Defending it: privilege, cure periods, and the preemption endgame

Lesson 5 of 5 in Capstone: Building and Defending a US AI Compliance Program.

Week ten the Colorado AG’s office sends a civil investigative demand about SiftIQ notices. This is where “defensible” stops being a slide-deck word. Three assets decide how this goes.

The RMF posture. In Texas, substantial compliance with the NIST AI RMF is a statutory defense under TRAIGA. Everywhere else it is reasonableness evidence — the thing that reframes the conversation from did anything ever go wrong (something always did) to did you run a serious program that found and fixed it. Regulators settle with the second company and make examples of the first.

The cure period. Colorado’s 60-day cure (available until January 1, 2030) and TRAIGA’s 60-day cure are not grace — they are a test of operational readiness. A cure letter answered with fixed notices, dated remediation records, and a root-cause memo inside the window usually ends the matter. A cure window spent locating documents is an admission dressed as a deadline. This is why every artifact in this module was built with a template and an owner.

Privilege discipline. Route candid legal-risk analyses through counsel for legal advice — those can claim attorney client privilege. But know its limits: routine compliance artifacts are generally not privileged, and some are designed for regulators’ eyes (CCPA risk-assessment submissions from April 2028, LL144 published summaries, AB 2013 postings). The working rule: facts and required assessments will be seen — write them accurate and neutral; strategic legal analysis stays in the privileged channel. A program that tries to privilege everything ends up protecting nothing and looking obstructive doing it.

Documentation that helps: the dated remediation trail

Finding → owner → decision → fix → re-test, all dated. The single most persuasive artifact in any inquiry: it proves the program operates. The SiftIQ 0.68 finding followed by threshold analysis, vendor escalation, and a re-audit is a defense exhibit.

Documentation that helps: scoping and risk-acceptance memos

A reasoned, dated memo explaining why a system was tiered where it was — or why a residual risk was accepted, by whom, with what authority — converts hindsight questions into evidence of governance. Silence on the same points reads as negligence.

Documentation that hurts: the unactioned red flag

The worst document in American litigation is the internal analysis that names a risk nobody addressed. If you measure it, you must disposition it — mitigate, accept with sign-off, or escalate. An impact assessment describing a disparity, followed by nothing, is a plaintiff’s opening exhibit.

Documentation that hurts: adjectives and adversaries

“The model is probably illegal in Illinois but ship it” in a Slack thread will outlive everyone in the thread. Train teams to write facts, options, and decisions — not verdicts. And never let marketing write “bias-free AI” into a deck: every overstated claim is an FTC deception theory and a warranty you did not mean to give.

Last briefing to the board: the preemption endgame. EO 14365 set DOJ against state AI laws; states kept legislating; nothing is resolved. You cannot predict the outcome, so you plan across it.

Scenario: DOJ wins some

Courts strike parts of some state laws — most plausibly extraterritorial reaches under the dormant Commerce Clause or compelled-speech aspects of disclosure mandates under the First Amendment. Posture: almost nothing changes for you. Duties fall unevenly and slowly; the surviving patchwork still sets your floor, and Title VII/ECOA never depended on any of it.

Scenario: federal framework passes

Congress enacts a national AI framework with express preemption — the White House’s March 2026 legislative framework is the template. Posture: the crosswalk earns its keep; you re-render existing controls to one federal target. History says national standards land near the strictest state practice, so HCD design was the hedge all along.

Scenario: stalemate persists

The most likely 2027: no comprehensive statute, revived moratorium attempts fail, litigation grinds, states add laws each session. Posture: exactly this module — strictest-state design, quarterly horizon scanning, contracts that flex. Plan for this one; treat the others as options.

Scenario: moratorium returns

A future Congress attaches a narrower moratorium to must-pass legislation and it survives. State AI-specific enforcement pauses — but generally applicable law (civil rights, consumer protection, breach notification) is untouched, and Spending Clause coercion limits (NFIB v. Sebelius) constrain funding-condition workarounds. Posture: keep the program; the RMF spine and sectoral duties never blinked.

And build the horizon-scanning loop as a standing control, not a newsletter subscription: a quarterly cycle that tracks state legislative sessions, the Colorado AG and CPPA rulemakings (both due January 1, 2027), the NIST RMF revision now underway, EO 14409’s voluntary frontier framework (a participation decision for your vendor — and diligence question for you), and DOJ’s EO 14365 docket. Each item gets an owner, a trigger condition, and a pre-agreed response path — regulatory change management is just drift monitoring pointed at the law.

One closing discipline separates the programs that age well: ethics beyond compliance. The law you just mastered is a floor with holes — no state statute yet reaches most internal productivity uses, and cure periods forgive paper more readily than people. Windrose’s program keeps an internal review board for uses the statutes miss, invites affected-worker feedback (GOVERN 5 — the appeal channel data that finds problems before regulators do), and publishes a voluntary transparency report. Not because a statute requires it — because the next statute will, and because the record of having done it unforced is the most credible defense exhibit of all.

Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.