Loading…
Loading…
Super Intelligence definition proposal due (60 days) · Nov 28, 2026 · See what changes

AI Expert
Johnie T Young is an AI expert and governance practitioner with deep experience helping fast-moving technology companies implement responsible AI practices at small-team scale. With a focus on practical, actionable frameworks, Johnie built AI Policy Desk to close the gap between enterprise-grade compliance tooling and the real-world needs of lean product teams. Before founding AI Policy Desk, Johnie worked across a range of technology companies advising on AI risk management, GDPR readiness, and EU AI Act compliance. With the rapid emergence of AI regulation globally, Johnie identified a clear need: governance resources written for 10-person teams, not Fortune 500 legal departments — practical templates, checklists, and guides that teams can pick up and use today.
376 articles by Johnie T Young
ChatGPT Dreaming V3 persists your team's data across sessions. GDPR Article 17 applies. 4 enterprise actions: audit, disable, and update your vendor DPA.
Shadow AI adds $670K to breach costs, and small teams have the highest exposure. How to detect unsanctioned AI tools and govern them without an IT team.
Which AI red-teaming security testing requirements apply in 2026? NIST AI 600-1 explained, plus how small teams run a testing program.
Which 12 training data disclosures does California AB 2013 require? AI training data transparency rules, who's covered, and the failed xAI suit.
AI governance for legal teams and general counsel: check these 3 2026 risks before privilege waiver, ethics violations, or sanctions hit your firm.
Amazon scrapped KiroRank after staff gamed it with tokenmaxxing. Build AI adoption metrics that reward outcomes, not fake usage volume.
Which AI tools trigger BIPA in 2026? Facial recognition, voice, and video-interview tools need written consent, a retention schedule, and a no-sale rule.
Colorado replaced its original AI Act with SB 26-189, signed May 14, 2026. The new law drops bias audits and impact assessments in favor of a lighter notice-and-transparency framework. Effective January 1, 2027, it requires pre-use notice, post-adverse-action notice within 30 days, and 3-year recordkeeping for any employer using AI in hiring, promotions, or terminations.
A self-spreading worm compromised 57 npm packages in under 2 hours using binding.gyp instead of postinstall scripts, bypassing security scanners. What it means for teams that run npm install, and the 5 controls that limit your exposure.
Hackers social-engineered Meta AI into resetting passwords on high-profile Instagram accounts by simply asking. What the attack means for any team deploying an AI chatbot that can take account actions, and the 6 controls that prevent it.
EU AI Act Omnibus confirmed June 29, 2026 -- standalone high-risk to Dec 2, 2027, embedded products to Aug 2, 2028. Article 50 still applies Aug 2, 2026.
Reviewing AI-generated pull requests? Follow this 9-point checklist for who signs off, what to require, and where AI code fails review.