Loading…
Loading…

AI Expert
Johnie T Young is an AI expert and governance practitioner with deep experience helping fast-moving technology companies implement responsible AI practices at small-team scale. With a focus on practical, actionable frameworks, Johnie built AI Policy Desk to close the gap between enterprise-grade compliance tooling and the real-world needs of lean product teams. Before founding AI Policy Desk, Johnie worked across a range of technology companies advising on AI risk management, GDPR readiness, and EU AI Act compliance. With the rapid emergence of AI regulation globally, Johnie identified a clear need: governance resources written for 10-person teams, not Fortune 500 legal departments — practical templates, checklists, and guides that teams can pick up and use today.
295 articles by Johnie T Young
On June 10-11, 2026, Anthropic announced a $200M research program on AI economic impact and Dario Amodei proposed taxing AI companies to fund universal basic income. On June 18, Senator Sanders introduced a sovereign wealth fund bill targeting AI firms. Here is what the governance signal means for enterprise teams.
Malpractice claims involving AI tools rose 14% between 2022 and 2024, with most in radiology, cardiology, and oncology. When an AI diagnostic recommendation leads to patient harm, liability may fall on the AI developer (product liability), the hospital (negligent implementation), or the physician (failure to exercise independent judgment). Here is how courts and state laws are distributing that risk.
FDA issued updated Clinical Decision Support guidance on January 6, 2026, replacing the 2022 version. It clarifies which AI tools qualify as Non-Device CDS exempt from medical device regulation and which cross the line into regulated SaMD. Key change: enforcement discretion for singular-output CDS. Here is what the four-factor test means in practice.
FDA has authorized more than 1,350 AI-enabled medical devices as of early 2026. The framework covers classification (Class I, II, III), the 510(k) vs PMA pathway, Good Machine Learning Practices, and Predetermined Change Control Plans for AI systems that update after clearance. A compliance guide for healthcare AI developers and deployers.
ChatGPT Enterprise can sign a HIPAA BAA. ChatGPT Health cannot. Claude API can. Microsoft Copilot for Healthcare can. Getting this wrong is a reportable breach under HIPAA regardless of whether data leaked. A plain-English guide to BAA requirements for AI tools used in healthcare workflows.
Midjourney announced a full-body ultrasonic scanner in June 2026, 60x faster and 10x cheaper than MRI, it claims. But it deliberately avoids diagnostic claims because those trigger FDA medical device clearance. Here is what the SaMD pathway requires, why the regulatory gate exists, and what it means for every team using AI tools that touch patient data.
FCRA AI hiring disclosure requirements: written notice, authorization, and adverse action notices, three steps most AI screening tools skip.
A DOJ court filing on June 15, 2026 disclosed that the Pentagon used Grok AI in Operation Epic Fury to help coordinate strikes on 2,000 Iranian targets in 96 hours. Sen. Gillibrand responded with the Secure and Accountable Military AI Act: mandatory human approval gates, 15-day Congressional notice, and 72-hour incident reporting from AI contractors. Five-step audit for your AI oversight policy.
5 controls to govern AI agents that open PRs while you sleep. Copy this unattended AI coding agent governance policy with merge gates and a kill switch.
Anthropic CEO Dario Amodei published "Policy on the AI Exponential" in June 2026, calling for mandatory third-party safety testing of frontier AI, pro-employment retention incentives, and UBI funded by an AI company tax. What the five-pillar agenda means for teams using AI today.
The revised EU Product Liability Directive takes effect December 9, 2026, and treats software and AI systems as "products" subject to strict liability. AI deployers, not just developers, can face liability claims when AI outputs cause damage. What this means, who is exposed, and what governance controls reduce your risk.
A Munich court ruled May 28, 2026 that Google is directly liable for defamatory false claims generated by AI Overviews, stripping platform immunity because AI search summaries are an "additional function," not infrastructure. First ruling to hold an AI company liable for AI-generated speech. What it means for teams deploying AI that makes claims about people or businesses.