Gabriel Goodhart
AI Governance & Applied AI
Summary
AI governance and applied AI leader with 25 years leading consequential work in regulated industries and direct experience building production AI systems since July 2023. Built 35 AI systems, put 25 into production, and designed three care-sector products around consent, privacy, auditability, evaluation, and human oversight. Turns technical failure modes into practical release conditions, monitoring actions, accountable owners, and evidence a cross-functional decision group can inspect.
Experience Across Regulated Operations
The AI work on this page sits on a 25-year operating career in regulated industries. Organizations, titles and dates below; references on request.
OOG Consulting, Oakland, CA
2014 – Present
President and Senior Project Manager
AI systems and AI governance practice · 2023 – Present
- Built and governed 35 AI systems since July 2023, including 25 in production, using evaluation, release, monitoring, consent, privacy, and human-oversight controls tied to explicit ship, revise, or stop decisions.
- Converted Stillwell's consent, identity, privacy, retention, and escalation requirements into a rule-to-control-to-test matrix and a 3,831-test release gate across 253 files that blocks policy violations before release.
- Designed three care-sector products around explicit data, function, authority, and evidence boundaries; trained non-technical owners in safe AI adoption with plain-language SOPs and risk guidance.
Regulated-industry risk and compliance programs · 2014 – 2022
- Led 10-plus-person multidisciplinary teams through regulated remediation decisions spanning legal, licensing, environmental, engineering, contractor, and operating constraints; delivered the project on budget.
- Built KPI and risk dashboards for live project auditing; a behavior-based safety and coaching program developed with the labor supervisor reduced workers' compensation claims dramatically in year one.
Oakland Farm & Feed, Oakland, CA
2007 – 2014
Managing Director
- Designed and brought to market fertigation technology that became an industry standard; the partnership with Dosatron led to a multimillion-dollar acquisition.
- Launched a product catalog that drove sustained year-over-year growth and more than doubled sales; negotiated 10+ vendor contracts.
Ameriprise Financial, San Francisco, CA
2001 – 2007
Corporate and High-Net-Worth Financial Planner
- Advised corporate and high-net-worth clients in a FINRA/SEC-regulated practice under strict suitability, privacy and documentation requirements.
- Held Series 7, 63 and 65 registrations plus California Life and Health licenses; exceeded asset and client acquisition targets every year and ranked in the top 10% nationally for relationship management and insurance-based risk management.
Education & Credentials
- B.A., Environmental Science, University of California, Santa Cruz
- B.A., Political Science, University of California, Santa Cruz
- IAPP AI Governance Professional (AIGP) candidate — enrolled August 2026.
- HIPAA Privacy and Security Awareness training certificate, HIPAAExams.com, August 2026.
- NIST AI Risk Management Framework (AI RMF) course certificate, Udemy, August 2026.
- CAHIMS candidate (Certified Associate in Healthcare Information and Management Systems, HIMSS) — application submitted August 2026.
Selected Work
A family answering line built so it cannot pretend to be a person, cannot be talked past by a persistent caller, and keeps no verbatim recording. Consent is checked at call time and revocation lands on the next call. I wrote its governing standard, then audited the code against it and published the gaps: 3,831 tests across 253 files, an 84-attack adversarial corpus with zero escapes, and a rule-to-control-to-test matrix where every partial cell is a named finding.
Consent enforced per call · fail-closed admission · no verbatim transcript · red-team CI · RUAIH self-assessment
Clients practise between sessions and their counsellor sees what was worked on, without the platform ever storing a free-text clinical note or a conversation transcript. Constraint set before the first feature, not retrofitted: synthetic data only until compliance sign-off, row-level isolation between practices, append-only consent and audit evidence, signed agreements gating any real-client use.
No clinical notes stored · row-level isolation · append-only consent evidence · BAAs gate real-client use
Plate Check — where the medical-device line is
AILIVE
It will not tell you what dose to take and cannot be talked into it: model output is screened before it reaches the screen, a dose-shaped sentence is removed surgically rather than the whole answer discarded, and the schema has no field a dose could live in. I read the statute, drew the device boundary, and deleted four features that crossed it — including the one users ask for most. Then scored the vision model against a labelled dataset, missed the target, and left the feature off.
Device-boundary analysis · HIPAA scoping memo · dose-language screening · labelled-dataset eval
agent-gate — safety fence for autonomous agents
AI
Stops a coding agent leaking secrets, deleting data, or claiming success without proof. Any edge it does not recognise halts the run rather than guessing. I then audited it against my own résumé and found I had overstated it; closing that and two other findings took the suite from 54 tests to 79.
Stdlib-only Python · deterministic rules · fail-closed · 79-test suite
Capabilities & Stack
Governance and lifecycle
Intake and risk tiering
Impact assessment
Release and change control
Monitoring and incident response
AI evaluation and observability
Dataset-backed evals
Reviewer calibration
Multi-model routing
Agent tool traces
Human override
Frameworks and delivery
NIST AI RMF
CHAI
ISO/IEC 42001 and 42005
Next.js
TypeScript
Supabase
Playwright