AI Governance · Enterprise Transformation

Governance isn't the brake on AI adoption. It's the engine.

Hi! I'm glad you're here. For over 15 years, I've dedicated my career to helping large, highly regulated organizations take change head on. First cloud, now AI. I was in Brussels when GDPR was taking shape, and now I'm fine-tuning that same paradigm for AI, turning the EU AI Act and frameworks like NIST AI RMF into competitive advantage for you and your organization.

15+ Years AWS · Microsoft · Thomson Reuters
J.D. EU Policy · Mergers & Acquisitions · IP
Brussels, 2015 Inside the Berlaymont as the EU set GDPR's path
Portrait of Rosa (RJ) Combs
Rosa (RJ) Combs, J.D. | AI Governance & Enterprise Transformation
About

Where policy, law, and enterprise execution meet.

I've built my career at the intersection of technology, law, operations, and organizational change. I've led AI adoption, cloud modernization, governance, and enterprise transformation for AWS, Microsoft, Thomson Reuters, federal agencies, and my own consulting firm. My work spans healthcare, financial services, judicial systems, and aerospace and defense.

My early policy experience was on Capitol Hill as a legislative assistant, where I conducted legislative research and drafted legislative language for bills that advanced to the House floor. I watched those bills debated before they were ultimately enacted into law. I later earned a J.D. focused on EU policy, international economics, mergers & acquisitions, and intellectual property.

In the summer of 2015, my legal studies took me inside the Berlaymont Building in Brussels, just two days before the Council of the European Union finalized the mandate that sent GDPR into its final negotiations. I didn't know the significance of the moment at the time. But that summer permanently changed how I think about compliance: not as a checklist, but as an ongoing relationship between organizations and the societies they serve. Some rooms you sit in shape how you view everything that comes after.

Throughout that period, I also led Requisite Capital Group, my own consulting practice. Upon relocating to the Netherlands, I expanded my international perspective and professional credentials. The Great Friction continues the independent body of work I began through that practice.

"When others don't open doors for you, you have to build your own doors to walk through."

Today, I work across four disciplines at once: technology, operations, law, and change management. Executives bring me in to translate strategic priorities into governance programs their teams can execute. That means operating models, executive cadences, and adoption strategies that move organizations from intent to measurable outcomes, not policy that remains on paper.

2022 – Present
Amazon Web Services
Senior Customer Solutions Manager, Global Accounts | Led enterprise modernization, governance, and adoption across a global MedTech portfolio spanning North America, Latin America, EMEA, and Asia-Pacific/Japan.
2021 – 2022
Glowforge
Senior Business Transformation Program Manager | Led international business transformation and embedded GDPR compliance across operations from a Netherlands base.
2014 – 2021
Requisite Capital Group LLC
Founder & Managing Director | Led digital transformation, process improvement, and technology-enabled operations engagements for public and private sector clients.
2018 – 2020
Microsoft
Senior Customer Success Manager, PubSec (National Security) | Led federal cloud adoption and transformation across national security environments.
2016 – 2018
Thomson Reuters
IT Business Analyst | Led legal technology implementation across state and territorial judicial systems.
2013 – 2014
National Credit Union Administration
IT Business Analyst and Program Management Contractor | Led the agency's largest technology modernization initiative.
Credential
Juris Doctor (J.D.)
EU policy, international economics, mergers & acquisitions, and intellectual property.

Governance Minute

My signature short-form format takes one breaking AI story and turns it into a 60–90-second practical governance lesson: no jargon, no hedging, one clear takeaway.

From the Workday AI hiring lawsuit:

"Buying an AI tool does not transfer accountability. It shares it. That's your Governance Minute."

Writing & Insights

The Great Friction: AI Governance Series

Practitioner-facing writing exploring where regulatory history, enterprise AI adoption, and accountability collide. From the EU AI Act's transparency obligations to the Shadow AI conversations already happening inside your organization, this work examines what these shifts mean and what to do next.

Editorial illustration of European institutional architecture in muted teal and gold tones
Flagship Essay · Published on LinkedIn

I Was in Brussels When GDPR Was Born. Here's What the EU AI Act Is Really Repeating.

In the summer of 2015, I stood inside the Berlaymont Building in Brussels, the seat of the European Commission, as a law student studying comparative international law. Two days after my program ended, the Council of the EU finalized the document that gave it the mandate to enter Trilogue and negotiate what became the General Data Protection Regulation.

What I did know, from six weeks of briefings across Paris, Strasbourg, Brussels, and London, was that something tectonic was shifting beneath the surface of European law, and that the United States had very little idea it was coming.

Read the full essay

The Room Where It Happened. The Comparative Law Program I participated in was not a tourist circuit: it was a structured immersion into the institutions shaping international law in real time. In Strasbourg, we sat inside the Grand Chamber courtroom of the European Court of Human Rights, and afterward Judge Nona Tsotsoria of Georgia took our group into a private chamber for a direct discussion. In Brussels, at the Justus Lipsius Building, home of the European Council, we were close to negotiations that had been deadlocked for three years, and briefed by attorneys at Steptoe & Johnson who walked us through the legislative landscape with the clarity you only get from practitioners watching a bill take shape in real time. Having spent time on Capitol Hill as a legislative assistant drafting legislation that became law, I recognized the texture of that room immediately. This wasn't theoretical. This was the machinery.

What I took away from those weeks was not a summary of GDPR's key articles. It was an understanding of the underlying tensions: who has jurisdiction over foreign companies, what constitutes a legitimate reason to process personal data, how high fines should be set before they actually change corporate behavior. And underneath all of it, a transatlantic fault line: the Safe Harbor Agreement, visibly under strain, was struck down by the Court of Justice of the EU that October in the Schrems I ruling.

The EU AI Act Is the Same Fight, Wearing Different Clothes. Now, working across GRC, AI governance, and regulatory compliance, I find myself reading the EU AI Act with an odd sense of familiarity. The territorial scope fight under Article 2, whether EU law should bind foreign companies whose AI systems affect EU residents, is the same argument as GDPR's Article 3. The EU's answer with GDPR was yes, and the enforcement record since then has demonstrated they meant it. The exemptions carved out for general-purpose AI models carry an uncomfortable resemblance to the "legitimate interest" loophole that consumed so much of the GDPR Trilogue. And the transatlantic tension that produced Safe Harbor's collapse in 2015, Privacy Shield's collapse in 2020, and the ongoing fragility of the EU-U.S. Data Privacy Framework is now playing out in AI governance divergence. The EU is building a risk-tiered regulatory architecture. The United States is not.

What Practitioners Need to Carry Forward. The organizations that navigated GDPR most effectively were not the ones that waited for the regulation to take final shape before beginning their work. They were the ones that understood the intent behind the rules: the values, the fears, the political compromises, and built governance programs durable enough to absorb the details as they evolved. The EU AI Act is in a similar position now. The text is finalized, but the standards, implementing acts, and enforcement precedents are still being written. The practitioners who will be most effective are those who understand why these rules exist, not just what they require.

Some rooms you sit in shape how you view everything that comes after. That summer spent in Europe was one of mine. If you're working on EU AI Act readiness, GDPR compliance, or cross-jurisdictional governance, I'd welcome the conversation.

Enterprise AI Governance Series

An ongoing series on making AI governance operational inside real enterprises, exploring why guardrails accelerate adoption instead of slowing it down. Grounded in ISO/IEC 42001 and the NIST AI RMF GOVERN function.

"Governance Doesn't Slow AI Adoption. It Makes It Possible."

Governance in the Wild

A governance intelligence brief for CPOs, Legal, and Risk, mapping current AI developments to the EU AI Act, GDPR, NIST AI RMF, and ISO/IEC 42001, with each edition closing with a practical governance lesson.

Governance Brief Top 5

Global Regulatory Horizon Scan

A 24-month executive scan of GDPR, the EU AI Act, and cross-border data protection signals. Current coverage includes Article 50's machine-readable marking obligations and the limited grace period through December 2, 2026, for qualifying generative AI systems placed on the market before August 2, 2026.

12-Signal Tracker Regulatory Outlook
Career One-Pager

Fifteen years, five industries, one throughline

Enterprise transformation, AI governance, and cloud modernization across aerospace and defense, healthcare, financial services, judicial systems, and the public sector, condensed.

Rosa (RJ) Combs, J.D.

Enterprise Transformation & AI Governance Leader · Salt Lake City, UT

Request Full Résumé
Enterprise Impact
  • AWS | Directed $90M+ in enterprise modernization roadmaps across a global MedTech portfolio spanning North America, Latin America, EMEA, and Asia-Pacific/Japan, aligning technology investments, governance, and executive priorities across Corporate IT, MedTech, supply chain, and manufacturing.
  • Glowforge | Expanded warranty revenue while embedding GDPR compliance across international operations.
  • Requisite Capital Group | Founded and led an independent consulting practice delivering digital transformation and technology-enabled operations engagements for public- and private-sector clients, including federal modernization work.
  • Microsoft | Directed cloud adoption and federal contract governance for DoD and DOJ customers, including a global defense and aerospace organization, aligning technology strategy with mission-critical national security requirements.
  • Thomson Reuters | Reversed a prior lost bid to win a $3M+ multiyear contract with the Superior Court of the Virgin Islands and led the implementation through go-live and adoption.
  • NCUA | Led the agency's largest IT modernization and trained 1,250+ employees; delivered the RFP its CIO called the best the department had ever produced.
Core Expertise
  • AI governance & regulatory translation: EU AI Act, GDPR, NIST AI RMF, ISO/IEC 42001
  • Enterprise cloud & AI adoption strategy across regulated industries
  • Governance forums, executive steering committees, and operating model design
  • M&A technology integration and cross-border business transformation
  • Contract negotiation, commercial governance, and executive stakeholder alignment
  • Public speaking, executive communications, and change management leadership
Credentials
  • Juris Doctor (J.D.) | EU policy, international economics, mergers & acquisitions, and intellectual property
  • AWS Certified Solutions Architect
  • PROSCI Certification
  • MIT Digital Transformation Credential
  • International Association of Privacy Professionals (IAPP), Artificial Intelligence Governance Professional (AIGP) certification: Pending

Services are educational and strategic and do not constitute legal advice.

$90M+Modernization roadmaps directed
2,500+End users trained
$30B+M&A technology integration
5Regulated industries navigated
Speaking

Talks & workshops

Session concepts built for conferences, executive briefings, and enterprise learning programs, drawn from the same governance work covered in the series above. Open to keynotes, panels, and workshop formats.

01

After August 2: What Article 50 Requires Now

A practical walkthrough of machine-readable content marking, AI-interaction disclosures, and biometric notification obligations now in effect, including the limited December 2026 transition for Article 50(2) marking and detection duties for systems placed on the market before August 2, 2026.

EU AI ActCurrent RequirementsKeynote
02

Governance Doesn't Slow AI Adoption: It Makes It Possible

Why clear guardrails and approved pathways move AI initiatives faster than an open field, using ISO/IEC 42001 and the NIST AI RMF GOVERN function as the operating backbone.

AI GovernanceEnterprise AdoptionWorkshop
03

From GDPR to the AI Act: Lessons From Inside Brussels

A first-person account of being inside the Berlaymont in 2015, two days before the Council cleared the way for GDPR's Trilogue negotiations, and the structural parallels emerging in EU AI Act implementation today, for legal, compliance, and policy audiences.

EU RegulationFireside / Panel
04

Shadow AI: Turning an Enablement Failure Into a Governance Win

Why unsanctioned AI use inside organizations is a symptom of missing pathways, not a discipline problem, and how to convert it into a compliant adoption program.

Shadow AIRisk & Compliance
05

Ethical AI: Reasoning, Responsibility, and Real-World Practice

A case-based curriculum spanning healthcare, legal, and consulting AI failures, teaching accountability and what to do when AI systems cause or amplify harm, for L&D leaders and academic partners alike.

AI EthicsCurriculum Design
06

Governance Minute Live

An interactive workshop format that takes top AI headlines from around the globe and translates them into a governance action in real time, 60 to 90 seconds at a time.

Interactive WorkshopLive Format

Let's talk governance.

Whether you're preparing for the EU AI Act, building an AI governance program from scratch, or looking for a speaker who's translated GDPR-scale regulatory change before, I'd welcome the conversation.