AI Governance

Existing law, applied to new systems.

Counselize advises on the obligations that attach when a business uses artificial intelligence in decisions about people, and on the governance record that shows those obligations are being met.

There is no advanced-technology exception to existing law. A model that decides who gets credit, what a customer is charged, who is hired, or which transactions are escalated carries the obligations that already applied to those decisions, whether or not anyone called the system artificial intelligence when it was built. The common failure is not a bad model. It is a sound model deployed with no record of who approved it, what it was tested against, and who answers for it when it is wrong.

In practice that means fair lending and disparate impact analysis wherever a model touches credit, unfair or deceptive practices exposure wherever outputs reach consumers, adverse action notices that give actual and specific reasons rather than the fact that a model declined, and the model risk discipline supervised institutions are expected to apply, covering development standards, validation independent of the people who built the model, and ongoing performance monitoring.

A second layer is arriving from state and foreign law. Colorado has adopted obligations for developers and deployers of high-risk systems, several state privacy laws now carry automated-decision disclosure and opt-out rights, and the EU AI Act imposes duties on systems placed on that market. Each of these turns on classification, so the threshold work is an inventory of where artificial intelligence is used, what each use decides, and which category it falls into.

Counselize builds the governance around that inventory. An AI use policy, roles and approval gates before deployment, documentation of testing and validation, human oversight and escalation a person can realistically exercise, disclosure to the people affected, and the vendor terms that matter when the model belongs to someone else, including training-data rights, output ownership, indemnity, and the right to audit.

Scope

What this covers.

01Use inventory and classificationA record of where artificial intelligence is used in the business, what each use decides, who is affected, and how it classifies under the frameworks that apply to it.
02Governance policy and approvalAn AI use policy with defined roles, approval gates before deployment, change control, and periodic review, written so it can be followed rather than filed.
03Credit and consumer decisionsFair lending and disparate impact analysis, unfair or deceptive practices exposure in model-driven outputs, and adverse action notices that state actual and specific reasons.
04Model risk documentationDevelopment standards, validation independent of the model's builders, performance monitoring, and the documentation supervised institutions are expected to maintain.
05Human oversightEscalation and override protocols that a person can realistically exercise, with the record showing when oversight was applied and by whom.
06Disclosure and individual rightsAutomated decision disclosure, opt-out and appeal rights under state privacy law, and the procedures that make them operational.
07Vendor and licensed modelsTraining-data rights, output ownership, indemnity, audit rights, use restrictions, and confidentiality where the model or the data belongs to a third party.
08State and EU obligationsColorado's developer and deployer duties for high-risk systems, comparable state requirements as they take effect, and EU AI Act classification for systems placed on that market.
Counselize advises on the legal and regulatory obligations attaching to AI systems and on the governance record supporting them. Model development, statistical testing, and validation are performed by the business or its technical advisers.

Start with a conversation.