Bias Auditing & Human Oversight

Multi-modal content moderation across 14 harm categories (hate/self-harm/harassment/CBRN), demographic parity and equalized odds fairness auditing, and human-in-the-loop escalation controls.

🏢 Companies
Azure Content SafetyAzure Content SafetyOpenAIOpenAIAnthropicAnthropicGoogle CloudGoogle CloudArize AIArize AI
🛠️ Tech Stack
Harm TaxonomyBias AuditingDemographic ParityEqualized OddsHuman OversightAzure Content SafetyConstitutional AI
💼 Roles & Salary
AI Safety Engineer、Responsible AI Engineer、Safety Researcher
💰 $200K - $430K / year (Responsible AI & Alignment) | ¥550K - ¥1.3M / year

Model Cards, System Cards Transparency & Incident Response

Standardized Model & System Cards transparency reporting, intended use and out-of-scope boundary definitions, MITRE ATLAS threat mapping, and Coordinated Vulnerability Disclosure (CVD).

🏢 Companies
Hugging FaceHugging FaceOpenAIOpenAIAnthropicAnthropicGoogle CloudGoogle Cloud
🛠️ Tech Stack
Model CardsSystem CardsMITRE ATLASVulnerability DisclosureIncident ResponseHugging Face
💼 Roles & Salary
Responsible AI Engineer、Model Risk Manager、AI Safety Engineer
💰 $190K - $410K / year (Model Risk & Transparency Governance) | ¥520K - ¥1.22M / year
9.3

9.3 AI Governance, Compliance & Audit Evidence

Open Sub-Page

GDPR/CCPA privacy compliance, Zero Data Retention (ZDR), policy-as-code (Rego), NIST AI RMF 1.0, EU AI Act conformity, and automated audit evidence bundles.

Privacy Compliance, Zero Data Retention & Policy-as-Code

GDPR/CCPA compliance, Zero Data Retention (ZDR) enforcement, user consent ledgers, Open Policy Agent (OPA/Rego) declarative policy gates, and automated access control reviews.

🏢 Companies
OneTrustOneTrustBigIDBigIDDatabricksDatabricksCredo AICredo AI
🛠️ Tech Stack
Data PrivacyZero Data Retention (ZDR)Policy-as-CodeOPA / RegoConsent LedgerOneTrustBigID
💼 Roles & Salary
AI Governance Specialist、Privacy Engineer、Compliance Engineer
💰 $195K - $420K / year (AI Privacy & Policy-as-Code) | ¥540K - ¥1.28M / year

NIST AI RMF Mapping, Third-Party Model Vetting & Audit Evidence

NIST AI RMF 1.0, ISO/IEC 42001, and EU AI Act regulatory mappings, third-party model vendor vetting, tamper-proof automated audit evidence bundles, and exception management.

🏢 Companies
Credo AICredo AIwatsonx.governancewatsonx.governanceOneTrustOneTrustMicrosoftMicrosoft
🛠️ Tech Stack
NIST AI RMFISO 42001EU AI ActAudit EvidenceThird-Party VettingCredo AIIBM watsonx
💼 Roles & Salary
AI Governance Specialist、Compliance Engineer、AI Risk Consultant
💰 $200K - $435K / year (AI Governance & Regulatory Audit) | ¥560K - ¥1.32M / year
9.4

9.4 AI Observability, Quality & Incident Response

Open Sub-Page

OpenTelemetry GenAI semantic conventions, end-to-end span distributed tracing, embedding drift (MMD/Wasserstein), online quality probes, and error budget burn rate alerts.

End-to-End Distributed Tracing & OpenTelemetry GenAI

Standardized OpenTelemetry GenAI semantic conventions, nested agent/tool/RAG span cascaded tracing, TTFT and TPOT latency breakdowns, real-time payload inspection, and interactive visualization.

🏢 Companies
LangfuseLangfuseArize PhoenixArize PhoenixDatadogDatadogDynatraceDynatraceBraintrustBraintrust
🛠️ Tech Stack
Distributed TracingOpenTelemetry GenAISpan CascadeTTFT / TPOTLangfuseArize PhoenixDatadog
💼 Roles & Salary
Observability Engineer、LLMOps Engineer、AI Platform Engineer
💰 $195K - $410K / year (Distributed Tracing & GenAI APM) | ¥520K - ¥1.22M / year

Quality Drift Monitoring, Embedding Drift & Incident Response

High-dimensional embedding drift detection via MMD & PSI, online quality and feedback probes, SLO error budget burn rate alerting, and cross-layer security incident response runbooks.

🏢 Companies
Arize AIArize AILangfuseLangfuseWhyLabsWhyLabsDatadogDatadogDynatraceDynatrace
🛠️ Tech Stack
Embedding DriftMMDPSIQuality ProbesError Budget Burn RateIncident ResponseWhyLabsArize AI
💼 Roles & Salary
Observability Engineer、SRE、Evaluation Engineer
💰 $190K - $400K / year (AI Quality Drift & SRE Reliability) | ¥500K - ¥1.18M / year