AI Counsel Blog Posts

Sort By

AI Risk Management: Tackling the “Shadow AI” Problem

by John Jenkins

August 28, 2025

A recent Jones Walker blog summarizing the results of IBM’s latest Cost of a Data Breach Report commented on the report’s findings concerning the growing problem of “shadow AI”: The report documents “shadow AI” — AI tools that employees use without organizational knowledge or approval. One in five organizations reported a breach due to security […]

Cybersecurity: Threats Outpace Defenses & AI Escalates the Challenge

by John Jenkins

August 27, 2025

According to a recent Accenture report, cyber threats are evolving faster than companies can adapt their defenses to them, and the rapid adoption of AI tools is escalating the challenges businesses face.  The report surveyed nearly 2,300 CISOs and CIOs from $1 billion-plus enterprises across 24 industries and 17 countries.  The results are sobering. Here’s […]

The Challenges of 3rd Party AI Risk Management

by John Jenkins

August 26, 2025

Over on Radical Compliance, Matt Kelly has posted an interesting discussion of the challenges associated managing risks associated with 3rd party AI tools incorporated into your own systems.  Matt points out that one of the biggest challenges is actually determining how many of these systems you’re using. To complicate things further, this process is one […]

AI Intellectual Property: Trade Secrets May Top Patent Protection

by John Jenkins

August 25, 2025

A recent Risk Management Magazine article written by three Husch Blackwell lawyers highlights the challenges businesses face in obtaining patent protection for AI innovations, and says that trade secret law may provide a better path toward protecting proprietary AI-related technology: Unlike patents, trade secrets do not require public disclosure. If you can keep valuable information […]

Tips for Selecting AI Bias Auditors

by Zachary Barlow

August 21, 2025

I’ve harped on the dangers of algorithmic discrimination and bias in many of our previous blogs. My soapbox isn’t without merit; bias in automated decision-making is a leading driver of risk in AI. Failure to test for biased outputs has resulted in lawsuits and settlements, especially in the context of HR and highly regulated industries. […]

Proposed Illinois Bills Aim to Regulate AI

by Zachary Barlow

August 20, 2025

Federal policy currently favors AI deregulation, but states are taking up AI issues, creating a regulatory patchwork across the U.S. A recent Saul Ewing memo focuses on legislative activity at the Illinois legislature. Twelve AI bills are currently pending, which would regulate AI with new laws related to insurance, education, consumer protection, and employment: “Evidently, […]

The EU Data Act Introduces New IOT Requirments

by Zachary Barlow

August 19, 2025

In today’s world, full of “smart” devices, many ordinary objects connect to the internet. Everything from automobiles and appliances to industrial agriculture equipment has internet connectivity. This ecosystem of internet-enabled products is often referred to as the “Internet of Things” (IOT). In addition to connectivity features that allow for remote monitoring and operation, these devices […]

Communicating Your AI Policy Internally

by Zachary Barlow

August 18, 2025

Internal policies are critical tools for AI risk management. We’ve talked about the importance of policies and what should go in them. However, there’s a critical flaw in many AI policies: communication. To explain, let me defer to an age-old thought experiment: If a tree falls in the middle of the forest and no one […]

Cybersecurity: Beware the False Claims Act

by John Jenkins

August 14, 2025

Last month, the DOJ announced a settled enforcement action against Illumina arising out of the sale of certain genetic sequencing systems to the federal government that contained cybersecurity vulnerabilities. The DOJ alleged that Illumina’s sale of these products to the government with these vulnerabilities violated the False Claims Act, and Illumina agreed to pay $9.8 […]

Cybersecurity: Regulators Differ in Approach to Risk Assessment Oversight

by John Jenkins

August 13, 2025

Government contractors are required to conduct cybersecurity risk assessments in accordance with NIST standards, but an IAPP article published earlier this month says that regulators differ in the way they approach their oversight of risk assessments.  Here’s an excerpt: Across the patchwork quilt of cybersecurity regulation in the U.S., enforcement agencies — including the Federal […]