Maja Kurek
Founder & Principal, RuleBridge Advisory — AIGP · CIPM · CIPP/E
Maja Kurek has spent her career on the receiving end of regulation — close to a decade inside supervised technology organisations that had to make it work. At Google, Photomath and Uber, regulation was never a document but an operating condition. Her mandates sat where new and evolving rules met live, cross-border operations: converting obligations into processes, controls, documented decisions and evidence that hold up under scrutiny, while the platforms kept running.
The result is a particular kind of judgement: which function can actually carry an obligation, what will change in daily operations, what evidence will exist, and where an arrangement will break under pressure. At RuleBridge, she applies that operator’s discipline to AI governance — where the same questions determine whether formal responsibility holds in practice.
Experience behind the practice.
1. Governance of a distributed expert ecosystem — Photomath
Behind Photomath’s AI product stood more than 10,000 external mathematics experts — the human layer of an AI-powered learning product, at scale. Maja governed that global network’s full lifecycle: who was admitted, and on what competence; what each expert could access, and on what basis; how requirements reached ten thousand people in a form they could act on; how work was paid securely across borders and the data around it protected; and how access ended when it had to — with controls strengthened as the rules around the network kept changing.
2. Governance-sensitive integration and transition — Photomath → Google
Following Google’s acquisition of Photomath, an operation that already worked had to be carried into the control environment of one of the most heavily supervised technology companies in the world — without being interrupted. Maja led her team’s integration and substantial content migration into Google’s systems — a regulated transition of content and data, carried out under the EU’s New Deal for Consumers standards and related regulatory requirements to mitigate legal risk. She also supported the coordinated transition of the Photomath platform and its expert network to a new vendor, with payment security, data protection and cross-border regulatory requirements held throughout.
3. Regulated platform adaptation — Uber
At Uber, Maja worked inside a business as its regulatory environment moved from contested status to formal regulation. As transport, tax and labour requirements arrived and changed, she led a cross-functional programme adapting operations to them, and designed and implemented the compliance processes through which an ecosystem of independent fleet partners was brought into line while the rules were still moving. The work meant translating each obligation into partner-facing processes, payment compliance, vendor service levels and monitoring routines that had to hold at scale, under public and regulatory attention, without interrupting the service.
Across these environments, the recurring challenge was never simply to interpret a requirement, but to make responsibility workable across functions, systems and external parties — controls over data and access, payment safeguards, vendor and third-party accountability, documentation, evidence and continuity — and to keep it working through change. Frameworks name these controls; she has operated them. That is the operating layer from which Maja approaches AI governance.
Selected AI-governance work.
Maja developed and published AI Change Accountability & Reauthorisation, a practitioner-derived, organisation-side method that traces one AI change from signal to actual authority, a current decision, assigned action and evidence of closure.
She applied it in a first organisational field pilot on a real AI consolidation initiative, working directly with the organisation’s actual decision-makers. Her working paper, Governing AI After Deployment, contributes field evidence on how post-deployment AI change travels across provider, platform, configuration and organisational-authority boundaries — and what must connect technical visibility or rollback to a current, owned and evidenced response.
- AIGP — Artificial Intelligence Governance Professional (IAPP)
- CIPM — Certified Information Privacy Manager (IAPP)
- CIPP/E — Certified Information Privacy Professional / Europe (IAPP)
- Master’s degree in Business Economics, Management
At RuleBridge, that experience is applied to one discipline: operational accountability for AI.