What enterprise security teams actually ask AI vendors
The AI-specific questions that stall deals after SOC 2 — training use, LLM subprocessors, prompt retention, tenant isolation — with what a passing answer looks like. Score your own readiness.
Practical writing on the legal questions AI-native teams actually hit, and the ones enterprise buyers ask. Plain language, not legal advice. New posts in progress.
The AI-specific questions that stall deals after SOC 2 — training use, LLM subprocessors, prompt retention, tenant isolation — with what a passing answer looks like. Score your own readiness.
Generic "to improve our services" no longer clears CCPA, GDPR, or the EU AI Act. Answer a few questions and get starter disclosure language your policy and ToS need to match.
A decision tree that lands your product in the right bucket — minimal, transparency, high-risk, GPAI, or out of scope — with the concrete obligations and 2026 dates for each.
Enter your call volume and consent posture to see your statutory-damages exposure — and the consent and disclosure controls that close it.
A pre-fundraise checklist of the assignment and ownership gaps a diligence team will find, flagged by severity. See where you'd fail today.
A short, occasional note on AI product-legal that you can actually use. Newsletter signup goes live with the site.
Get in touch →