TL;DR: As GenAI safety responsibility shifts from Trust and Safety into Responsible AI and AI safety teams, ActiveFence’s Alice argues that T&S leaders risk losing budget, influence, and practical safety coverage unless they partner early, shape policy, and own post-launch monitoring. The underlying governance problem is not just organisational politics, but a widening gap between model testing and the real-world abuse patterns that emerge after deployment.
NHIMG editorial — based on content published by ActiveFence: Keeping Up with New Business Priorities, a crash course in GenAI safety for T&S professionals
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, 46% confirmed and 26% suspected.
Questions worth separating out
Q: How should security teams govern GenAI safety when Trust and Safety and AI teams are split?
A: They should assign explicit ownership for policy, abuse taxonomy, red teaming, monitoring, and enforcement before launch.
Q: Why do GenAI safety programmes need identity and user-behaviour controls?
A: Because many real-world failures happen after launch, when harmful users, repeated abuse patterns, and evasive behaviour emerge in production.
Q: What do organisations get wrong about AI safety and access control?
A: Organisations often focus on model outputs while ignoring the privileges behind the model.
Practitioner guidance
- Map GenAI safety ownership across teams Document which team owns policy, abuse taxonomy, red teaming, post-launch monitoring, and escalation so gaps do not emerge between Responsible AI and Trust and Safety.
- Co-author abuse taxonomies with safety and identity teams Build shared risk maps that include harmful content, evasion tactics, repeat-abuse patterns, and identity-linked enforcement triggers.
- Define post-launch monitoring as a control requirement Treat user flagging, investigation workflows, and behavioural scoring as part of the release criteria for any GenAI feature, not as a later enhancement.
What's in the full article
ActiveFence's full blog covers the operational detail this post intentionally leaves for the source:
- The article’s step-by-step breakdown of how T&S teams can map GenAI responsibilities to internal stakeholders and decision owners.
- The practical examples of policy development, filtering, and training-data collaboration that the source uses to show where teams lose influence.
- The discussion of post-launch mitigation systems, including user flagging, scoring, and incident handling in live GenAI environments.
- The source’s perspective on how T&S teams can stay relevant as AI safety budgets and ownership shift across the organisation.
👉 Read ActiveFence's analysis of GenAI safety, Trust and Safety, and AI governance →
GenAI safety governance is moving out of T&S teams: what now?
Explore further
Trust and Safety is becoming an identity-adjacent control layer in GenAI governance. The article shows that safety work is no longer confined to model quality or content moderation. Once platforms need to identify abusive users, score accounts, and connect behaviour to enforcement, Trust and Safety becomes part of the wider identity control plane. That is why IAM, identity verification, and access governance teams should treat AI safety as a shared operating model, not a separate specialist lane.
A question worth separating out:
Q: Who should own accountability for deployed AI agents?
A: Accountability should sit with the business or governance owner who can approve scope, review changes and retire the agent when it is no longer needed. Shared ownership without clear decision rights usually turns into no ownership, which is how agents become difficult to audit and even harder to decommission.
👉 Read our full editorial: GenAI safety is shifting budgets, roles, and governance power