Loading…
Loading…

AI Expert
Johnie T Young is an AI expert and governance practitioner with deep experience helping fast-moving technology companies implement responsible AI practices at small-team scale. With a focus on practical, actionable frameworks, Johnie built AI Policy Desk to close the gap between enterprise-grade compliance tooling and the real-world needs of lean product teams. Before founding AI Policy Desk, Johnie worked across a range of technology companies advising on AI risk management, GDPR readiness, and EU AI Act compliance. With the rapid emergence of AI regulation globally, Johnie identified a clear need: governance resources written for 10-person teams, not Fortune 500 legal departments — practical templates, checklists, and guides that teams can pick up and use today.
322 articles by Johnie T Young
EU AI Act compliance small teams -- high-risk deadline moved to Dec 2, 2027; GPAI rules still enforce Aug 2, 2026. Classify your AI use case now.
AI credit and lending decisions trigger CFPB adverse action notice requirements, FCRA accuracy obligations, and EU AI Act high-risk classification. Templates and compliance steps.
HR AI governance for hiring decisions: EU AI Act high-risk rules hit by Dec 2027, EEOC bars disparate impact. Assessments, bias tests, disclosure required.
5 AI APIs that don't train on your data: Claude, Azure OpenAI, Vertex AI, Mistral, OpenAI API. DPA links, EU data residency, zero-retention configs included.
4 TypeScript modules for AI agent security: injection guard, circuit breaker, audit logger, tool auth gate. Drop into Express or Next.js. Vitest tested.
Small health‑care teams face a growing maze of federal and state national security rules that tighten health data security, demanding compliance strategies
DOJ's Bulk Data Rule compels small health teams to keep data in the US, ban foreign tools, and enforce health data security as security laws tighten.
AI supply chain attacks: contractor gets infected, tokens stolen, your systems hit. Checklist to map vendor exposure, scope access, and respond within 24 hours.
AI features in VDRs create data handling and compliance obligations. Access controls, training opt-outs, and audit log requirements before enabling VDR AI.
30-question AI vendor due diligence checklist: security, data handling, compliance, and contract terms. Pass/fail criteria for each. Copy into your review.
Which box do you check? Copy the exact Amazon KDP AI disclosure wording for text, images, and translations, plus a 3-question decision flowchart.
Copilot and Cursor send source code to vendor servers. IP risk, licensing exposure, and the org settings and policy rules engineering teams need to govern this.