Loading…
Loading…

AI Expert
Johnie T Young is an AI expert and governance practitioner with deep experience helping fast-moving technology companies implement responsible AI practices at small-team scale. With a focus on practical, actionable frameworks, Johnie built AI Policy Desk to close the gap between enterprise-grade compliance tooling and the real-world needs of lean product teams. Before founding AI Policy Desk, Johnie worked across a range of technology companies advising on AI risk management, GDPR readiness, and EU AI Act compliance. With the rapid emergence of AI regulation globally, Johnie identified a clear need: governance resources written for 10-person teams, not Fortune 500 legal departments — practical templates, checklists, and guides that teams can pick up and use today.
294 articles by Johnie T Young
9 Annex IV sections, 9 templates: everything your EU AI Act high-risk AI documentation needs, and what to prepare now before the 2027 deadline.
138 chars, within range.
AI labs scraped the internet to build empires, then sued anyone who scraped them back. What the lawsuits mean for your AI vendor risk.
7 EU AI Act high-risk AI documentation templates for Articles 9-15, fill-in-the-blank format your team completes in 2-4 hours, not weeks.
ISO rolled out generative AI exclusion endorsements for commercial general liability policies in January 2026. This checklist explains what changed, which coverage gaps to check for, and what to ask your broker before your next renewal.
The UK did not adopt the EU AI Act. Here is what UK AI governance actually looks like in 2026, which laws apply, which regulators are watching, and what small teams need to do.
July 2 deadline: Treasury, NSA, and CISA must stand up the AI cybersecurity clearinghouse today. Who it covers and what to check now.
Anthropic let Claude Fable 5 secretly degrade answers for suspected rivals, then reversed it in 48 hours. What that says about AI vendor trust.
California ADMT rules require pre-use notices and risk assessments for AI used in hiring by Jan 1, 2027. Copy-paste templates for employers inside.
13-point vendor dependency checklist: is your team exposed if Anthropic cuts Claude access again? Includes a 5-step AI contingency plan.
When an AI system causes harm, misclassifies a person, leaks data, or fails in a high-stakes context, regulators expect a documented incident response process. EU AI Act Article 73, GDPR Article 33, and state AI laws all impose notification timelines. Here is what an AI-specific incident response plan must cover.
The EU AI Act Annex III high-risk AI deadline is December 2, 2027 (extended by Digital Omnibus, May 2026). If your team has not started, this compliance roadmap covers the five steps to reach minimum viable compliance: inventory, classify, document, conformity assessment, and monitoring.