The first question any AI regulator asks is where the training data came from. According to this survey, roughly four in five organisations cannot answer it.
Short answer: 78% of organisations cannot validate data before it enters AI training pipelines and 77% cannot trace where it came from, according to the Kiteworks 2026 forecast report. That gap is why data governance roles are being hired against.
Key takeaways
- The Kiteworks 2026 Data Security, Compliance and Risk Forecast Report surveyed organisations across six core training data governance capabilities. It found 78% cannot validate data before.
- 50 live listings in this category publish a rate, at a median top-of-range of $120 an hour and a ceiling of $170.
- The work is remote contract work, asynchronous, with no set hours and no guaranteed volume.
- Applications screen on a short skills assessment rather than a resume or interview.
What was reported
The finding
The Kiteworks 2026 Data Security, Compliance and Risk Forecast Report surveyed organisations across six core training data governance capabilities. It found 78% cannot validate data before it enters AI training pipelines and 77% cannot trace where their training data originated, meaning they cannot demonstrate to a regulator that the data feeding their AI systems meets quality, legality or consent requirements. Further gaps: 65% lack dataset access controls, 62% cannot demonstrate data minimisation practices for AI, and 59% do not encrypt training data. Colorado's AI Act and California's CCPA rules impose mandatory risk assessments, transparency and controls for high-risk AI systems from 2026 to 2027.
Kiteworks measured six governance capabilities and found failures across all of them: 78% cannot validate data before it enters training pipelines, 77% cannot trace its origin, 65% lack dataset access controls, 62% cannot demonstrate data minimisation, and 59% do not encrypt training data at all. These are not aspirational gaps. They are the specific things enforcement will test.
What the listings pay
The timing is what makes it a hiring problem rather than a reporting one. Colorado's AI Act and California's CCPA rules impose mandatory risk assessments, transparency and controls for high-risk systems across 2026 to 2027, and the EU AI Act's high-risk requirements became enforceable in August 2026.
| # | Role | Advertised rate | Platform |
|---|---|---|---|
| 1 | Clinical Regulatory Expert | $130 to $170 an hour | Mercor |
| 2 | Legal / Commercial Expert | $80 to $160 an hour | Mercor |
| 3 | Legal Expert: Tier 1 Specialist (Project Donna) | $150 to $150 an hour | Mercor |
| 4 | Partner & General Counsel - Legal Domain Expert | $100 to $150 an hour | Mercor |
| 5 | Compliance Attorney | $90 to $150 an hour | micro1 |
| 6 | Australian Legal Expert | $120 to $140 an hour | Mercor |
| 7 | Legal Expert: Disputes & International, UK (Project Donna) | $130 to $130 an hour | Mercor |
| 8 | Securities & Wealth-Management Compliance / Supervisory Analyst | $100 to $130 an hour | Mercor |
| 9 | Legal Expert: Corporate & Capital Markets (Project Donna) | $100 to $120 an hour | Mercor |
| 10 | Senior Counsel, Legal Domain Expert | $85 to $120 an hour | Mercor |
Source: 50 live listings on this board that publish a rate, read directly from each posting on 2026-09-06. Listings without a published rate are excluded rather than estimated.

How this compares across the board
A rate only means something next to the alternatives. This is every category we track with at least five listings publishing a rate, ranked by median top-of-range, so you can see where this work sits rather than taking a single number on trust.
| Category | Listings | Median low | Median top | Highest |
|---|---|---|---|---|
| Legal | 95 | $100 | $140 | $400 |
| Medical | 68 | $77 | $120 | $400 |
| Consulting | 45 | $80 | $120 | $280 |
| Finance | 94 | $80 | $110 | $280 |
| Engineering | 114 | $70 | $100 | $300 |
| Research/PhD | 132 | $70 | $90 | $280 |
| Writing | 36 | $40 | $80 | $280 |
| Bilingual | 78 | $44 | $52 | $120 |
| Annotation | 25 | $12 | $24 | $120 |
Same source and date as above. Categories are matched on listing title, so a role can appear in more than one.
What it means for you
Across 50 live compliance, privacy and governance listings on our board that publish a rate, the median top-of-range is $120 an hour, reaching $170. This category rewards people who can read a regulation and translate it into a control, which is a rarer combination than either skill alone.
Why provenance is the hard part
Validating data before it enters a pipeline requires knowing what the data is, where it came from, and what permissions attached to it. Most organisations assembled their training corpora before anyone asked those questions.
Retrofitting provenance onto an existing corpus is genuinely difficult work. It means auditing sources, reconstructing consent chains, and in some cases concluding that a dataset cannot be defended and has to be removed. That is expensive, which is why 77% have not done it.
It is also why the work is being outsourced to people who have done regulatory evidence work before. The task is closer to an audit than to engineering.
What the roles actually ask for
Most listings in this category want a mix that is unusual: enough legal literacy to read a regulation precisely, and enough technical fluency to understand how a data pipeline works. Neither alone is sufficient.
Backgrounds that map well include privacy counsel, data protection officers, internal audit, information governance, and compliance analysts from regulated industries. Employment or sector-specific regulatory experience raises your rate because jurisdiction-specific knowledge is what models handle worst.
Certifications help with matching but are rarely the gate. Demonstrated experience translating a rule into a testable control is what the assessment looks for.
Who should apply
Two checks before you spend time on an application. Confirm the role accepts applicants from your country with the eligibility checker, since a meaningful share of listings carry location requirements. Then run the advertised rate through the take-home calculator, because this is contract work and the headline figure is before self-employment tax.
Applications complete on the hiring platform and usually take a few minutes, with a short skills assessment in place of an interview. Fill in every credential, language and professional background field on your profile. Those are what route you to the better paid listings, and most applicants leave them blank.
Frequently asked questions
What did the Kiteworks survey find?
78% of organisations cannot validate data before it enters AI training pipelines and 77% cannot trace where their training data originated.
What other gaps were found?
65% lack dataset access controls, 62% cannot demonstrate data minimisation practices for AI, and 59% do not encrypt training data.
Why does this matter now?
Colorado's AI Act and California's CCPA rules impose mandatory risk assessments and controls for high-risk AI systems across 2026 to 2027, and the EU AI Act's high-risk requirements became enforceable in August 2026.
What does compliance AI work pay?
Across 50 live compliance and governance listings publishing a rate, the median top-of-range is $120 an hour, reaching $170.
What background do these roles want?
A combination of legal literacy and technical fluency. Privacy counsel, data protection officers, internal audit and compliance analysts from regulated industries all map well.
Do I need a certification?
Rarely the gate. Demonstrated experience turning a regulation into a testable control is what the assessment looks for.
Is this work remote?
Yes, and asynchronous. Like the rest of the board it is contract work with no set hours, so it fits alongside an existing role subject to your employer's outside-work policy.
Sources
See every live role
The full board updates several times a week, with the advertised rate on each listing and closed roles removed.