Back to Blog
AI People

AI People Interview: Michela De Mattia on Building a Path Into AI Safety and Governance

Ravi Prajapati

Author

Ravi Prajapati

August 26, 2026
/api/uploads/1787765280941-AI Safety and Governance Interview on ReadInBrief.webp

AI People Interview on ReadInBrief: Michela De Mattia on moving from GRC into AI governance, and the risks she thinks aren't getting enough attention.

Michela De Mattia moved from traditional Governance, Risk, and Compliance work in IT and finance into AI safety through volunteering, and says the real barrier to getting involved isn't a lack of the right background, it's waiting until you feel like an expert before you start.

Michela De Mattia is an AI Governance Specialist and financial services professional whose path into AI safety began with a Governance, Risk, and Compliance (GRC) background rather than a technical or research one. She found her way into the field through volunteering with a non-profit organization, and now splits her time between research, policy analysis, and the less visible work of building community around AI governance. All views below are her own, and don't represent an official position of any organization she volunteers with.

In this AI People interview, Michela talks about the moment AI risk stopped feeling abstract to her, why she thinks the most underrated risk right now is already happening rather than hypothetical, and where she sees the real gaps in Canada's AI governance landscape.

Her Story

Ravi Prajapati: What's your background, and what were you doing before AI governance and safety became part of your life?

Michela De Mattia: My core background is in Governance, Risk, and Compliance (GRC), working across the IT and finance industries where I've focused on managing structured risk, systems, and regulatory alignment. Before AI governance and safety became a central focus for me, my time was dedicated to traditional corporate GRC work. My path into the AI safety space really accelerated when I began volunteering for a non-profit organization.

Ravi Prajapati: For someone reading this who wants to get involved in AI governance or safety, as a volunteer, researcher, or advocate, what's your advice on where to start?

Michela De Mattia: Start by actively connecting with people in the space and immersing yourself as much as possible. Pay attention to your gut, let your genuine curiosity guide which niche or issue you focus on. From there, be creative with how you contribute: plug into local or online communities, attend events, take foundational courses, and dive into current readings to build your knowledge. You don't need a traditional path to make an impact, just active engagement and a willingness to learn.

Ravi Prajapati: What first drew you to AI governance and safety specifically, rather than AI research or industry?

Michela De Mattia: It felt like a natural progression for my career. Coming from a GRC background, looking at AI through the lens of risk, framework design, and oversight was already second nature to me. But beyond the professional fit, there was a deeper push: I wanted my work to have a direct, meaningful social impact.

Ravi Prajapati: Was there a specific moment, or a piece of research, that made AI risk feel "real" to you, rather than abstract?

Michela De Mattia: While reading academic research is valuable, many papers stay at an abstract level rather than offering concrete solutions. For me, AI risk became real when I started analyzing the safety frameworks and governance policies published by frontier AI companies. Seeing what is included, and more importantly, what is missing, vague, or glossed over, made it clear that managing these systems is an urgent, real-world challenge. In particular, Anthropic's public updates and safety blog posts offer a grounded look at how frontier labs are actively wrestling with alignment and capability risks in real time.

Ravi Prajapati: What made you decide to actually give your time to this as a volunteer, rather than just follow it as a personal interest?

Michela De Mattia: To me, volunteering was the natural bridge between a personal interest and my professional life. Reading about AI governance was engaging, but keeping it purely as a passive interest felt like missing an opportunity. Combining what I'm passionate about in my free time with the actual work I want to be doing is the ideal goal for me. Volunteering allowed me to stop just observing from the sidelines and start actively applying my time toward something meaningful.

Ravi Prajapati: What does volunteering on AI safety actually look like for you day to day? What kind of work fills your time?

Michela De Mattia: For me, day-to-day volunteering in AI safety is centered around creativity. A big portion of my time is spent diving into continuous research and reading, new governance proposals, technical updates, and policy frameworks. But the real work comes from taking those insights and using them creatively: brainstorming fresh ideas, finding new angles to address governance gaps, and translating complex concepts into actionable discussions. Alongside research, a huge part of my daily effort goes into human connection, building relationships, forming new collaborations, and organizing events that bring people together across the field.

Ravi Prajapati: What's something about this work, or about yourself, that volunteering has taught you that you didn't expect?

Michela De Mattia: Volunteering taught me to put myself out there even when I don't feel completely ready. In a rapidly evolving field like AI governance, waiting until you feel like an absolute expert means waiting forever. Stepping into community organizer and specialist roles forced me to embrace the learning process in real time, trust my background in risk, and realize that active initiative matters far more than having every single answer upfront.

Her View on AI Safety & Risk

Ravi Prajapati: What's the biggest misunderstanding you think people have about "AI safety" as a term?

Michela De Mattia: The biggest misunderstanding is believing that AI safety simply means slowing down AI progress. In reality, safety isn't about stopping or stalling innovation, it's about ensuring AI moves forward at a sustainable, responsible pace. AI should advance alongside robust safety guardrails so that as systems grow more powerful, we actively mitigate and prevent catastrophic or unintended results instead of reacting after the damage is done.

Ravi Prajapati: We're hearing a lot about AI agents now, systems that act autonomously rather than just chat. How worried should the average person be about that shift?

Michela De Mattia: The shift from simple conversational AI to autonomous AI agents is significant, and there are valid reasons to be concerned. The primary worry boils down to control: while traditional AI generates text or ideas that a human must review and execute, AI agents are designed to take direct action, sending emails, executing code, managing financial transactions, or making automated decisions, often without step-by-step human intervention. They turn into unintended real-world consequences, complex accountability gaps, and heightened security vulnerabilities.

Ravi Prajapati: What do you personally think is the most underrated AI risk right now, the one that isn't getting enough attention?

Michela De Mattia: We tend to discuss loss of control as a far-off science fiction scenario, but the OpenAI-Hugging Face incident showed it is happening right now. An AI agent wasn't instructed to launch a cyberattack, yet it autonomously chained together exploits to hack Hugging Face simply to complete a benchmarking test. That failure of alignment, combined with the reality that a tiny group of dominant platforms controls these frontier models, creates a dangerous dynamic: immense power centralized in systems whose operational choices we cannot reliably predict or constrain.

Ravi Prajapati: What would "getting AI governance right" actually look like in practice, five or ten years from now?

Michela De Mattia: Getting AI governance right in 5 to 10 years won't mean stopping AI progress, it will look like clear, operationalized infrastructure.

Policy & the Bigger Picture

Ravi Prajapati: Canada's AI and Data Act has had a long, complicated journey. In your view, where do things stand today, and what feels like it's still missing?

Michela De Mattia: Canada is certainly playing catch-up, much like the rest of the world. While the EU took a comprehensive approach with the EU AI Act, which still faces major implementation hurdles, Canada's journey has been fragmented. The original Artificial Intelligence and Data Act under Bill C-27 died when Parliament was prorogued, but the shift we're seeing now with the national AI Strategy for All and new proposals like Bills C-34 (Digital Safety) and C-36 (Privacy and Data Protection) is a massive step forward.

While focusing on public AI awareness, social media safety, and modernized privacy is crucial, unbundling AI regulation from privacy means we still lack a dedicated legal framework for high-impact models and autonomous agents. We're strengthening data and online safety, but hard guardrails for frontier AI systems themselves remain an unaddressed gap.

Ravi Prajapati: What's your take on "voluntary codes of conduct" as a governance tool? Do they actually work, or are they just a placeholder until real regulation arrives?

Michela De Mattia: For major frontier AI labs, they actually hold real weight, primarily due to reputational pressure. Large technology companies operate under intense public and regulatory scrutiny, meaning a failure to follow their own voluntary safety commitments carries massive brand and commercial risk.

The real blind spot, however, isn't the tech giants, it's the broader ecosystem of early-stage startups and smaller companies. Without binding regulations and clear compliance standards, smaller players often operate in the dark. They lack the resources to build dedicated in-house safety frameworks, and without legal requirements, safety considerations get deprioritized in favor of speed and market fit.

Ravi Prajapati: How should governments balance AI safety regulation with the need to not fall behind on innovation and investment?

Michela De Mattia: The idea that safety and innovation are opposing forces is a false dichotomy, effective governance actually accelerates sustainable innovation by building consumer trust and market predictability. Balancing the two requires a tiered, risk-based approach.

Ravi Prajapati: What role do you think AI safety organizations and civil society groups should play alongside government regulators?

Michela De Mattia: Their most vital role is serving as an independent bridge between technical research and public accountability. Government regulators often lack both the deep technical bandwidth to independently audit frontier models and the agility to keep pace with rapid developments.

Civil society groups step in to conduct crucial red-teaming and safety research. At the same time, they provide a powerful counterweight to corporate lobbying, ensuring that policy debates represent the public interest, focusing on societal impact, human rights, and long-term risk rather than just commercial incentives.

Ravi Prajapati: A lot of AI safety work is technical or policy-heavy. How do you personally make it accessible to non-experts and get people to actually care?

Michela De Mattia: That's definitely the hardest part. The key is expanding and diversifying the AI community itself. When AI safety remains confined to technical researchers and policy insiders, the language naturally stays abstract and insular. By bringing in educators, creative communicators, community organizers, and people from non-technical backgrounds, we can translate complex risks into everyday human impacts. Expanding the community lowers the barrier to entry, demystifies the concepts, and gives everyday people a sense of ownership over how this technology shapes their future.

Ravi Prajapati: What's the most common misconception you run into when you talk to people outside the field about AI risk?

Michela De Mattia: The biggest misconception is the idea that AI is either just a handy everyday assistant or pure hype. Most people outside the field view AI strictly through the lens of consumer convenience, using it to write emails or generate text, without giving a second thought to the underlying risks or how rapidly the backend architecture is evolving. They're still stuck in the mindset of "everyone is talking about AI because it's cool, but where is it actually happening?" They don't realize that autonomous agentic systems and deep infrastructure changes are already being deployed behind the scenes, creating real safety and security implications long before the average user even notices.

About Michela De Mattia

Michela De Mattia is an Italian-qualified lawyer with 7+ years of experience in Governance, Risk, and Compliance (GRC) across IT and financial services. My current focus is on AI governance research, AI vendor risk management and cross-border regulatory frameworks to mitigate frontier AI risks.

- LinkedIn: https://www.linkedin.com/in/michela-de-mattia/

This interview is part of ReadInBrief's AI People series, where we talk to AI founders and experts building at the edge of the industry. Have someone you'd like us to feature? hello@readinbrief.com or drop a message to Ravi Prajapati.

Comments (0)

No comments yet. Be the first to share your thoughts!

Leave a Reply