
AI Governance & Ethics
There is no blanket U.S. disclosure rule. A practical answer depends on where the customer is, what the bot is doing, and whether chat becomes an AI-generated call.
Irene Vasko · 8 min read

AI Governance & Ethics
A public audit can reveal which hiring system was tested, whose outcomes were counted, and where selection rates diverged. It can also conceal job-level differences and omit demographic groups.
Irene Vasko · 8 min read

AI Industry & Models
Commercial use can be allowed while attribution, use restrictions, redistribution rules, or scale thresholds still apply. Run this four-part check before release.
Tobias Lund · 8 min read

AI Governance & Ethics
A support-ticket summary may pass through six companies even when the settings page names one. Trace the full route before prompts, attachments, and logs contain customer data.
Irene Vasko · 8 min read

AI Governance & Ethics
An exclusion request tied only to a URL or embedded tag can vanish after scraping. Operational opt-outs need durable identifiers, copy lineage and deletion receipts.
Irene Vasko · 8 min read

AI Governance & Ethics
A signed agreement can cover Amazon Bedrock while leaving prompt logs, application code, and downstream tools outside a safe design. The unit to review is the full data path.
Irene Vasko · 9 min read

AI Governance & Ethics
US disclosure duties turn on location, purpose, profession, and channel. A visible label at first contact is the cleanest baseline, but voice callbacks and human handoffs need separate controls.
Irene Vasko · 8 min read

AI Governance & Ethics
New York City requires annual bias audits for covered hiring tools, but a results page cannot prove the test used the right data, workflow, or software version.
Irene Vasko · 8 min read

AI Governance & Ethics
A business associate agreement can cover an AI vendor’s HIPAA duties without revealing its data path. Hospitals should trace prompts, files, logs, model use, and subprocessors before sending patient data.
Irene Vasko · 8 min read

AI Governance & Ethics
A vendor may call it analytics, but if it changes who gets housing, credit, work, or service, put it on the map. New Jersey’s existing laws and proposed rules make the missing records matter.
Irene Vasko · 8 min read

AI Governance & Ethics
The Colorado AI Act turns on how a system affects a decision, not whether a vendor calls it AI. Start with one row per workflow, then determine which rows need legal review and impact assessments.
Irene Vasko · 8 min read

AI Governance & Ethics
Businesses using AI for hiring, lending and other consequential decisions must build the compliance record. Vendor documentation helps, but it does not replace the deployer’s assessment.
Irene Vasko · 8 min read

AI Industry & Models
Regional endpoints make in-region model inference practical, but they do not govern every log, review queue, support session, or connected search tool.
Tobias Lund · 8 min read

AI Governance & Ethics
A usable inventory must connect each AI system to the decision it influences, the people affected, its controls, and the evidence its vendor has not supplied.
Irene Vasko · 8 min read

AI Governance & Ethics
TikTok, YouTube, Instagram, and X attach warnings to posts, not necessarily files. A download-and-repost audit shows why disclosure needs provenance that travels.
Irene Vasko · 8 min read

AI Governance & Ethics
New York City regulates what employers tell candidates and what they test about hiring tools. Those duties run on different evidence, owners, and clocks.
Irene Vasko · 8 min read

AI Industry & Models
A code sandbox can turn a plausible answer into a reproducible calculation. It also needs strict limits on network access, files, packages, runtime, and output.
Tobias Lund · 8 min read

AI Governance & Ethics
A hiring rejection can pass through several vendor models without appearing in an AI register. This worksheet traces the decision, evidence, notice, appeal, and accountable team.
Irene Vasko · 8 min read

AI Governance & Ethics
An auditor’s report covers one requirement under Local Law 144. Employers still have to resolve scope, publish the required summary, deliver notices, and preserve evidence of what candidates saw.
Irene Vasko · 8 min read

AI Governance & Ethics
A signed BAA can govern protected health information without answering how long audio survives or whether transcripts train models. Trace the data path and test deletion before the first patient visit.
Irene Vasko · 8 min read

AI Governance & Ethics
Local Law 144 does not cover every recruiting bot. This worksheet traces whether a tool’s output substantially assists a hiring or promotion decision and, if so, what records counsel needs.
Irene Vasko · 8 min read

AI Governance & Ethics
A hiring model’s assessment must follow its data, decisions, notices, appeals, and material changes. Here is how to build that work into deployment rather than filing it once.
Irene Vasko · 8 min read

AI Governance & Ethics
A vendor’s audit PDF is evidence about a particular test, not a compliance passport. Employers need to match its data, jobs and decision point to the deployment.
Irene Vasko · 7 min read

AI Governance & Ethics
Feature importance can describe a model’s calculation without explaining the decision. A usable denial notice must trace the outcome to records a person can inspect and challenge.
Irene Vasko · 8 min read

AI Governance & Ethics
Feature importance may describe a model without explaining a denial. A defensible workflow connects customer-facing reason codes to the data, rules, and model output used in that case.
Irene Vasko · 8 min read

AI Governance & Ethics
Captions and platform labels can vanish one repost later. Campaigns need disclosures in the media itself, backed by provenance records and tested across common copying paths.
Irene Vasko · 7 min read

AI Governance & Ethics
A platform can label an AI-altered election ad without making that disclosure portable. Downloads, screen recordings, crops, and reposts each preserve different evidence.
Irene Vasko · 7 min read

AI Governance & Ethics
A useful employment AI inventory follows one candidate through each decision, records how software changes the outcome, and separates enforced rules from enacted or proposed duties.
Irene Vasko · 8 min read

AI Governance & Ethics
New Jersey’s discrimination law already reaches algorithmic hiring decisions, while more specific proposals remain unsettled. An inventory shows which tools require scrutiny and which merely hold records.
Irene Vasko · 8 min read

AI Governance & Ethics
A business associate agreement can cover an AI scribe without covering every service behind it. Trace the visit audio through transcription, generation, storage and model training before procurement signs off.
Irene Vasko · 8 min read

AI Governance & Ethics
A business associate agreement covers obligations, not the complete route taken by a patient recording. Practices need a data map that includes model providers, storage, support tools, and deletion.
Irene Vasko · 8 min read

AI Governance & Ethics
Colorado’s AI law turns system purpose and decision influence into compliance facts. A recruiting ranker shows how to document vendors, impact assessments, notices, and appeals.
Irene Vasko · 8 min read

AI Governance & Ethics
A HIPAA review must follow one visit from microphone capture through transcription, note generation, support access, analytics, export, and deletion. The vendor’s BAA is the start, not the map.
Irene Vasko · 8 min read

AI Governance & Ethics
Overturning one AI-assisted decision is not enough. A correction path must trace the error into source systems, preserve the dispute and stop bad data from returning.
Irene Vasko · 8 min read

AI Governance & Ethics
For covered credit decisions, existing federal rules require specific reasons tied to the individual outcome. A model summary or low score may explain the system without explaining the denial.
Irene Vasko · 8 min read

AI Governance & Ethics
Removal and disclosure rules identify suspect media after publication. Campaigns need a verification packet that lets newsrooms authenticate a disputed genuine clip.
Irene Vasko · 8 min read

AI Governance & Ethics
Before ranking hundreds of AI systems by risk, identify uses that may be prohibited outright. A focused interview can expose issues hidden by product names and vendor claims.
Irene Vasko · 8 min read

AI Governance & Ethics
A model name or risk score does not tell an applicant why credit was denied. A defensible notice connects the outcome to specific factors and preserves the records needed to challenge them.
Irene Vasko · 7 min read

Agentic AI & Orchestration
Indirect prompt injection turns page content into commands for an AI agent. Authenticated sessions raise the stakes because the agent may already have access to files, email, purchases, or account settings.
Mara Quintero · 8 min read