Loading…
Loading…

AI Expert
Johnie T Young is an AI expert and governance practitioner with deep experience helping fast-moving technology companies implement responsible AI practices at small-team scale. With a focus on practical, actionable frameworks, Johnie built AI Policy Desk to close the gap between enterprise-grade compliance tooling and the real-world needs of lean product teams. Before founding AI Policy Desk, Johnie worked across a range of technology companies advising on AI risk management, GDPR readiness, and EU AI Act compliance. With the rapid emergence of AI regulation globally, Johnie identified a clear need: governance resources written for 10-person teams, not Fortune 500 legal departments — practical templates, checklists, and guides that teams can pick up and use today.
322 articles by Johnie T Young
GDPR AI fines 2026: 7.1 billion euros and counting. Five enforcement cases explain why your vendor DPA will not shield small teams from risk.
AI compliance cost for small teams in 2026: most 1-50 person orgs pay under $5,000 a year unless bias audits apply. Full breakdown by size.
24-hour runbook for leaked AI agent tokens: revoke, rotate, audit blast radius, and restore access before costs spiral. 7 copy-paste steps.
EU Digital Omnibus entered into force July 27, 2026. Annex III high-risk deadline is now December 2, 2027 -- binding law. Article 50 and GPAI still apply August 2, 2026.
OpenAI Codex was silently writing 640 TB/year to developer SSDs through a logging bug. This is a governance gap most acceptable-use policies miss. Here is what IT and compliance teams need to add.
What does the NYC Local Law 144 AI bias audit require? Independent audits, published results, candidate notice, fines to $1,500 daily. Six-step checklist.
Trump signed a new AI executive order on June 2, 2026. Here is what it requires, what is voluntary, who must act, and what federal contractors and compliance teams should do now.
ChatGPT Atlas and Perplexity Comet act inside your logged-in sessions, which breaks the old browser security model. Here is a copy-paste governance policy for teams of 5-50, plus the prompt-injection risk you need to brief staff on now.
Does GDPR apply to AI meeting transcription tools? 8 apps compared for data privacy compliance, retention risk, and transfer rules.
Monthly new e-book releases on KDP nearly tripled between 2022 and 2025 as AI-generated content flooded the platform. Amazon has responded with account-level enforcement for undisclosed AI content. Here is what publishers and authors need to document before enforcement tightens further.
EU AI Act Article 14 sets specific technical and operational requirements for human oversight of high-risk AI; most vendor "human-in-the-loop" claims don't satisfy them. Here is what effective oversight actually means, how to evaluate vendor implementations, and a 10-item compliance checklist for deployers.
What trust.openai.com covers, which certs apply to each tier, and how to use the DPA to satisfy GDPR Article 28 before deploying ChatGPT Enterprise.