Frantz Ward is pleased to announce that the firm is launching a new AI Enterprise Governance practice, which will assist organizations in creating legal frameworks to safely and responsibly deploy artificial intelligence, while managing the legal and regulatory exposure that comes with it.
The practice builds on the firm’s Data Privacy and Cybersecurity Practice Group, leveraging the team’s experience providing data security counsel, breach response, and privacy compliance across various industries.
“The launch of our firm’s AI Enterprise Governance practice group underscores our commitment to anticipate our clients’ needs and guide them through emerging challenges and evolving regulations,” said Christopher G. Keim, firm Managing Partner. “Our team remains at the forefront of this oversight, assisting our clients in maximizing their productivity with AI while minimizing risks.”
Pioneered by Partner Jim Ickes, the team advises on the full range of AI governance and compliance issues, including acceptable use policies, board-level oversight frameworks, vendor and AI compute agreements, and regulatory compliance across federal and state AI requirements. The group also counsels on AI incident response planning and assesses AI output liability across employment, copyright, and consumer protection frameworks.
In doing so, the team stays current on the rapidly evolving regulatory landscape at the federal, state, and international levels, including FTC and NIST guidance as well as EU AI Act requirements affecting U.S. organizations and their vendors.
“AI governance is not a technology question. It is a legal and fiduciary one, and legal exposure is already here, just not evenly distributed yet,” said Jim. “The questions at the center of governance are not answered by IT departments, but rather lawyers working alongside management and the board. That is what this practice is built to do.”
In the first article of his three-part series on AI governance and cybersecurity exposure, “Mythos, Fable, and the Governance Gap: What AI’s Most Consequential Week Tells Us About Enterprise Risk,” Jim describes how organizations should address the threat environment created by AI.
Jim has spent more than a decade advising clients on data privacy and cybersecurity as the regulatory frameworks governing those fields were written. He holds Health Care Information Security and Privacy Practitioner (HCISPP) emeritus certification and assists both public health departments and private medical practices with HIPAA compliance, including program design, training, documentation, and regulatory response protocols, in addition to his cannabis practice.
Jim’s experience in one of the most heavily regulated data environments in the country translates directly to the AI governance moment, where the standards are still forming and the organizations that act now will define the baseline the industry is eventually measured against. His work in cannabis and hemp deepens that instinct further: counseling clients through a legal landscape that shifted state by state and year by year, Jim understands what it means to build a compliant, defensible business when the rules are still being written.