{"id":973,"date":"2025-07-31T21:14:47","date_gmt":"2025-07-31T21:14:47","guid":{"rendered":"https:\/\/bryanlopez.com\/?p=973"},"modified":"2025-07-31T21:14:58","modified_gmt":"2025-07-31T21:14:58","slug":"10-questions-corporate-counsel-must-ask-before-green%e2%80%91lighting-ai-solutions","status":"publish","type":"post","link":"https:\/\/bryanlopez.com\/?p=973","title":{"rendered":"10 Questions Corporate Counsel Must Ask Before Green\u2011lighting AI Solutions"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">1. <strong>Does the proposed AI system comply with U.S. federal and state privacy laws, and international frameworks?<\/strong><\/h2>\n\n\n\n<p>AI systems processing personal data must meet GDPR standards (e.g. data minimization, lawful basis, rights of access\/deletion), and U.S. laws like CCPA, Nevada\u2019s AI data collection bill, and Utah\u2019s AI Policy Act (effective May\u202f1,\u202f2024) (<a href=\"https:\/\/azure.microsoft.com\/en-us\/blog\/explore-the-business-case-for-responsible-ai-in-new-idc-whitepaper\/?utm_source=chatgpt.com\">Microsoft Azure<\/a>). Microsoft\u2019s AI platforms offer data residency, Privacy Management in Microsoft 365, and tools like differential privacy and transparency dashboards tailored to these jurisdictions (<a href=\"https:\/\/www.microsoft.com\/en-us\/ai\/responsible-ai?utm_source=chatgpt.com\">Microsoft<\/a>, <a href=\"https:\/\/www.microsoft.com\/en-us\/corporate-responsibility\/responsible-ai-transparency-report\/?utm_source=chatgpt.com\">Microsoft<\/a>).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. <strong>Are you respecting algorithmic discrimination and explainability mandates?<\/strong><\/h3>\n\n\n\n<p>The EU\u2019s AI Act (effective August\u202f1,\u202f2024) imposes heightened obligations for \u201chigh\u2011risk\u201d AI systems, including fairness testing, human oversight, and transparency (<a href=\"https:\/\/en.wikipedia.org\/wiki\/Artificial_Intelligence_Act?utm_source=chatgpt.com\">Wikipedia<\/a>). U.S. regulators echo concerns under FTC and EEOC enforcement. Microsoft provides tools such as Fairlearn, Content Safety, and model interpretability features designed to identify and mitigate bias.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. <strong>Does the AI deployment meet professional legal ethics standards?<\/strong><\/h3>\n\n\n\n<p>In legal practice, ABA Model Rules (1.1 Competence; 1.6 Confidentiality; 5.1 Supervision) and bar guidance\u2014including the NYC Bar \u201cSeven&nbsp;C\u2019s\u201d\u2014require lawyers to understand AI risks, supervise outputs, ensure confidentiality, and obtain informed consent (<a href=\"https:\/\/www.reuters.com\/legal\/legalindustry\/navigating-seven-cs-ethical-use-ai-by-lawyers-2024-12-20\/?utm_source=chatgpt.com\">Reuters<\/a>). Microsoft Copilot solutions support enterprise-only deployment, do not retain client prompt history by default, and are configurable within compliance controls.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4. <strong>Are cybersecurity safeguards sufficient under federal and industry regulation?<\/strong><\/h3>\n\n\n\n<p>SECs, NIST (800\u201153), FISMA, and CMMC require robust risk disclosure and cyber resilience. Microsoft\u2019s Azure, Microsoft 365 GCC High, and Defender for Cloud meet FedRAMP High, CMMC levels, and support policy enforcement and real\u2011time monitoring.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5. <strong>Is there clear governance over models, training data, and outputs?<\/strong><\/h3>\n\n\n\n<p>Governance requires impact assessments, audit trails, and lifecycle controls. Microsoft mandates internal Responsible AI Standard v2 process steps including impact assessments and annual reviews prior to development phases (<a href=\"https:\/\/cdn-dynmedia-1.microsoft.com\/is\/content\/microsoftcorp\/microsoft\/final\/en-us\/microsoft-brand\/documents\/Microsoft-Responsible-AI-Standard-General-Requirements.pdf?country=us&amp;culture=en-us&amp;utm_source=chatgpt.com\">cdn-dynmedia-1.microsoft.com<\/a>). Azure ML and Purview provide model lineage, approval workflows, and data asset governance tools.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">6. <strong>How do you assess IP risk and output liability?<\/strong><\/h3>\n\n\n\n<p>Generative AI raises questions about copyright ownership. Pamela Samuelson has argued that training and output rights pose evolving legal issues around fair use and authorship (<a href=\"https:\/\/en.wikipedia.org\/wiki\/Pamela_Samuelson?utm_source=chatgpt.com\">Wikipedia<\/a>). Microsoft publicly commits to content filters, red\u2011teaming to reduce hallucinations (~\u202f10\u202f% error baseline reduced to below\u202f10\u202f% via safety messaging and citation features), and prohibits use of its models for infringing IP (<a href=\"https:\/\/cdn-dynmedia-1.microsoft.com\/is\/content\/microsoftcorp\/microsoft\/msc\/documents\/presentations\/CSR\/Responsible-AI-Transparency-Report-2024.pdf?utm_source=chatgpt.com\">cdn-dynmedia-1.microsoft.com<\/a>, <a href=\"https:\/\/www.microsoft.com\/en-us\/corporate-responsibility\/responsible-ai-transparency-report\/?utm_source=chatgpt.com\">Microsoft<\/a>).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">7. <strong>Are there model-level security risks\u2014such as prompt injection or data poisoning?<\/strong><\/h3>\n\n\n\n<p>Academic and industry research warns of emerging model-exploitation tactics. Microsoft employs robust Red\u2011Teaming, secure model release controls, and is governed by its AETHER ethics board, embedding safety across design and deployment lifecycles (<a href=\"https:\/\/pmc.ncbi.nlm.nih.gov\/articles\/PMC8492454\/?utm_source=chatgpt.com\">PMC<\/a>).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">8. <strong>Have we vetted vendors and external certifications?<\/strong><\/h3>\n\n\n\n<p>Vendor vetting should extend beyond contracts: reputation, data handling, transparency, ISO 42001, and auditability matter. Bloomberg Law and Reuters reporting stress vetting practice and governance even for well-known providers (<a href=\"https:\/\/news.bloomberglaw.com\/artificial-intelligence\/the-ai-questions-that-keep-legal-departments-awake-at-night?utm_source=chatgpt.com\">Bloomberg Law<\/a>). Microsoft\u2019s voluntary commitments under the U.S. Biden\u2013Harris administration (July\u202f2023) include internal and external security testing, watermarking, public capability disclosures, bias research, and ecosystem collaboration (<a href=\"https:\/\/en.wikipedia.org\/wiki\/Regulation_of_AI_in_the_United_States?utm_source=chatgpt.com\">Wikipedia<\/a>).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">9. <strong>Is this aligned with broader AI regulatory and treaty developments?<\/strong><\/h3>\n\n\n\n<p>AI is governed globally via frameworks like the EU AI Act, Council of Europe AI treaty, and academic proposals for consistent international standards (<a href=\"https:\/\/en.wikipedia.org\/wiki\/Artificial_Intelligence_Act?utm_source=chatgpt.com\">Wikipedia<\/a>). Microsoft, UNESCO, and Partnership on AI work to advance cross\u2011border norms and ethical AI governance (<a href=\"https:\/\/www.microsoft.com\/en-us\/ai\/responsible-ai?utm_source=chatgpt.com\">Microsoft<\/a>).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">10. <strong>Does the deployment align with fiduciary duties and ESG responsibility?<\/strong><\/h3>\n\n\n\n<p>Boards and counsel must oversee AI risk disclosure, bias mitigation, privacy protection, and ethical use. Microsoft&#8217;s Responsible AI Transparency Reports (2025 edition) publicly detail its governance, risk\u2011management, and compliance framework evolution (<a href=\"https:\/\/www.microsoft.com\/en-us\/corporate-responsibility\/responsible-ai-transparency-report\/?utm_source=chatgpt.com\">Microsoft<\/a>). These documents support ESG reporting, third\u2011party oversight, and due diligence assessments.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">References<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Erd\u00e9lyi &amp; Goldsmith (2020)<\/strong> propose a global AI regulatory agency to harmonize standards and reduce governance fragmentation (<a href=\"https:\/\/arxiv.org\/abs\/2005.11072?utm_source=chatgpt.com\">arXiv<\/a>).<\/li>\n\n\n\n<li><strong>Alanoca et al. (2025)<\/strong> offer a taxonomy to understand regulatory variation across major jurisdictions (EU, U.S., Canada, China, Brazil), underscoring global alignment and legal clarity needs (<a href=\"https:\/\/arxiv.org\/abs\/2505.13673?utm_source=chatgpt.com\">arXiv<\/a>).<\/li>\n\n\n\n<li><strong>Stanford AI\u2011on\u2011Trial<\/strong> finds hallucinations in legal LLM use at a rate of 1\u2011in\u20116 queries or worse\u2014highlighting the importance of accuracy, citations, and human oversight (<a href=\"https:\/\/hai.stanford.edu\/news\/ai-trial-legal-models-hallucinate-1-out-6-or-more-benchmarking-queries?utm_source=chatgpt.com\">Stanford HAI<\/a>).<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Why Microsoft Is a Strong Option for Counsel<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Assurance Area<\/th><th>Microsoft Capabilities<\/th><\/tr><\/thead><tbody><tr><td><strong>Privacy &amp; Residency<\/strong><\/td><td>GDPR\/CCPA\u2011compliant controls, data residency options<\/td><\/tr><tr><td><strong>Responsible AI<\/strong><\/td><td>Six principles (fairness, accountability, etc.) embedded across engineering &amp; operations (<a href=\"https:\/\/www.microsoft.com\/en-us\/ai\/principles-and-approach?utm_source=chatgpt.com\">Microsoft<\/a>)<\/td><\/tr><tr><td><strong>Transparency Reports<\/strong><\/td><td>Annual public Responsible AI Transparency Report tracks governance, bias mitigation, security, and compliance updates (<a href=\"https:\/\/www.microsoft.com\/en-us\/corporate-responsibility\/responsible-ai-transparency-report\/?utm_source=chatgpt.com\">Microsoft<\/a>)<\/td><\/tr><tr><td><strong>Governance Tools<\/strong><\/td><td>AI Impact Assessments, model lineage in Azure ML, responsible dashboards<\/td><\/tr><tr><td><strong>Security Certifications<\/strong><\/td><td>FedRAMP, ISO, CMMC, ITAR blueprints, region-level compliance (e.g. GCC High)<\/td><\/tr><tr><td><strong>Ethics &amp; Oversight<\/strong><\/td><td>AETHER ethics board, red-teaming, and external audits (<a href=\"https:\/\/pmc.ncbi.nlm.nih.gov\/articles\/PMC8492454\/?utm_source=chatgpt.com\">PMC<\/a>, <a href=\"https:\/\/cdn-dynmedia-1.microsoft.com\/is\/content\/microsoftcorp\/microsoft\/msc\/documents\/presentations\/CSR\/Responsible-AI-Transparency-Report-2024.pdf?utm_source=chatgpt.com\">cdn-dynmedia-1.microsoft.com<\/a>)<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Key Takeaways for Corporate Counsel<\/strong><\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Frame AI initiatives through a legal risk lens: privacy, bias, IP, cybersecurity.<\/li>\n\n\n\n<li>Use academic and public-law frameworks to guide governance (e.g. Model Rules, AI Act, nonprofit proposals).<\/li>\n\n\n\n<li>Choose platforms\u2014like Microsoft&#8217;s\u2014that embed principles into engineering and governance.<\/li>\n\n\n\n<li>Document due diligence thoroughly: include board memos, impact assessments, transparency reports, and vendor audits.<\/li>\n<\/ol>\n\n\n\n<p>As legal professionals, your role extends beyond approving tools\u2014it includes shaping how AI is governed ethically, securely, and in compliance with both current laws and evolving regulations. Evaluating vendors like Microsoft through these lenses supports legal defensibility and fosters responsible innovation.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>1. Does the proposed AI system comply with U.S. federal and state privacy laws, and international frameworks? AI systems processing personal data must meet GDPR standards (e.g. data minimization, lawful basis, rights of access\/deletion), and U.S. laws like CCPA, Nevada\u2019s AI data collection bill, and Utah\u2019s AI Policy Act (effective May\u202f1,\u202f2024) (Microsoft Azure). Microsoft\u2019s AI [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":974,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ocean_post_layout":"","ocean_both_sidebars_style":"","ocean_both_sidebars_content_width":0,"ocean_both_sidebars_sidebars_width":0,"ocean_sidebar":"","ocean_second_sidebar":"","ocean_disable_margins":"enable","ocean_add_body_class":"","ocean_shortcode_before_top_bar":"","ocean_shortcode_after_top_bar":"","ocean_shortcode_before_header":"","ocean_shortcode_after_header":"","ocean_has_shortcode":"","ocean_shortcode_after_title":"","ocean_shortcode_before_footer_widgets":"","ocean_shortcode_after_footer_widgets":"","ocean_shortcode_before_footer_bottom":"","ocean_shortcode_after_footer_bottom":"","ocean_display_top_bar":"default","ocean_display_header":"default","ocean_header_style":"","ocean_center_header_left_menu":"","ocean_custom_header_template":"","ocean_custom_logo":0,"ocean_custom_retina_logo":0,"ocean_custom_logo_max_width":0,"ocean_custom_logo_tablet_max_width":0,"ocean_custom_logo_mobile_max_width":0,"ocean_custom_logo_max_height":0,"ocean_custom_logo_tablet_max_height":0,"ocean_custom_logo_mobile_max_height":0,"ocean_header_custom_menu":"","ocean_menu_typo_font_family":"","ocean_menu_typo_font_subset":"","ocean_menu_typo_font_size":0,"ocean_menu_typo_font_size_tablet":0,"ocean_menu_typo_font_size_mobile":0,"ocean_menu_typo_font_size_unit":"px","ocean_menu_typo_font_weight":"","ocean_menu_typo_font_weight_tablet":"","ocean_menu_typo_font_weight_mobile":"","ocean_menu_typo_transform":"","ocean_menu_typo_transform_tablet":"","ocean_menu_typo_transform_mobile":"","ocean_menu_typo_line_height":0,"ocean_menu_typo_line_height_tablet":0,"ocean_menu_typo_line_height_mobile":0,"ocean_menu_typo_line_height_unit":"","ocean_menu_typo_spacing":0,"ocean_menu_typo_spacing_tablet":0,"ocean_menu_typo_spacing_mobile":0,"ocean_menu_typo_spacing_unit":"","ocean_menu_link_color":"","ocean_menu_link_color_hover":"","ocean_menu_link_color_active":"","ocean_menu_link_background":"","ocean_menu_link_hover_background":"","ocean_menu_link_active_background":"","ocean_menu_social_links_bg":"","ocean_menu_social_hover_links_bg":"","ocean_menu_social_links_color":"","ocean_menu_social_hover_links_color":"","ocean_disable_title":"default","ocean_disable_heading":"default","ocean_post_title":"","ocean_post_subheading":"","ocean_post_title_style":"","ocean_post_title_background_color":"","ocean_post_title_background":0,"ocean_post_title_bg_image_position":"","ocean_post_title_bg_image_attachment":"","ocean_post_title_bg_image_repeat":"","ocean_post_title_bg_image_size":"","ocean_post_title_height":0,"ocean_post_title_bg_overlay":0.5,"ocean_post_title_bg_overlay_color":"","ocean_disable_breadcrumbs":"default","ocean_breadcrumbs_color":"","ocean_breadcrumbs_separator_color":"","ocean_breadcrumbs_links_color":"","ocean_breadcrumbs_links_hover_color":"","ocean_display_footer_widgets":"default","ocean_display_footer_bottom":"default","ocean_custom_footer_template":"","ofc_meta_disable_footer_callout":"","ofc_meta_callout_button_url":"","ofc_meta_callout_button_txt":"","ofc_meta_callout_text":"","ofc_enable_fullscreen":"disable","ofc_fullscreen_speed":0,"ofc_fullscreen_nav":"enable","ofc_fullscreen_nav_pos":"right","ofc_fullscreen_nav_color":"","ofc_fullscreen_nav_tooltip_color":"","ofc_fullscreen_responsive":0,"osp_disable_panel":"default","osh_disable_topbar_sticky":"default","osh_disable_header_sticky":"default","osh_sticky_header_style":"default","osh_sticky_header_effect":"","osh_custom_sticky_logo":0,"osh_custom_retina_sticky_logo":0,"osh_custom_sticky_logo_height":0,"osh_background_color":"","osh_links_color":"","osh_links_hover_color":"","osh_links_active_color":"","osh_links_bg_color":"","osh_links_hover_bg_color":"","osh_links_active_bg_color":"","osh_menu_social_links_color":"","osh_menu_social_hover_links_color":"","ocean_post_oembed":"","ocean_post_self_hosted_media":"","ocean_post_video_embed":"","ocean_link_format":"","ocean_link_format_target":"self","ocean_quote_format":"","ocean_quote_format_link":"post","ocean_gallery_link_images":"on","ocean_gallery_id":[],"footnotes":""},"categories":[18,17,36,32,19],"tags":[21,30,28,26],"class_list":["post-973","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai","category-cyber-policy","category-law","category-microsoft","category-risk","tag-ai","tag-cyber-law","tag-cybersecurity","tag-government","entry","has-media"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\r\n<title>10 Questions Corporate Counsel Must Ask Before Green\u2011lighting AI Solutions - Bryan Lopez<\/title>\r\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\r\n<link rel=\"canonical\" href=\"https:\/\/bryanlopez.com\/?p=973\" \/>\r\n<meta property=\"og:locale\" content=\"en_US\" \/>\r\n<meta property=\"og:type\" content=\"article\" \/>\r\n<meta property=\"og:title\" content=\"10 Questions Corporate Counsel Must Ask Before Green\u2011lighting AI Solutions - Bryan Lopez\" \/>\r\n<meta property=\"og:description\" content=\"1. Does the proposed AI system comply with U.S. federal and state privacy laws, and international frameworks? AI systems processing personal data must meet GDPR standards (e.g. data minimization, lawful basis, rights of access\/deletion), and U.S. laws like CCPA, Nevada\u2019s AI data collection bill, and Utah\u2019s AI Policy Act (effective May\u202f1,\u202f2024) (Microsoft Azure). Microsoft\u2019s AI [&hellip;]\" \/>\r\n<meta property=\"og:url\" content=\"https:\/\/bryanlopez.com\/?p=973\" \/>\r\n<meta property=\"og:site_name\" content=\"Bryan Lopez\" \/>\r\n<meta property=\"article:published_time\" content=\"2025-07-31T21:14:47+00:00\" \/>\r\n<meta property=\"article:modified_time\" content=\"2025-07-31T21:14:58+00:00\" \/>\r\n<meta property=\"og:image\" content=\"https:\/\/bryanlopez.com\/wp-content\/uploads\/2025\/07\/10questions.png\" \/>\r\n\t<meta property=\"og:image:width\" content=\"2100\" \/>\r\n\t<meta property=\"og:image:height\" content=\"1500\" \/>\r\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\r\n<meta name=\"author\" content=\"Bryan Lopez\" \/>\r\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\r\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Bryan Lopez\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\r\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/bryanlopez.com\\\/?p=973#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/bryanlopez.com\\\/?p=973\"},\"author\":{\"name\":\"Bryan Lopez\",\"@id\":\"https:\\\/\\\/bryanlopez.com\\\/#\\\/schema\\\/person\\\/fded6a4862b8f769e1548e07c1bddd88\"},\"headline\":\"10 Questions Corporate Counsel Must Ask Before Green\u2011lighting AI Solutions\",\"datePublished\":\"2025-07-31T21:14:47+00:00\",\"dateModified\":\"2025-07-31T21:14:58+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/bryanlopez.com\\\/?p=973\"},\"wordCount\":874,\"image\":{\"@id\":\"https:\\\/\\\/bryanlopez.com\\\/?p=973#primaryimage\"},\"thumbnailUrl\":\"\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/10questions.png\",\"keywords\":[\"ai\",\"cyber law\",\"cybersecurity\",\"government\"],\"articleSection\":[\"AI\",\"Cyber Policy\",\"Law\",\"Microsoft\",\"Risk\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/bryanlopez.com\\\/?p=973\",\"url\":\"https:\\\/\\\/bryanlopez.com\\\/?p=973\",\"name\":\"10 Questions Corporate Counsel Must Ask Before Green\u2011lighting AI Solutions - Bryan Lopez\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/bryanlopez.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/bryanlopez.com\\\/?p=973#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/bryanlopez.com\\\/?p=973#primaryimage\"},\"thumbnailUrl\":\"\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/10questions.png\",\"datePublished\":\"2025-07-31T21:14:47+00:00\",\"dateModified\":\"2025-07-31T21:14:58+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/bryanlopez.com\\\/#\\\/schema\\\/person\\\/fded6a4862b8f769e1548e07c1bddd88\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/bryanlopez.com\\\/?p=973#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/bryanlopez.com\\\/?p=973\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/bryanlopez.com\\\/?p=973#primaryimage\",\"url\":\"\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/10questions.png\",\"contentUrl\":\"\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/10questions.png\",\"width\":2100,\"height\":1500,\"caption\":\"Image that states 10 AI Policy Questions\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/bryanlopez.com\\\/?p=973#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/bryanlopez.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"10 Questions Corporate Counsel Must Ask Before Green\u2011lighting AI Solutions\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/bryanlopez.com\\\/#website\",\"url\":\"https:\\\/\\\/bryanlopez.com\\\/\",\"name\":\"Bryan Lopez - Technology & Cybersecurity\",\"description\":\"Technology &amp; Cybersecurity\",\"alternateName\":\"The official blog of Cyber policy and law expert Bryan Lopez\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/bryanlopez.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/bryanlopez.com\\\/#\\\/schema\\\/person\\\/fded6a4862b8f769e1548e07c1bddd88\",\"name\":\"Bryan Lopez\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c4ec14d2b0ff62a83483bd2dcbaec9d419161264e93784db6aa99045c4826361?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c4ec14d2b0ff62a83483bd2dcbaec9d419161264e93784db6aa99045c4826361?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c4ec14d2b0ff62a83483bd2dcbaec9d419161264e93784db6aa99045c4826361?s=96&d=mm&r=g\",\"caption\":\"Bryan Lopez\"},\"description\":\"Director &amp; Technology strategist with a demonstrated history in cybersecurity, systems architecture, cloud services and development. A trusted technical adviser to various security organizations within the federal government. Currently a part of the Federal Science and Research Division at Microsoft, supporting the Department of Energy.\",\"sameAs\":[\"https:\\\/\\\/bryanlopez.com\"],\"url\":\"https:\\\/\\\/bryanlopez.com\\\/?author=1\"}]}<\/script>\r\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"10 Questions Corporate Counsel Must Ask Before Green\u2011lighting AI Solutions - Bryan Lopez","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/bryanlopez.com\/?p=973","og_locale":"en_US","og_type":"article","og_title":"10 Questions Corporate Counsel Must Ask Before Green\u2011lighting AI Solutions - Bryan Lopez","og_description":"1. Does the proposed AI system comply with U.S. federal and state privacy laws, and international frameworks? AI systems processing personal data must meet GDPR standards (e.g. data minimization, lawful basis, rights of access\/deletion), and U.S. laws like CCPA, Nevada\u2019s AI data collection bill, and Utah\u2019s AI Policy Act (effective May\u202f1,\u202f2024) (Microsoft Azure). Microsoft\u2019s AI [&hellip;]","og_url":"https:\/\/bryanlopez.com\/?p=973","og_site_name":"Bryan Lopez","article_published_time":"2025-07-31T21:14:47+00:00","article_modified_time":"2025-07-31T21:14:58+00:00","og_image":[{"width":2100,"height":1500,"url":"https:\/\/bryanlopez.com\/wp-content\/uploads\/2025\/07\/10questions.png","type":"image\/png"}],"author":"Bryan Lopez","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Bryan Lopez","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/bryanlopez.com\/?p=973#article","isPartOf":{"@id":"https:\/\/bryanlopez.com\/?p=973"},"author":{"name":"Bryan Lopez","@id":"https:\/\/bryanlopez.com\/#\/schema\/person\/fded6a4862b8f769e1548e07c1bddd88"},"headline":"10 Questions Corporate Counsel Must Ask Before Green\u2011lighting AI Solutions","datePublished":"2025-07-31T21:14:47+00:00","dateModified":"2025-07-31T21:14:58+00:00","mainEntityOfPage":{"@id":"https:\/\/bryanlopez.com\/?p=973"},"wordCount":874,"image":{"@id":"https:\/\/bryanlopez.com\/?p=973#primaryimage"},"thumbnailUrl":"\/wp-content\/uploads\/2025\/07\/10questions.png","keywords":["ai","cyber law","cybersecurity","government"],"articleSection":["AI","Cyber Policy","Law","Microsoft","Risk"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/bryanlopez.com\/?p=973","url":"https:\/\/bryanlopez.com\/?p=973","name":"10 Questions Corporate Counsel Must Ask Before Green\u2011lighting AI Solutions - Bryan Lopez","isPartOf":{"@id":"https:\/\/bryanlopez.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/bryanlopez.com\/?p=973#primaryimage"},"image":{"@id":"https:\/\/bryanlopez.com\/?p=973#primaryimage"},"thumbnailUrl":"\/wp-content\/uploads\/2025\/07\/10questions.png","datePublished":"2025-07-31T21:14:47+00:00","dateModified":"2025-07-31T21:14:58+00:00","author":{"@id":"https:\/\/bryanlopez.com\/#\/schema\/person\/fded6a4862b8f769e1548e07c1bddd88"},"breadcrumb":{"@id":"https:\/\/bryanlopez.com\/?p=973#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/bryanlopez.com\/?p=973"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/bryanlopez.com\/?p=973#primaryimage","url":"\/wp-content\/uploads\/2025\/07\/10questions.png","contentUrl":"\/wp-content\/uploads\/2025\/07\/10questions.png","width":2100,"height":1500,"caption":"Image that states 10 AI Policy Questions"},{"@type":"BreadcrumbList","@id":"https:\/\/bryanlopez.com\/?p=973#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/bryanlopez.com\/"},{"@type":"ListItem","position":2,"name":"10 Questions Corporate Counsel Must Ask Before Green\u2011lighting AI Solutions"}]},{"@type":"WebSite","@id":"https:\/\/bryanlopez.com\/#website","url":"https:\/\/bryanlopez.com\/","name":"Bryan Lopez - Technology & Cybersecurity","description":"Technology &amp; Cybersecurity","alternateName":"The official blog of Cyber policy and law expert Bryan Lopez","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/bryanlopez.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/bryanlopez.com\/#\/schema\/person\/fded6a4862b8f769e1548e07c1bddd88","name":"Bryan Lopez","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/c4ec14d2b0ff62a83483bd2dcbaec9d419161264e93784db6aa99045c4826361?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/c4ec14d2b0ff62a83483bd2dcbaec9d419161264e93784db6aa99045c4826361?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/c4ec14d2b0ff62a83483bd2dcbaec9d419161264e93784db6aa99045c4826361?s=96&d=mm&r=g","caption":"Bryan Lopez"},"description":"Director &amp; Technology strategist with a demonstrated history in cybersecurity, systems architecture, cloud services and development. A trusted technical adviser to various security organizations within the federal government. Currently a part of the Federal Science and Research Division at Microsoft, supporting the Department of Energy.","sameAs":["https:\/\/bryanlopez.com"],"url":"https:\/\/bryanlopez.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/bryanlopez.com\/index.php?rest_route=\/wp\/v2\/posts\/973","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bryanlopez.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bryanlopez.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bryanlopez.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bryanlopez.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=973"}],"version-history":[{"count":1,"href":"https:\/\/bryanlopez.com\/index.php?rest_route=\/wp\/v2\/posts\/973\/revisions"}],"predecessor-version":[{"id":975,"href":"https:\/\/bryanlopez.com\/index.php?rest_route=\/wp\/v2\/posts\/973\/revisions\/975"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bryanlopez.com\/index.php?rest_route=\/wp\/v2\/media\/974"}],"wp:attachment":[{"href":"https:\/\/bryanlopez.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=973"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bryanlopez.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=973"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bryanlopez.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=973"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}