AI Governance & Responsible AI

Adopt AI with confidence — and with the documentation to show for it.

Your staff are already using AI tools, and your vendors are adding AI to software you already own. We help you decide what's approved, what data can go where, and who reviews new uses — using published frameworks, sized to your organization, designed so innovation and oversight move together.

What we build

The working parts of an AI governance program.

Know what you have

AI system inventory

Every AI tool and AI-enabled feature in use or on order: who uses it, for what, with what data, and who owns it.

Set the rules

AI use & acquisition policies

Approved and prohibited uses, data-handling rules, human-review requirements, and an intake path for new tools, drafted for your approval.

Buy carefully

Vendor AI due diligence

Questionnaires and review steps covering data retention, training on your data, security, accuracy testing, and incident notice.

Assess risk

Risk & impact assessments

Facilitated assessments against the NIST AI Risk Management Framework's Govern, Map, Measure, and Manage functions, and, for Maryland public bodies, the State's Responsible AI Policy.

Decide well

Governance structure

A review committee or accountable owner, decision rights, escalation, and a review cycle that fits how you actually operate.

Make it stick

Training & records

Practical staff training on the policy, with completion and attestation records you can produce when asked.

Who we work with

Built for organizations without an AI office.

Maryland state and local public bodies

  • Inventories and assessments aligned to the State's Responsible AI Policy
  • Acquisition policies and vendor review for AI-enabled procurements
  • Board and leadership briefings on AI oversight

Nonprofits, associations, and businesses

  • A right-sized AI use policy and approved-tool list
  • Vendor due diligence for donor, member, customer, and employee data
  • Assessments for AI used in hiring, eligibility, pricing, or marketing
  • Coordination with MODPA readiness where AI profiles consumers

For law firms and legal departments

Lawyers' duties of competence, confidentiality, communication, supervision, and reasonable fees all apply to generative AI, as the ABA's Formal Opinion 512 (2024) and a growing number of state bar opinions explain. Your firm's ethics counsel decides what those duties require. We build the operational program that lets you show you've met them:

  • An inventory of the AI tools in use across the firm, including AI features inside existing practice-management and research platforms
  • A firm AI use policy drafted for your ethics partner's or general counsel's approval
  • Vendor due diligence focused on client confidentiality: data retention, training on client data, access controls, and subprocessors
  • An intake and approval step for new tools, plus training and attestation records

Ulyx Advisory does not provide legal advice or interpret rules of professional conduct; those determinations remain with your firm's counsel.

Engagements

Three ways to start.

Each is fixed-scope and fixed-fee, quoted after a 30-minute discovery call based on the number of tools, teams, and data types involved.

Start here

AI Governance Snapshot

Inventory of AI in use, a gap review against the NIST AI RMF, and a prioritized roadmap.

Combined

MODPA + AI Readiness

One engagement covering both privacy readiness and AI governance, for organizations whose AI tools touch consumer data.

Questions

Frequently asked

We're a small organization. Do we really need AI governance?

If your staff use AI tools, or your vendors have added AI features to software you already pay for, you are already making decisions about AI. Governance just makes those decisions deliberate: which tools are approved, what data can go into them, and who reviews new uses. For a small organization, that can be a short policy, an inventory, and a simple approval step.

What frameworks do you use?

Published, public frameworks: primarily the NIST AI Risk Management Framework (AI RMF 1.0) and its Generative AI Profile, and, for Maryland public bodies, the State's Responsible AI Policy. We tailor them to your size and risk rather than applying them wholesale.

Is this legal advice?

No. We provide operational, non-legal consulting: inventories, policies drafted for your approval, assessments, and training. Your counsel decides what laws and professional rules require of you. For law firms, that means your general counsel or ethics partner.

Can you help us choose an AI vendor?

We build the due-diligence process and questionnaire you use to evaluate vendors, and we can facilitate the review. The purchasing decision and contract terms stay with you and your counsel.

How does this relate to MODPA?

MODPA requires data protection assessments for profiling and other higher-risk processing. If your AI tools profile consumers or make decisions about them, the AI inventory and risk assessment feed directly into that work, so the two engagements can share effort.

Ulyx Advisory provides non-legal governance consulting using published frameworks. We do not provide legal advice or representation, and we do not interpret laws or rules of professional conduct for clients.

Start with what you're already using.

On a 30-minute call we'll map where AI shows up in your organization today and which engagement fits.

Schedule an AI Governance Call