Skip to main content

Nixon Peabody LLP

  • People
  • Capabilities
  • Insights
  • About
Trending Topics
    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    • Contact Us
    Practices

    View All

    • Affordable Housing
    • Community Development Finance
    • Corporate & Finance
    • Cybersecurity & Privacy
    • Entertainment & Sports
    • Environmental
    • Franchising & Distribution
    • Government Investigations & White Collar Defense
    • Healthcare
    • Intellectual Property
    • International Services
    • Labor, Employment, and Benefits
    • Litigation
    • Private Wealth & Advisory
    • Project Finance
    • Public Finance
    • Real Estate
    • Regulatory & Government Relations
    Industries

    View All

    • Advanced Manufacturing and Industrials
    • Art and Cultural Property
    • Aviation
    • Cannabis
    • Consumer
    • Energy
    • Entertainment & Sports
    • Financial Institutions
    • Healthcare
    • Higher Education
    • Infrastructure
    • Nonprofit Organizations
    • Real Estate
    • Technology
    Value-Added Services

    View All

    • Alternative Fee Arrangements

      Developing innovative pricing structures and alternative fee agreement models that deliver additional value for our clients.

    • Continuing Education

      Advancing professional knowledge and offering credits for attorneys, staff and other professionals.

    • Crisis Advisory

      Helping clients respond correctly when a crisis occurs.

    • eDiscovery

      Leveraging law and technology to deliver sound solutions.

    • Environmental, Social, and Governance (ESG)

      We help clients create positive return on investments in people, products, and the planet.

    • Global Services

      Delivering seamless service through partnerships across the globe.

    • Innovation

      Leveraging leading-edge technology to guide change and create seamless, collaborative experiences for clients and attorneys.

    • IPED

      Industry-leading conferences focused on affordable housing, tax credits, and more.

    • Legal Project Management

      Providing actionable information to support strategic decision-making.

    • Legally Green

      Teaming with clients to advance sustainable projects, mitigate the effects of climate change, and protect our planet.

    • Nixon Peabody Trust Company

      Offering a range of investment management and fiduciary services.

    • NP Capital Connector

      Bringing together companies and investors for tomorrow’s new deals.

    • NP Second Opinion

      Offering fresh insights on cases that are delayed, over budget, or off-target from the desired resolution.

    • NP Trial

      Courtroom-ready lawyers who can resolve disputes early on clients’ terms or prevail at trial before a judge or jury.

    • Social Impact

      Creating positive impact in our communities through increasing equity, access, and opportunity.

    • Women in Dealmaking

      We provide strategic counsel on complex corporate transactions and unite dynamic women in the dealmaking arena.

    1. Home
    2. Insights
    3. Articles
    4. Minimum viable AI governance: How growing companies can manage AI risk without slowing down

      Articles

    Article

    Minimum viable AI governance: How growing companies can manage AI risk without slowing down

    Sep 29, 2026

    LinkedInX (Twitter)EmailCopy URL

    AI governance starts with knowing what your AI does, what data it uses, and what could go wrong. Then building controls that match the risk.

    Authors

    • Troy Lieberman

      Counsel
      • Boston +1 617.345.1306
      • tlieberman@nixonpeabody.com
      Troy Lieberman

    Growing companies do not need a sprawling compliance program in place before deploying AI. Rather, a focused approach can address the risks that matter most while your governance program grows alongside the business.

    If your company is adopting AI, you are probably hearing a deceptively simple question: Are you AI compliant? A better answer focuses on three questions: What are you using AI for? What could go wrong? And what are you doing about it?

    Some requirements are clear: a company either satisfies them, or it does not. But there is no single rulebook that determines whether a company is broadly “AI compliant.” Companies instead must navigate a patchwork of privacy, consumer-protection, anti-discrimination, sector-specific, and AI-specific laws, along with voluntary standards and increasingly detailed contractual requirements from sophisticated customers. Federal efforts to harmonize AI regulation have not changed that existing landscape.

    For most companies, particularly startups and growth-stage businesses, governance does not mean spending six months designing the perfect AI program before putting AI to work. It means identifying the risks that matter, putting reasonable controls around them, and building from there.

    Start with the use case, not the technology

    You do not need to start with an exhaustive inventory of every technical feature of an AI model. Start with four practical questions: 

    • What data is going in?
    • What is the system doing with it?
    • What is the desired output?
    • And what happens if it is wrong?

    For the first question, ask: Where is the data coming from? Do you have the right to use it for this purpose? Is it shared with a third party, such as the model provider? How long is it retained? Is it used to train a model? Does it include personal information, health information, or confidential customer data?

    The last question matters most. A system that hallucinates while summarizing an internal email creates a different risk than one that makes or influences a recommendation about healthcare, employment, credit, or another consequential decision. The controls should match the consequences.

    Answering these questions early is easier, and usually cheaper, than answering them after the product is fully built.

    A common pattern companies follow when adopting AI is loading all available data into an AI system because it is the fastest way to develop or improve the product. Nobody stops to separate customer data from other data, distinguish between training and inference, or build controls around retention and downstream providers.

    Later, a sophisticated enterprise customer may ask: Is our data training your model? Where does it go? Which third parties can see it? Can you delete it? 
    Suddenly, what began as a quick technical decision becomes a legal issue, a contract negotiation, a sales obstacle, and an architectural problem. That is compliance debt: a risk that is relatively inexpensive to address early but much costlier to unwind later.

    Test how AI fails, not just whether it works

    Product teams naturally focus on whether a system performs its intended function. In high-risk use cases, they also need to ask how it fails.

    That does not mean demanding zero failures. It means understanding reasonably foreseeable failure modes and deciding which call for more testing, guardrails, human intervention, use restrictions, or other controls.

    Ask practical questions: What happens if the model hallucinates, produces a biased result, exposes confidential information, relies on stale or inaccurate data, or makes a recommendation that a human accepts without meaningful review?

    Let the consequences drive the response. The greater the potential harm, the stronger the case for evaluation, documentation, human oversight, and/or restrictions on how the system can be used.

    Build “minimum viable” AI governance

    Growing companies often get pulled toward one of two extremes: deploying AI with little oversight or trying to recreate a global bank’s governance program before the company’s resources or risk profile justify it.

    The practical middle ground is minimum viable AI governance.

    For an early-stage company, it should include at least five things:

    • Know what AI you are using. You cannot govern what you do not know exists. Include both customer-facing systems and internal tools employees use.
    • Know what you are using it for. For each system, understand the use case, the data involved, the people affected, and the consequences if it performs incorrectly.
    • Identify the meaningful risks. Decide where AI can and cannot be used, and which applications warrant additional scrutiny.
    • Put safeguards around high-risk uses. Depending on the use case, measures may include evaluation and testing, human review, security and data controls, documentation, or limits on deployment.
    • Give someone ownership. AI governance does not necessarily require a new department or committee, but someone needs to own the process.

    The goal is not a perfect governance program on day one. Pick the changes that meaningfully reduce risk and create good habits, then mature the program as the company, product, and risks evolve.

    Bring legal in early, not to ask whether you can use AI, but to explain what you are trying to build and identify the fastest responsible way to build it.

    For enterprise-facing AI companies, compliance is part of the pitch

    It is easy to treat AI governance as overhead. But for companies selling technology into regulated enterprises, this misses an important part of the business case.

    Banks, healthcare organizations, insurers, large employers, and other sophisticated customers are already conducting their own AI diligence. They want to know which model providers you use, whether customer data trains a model, how data is secured and retained, whether humans review outputs, how the system is tested and audited, and who owns governance. Those expectations may go beyond what applicable law currently requires. For many companies, your customer will likely be your toughest AI regulator for the next several years.

    A startup that can readily answer these questions will move through diligence faster. A company that waits for those questions to arrive before figuring out the answers can lose weeks, and potentially a deal.

    That makes AI governance more than risk mitigation. It can be a real competitive advantage. Answering a customer’s AI diligence questionnaire in two days, instead of spending three weeks figuring out how your own product works, can help close the deal. The same infrastructure that helps a company respond efficiently to enterprise diligence can also help it prepare for emerging regulatory requirements.

    Don’t wait for AI regulation to settle

    It is tempting to wait for lawmakers to establish clearer rules before investing in governance. That is increasingly difficult to justify.

    The regulatory landscape is fragmented and moving fast. Existing privacy, consumer-protection, anti-discrimination, and industry-specific laws already apply to many AI uses. States continue to enact AI-specific requirements, while federal regulators can use existing authority rather than wait for a comprehensive AI statute. 

    The market is moving too. Sophisticated customers are already setting operational standards through diligence and contracts. And while federal efforts to create a more uniform framework continue, they have not eliminated the state-law patchwork. 

    You do not need to predict precisely what an AI statute will require several years from now. Instead, build around durable risk-management principles: understand the system and its data, evaluate meaningful risks and failure modes, document important decisions, and be able to explain the controls you put in place. 

    An increasingly useful principle is “show your work”

    If a regulator, customer, board, or litigant asks what happened, the first questions may be simple: What did you say the product would do? What did you know about its limitations? What testing did you perform? What did you do when you found a problem?

    Companies will be in a stronger position if they can answer those questions and explain why they chose their controls. This does not require enormous documentation. It requires a defensible process proportionate to the risk.

    What companies should do now

    Inventory AI use. Identify customer-facing systems, as well as material internal AI tools. Focus first on uses involving sensitive data, consequential decisions, external-facing outputs, or regulated activities. 

    Map the data. For each system, determine what information enters it, where that information came from, whether the company has the right to use it, where it goes, whether third parties retain it, and whether it is used for model training.

    Identify and test failure modes. Do not limit testing to whether a product performs as expected. Consider reasonably foreseeable ways it can fail and the consequences of those failures.

    Prioritize controls by risk. Reserve more significant testing, human oversight, documentation, and approval processes for high-risk uses rather than imposing the same controls on every AI application.

    Review enterprise readiness. If you sell AI-enabled products, pressure-test whether you can answer the questions sophisticated customers are already asking about data use, security, model providers, testing, human oversight, and governance.

    Document the important decisions. Do not create paperwork for its own sake. But be able to show why you approved high-risk AI uses, what risks you considered, and what controls you selected.

    Bring legal in early. Do not wait until the product is built or a customer questionnaire arrives. Explain what you are trying to build so legal can help identify the design choices that will be expensive to change later.

    The bottom line: Don’t start by asking whether your company is “AI compliant.” Start by understanding what your AI is doing, what data it is using, and what happens when it is wrong. From there, you can build governance around the risks that actually matter, without letting compliance dictate the product.

    Practices

    Emerging Companies

    Industries

    Technology

    Insights And Happenings

    • Article

      Equity compensation strategies for early-stage technology companies

      Sep 25, 2026
    • Article

      Protecting your brand from day one: Trademark and IP basics for consumer startups

      Aug 19, 2026
    • Alert

      Lessons from Shealy v. Seaside: When client AI use can sink work product protection

      July 29, 2026
    The foregoing has been prepared for the general information of clients and friends of the firm. It is not meant to provide legal advice with respect to any specific matter and should not be acted upon without professional counsel. If you have any questions or require any further information regarding these or other related matters, please contact your regular Nixon Peabody LLP representative. This material may be considered advertising under certain rules of professional conduct.

    Subscribe to stay informed of the latest legal news, alerts, and business trends.Subscribe

    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    • Contact Us
    • Privacy Policy
    • Terms of Use
    • Accessibility Statement
    • Statement of Client Rights
    • Supplier Code of Conduct
    • Nixon Peabody International LLP
    • PAL
    © 2026 Nixon Peabody. All rights reserved