Question Keywords in the AI Governance Market
What 862 AI governance keywords show about buyer questions: definitions first, tasks later. Method and limits.
If you write about AI governance, security or regulation, the questions your reader asks come in a particular order. This post reports what a keyword pull showed about that order, how we cut the data, and where it stops being reliable. It reports counts we can reproduce and says so where a number is loose. It does not predict traffic.
The data and how we cut it
The source is a DataForSEO keyword set pulled on 6 October 2026, stored in the repository as docs/growth/seo/keyword-universe.csv. It has 6,872 rows. Each row has a modelled monthly search volume (we use the "baseline" column, which removes news spikes), a cluster, an inferred intent, and flags for the SERP features Google showed when we checked, such as People Also Ask (PAA) and AI Overviews. Volumes are modelled estimates, not measured traffic, and the set was seeded from product and topic terms, so it describes the markets we chose to look at rather than all searches.
To isolate the governance end of the market we matched keywords with a plain text pattern for governance, the EU AI Act, GDPR, ISO 42001, NIST, shadow AI, prompt injection, red teaming, AI risk, audit, human in the loop, HIPAA, DPIA, compliance, responsible AI, AI policy and MCP. That pattern is blunt. It picks up a few false matches (the phrase "ai actor" matches "ai act"), so read the totals as approximate. The picture it gives is stable enough to draw conclusions from; the third decimal place is not.
What the cut showed
The pattern matched 862 keywords carrying about 165,600 baseline monthly searches in total. Of those, 66 start with a question word, carrying about 8,400 searches, which is roughly one search in twenty. 541 of the 862 carry a People Also Ask flag, so the question boxes are present even where the query itself is not phrased as a question.
The question words themselves skew heavily toward definitions: 32 of the 66 start with "what" and 16 with "is", against 10 for "how". The largest question keywords, with their modelled monthly volume, are:
| Keyword | Volume | SERP features flagged |
|---|---|---|
| what is shadow ai | 1,900 | AIO, PAA, Video |
| what is prompt injection | 1,300 | AIO, PAA |
| what is ai governance | 1,000 | AIO, PAA, Video |
| what is red teaming in ai | 320 | AIO, PAA |
| what is the eu ai act | 320 | AIO, PAA |
| what is iso 42001 | 260 | AIO, PAA |
| how does prompt injection work in generative ai | 210 | AIO, PAA, Video |
| what is a prompt injection attack | 170 | AIO, PAA |
| what is dora compliance | 110 | AIO, PAA |
| what is nist ai rmf | 110 | AIO, PAA, Video |
| how to prevent prompt injection | 110 | AIO, PAA |
The pattern is consistent: the first question a buyer asks is "what is it", and the answer box (AIO) appears on all of them. The how-to questions show up further down, at lower volume, and mostly in security ("how to prevent prompt injection"), where there is a concrete task.
Below the questions sit the head terms that are not phrased as questions at all, and these carry the volume: "eu ai act" and "european ai act" at 8,100 each, "iso 42001" and "prompt injection" and "ai governance" at 5,400 each, "nist ai rmf" at 4,400, "shadow ai" at 3,600, "ai governance framework" at 1,650. Most people look for the topic by name first.
The smaller question keywords are revealing in a different way. Several are about named products and whether they meet a standard ("is otter ai hipaa compliant", 170; "is claude ai hipaa compliant", 90). Some read like exam or course questions ("why is a funded mandate critical to effective ai governance", 63; "how does maintaining an ai inventory support responsible governance", 61). These are real queries, and they show two audiences: practitioners asking about a tool, and people studying for a governance certification.
What we do with this
Lead with a definition, then hand over to a task. A page about the EU AI Act should answer "what is it" in the first paragraph, because that is the question with the answer box. Then it should move to what the reader has to do. That is the structure of our how to prepare for the EU AI Act guide: a short answer, then an inventory, a risk classification, and a list of obligations by role.
Own the head term and the how-to separately. "What is the EU AI Act" is an explainer. "How to prepare for it" is a workflow. They are different intents and should not share a page. We keep the explainers where they already are (for example the EU AI Act overview and the pages under /eu) and add the how-to as its own URL.
Answer product-compliance questions carefully or not at all. "Is X HIPAA compliant" is a question about a specific vendor's contracts and configuration. A page that says yes or no without evidence is wrong more often than it is right. Our rule is to describe what a customer has to check (a signed business associate agreement, the configuration, the data flow), not to rule on someone else's product. For our own claims we name what the founder has confirmed, and nothing more.
Use the SERP features as a reading list. Where PAA is present, we read the visible related questions and write FAQ entries from them. Where our search tool returned no PAA text (which was the usual case), we did not invent any, and used the keyword rows instead.
What each kind of question needs on the page
The three question types in this market want different things, and a page that tries to serve all three at once serves none.
"What is X" (shadow AI, prompt injection, ISO 42001). The reader wants a definition they can repeat to a colleague. Give it in two sentences, say what it is not, and name the closest neighbouring term, because confusion between neighbours (AI governance and AI compliance, for example) is half of what these searches are about. Then link to the task.
"How do I X" (prevent prompt injection, prepare for the AI Act). The reader has a deadline or an incident. Give prerequisites, the order of work, what to expect at each point and who needs to be involved. Say what you cannot promise: prompt injection cannot be fully prevented, only made harder and less damaging, and a page that says otherwise is not credible to anyone who has tried.
"Is X compliant" (is a given tool HIPAA compliant). The reader wants a yes or no. The honest answer is almost always "it depends on the contract and the configuration", and the useful page lists exactly what to check. Do not answer for a vendor you do not speak for.
A page can serve a definition and a task if it is long enough to hold both clearly, but our default is two pages with one pointing at the other, because each can then be updated on its own schedule: definitions rarely change, procedures often do.
Gaps this points to
Using the topic map we built to track coverage, the governance and compliance topics where the keyword data has clear demand and the site has no owner page for a given intent include checklists and templates for AI governance, a "what is" page for GDPR and AI, and a how-to for human approval of agent actions. The last of these we have now written: how to set up human approval for AI agents. The coverage report that lists the rest is generated by pnpm seo:coverage and stored beside the keyword data.
Limits
- Volumes are modelled, and small-volume rows (under about 100) are noisy.
- The pattern match is crude: it overcounts a little.
- A seeded keyword set cannot show you questions it was not seeded with. The absence of "step by step" keywords in the file tells you the file lacks them, not that nobody types them.
- Question keywords are a minority of searches. Do not retitle every page as a question: put the question in the H1 where the page really answers one, and keep noun-phrase titles where people search by name.
How to repeat this for your own market
- Export your keyword set with volume, intent and SERP features.
- Split question-form from everything else. Count both, by volume.
- Within the questions, separate "what is" from "how to" from "is X compliant".
- Check which questions already have an answer box. That is where a short, quotable answer matters most.
- Write the definition and the workflow as two pages, and link them.
- Re-pull in a quarter and compare, rather than trusting a single snapshot.
If you want to see the result, the how-to hub lists the governance, secure and comply guides. Start with how to govern AI agents or how to do a DPIA for AI.