Skip to content

AI governance that survives contact with procurement.

Your customers' lawyers are asking questions nobody asked two years ago, your model vendors have quietly rewritten their terms, and the rules moved twice while you were building. This is the practice for that.

An engraving of taking a celestial position fix
  1. 1

    The AI addendum from an enterprise customer wants no-training-by-default, deletion from backups, and subprocessor objection rights. You have 48 hours to answer it.

  2. 2

    The board asked who owns AI risk, and the room went quiet.

  3. 3

    You shipped a feature that scores or screens people, and a customer's lawyer just asked whether that makes you the "provider" of a "high-risk system."

The paper procurement asks for, by name

AI use policy, AI risk register, model cards, data-flow diagrams, AI subprocessor list. Procurement asks for these by name, so we build them against what engineering actually ships rather than what a template imagined. A register you can't stand behind is worse than no register at all.

The AI addendum, negotiated

Here are the clauses that actually get fought over. No-training-by-default, and the carve-outs that quietly eat it, like "aggregated and de-identified" or "to improve the Services." Purpose limitation. Retention and deletion, backups included. Subprocessor objection rights. Who owns the inputs and who owns the outputs. What happens when the order form contradicts the master agreement, because one of them wins and it usually isn't the one you drafted. We can tell you which concessions you will survive and which ones follow you for years.

Where you sit on the map

Provider or deployer: that is the first question under the EU AI Act, and under the state laws that copied its shape. An application-layer company that ships a hiring, credit, or education feature under its own brand can become the provider of a high-risk system without ever training a model. So we place you on the map, date the placement and hedge it where the map itself is still moving, and revisit it as the rules change.

The claims on your own homepage

For most companies at your stage, the nearest AI enforcement risk isn't in Brussels. It's in your own marketing. The FTC has been bringing actions over AI capability and earnings claims since 2024, and it hasn't stopped. So we read what you say you can do, on the homepage, in the deck, in the sales one-pager, the way a regulator would read it.

Open-weight is not open source

Model licenses carry usage caps, competitor restrictions, and research-only limits, and none of it bites while you're small. It bites at scale, or on the afternoon an acquirer's counsel sits down and reads the licenses you're built on. We inventory them first, so that afternoon holds no surprises.

Where we stop

We handle the legal and policy side: the analysis, the paper, the negotiation. We don't build technical controls, run evaluations, or audit models. Where a framework needs real engineering, we work next to your team and say plainly which parts are ours and which are yours.

Fifteen minutes. No pitch.

You talk, we diagnose. You leave with the two or three exposures worth addressing first, along with a straight answer on whether you need counsel now, including "not yet."