Cybersecurity professional researching and building at the intersection of artificial intelligence, governance, risk, and compliance. Founder of AIxGRC and graduate student at Georgetown University studying AI governance and cybersecurity policy.
Olivia Athelus is a cybersecurity professional focused on artificial intelligence governance, risk management, and responsible technology oversight.
She created AIxGRC as a platform to document research, frameworks, and projects exploring how organizations can responsibly deploy AI while aligning with global governance standards such as the NIST AI Risk Management Framework, ISO/IEC 42001, and emerging regulatory policies.
Olivia is currently pursuing graduate studies at Georgetown University, where her research focuses on AI governance, cybersecurity policy, and regulatory risk management. Her long-term work explores how AI governance intersects with ethics, public policy, and high-impact sectors such as healthcare.
Projects, research, and whitepapers built through academic coursework, independent study, and the AIxGRC brand.
A deep-dive whitepaper analyzing how the EU AI Act's high-risk classification applies to biometric retail AI — using Sephora as a case study.
Research mapping PCI DSS, SOC 2, and ISO 27001 requirements onto AI systems in financial services — credit scoring, fraud detection, and risk modeling.
Analysis of emotional AI chatbot case studies — examining where ethical design failed and what responsible safeguards look like for at-risk populations.
Comparative mapping of NIST AI RMF, ISO 42001, and the EU AI Act — identifying overlaps, gaps, and practical implementation priorities for organizations.
A practitioner-ready AI risk assessment template built on NIST AI RMF principles, designed for teams beginning their AI governance journey.
Graduate-level research project in progress. Details to be shared upon completion. Topics span AI policy, risk governance, and regulatory compliance.
How Sephora's virtual try-on and biometric AI tools come under the EU AI Act's high-risk classification — and what responsible retail AI compliance looks like in practice.
A practical GRC guide to translating PCI DSS, SOC 2, and ISO 27001 for AI systems in credit, fraud detection, and financial risk modeling.
A technical exploration of how AI pipelines can be simulated and stress-tested using gates, feedback loops, and batch processing patterns.
A look at what I'm building next — ongoing projects, planned research, and future directions for the AIxGRC brand.
Publishing in-depth whitepapers on AI governance topics — starting with EU AI Act compliance and financial AI security alignment.
Building open, practitioner-ready templates — AI risk assessment tools, policy frameworks, and audit checklists grounded in NIST and ISO standards.
Real-world AI governance analyses across industries — retail, finance, healthcare, and the public sector — applying regulatory frameworks to actual deployments.
Sharing academic research and capstone work from Georgetown University as it develops — connecting theory to practice in AI policy and risk governance.
The regulatory and risk management frameworks that form the foundation of my research and applied work in AI governance.
The National Institute of Standards and Technology AI Risk Management Framework — a voluntary, flexible framework for managing risk throughout the AI lifecycle.
The international standard for AI management systems — providing requirements and guidance for responsible development, deployment, and governance of AI.
The European Union's landmark AI regulation applying a risk-based classification system to AI systems, with binding obligations for high-risk deployments.
The globally recognized standard for information security management systems — foundational for securing the data and infrastructure underpinning AI systems.
The AICPA trust services framework evaluating security, availability, processing integrity, confidentiality, and privacy — critical for AI-powered SaaS platforms.
Payment Card Industry Data Security Standards — applicable wherever AI systems process, transmit, or store cardholder data in financial services contexts.
Monitoring emerging AI regulations across the U.S., UK, Canada, and beyond — including executive orders, sector-specific rules, and proposed legislative frameworks.
I'm always open to conversations about AI governance, research collaborations, speaking opportunities, or just connecting with others in the GRC space. Reach out — I'd love to hear from you.