Questions I Am Asked Most.
Short, direct answers to the questions that come up in first conversations — about governance programs, the standards and statutes behind them, and how the work is structured. Nothing here is legal advice or creates an attorney–client relationship.
What does an AI governance engagement actually produce?
A management system, not a binder. Typically: an AI policy and acceptable use policy grounded in what your organization is actually running, a governance charter with named decision rights, a model registry, vendor intake and diligence criteria, human-oversight procedures, an incident response playbook, and the audit evidence each of those generates. The test I hold the work to is whether an engineer can implement it, an executive can defend it, and a regulator can trace it.
Do I need ISO/IEC 42001 certification?
Usually not on day one. ISO/IEC 42001 is a management-system standard, and its value is the operating discipline it imposes — certification is a separate decision driven by customer or procurement pressure. Most organizations get more out of building to the standard, mapping it against the NIST AI Risk Management Framework and the regulations that already bind them, and certifying later if a counterparty requires it.
What is TRAIGA and does it apply to my organization?
The Texas Responsible Artificial Intelligence Governance Act imposes obligations on organizations that develop or deploy AI systems touching Texans, with disclosure, documentation, and prohibited-use provisions. Whether it reaches you depends on your role in the chain — developer, deployer, or distributor — the sector you operate in, and the data involved. It rarely arrives alone: the same deployment often implicates the EU AI Act, state privacy statutes, FTC enforcement posture, and HIPAA at once, which is why I map obligations against each other rather than one at a time.
How is the EU AI Act different from the NIST AI Risk Management Framework?
The EU AI Act is binding law with risk classifications and penalties. The NIST AI RMF is a voluntary framework describing how to govern, map, measure, and manage AI risk. They are complementary: the framework gives you the practice, the Act tells you what is mandatory and by when. A well-built program uses the framework to produce the evidence the Act will ask for.
What is a fractional Chief AI Officer, and when does it make sense?
A fractional CAIO owns the AI function — strategy, risk appetite, model oversight, build-versus-buy, the board relationship — at a fraction of a full-time seat. It fits organizations that have AI in production, or about to be, but not enough scale to justify a full-time executive. An interim CAIO is the same ownership through a defined period: a launch, a regulatory deadline, a transaction, or the search for a permanent hire.
Who owns the output of a generative AI system?
Ownership splits into three questions that are often conflated: rights in the training data, rights in the model, and rights in the output. In the United States, copyright requires human authorship, so purely machine-generated output generally is not protectable, while human-directed and human-edited work may be. Contract terms with your model provider frequently control more of the practical answer than copyright does, which is why I read those terms before advising on the IP position.
Can an AI system be named as an inventor on a patent?
No. Under current U.S. law an inventor must be a natural person, and the Federal Circuit has confirmed it. That does not mean AI-assisted inventions are unpatentable — it means inventorship analysis has to identify the human contributions to conception, and your disclosure practice has to capture them contemporaneously. Getting that record right at the time of invention is far cheaper than reconstructing it during litigation.
What is shadow AI and why does it matter?
Shadow AI is the AI already in use inside an organization that no one registered, approved, or classified data for. It matters because governance written from assumptions governs an organization that does not exist. Surfacing it is what SurvAIable does: anonymous, role-based intake that produces a defensible picture of actual usage before anyone writes a policy.
Do you take patent prosecution and litigation work, or only AI governance?
Both, and they are increasingly the same file. I am a registered patent attorney and prosecute, litigate, and license patents, trademarks, and copyrights across cryptocurrency and blockchain, semiconductors, AR and VR, VTOL and rotorcraft, control systems, and machine learning — including multinational enforcement and PTAB and TTAB proceedings.
How do engagements usually start?
With an honest inventory. Most begin with a readiness assessment of the AI already deployed — what it is, who owns it, what data it touches, and what obligations attach — followed by a sequenced plan that fixes the highest-exposure gaps first. You do not need a finished program to begin.