AI Governance · EU AI Act Readiness
High-risk AI obligations phase in through August 2026, and US state AI laws are converging fast. We help companies classify their AI, close the gaps, and build practical governance — counsel from an AIGP-certified attorney who was a software engineer first.
General information, not legal advice. Booking a call does not by itself create an attorney-client relationship.

The rules are here and they reach US companies. Getting ahead of them is far cheaper than retrofitting under enforcement pressure.
A risk-tiered law with fines up to €35M or 7% of global turnover. Prohibited practices are already in force; high-risk obligations phase in through August 2026.
The Act can apply where AI is placed on the EU market or its outputs are used in the EU — many US startups are in scope without realizing it.
California, Colorado and others are regulating the same high-risk AI uses. Build governance once and comply across regimes.
AI governance lives where law, privacy, and engineering meet — which is exactly this attorney's background.
Built large-scale data systems at PayPal and Meta before practicing law. We translate the Act into things your product and engineering teams can actually implement.
Six IAPP certifications including the AI Governance Professional (AIGP), plus deep CCPA and GDPR experience.
You get an AI inventory, a risk classification, a prioritized gap list, and the documentation regulators expect — calibrated to your stage, not a 100-page memo.
We map the AI systems you build or use, and where their outputs go.
We assess how each maps to the EU AI Act tiers and US state laws, flagging anything prohibited or high-risk.
We identify the obligations that apply and a prioritized plan: documentation, human oversight, data governance, transparency.
We help you produce the records regulators expect and set up lightweight ongoing governance.
When do EU AI Act obligations take effect?
The Act phases in over time. Prohibited-practice rules and AI-literacy duties applied first; obligations for high-risk AI systems phase in through 2026, with a key milestone in August 2026. Exact timing depends on the system.
Does the EU AI Act apply to my US company?
It can. The Act has extraterritorial reach: it may apply where your AI is placed on the EU market or its outputs are used in the EU, even with no EU office. It's fact-specific.
What makes an AI system "high-risk"?
Use in areas like biometrics, employment/HR, credit and essential services, education, law enforcement, migration, or justice — or as a safety component of a regulated product. We assess your specific use.
Can you help with US state AI laws too?
Yes. We build governance that addresses the EU AI Act and the converging US state regimes together, so you can build once and comply broadly.