The brief: one company, every regime at once
Lesson 1 of 5 in Capstone: Building and Defending a US AI Compliance Program.
First move: resist the urge to start with any single statute. Start with the spine — the NIST AI RMF — because every regime you must satisfy either references it (TRAIGA’s defense), rhymes with it (Colorado’s dead risk-program mandate, ISO 42001), or rewards it as reasonableness evidence (FTC, EEOC, AG inquiries). Programs built statute-first collapse the day a statute changes; Colorado just proved statutes change. Programs built RMF-first treat each law as a rendering target for controls that exist anyway.
Week one produces four artifacts. A charter — board-approved, naming an accountable executive and an AI governance committee with authority to block launches (GOVERN 1 and 2). An AI inventory — every system, its owner, its role split, its affected populations; you cannot govern what you have not listed, and OMB requires exactly this of federal agencies for a reason. A risk-tiering methodology — likelihood × severity of harm to people, not to the company, mapped to control intensity. And a nexus analysis: for each system, where does law attach?
Nexus is where multistate strategy is decided, so do the analysis honestly. SiftIQ screens candidates for NYC roles → LL144 attaches to the jobs, not to where Windrose is incorporated. Illinois workers → HB 3773. Colorado is home turf → SB 26-189 for employment ADMT. California applicants → CCPA ADMT regulations. Texas operations → TRAIGA. AdvanceScore is credit → ECOA and Regulation B follow the applicant everywhere, no state nexus required. Windy talks to consumers in Utah → disclosure duties. And Windrose’s frontier-lab vendor carries its own SB 53 duties, which you will exploit contractually rather than duplicate.
Then make the strategic call every multistate company faces: highest-common-denominator design (one control set meeting the strictest applicable rule, everywhere) versus state-by-state gating (geofencing features and notices per state). The default answer is HCD for substance — one explanation workflow, one audit program, one documentation standard — with thin state-specific rendering on top: the LL144 posting, the Illinois notice text, the Colorado 30-day clock. Gate by state only where a duty is genuinely expensive and localized. Remote work makes geography leak; a control that depends on knowing where every candidate sits will fail an AG’s first document request.
Ninety days to a defensible program
- Charter + accountable executive (GOVERN 1–2)
Board resolution; committee with launch-blocking authority; policies mapped to GOVERN subcategories.
- AI inventory + role assignment
Every system: owner, developer/deployer role, affected populations, lifecycle stage.
- Nexus analysis per system
Which states, which sectors, which regulators. LL144 follows NYC jobs; ECOA follows credit applicants everywhere.
- Risk-tier each system
Likelihood × severity of harm to individuals. Consequential decisions land in the top tier automatically.
- Design controls at highest common denominator
One control set: notices, explanations, human review, testing, documentation, records.
- Render state-specific artifacts
LL144 audit posting, Illinois notice, Colorado 30-day explanation, CCPA pre-use notice, ECOA adverse-action letters.
- Operate: monitor, audit, respond, improve
The Map–Measure–Manage loop, forever. Launch is the start of obligations.
Key terms: NIST AI Risk Management Framework, automated decision-making technology, deployer, developer, consequential decision, risk tiering
Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.