Loading…
Loading…

AI Expert
Johnie T Young is an AI expert and governance practitioner with deep experience helping fast-moving technology companies implement responsible AI practices at small-team scale. With a focus on practical, actionable frameworks, Johnie built AI Policy Desk to close the gap between enterprise-grade compliance tooling and the real-world needs of lean product teams. Before founding AI Policy Desk, Johnie worked across a range of technology companies advising on AI risk management, GDPR readiness, and EU AI Act compliance. With the rapid emergence of AI regulation globally, Johnie identified a clear need: governance resources written for 10-person teams, not Fortune 500 legal departments — practical templates, checklists, and guides that teams can pick up and use today.
372 articles by Johnie T Young
Colorado AI Act compliance -- enforcement suspended April 27, 2026. SB 189 resets the deadline to January 1, 2027. Get the 7-step plan and templates.
No federal AI preemption has passed. 10+ state AI laws are live obligations now. Which states apply to your team and what changes if preemption passes.
The SEC embedded AI oversight into every FY2026 exam category. The questions examiners ask and documentation needed for investment and compliance teams.
When your AI vendor has a security incident, your team has hours to respond. Scope, credential rotation, and documentation steps for small teams.
Which of 9 AI tools are GDPR and CCPA compliant? Compare DPA status, training data opt-out rules, and 2026 enforcement fines for small teams.
Three named roles cover AI governance for teams of 5-50 without dedicated compliance staff. Copy-paste RACI, escalation matrix, and EU AI Act role requirements included.
Notion AI, Copilot, HubSpot AI, and Zoom AI ship embedded features your team uses whether you approved them or not. How to audit and govern each tool.
Copy-paste AI register template: one row per tool, tracks owner, data sensitivity, DPA status, and review date. Covers approved tools and shadow AI.
AI vendor due diligence in 30 minutes: 5 pass/fail gate questions, 8 deep questions, a 1-3 scoring sheet, and a copy-paste procurement email. No dedicated security team required.
Checklist to evaluate AI vendors before signing: data handling, training opt-out, DPA availability, security certifications, and exit rights. Under 30 min.
Quarterly AI governance checklist for small teams: inventory, policy currency, vendor DPA status, incident log review, and training refresh.
Copy this 3-tier ChatGPT usage policy for employees: what staff can paste freely, what needs manager approval, and what is off-limits entirely.