Practice · AI governance and regulatory
AI governance and regulatory counsel for companies taking models to market
Enterprise buyers and lead investors ask AI startups about AI governance before a regulator does. Penwell Law prepares the AI use policy, the model and vendor risk assessments, the audit-ready documentation and the regulatory strategy behind them for AI companies shipping from California.
The regimes that reach a California AI company
The EU AI Act reaches a U.S. company when its AI system is placed on the European market or its output is used in the EU. Penwell Law counsels U.S. companies on risk classification, the general-purpose AI model obligations and the transparency duties as compliance exposure, starting with the product's risk tier and the documentation that tier requires. Section 5 of the FTC Act reaches a company's claims about what its AI does, and the Commission has treated unsubstantiated AI performance claims and undisclosed training uses as deceptive. California's CCPA and CPRA govern the data side, including the California Privacy Protection Agency's automated decision-making regulations. California also regulates AI directly through the AI Transparency Act (SB 942, as amended by AB 853) and its provenance and disclosure duties, AB 2013's training-data disclosures for generative AI developers, and the Transparency in Frontier Artificial Intelligence Act (SB 53) for developers of frontier models. Advertising and consumer protection law apply to the marketing copy, the onboarding flow and the pricing page, and Penwell Law reviews launch copy before release. Other U.S. states have their own AI and privacy statutes; Penwell Law tracks them for companies selling nationally and advises directly on federal and California law.
What AI governance documentation contains
Enterprise buyers and investors request a consistent set of AI governance documents: an AI use policy governing the company's own use of third-party models; a model inventory with intended use, known limitations and the evaluation record; vendor risk assessments for each model and data provider; a data governance record of what the model was trained on and under what rights; incident and escalation procedures for model failures; and customer-facing disclosures and disclaimers that match those procedures. Most buyers recognize the NIST AI Risk Management Framework, and Penwell Law maps a company's practices to that framework. These documents are operating records, not legal opinions, and Penwell Law writes them for the company's team to maintain.
Trust and safety: the policies a platform runs on
A platform needs its trust and safety framework in place before its first abuse report, takedown notice or regulator inquiry. Penwell Law drafts the acceptable-use policies, community guidelines, and content-moderation and escalation frameworks that platforms operate at scale, covering user-generated-content governance, DMCA notice-and-takedown, transparency reporting, the notice-and-action duties that reach U.S. hosting services under the EU Digital Services Act, and the systemic-risk assessments required of very large online platforms. For generative AI products, the framework also covers rights, output safety and product design, and Penwell Law sets the escalation path for sensitive content before launch.
Regulatory horizon: what is settled, and what is coming
Most AI law is settled enough to build on. The GDPR has years of enforcement behind it, the CCPA and CPRA have final regulations and a dedicated agency, the FTC has addressed AI claims through enforcement, and the EU AI Act's obligations take effect on a published schedule. Penwell Law tracks pending legislation, agency rulemaking, enforcement actions and litigation in Sacramento, Washington and Brussels. Clients learn of a requirement at the proposal stage, with an assessment of whether it will apply to them and what to build before it takes effect. Where a question is open, Penwell Law says so, states the position the company is taking and why, and documents it. Penwell Law records a written position on each recurring regulatory question and trains product and engineering teams on it, so later launches reuse the answer.
Common questions
Frequently asked questions.
Does the EU AI Act apply to a U.S. startup?
It can. The Act applies to providers placing AI systems on the EU market and to systems whose output is used in the EU, regardless of where the provider sits. Penwell Law counsels U.S. companies on that exposure: risk classification, general-purpose model obligations and the documentation each tier requires.
What AI governance documents do enterprise customers ask for?
Most requests converge on an AI use policy, a model inventory with limitations and evaluations, vendor risk assessments for models and data providers, a training-data governance record, incident procedures, and customer-facing disclosures. The practice drafts these to align with the NIST AI Risk Management Framework, which most buyers recognize.
Can the FTC act against an AI startup?
Yes. Section 5 of the FTC Act reaches deceptive or unfair practices, and the Commission has pursued unsubstantiated AI performance claims and undisclosed uses of customer data for training.
Does Penwell Law advise on other states' AI laws?
Penwell Law advises on California and federal law, tracks other U.S. state AI and privacy statutes for companies selling nationally, and refers state-specific questions to local counsel where required.
Writing
Liam writes on the legal questions behind building and shipping technology: AI governance, privacy, and content rights. Read the blog →
Latest: Your Crawler Needs an Alibi
Start the conversation.
Contact
Based in Burlingame, California, working with clients and teams across Silicon Valley, the Bay Area, and nationally.
Inquiries