Loading…
Loading…

AI Expert
Johnie T Young is an AI expert and governance practitioner with deep experience helping fast-moving technology companies implement responsible AI practices at small-team scale. With a focus on practical, actionable frameworks, Johnie built AI Policy Desk to close the gap between enterprise-grade compliance tooling and the real-world needs of lean product teams. Before founding AI Policy Desk, Johnie worked across a range of technology companies advising on AI risk management, GDPR readiness, and EU AI Act compliance. With the rapid emergence of AI regulation globally, Johnie identified a clear need: governance resources written for 10-person teams, not Fortune 500 legal departments — practical templates, checklists, and guides that teams can pick up and use today.
221 articles by Johnie T Young
Everything a small team needs to govern AI: policy, risk assessment, vendor due diligence, sector compliance, monitoring, and red teaming. With templates and checklists.
EU AI Act high-risk provisions (Annex III) are enforceable December 2, 2027 (extended from August 2026 by EU Digital Omnibus). What small teams must do: classify your AI systems, run conformity assessment, implement human oversight, and register high-risk systems.
AI credit and lending decisions trigger CFPB adverse action notice requirements, FCRA accuracy obligations, and EU AI Act high-risk classification. Templates and compliance steps.
AI hiring tools are classified high-risk under the EU AI Act. What that means: impact assessments, bias testing, candidate disclosure, and EEOC disparate impact requirements.
Claude, Azure OpenAI, Vertex AI, OpenAI, and Mistral all offer zero-training configs. Includes GDPR Article 28 DPA templates, CCPA service provider terms, and EU data residency options.
4 TypeScript modules for AI agent security incidents: prompt injection detector, circuit breaker, audit logger, tool authorization gate. Express and Next.js compatible with full Vitest test suite.
Small health‑care teams face a growing maze of federal and state national security rules that tighten health data security, demanding compliance strategies
DOJ's Bulk Data Rule compels small health teams to keep data in the US, ban foreign tools, and enforce health data security as security laws tighten.
AI supply chain attacks: contractor gets infected, tokens stolen, your systems hit. Checklist to map vendor exposure, scope access, and respond within 24 hours.
AI features in VDRs create data handling and compliance obligations. Access controls, training opt-outs, and audit log requirements before enabling VDR AI.
30-question AI vendor due diligence checklist: security, data handling, compliance, and contract terms. Pass/fail criteria for each. Copy into your review.
Amazon KDP AI disclosure official requirements 2026: the exact checkbox wording, how Amazon distinguishes AI-generated from AI-assisted, what readers actually see, and 5 real enforcement scenarios. Decision flowchart included, no guessing which box to check.