Loading…
Loading…

AI Expert
Johnie T Young is an AI expert and governance practitioner with deep experience helping fast-moving technology companies implement responsible AI practices at small-team scale. With a focus on practical, actionable frameworks, Johnie built AI Policy Desk to close the gap between enterprise-grade compliance tooling and the real-world needs of lean product teams. Before founding AI Policy Desk, Johnie worked across a range of technology companies advising on AI risk management, GDPR readiness, and EU AI Act compliance. With the rapid emergence of AI regulation globally, Johnie identified a clear need: governance resources written for 10-person teams, not Fortune 500 legal departments — practical templates, checklists, and guides that teams can pick up and use today.
295 articles by Johnie T Young
Does Maryland's 2026 surveillance pricing law cover your grocery store? HB 895 bans personalized pricing from consumer data, effective October 1.
Washington's AI likeness and deepfake law took effect June 10, 2026. Signed by Governor Ferguson. What is prohibited, who is liable, and what your tech stack must satisfy now that the law is in force.
12 AI vendor contract clauses to add, fix, or reject before signing. Copy-paste redline language for: no training on your data, 72-hour breach notification, data deletion, sub-processor limits, audit rights, and model version control.
Side-by-side comparison of Anthropic and OpenAI GDPR terms: DPA availability, data retention, EU hosting, sub-processors, breach notification, and training data opt-out. Which is safer for EU personal data?
EU AI Act deadline extension 2026: Annex III moves to December 2, 2027. GPAI enforcement holds at August 2, 2026. Use the 6-point checklist.
Fill-in-the-blanks AI acceptable use policy template for small teams. Copy the policy, replace 5 bracketed fields, and you have a compliant AI use policy covering approved tools, prohibited uses, data rules, and human oversight in under 30 minutes.
AI vendor DPA tracker: 25+ tools in one table with GDPR DPA availability, training opt-out status, EU data residency, and direct DPA request links. Free to copy. Updated May 2026.
AI coding tools governance policy: which of Copilot, Cursor, or Claude Code trains on your code? DPAs, SOC 2, IP indemnification, and a use policy.
Administrative monetary penalties are reshaping data protection enforcement, giving small teams clearer risk signals and practical compliance steps to stay
A complete AI acceptable use policy template for teams of 5-50. Covers approved tools, prohibited uses, data classification, incident reporting, and employee acknowledgment. Copy into your team wiki.
40 AI vendor evaluation prompts to copy-paste into RFPs, procurement calls, and security reviews on privacy, security, compliance, SLA, and contracts.
The EU AI Act is a binding EU law classifying AI systems by risk level. High-risk AI (hiring, credit, medical) faces mandatory audits and registration. In force August 2024, high-risk AI rules apply from December 2027 (extended from August 2026 by the EU Digital Omnibus).