State and local AI law
Dated obligations that land on the business deploying the system, not the vendor that built it.
Insight
State AI law and the obligations that land on the buyer
Which US state and local AI rules bind the business deploying the system rather than the vendor that built it, with dates. Covers Texas, California, Illinois, Connecticut, New York City, and Colorado.
Read insight →Insight
AI deployment review in California: what the CCPA ADMT rules require before January 2027
California's ADMT rules set a January 2027 compliance date and a documented risk-assessment duty for covered businesses using the technology, not the vendor that built it.
Read insight →Insight
AI deployment review in Texas: what TRAIGA changes for buyers
What the Texas Responsible AI Governance Act requires, what it does not, and how a documented deployment review supports its affirmative defenses and 60-day cure period.
Read insight →Deployment assurance
How deployment review works in practice, and what it answers that a vendor assessment does not.
Insight
Vendor risk assessment vs deployment review
Why vendor credibility and deployment safety are different questions, and why an enterprise AI approval needs both answered.
Read insight →Insight
Securing agentic AI: what can the agent actually do
A deployment-focused way to examine agent access, actions, identity, monitoring, and incident investigation before go-live.
Read insight →Case study
Microsoft Copilot readiness review
An anonymized review showing how Microsoft 365 permission hygiene shaped a phased, risk-based Copilot go-live decision.
Read case study →