1. AI Compliance Begins with a Use-Case Map

A workable compliance review starts by identifying what each AI system does, who makes decisions about it, whose interests it affects, and which business process it supports. That prevents a company from applying the same policy to systems that raise materially different legal issues.
The System’S Function Drives the Legal Analysis
Consumer-facing AI can implicate Section 5 of the FTC Act where FTC jurisdiction applies. AI used in hiring or other employment decisions can raise Title VII or ADA issues for covered employers, while credit decisions remain subject to ECOA and Regulation B when those laws apply. State and local requirements may add separate duties, but they should be analyzed independently rather than folded into a single nationwide rule.
| AI Activity | Primary Compliance Question | Records to Examine |
|---|---|---|
| Consumer-facing system | Are claims, disclosures, and system behavior consistent? | Testing, marketing materials, complaints |
| Hiring or workforce tool | Do selection criteria or system operation create employment-law concerns? | Criteria, testing, accommodation and review procedures |
| Credit decision system | Are applicable credit-law requirements reflected in the decision process? | Inputs, decision records, notices, model documentation |
Consumer-facing system
- Primary Compliance QuestionAre claims, disclosures, and system behavior consistent?
- Records to ExamineTesting, marketing materials, complaints
Hiring or workforce tool
- Primary Compliance QuestionDo selection criteria or system operation create employment-law concerns?
- Records to ExamineCriteria, testing, accommodation and review procedures
Credit decision system
- Primary Compliance QuestionAre applicable credit-law requirements reflected in the decision process?
- Records to ExamineInputs, decision records, notices, model documentation
2. Governance Turns Legal Analysis into Day-to-Day Controls
A legal analysis has limited operational value unless the company assigns responsibility for approval, monitoring, changes, and escalation. Governance should reflect the actual use of each system rather than relying on an enterprise AI policy that treats materially different deployments alike.
Voluntary Frameworks Are Not Substitutes for Applicable Law
The NIST AI Risk Management Framework is voluntary, and AI RMF 1.0 is currently being revised. Its Govern, Map, Measure, and Manage functions can organize internal risk work, but adopting the framework does not by itself satisfy a statute or regulation that applies to a particular deployment.
Third-Party AI Still Requires Customer-Side Review
A vendor contract can allocate responsibilities, but it does not automatically resolve duties imposed directly on the company using the system. Review may cover permitted data use, product representations, access to testing information, material system changes, incident reporting, indemnity, and termination rights. These questions can also overlap with broader Technology practice issues involving software procurement and commercialization.
3. The Record Should Match the System in Production
AI governance records should show what the company actually reviewed and approved, not merely what a policy said before deployment. A change in the model, vendor, data source, affected population, or business purpose can make earlier assumptions incomplete.
What Should a Company Document?
Useful records depend on the use case, but they often include:
- System inventory and approval records — identify the system, owner, intended purpose, and approval authority.
- Testing and change records — show what was evaluated and whether later modifications received review.
- Vendor diligence and contracts — document data rights, representations, responsibilities, and notice obligations.
- Claims, disclosures, and complaints — compare what users were told with how the system performed in practice.
The point is not to generate paperwork for its own sake. Records should allow legal, compliance, and business teams to reconstruct why a system was approved and what happened when its operation changed.
Preservation Matters When a Dispute or Inquiry Emerges
Once litigation, an investigation, or another dispute is reasonably anticipated, routine deletion settings deserve separate attention. Relevant communications, testing files, system logs, approval records, and vendor materials can become important evidence. Data retention, security, and incident-response questions may also overlap with broader IT legal services.
4. Practical Pitfalls in AI Compliance
The recurring problem is usually not the absence of an AI policy. It is a gap between written policy and the system operating in the business: unreviewed changes, unsupported claims, unclear ownership, incomplete vendor information, or records that no longer describe the current deployment.
Do Not Treat Old Agency Guidance As Current Law
Regulatory materials can change without changing the underlying statute. The CFPB, for example, withdrew Circulars 2022-03 and 2023-03 concerning complex algorithms and adverse-action notices on May 12, 2025. That withdrawal did not repeal ECOA or Regulation B, which require a separate current-law analysis.
A “Compliant” Product Label Is Not a Legal Conclusion
Vendor statements such as “compliant,” “fair,” or “secure” answer little without context. The same tool can present different issues when a customer changes its data, configuration, decision process, or affected population. Diligence should therefore test vendor representations against the company’s intended deployment.
5. How Counsel Supports an AI Compliance Program
Counsel’s role is to connect applicable law with the company’s technology, contracts, governance process, records, and regulatory posture. The scope should follow the actual deployment rather than a standard compliance package.
Before Deployment or a Material Change
Legal work may include mapping applicable laws and agency authority, reviewing product claims and data practices, assessing vendor terms, examining risk assessments, defining approval responsibilities, and identifying where additional testing, documentation, or human review warrants consideration.
After a Complaint, Internal Finding, or Government Contact
Counsel can determine which legal framework applies, identify and preserve relevant records, assess privilege, review communications and system history, coordinate fact development, and evaluate remediation or a regulatory response. A compliance program supports that work; it does not guarantee that an investigation, claim, or enforcement action will not occur.
6. Frequently Asked Questions
When should an AI system receive another compliance review?
Material changes to the system’s purpose, data, vendor, decision process, user population, or technical configuration can justify renewed review. A fixed annual schedule may not capture changes that alter the legal analysis between review cycles.
What records are useful if a regulator asks about an AI system?
The answer depends on the issue, but approval records, testing materials, system-change history, vendor documentation, relevant communications, disclosures, complaints, and decision records can help establish what the company knew and how it responded.
Does using a third-party AI product eliminate the customer’s compliance obligations?
No. Contract terms can allocate responsibility between the parties, but duties imposed by statute or regulation must be assessed separately based on the customer’s role and use of the system.
7. AI Compliance Legal Review
A legal review can examine the company’s AI inventory, specific use cases, applicable federal law, data flows, vendor terms, testing and approval records, material system changes, complaints, and government contacts. From that record, counsel can identify gaps in legal analysis, governance, preservation, contracts, disclosures, or response procedures and determine which issues require further action.
15 Sep, 2026

