Practice area 02
AI Governance and Ethics Consulting
Buying or building a model is a business decision with legal consequences attached. We help you make that decision deliberately, with a record of what the system does, what it was tested against, who approved it, and what happens when it gets something wrong.
Frameworks in scope
- EU AI Act
- NIST AI RMF
- ISO/IEC 42001
- Colorado AI Act
- State automated decision rules
AI risk assessments
Risk in AI is specific to the use, not the technology. The same model is unremarkable in one workflow and consequential in another, and the law increasingly turns on that distinction. We assess each use case on the terms regulators are adopting: what decision the system influences, about whom, with what consequence, and with what human involvement.
- Inventory of AI and automated decision systems in use, including the ones procured by business teams without engineering involvement.
- Classification against the EU AI Act risk tiers and the emerging US state rules on consequential decisions.
- Data provenance and training data review, including licensing, scraped sources, and personal data used for training or fine-tuning.
- Assessment of foreseeable harms, including accuracy, bias, explainability, security, and the effect of failure on the person on the other side of the decision.
Ethical frameworks that survive contact with a deadline
A set of principles that no one can apply is a liability, because it establishes a standard you are then measured against. We turn principles into decision rules: what is prohibited outright, what requires review, what requires disclosure to the affected person, and who is empowered to say no. The result is short enough to be read and specific enough to be used.
- Value statements translated into acceptable-use boundaries for each product line.
- A review path with named owners, defined thresholds, and a documented escalation route.
- Human oversight defined as a real intervention with authority, not a person nominally in the loop.
- Transparency language for users, customers and employees that says what the system does without overstating it.
Policy development and responsible implementation
Governance holds when it is wired into how software actually ships. We work with product and engineering to place controls at the points that already exist: intake, design review, procurement, testing, release, and incident handling. Where a control has no natural home, we build the smallest process that will still be followed a year from now.
- AI use policy for employees, covering permitted tools, prohibited inputs, and the handling of confidential and personal data.
- Development standards covering documentation, evaluation, versioning and change management.
- Procurement standards and contract terms for third-party models and AI-enabled vendors, including indemnities and audit rights.
- Incident handling for model failures, harmful outputs, and the discovery of prohibited training data.
Where AI governance meets privacy law
Most AI questions are also personal data questions. Training on customer records, inferring sensitive characteristics, profiling for eligibility decisions, and honouring deletion requests against a trained model are all governed by privacy law that already exists. Running the two disciplines from one desk avoids the common outcome where an AI committee approves something the privacy program has already prohibited.
What you receive
Work product, dated and defensible.
Every engagement in this area is scoped to end in artefacts you can hand to a regulator, a customer or an acquirer without rewriting them first.
- AI and automated decision system inventory
- Use-case risk classification and written assessments
- AI governance framework with defined review gates
- Employee AI use policy and development standards
- Vendor and model procurement requirements
- Board and customer-facing governance summary
How the engagement runs
Four stages, agreed before we start.
- 01
Find the systems
A structured inventory across product, operations, marketing and HR, including embedded AI features in tools you already licence.
- 02
Rank the exposure
Classify each use case by consequence and applicable regime, and separate the genuinely high-risk from the merely novel.
- 03
Build the framework
Draft policy, review gates and documentation standards, then test them against a live project rather than a hypothetical one.
- 04
Operate and review
Train the reviewers, sit in on early assessments, and revise the framework once real cases have gone through it.
Common questions
Asked before most engagements.
We only use third-party models through an API. Do we need governance?
Yes, and often more urgently. Using someone else’s model does not transfer your obligations to them. You still decide what data goes in, what the output is used for, and who is affected by it, and those are the points the law regulates.
Does the EU AI Act apply to a US company?
It can, where the system is placed on the EU market or its output is used in the EU. As with the GDPR, the analysis follows the use rather than the address. We work through it with you and document the conclusion either way.
Will this slow our engineering team down?
Governance slows a team down when it arrives at the end. Placed at intake and design review, it usually prevents the far more expensive interruption of pulling a feature after launch. We aim for review that takes days on the highest-risk work and minutes on everything else.
Related practice areas
- 01
Data Privacy Compliance
GDPR, CCPA and CPRA, HIPAA and the widening set of US state privacy laws, mapped to how your company actually handles personal data.
Read more - 03
Data Security and Breach Response
Incident response planning before an event, and counsel-led investigation, notification and regulator handling during one.
Read more - 04
Privacy Program Development and Management
The standing capability behind compliance: data mapping, assessments, governance and ongoing management, built to run without counsel in the room.
Read more
Governance before the model ships, not after.
Bring a use case you are unsure about. We will tell you how it classifies and what it would take to deploy it defensibly.