Carnegie Mellon expands pioneering Privacy Engineering program to include AI Governance

Michael Cunningham

Sep 1, 2026

group photo of Carnegie Mellon University Privacy Engineering and AI Governance students and faculty members posing in front of a vintage trolley on display at the Heinz History Center

As artificial intelligence reshapes how organizations collect data, build products, and make decisions, the professionals responsible for protecting privacy are increasingly being asked to also contribute to and even coordinate AI governance activities, identifying key risks and mitigation strategies while working alongside other relevant roles in the enterprise. 

Carnegie Mellon is preparing students to respond to those challenges through the newly renamed Privacy Engineering and AI Governance program, an evolution of its pioneering graduate program in Privacy Engineering.

The change reflects both the rapid transformation of the field and an evolution that had already taken place throughout the program’s curriculum over the years. Privacy engineers working across industry, government, consulting, and nonprofit organizations are increasingly being called upon to help establish and operate AI governance programs alongside their traditional privacy responsibilities.

“At the end of the day, it’s the recognition that people who were being trained in privacy engineering were also being asked to deal with AI governance issues,” said Norman Sadeh, co-director of the Privacy Engineering and AI Governance program.

That transition is a natural one, Sadeh said, because privacy engineering already requires professionals to identify risks, evaluate how technologies affect people, interpret regulations, and develop practical ways to reduce potential harms. Those same skills are increasingly essential for governing AI.

“AI governance is not a thing that lives in a vacuum,” said Sadeh. “It has to be integrated into all your other governance processes, including everything that you have in privacy.”

The new name formalizes changes that have been underway for years.

AI-related topics are already woven throughout courses in the program, covering areas including AI regulation, fairness, explainability, red teaming, model alignment, all the way to  risks associated with the rapid adoption of agentic AI.

The program also teaches students systematic approaches for identifying, assessing and mitigating risks throughout the design and deployment of AI-enabled products and services.

“You cannot do cybersecurity or privacy without thinking about what AI means, both in terms of risks and capabilities,” said Sadeh.

One of the most visible changes involves the program’s Responsible AI and AI Governance course. Introduced by Sadeh several years ago as an elective, the course quickly became one of the program’s most popular offerings and was taken by the vast majority of students. Beginning with the rebranded program, it is now a required course.

Sadeh said students have also reported that their experience in the course helped them secure jobs as employers increasingly look for professionals capable of working across privacy, data governance, and responsible AI. The broader curriculum prepares students to recognize potential problems and understand the range of technical, organizational, and regulatory tools available to address them.

AI governance is not a thing that lives in a vacuum.

Norman Sadeh, co-director, Carnegie Mellon University Privacy Engineering and AI Governance program

Over the years,  longstanding program courses have been gradually updated to keep up with the increasingly prominent role played by AI. For example, the program’s required “Information Security, Privacy, and Policy” course has been renamed “Information Security, Privacy, and Policy in the Age of AI,” reflecting the extent to which artificial intelligence now shapes discussions throughout the course.

“As students and practitioners, we must understand how AI is enabling bad actors to scale their attacks and operate at unprecedented tempos,” said Sadeh. “We discuss ways that AI can also be used to more quickly identify vulnerabilities in your systems and patch these vulnerabilities - both security and privacy vulnerabilities.”

Carnegie Mellon launched its Privacy Engineering program more than a decade ago in response to conversations with industry leaders who saw a need for professionals who could translate privacy principles into the design and operation of real-world systems.

Since then, the curriculum has continued to evolve through interactions with employers, sponsors, students, and alumni. Graduates of the program have gone on to careers at major technology companies as well as consulting firms, government agencies, and nonprofit organizations.

Sadeh said that the program’s evolution has always been closely tied to what organizations need from graduates in the workplace. Today, that increasingly means understanding AI.

The rebranding is intended in part to make those capabilities clearer to employers when graduates enter the job market. Rather than suggesting that students have been trained only in traditional privacy engineering, the new name more accurately communicates their experience assessing the broader legal, ethical, social and technical risks created by AI.

The evolution also comes as Carnegie Mellon expands the ways students and working professionals can receive that training.

The university now offers the Master of Science in Privacy Engineering and AI Governance, as well as the Master of Science in Privacy Technology and AI Governance, which includes a fully remote option designed for professionals who want to continue working while earning their degree.

For those who cannot commit to a full master’s program, Carnegie Mellon also offers a five-weekend, fully remote Privacy Engineering and AI Governance Certificate. The certificate provides a more concentrated introduction to the major technologies, regulations, and trends shaping privacy and AI governance, particularly for professionals seeking broader knowledge of the field without pursuing a full graduate degree.

The different formats are intended to serve people at different stages of their careers. Some students are seeking to pivot from backgrounds such as computer science, software engineering, or information systems into privacy, compliance, and AI governance. Others are already working in those areas but want more formal training to keep pace with technologies that have changed dramatically in recent years.

“There’s been so much change over the past 10 years in terms of regulations, technologies, and the impact of AI,” said Sadeh. “It’s a very different landscape.”