AI Governance & Risk Management

Covers legal frameworks for governing the use of AI, including compliance with emerging AI laws and standards, internal policies and oversight, documentation and auditing, and third‑party/vendor management. Addresses risk identification and mitigation across the AI lifecycle—privacy and data protection, bias and discrimination, transparency and explainability, cybersecurity, liability, and incident response.

3 posts
How to Draft an AI Vendor Contract Addendum to Meet the EU AI Act and Reduce Model Hallucination Liability in 2026

How to Draft an AI Vendor Contract Addendum to Meet the EU AI Act and Reduce Model Hallucination Liability in 2026

By 2026, an AI vendor addendum should hardwire EU AI Act obligations plus allocate hallucination risk through warranties, testing, audit rights, and indemnities. The EU AI Act’s risk-based duties will affect both EU deployments and many non-EU vendors supplying EU customers. This article provides a clause-by-clause drafting roadmap attorneys can use to reduce regulatory and […]
Read More
How to Build an AI Governance Program for California Law Firms Under the CPRA, ABA Model Rules, and SOC 2 Requirements

How to Build an AI Governance Program for California Law Firms Under the CPRA, ABA Model Rules, and SOC 2 Requirements

California law firms can build a defensible AI governance program in 30–90 days by combining a written CPRA compliance layer, ABA ethics controls, and SOC 2-style security evidence. The CPRA raises stakes for vendor risk, sensitive personal information, and data minimization, while ABA Model Rules require competence, confidentiality, supervision, and candid communications. This article provides […]
Read More
The EU AI Act Just Delayed — What American Companies Should Do Instead

The EU AI Act Just Delayed — What American Companies Should Do Instead

The EU AI Act’s key compliance deadlines have been pushed back, giving U.S. companies extra time—but not a free pass—to prepare. Despite the delay, expected obligations around high‑risk systems, governance, documentation, and transparency are still coming, and enforcement risk will grow as timelines firm up. This article explains what changed, what likely remains, and the […]
Read More
Scroll to Top