
AI Governance & Ethics
One privacy request can touch four separate data layers. Each needs its own remedy, owner, and evidence, while model weights may require testing, unlearning, or retraining.
Irene Vasko · 8 min read

AI Governance & Ethics
A permit-review prompt, its attachments, model output, and staff edits can carry different retention and disclosure duties. Agencies need a retrieval workflow before the first request arrives.
Irene Vasko · 8 min read

AI Governance & Ethics
Prompts and profile fields may be only part of the record. AI-generated labels, rankings, and summaries can also relate to a person and may need to be found, reviewed, and disclosed.
Irene Vasko · 8 min read

AI Governance & Ethics
Before testing whether an attention score is right, employers need to know what the software extracts from workers, where it goes, and whether participation can be voluntary.
Irene Vasko · 7 min read

AI Governance & Ethics
Political synthetic media can trigger a platform label, a state-mandated disclaimer, both, or neither. A file-level compliance record helps teams identify which rule applies before publication.
Irene Vasko · 8 min read

AI Governance & Ethics
A defensible denial record connects the customer’s inputs, model result, business rule, human action and notice. New Jersey law does not reduce that chain to one AI log.
Irene Vasko · 8 min read

AI Governance & Ethics
A disclosure that looks clear in the master file can vanish when a platform crops, clips, or recompresses it. Test the published derivatives, not just the export.
Irene Vasko · 8 min read

AI Governance & Ethics
A disclosure added at upload may vanish when a synthetic video is downloaded, clipped, or reposted. Test the exported file, not just the original post.
Irene Vasko · 8 min read

AI Governance & Ethics
A small company does not need a binder of AI policies. It needs retrievable records showing who approved the system, how it was tested, what counts as an incident, and what changed.
Irene Vasko · 8 min read

AI Governance & Ethics
Selection-rate testing can reveal disparities in one hiring workflow. It cannot certify accuracy, fairness or compliance when the software, applicant pool or deployment has changed.
Irene Vasko · 8 min read

Consumer AI Hardware
Use an isolated connection and one harmless test phrase to check who controls the toy, what it records, whether mute works, and how deletion behaves.
Devin Oyelaran · 7 min read

AI Governance & Ethics
A disclosure that appears on the approved political ad can vanish during a routine crop or reupload. Compliance teams need records for every exported variant, not just the master.
Irene Vasko · 7 min read

AI Governance & Ethics
A disclosure in the caption or first frame can disappear while the synthetic video keeps moving. Durable labeling requires visible, audible, and machine-readable signals that fail differently.
Irene Vasko · 8 min read

AI Governance & Ethics
Colorado’s AI law turns ordinary system documentation into compliance evidence. Start with one record per decision workflow, including its inputs, reviewers and vendor dependencies.
Irene Vasko · 8 min read

AI Governance & Ethics
A policy statement cannot prove that an AI control operated. Auditable governance ties each model release to tests, ownership, approval, deployment records, and a defined stop condition.
Irene Vasko · 8 min read

AI Governance & Ethics
A support prompt retained for testing can cross from service delivery into product improvement. Approval should depend on purpose, controls, deletion coverage, and evidence.
Irene Vasko · 8 min read

AI Governance & Ethics
A national campaign cannot treat a political deepfake disclosure as one line of boilerplate. The trigger, wording, placement, timing, and enforceability change across state lines.
Irene Vasko · 8 min read

AI Governance & Ethics
An official AI chat can leave four record candidates: the prompt, uploaded source file, generated draft, and vendor log. Agencies need retention and export controls before employees start using it.
Irene Vasko · 8 min read

AI Governance & Ethics
A visible badge, file metadata, generation log, and signed Content Credential answer different questions. Cropping and reposting expose the gaps between them.
Irene Vasko · 8 min read

AI Governance & Ethics
There is no blanket U.S. disclosure rule. A practical answer depends on where the customer is, what the bot is doing, and whether chat becomes an AI-generated call.
Irene Vasko · 8 min read

AI Governance & Ethics
A public audit can reveal which hiring system was tested, whose outcomes were counted, and where selection rates diverged. It can also conceal job-level differences and omit demographic groups.
Irene Vasko · 8 min read

AI Industry & Models
Commercial use can be allowed while attribution, use restrictions, redistribution rules, or scale thresholds still apply. Run this four-part check before release.
Tobias Lund · 8 min read

AI Governance & Ethics
A support-ticket summary may pass through six companies even when the settings page names one. Trace the full route before prompts, attachments, and logs contain customer data.
Irene Vasko · 8 min read

AI Governance & Ethics
An exclusion request tied only to a URL or embedded tag can vanish after scraping. Operational opt-outs need durable identifiers, copy lineage and deletion receipts.
Irene Vasko · 8 min read

AI Governance & Ethics
A signed agreement can cover Amazon Bedrock while leaving prompt logs, application code, and downstream tools outside a safe design. The unit to review is the full data path.
Irene Vasko · 9 min read

AI Governance & Ethics
US disclosure duties turn on location, purpose, profession, and channel. A visible label at first contact is the cleanest baseline, but voice callbacks and human handoffs need separate controls.
Irene Vasko · 8 min read

AI Governance & Ethics
New York City requires annual bias audits for covered hiring tools, but a results page cannot prove the test used the right data, workflow, or software version.
Irene Vasko · 8 min read

AI Governance & Ethics
A business associate agreement can cover an AI vendor’s HIPAA duties without revealing its data path. Hospitals should trace prompts, files, logs, model use, and subprocessors before sending patient data.
Irene Vasko · 8 min read

AI Governance & Ethics
A vendor may call it analytics, but if it changes who gets housing, credit, work, or service, put it on the map. New Jersey’s existing laws and proposed rules make the missing records matter.
Irene Vasko · 8 min read

AI Governance & Ethics
The Colorado AI Act turns on how a system affects a decision, not whether a vendor calls it AI. Start with one row per workflow, then determine which rows need legal review and impact assessments.
Irene Vasko · 8 min read

AI Governance & Ethics
Businesses using AI for hiring, lending and other consequential decisions must build the compliance record. Vendor documentation helps, but it does not replace the deployer’s assessment.
Irene Vasko · 8 min read

AI Industry & Models
Regional endpoints make in-region model inference practical, but they do not govern every log, review queue, support session, or connected search tool.
Tobias Lund · 8 min read

AI Governance & Ethics
A usable inventory must connect each AI system to the decision it influences, the people affected, its controls, and the evidence its vendor has not supplied.
Irene Vasko · 8 min read

AI Governance & Ethics
TikTok, YouTube, Instagram, and X attach warnings to posts, not necessarily files. A download-and-repost audit shows why disclosure needs provenance that travels.
Irene Vasko · 8 min read

AI Governance & Ethics
New York City regulates what employers tell candidates and what they test about hiring tools. Those duties run on different evidence, owners, and clocks.
Irene Vasko · 8 min read

AI Industry & Models
A code sandbox can turn a plausible answer into a reproducible calculation. It also needs strict limits on network access, files, packages, runtime, and output.
Tobias Lund · 8 min read

AI Governance & Ethics
A hiring rejection can pass through several vendor models without appearing in an AI register. This worksheet traces the decision, evidence, notice, appeal, and accountable team.
Irene Vasko · 8 min read

AI Governance & Ethics
An auditor’s report covers one requirement under Local Law 144. Employers still have to resolve scope, publish the required summary, deliver notices, and preserve evidence of what candidates saw.
Irene Vasko · 8 min read

AI Governance & Ethics
A signed BAA can govern protected health information without answering how long audio survives or whether transcripts train models. Trace the data path and test deletion before the first patient visit.
Irene Vasko · 8 min read