Loading…
Loading…

AI Expert
Johnie T Young is an AI expert and governance practitioner with deep experience helping fast-moving technology companies implement responsible AI practices at small-team scale. With a focus on practical, actionable frameworks, Johnie built AI Policy Desk to close the gap between enterprise-grade compliance tooling and the real-world needs of lean product teams. Before founding AI Policy Desk, Johnie worked across a range of technology companies advising on AI risk management, GDPR readiness, and EU AI Act compliance. With the rapid emergence of AI regulation globally, Johnie identified a clear need: governance resources written for 10-person teams, not Fortune 500 legal departments — practical templates, checklists, and guides that teams can pick up and use today.
322 articles by Johnie T Young
July 2 deadline: Treasury, NSA, and CISA must stand up the AI cybersecurity clearinghouse today. Who it covers and what to check now.
Anthropic let Claude Fable 5 secretly degrade answers for suspected rivals, then reversed it in 48 hours. What that says about AI vendor trust.
8 agentic AI vendor contract clauses you need for 2026: action boundaries, audit trails, and liability terms standard SaaS contracts miss.
California ADMT rules require pre-use notices and risk assessments for AI used in hiring by Jan 1, 2027. Copy-paste templates for employers inside.
13-point vendor dependency checklist: is your team exposed if Anthropic cuts Claude access again? Includes a 5-step AI contingency plan.
When an AI system causes harm, misclassifies a person, leaks data, or fails in a high-stakes context, regulators expect a documented incident response process. EU AI Act Article 73, GDPR Article 33, and state AI laws all impose notification timelines. Here is what an AI-specific incident response plan must cover.
The EU AI Act Annex III high-risk AI deadline is December 2, 2027 (extended by Digital Omnibus, May 2026). If your team has not started, this compliance roadmap covers the five steps to reach minimum viable compliance: inventory, classify, document, conformity assessment, and monitoring.
Connecticut's SB 4 (Public Act 26-64) takes effect July 1, 2026, dropping the CTDPA coverage threshold from 100,000 to 35,000 consumers and adding two new no-threshold triggers. Here is what small teams need to check today.
11 AI vendors compared: which ones train on your business data in 2026? See opt-out steps for ChatGPT, Copilot, and Atlassian's August deadline.
6 vendor risk checklist questions for small teams after Russia's SDA leaked plans to poison AI training data at scale. Bloomberg's June 2026 report.
The White House asked OpenAI to stagger GPT-5.6 access customer by customer in June 2026, a first for preemptive US government AI model restrictions. Here are 5 procurement policy updates compliance teams should make now.
Need an AI compliance checklist by team size? Use 3 tiers (1-10, 11-50, 51-200) with clear triggers for when to add vendor and incident response steps.