ATLAS/BRIEFINGLaw, organized for consequential decisions.

TAG

AI governance

Contracting and legal control over AI systems and outputs.

PRIV-04 · 01

Contracting With AI Vendors: Training Data, Output Rights, Security, and Liability

9 MIN · PRIV

Buying an AI system transfers your data and imports someone else's legal exposure. This brief works the seven terms that decide who carries that risk, with realistic fallback positions.

  • Default vendor terms often permit training on customer inputs; the restriction must be written, cover outputs, and bind subprocessors.
  • Output ownership is assigned by contract, but assignment cannot create copyright the law does not grant to purely machine-generated material.
  • IP indemnity is the term most negotiated and most conditioned; read the exclusions, caps, and required-use conditions before relying on it.
Read the full brief →

PRIV-05 · 02

Privacy and Data Protection Assessments: When They Are Required

8 MIN · PRIV

State privacy laws require a written assessment before high-risk processing begins. This brief identifies the trigger categories, the contents that hold up under scrutiny, and who can compel production.

  • Most state comprehensive privacy laws require a documented assessment for targeted advertising, sale of personal data, profiling with significant effects, and sensitive data.
  • The assessment must weigh benefits against risks and record mitigation, not merely describe the processing; a data inventory is not an assessment.
  • In most states nothing is filed; the assessment is produced on the attorney general's demand, usually through a civil investigative demand.
Read the full brief →