Your staff are already using AI tools, and your vendors are adding AI to software you already own. We help you decide what's approved, what data can go where, and who reviews new uses — using published frameworks, sized to your organization, designed so innovation and oversight move together.
Every AI tool and AI-enabled feature in use or on order: who uses it, for what, with what data, and who owns it.
Approved and prohibited uses, data-handling rules, human-review requirements, and an intake path for new tools, drafted for your approval.
Questionnaires and review steps covering data retention, training on your data, security, accuracy testing, and incident notice.
Facilitated assessments against the NIST AI Risk Management Framework's Govern, Map, Measure, and Manage functions, and, for Maryland public bodies, the State's Responsible AI Policy.
A review committee or accountable owner, decision rights, escalation, and a review cycle that fits how you actually operate.
Practical staff training on the policy, with completion and attestation records you can produce when asked.
Lawyers' duties of competence, confidentiality, communication, supervision, and reasonable fees all apply to generative AI, as the ABA's Formal Opinion 512 (2024) and a growing number of state bar opinions explain. Your firm's ethics counsel decides what those duties require. We build the operational program that lets you show you've met them:
Ulyx Advisory does not provide legal advice or interpret rules of professional conduct; those determinations remain with your firm's counsel.
Each is fixed-scope and fixed-fee, quoted after a 30-minute discovery call based on the number of tools, teams, and data types involved.
Inventory of AI in use, a gap review against the NIST AI RMF, and a prioritized roadmap.
Snapshot plus use and acquisition policies, vendor due-diligence process, risk assessments for priority uses, governance charter, and staff training.
One engagement covering both privacy readiness and AI governance, for organizations whose AI tools touch consumer data.
If your staff use AI tools, or your vendors have added AI features to software you already pay for, you are already making decisions about AI. Governance just makes those decisions deliberate: which tools are approved, what data can go into them, and who reviews new uses. For a small organization, that can be a short policy, an inventory, and a simple approval step.
Published, public frameworks: primarily the NIST AI Risk Management Framework (AI RMF 1.0) and its Generative AI Profile, and, for Maryland public bodies, the State's Responsible AI Policy. We tailor them to your size and risk rather than applying them wholesale.
No. We provide operational, non-legal consulting: inventories, policies drafted for your approval, assessments, and training. Your counsel decides what laws and professional rules require of you. For law firms, that means your general counsel or ethics partner.
We build the due-diligence process and questionnaire you use to evaluate vendors, and we can facilitate the review. The purchasing decision and contract terms stay with you and your counsel.
MODPA requires data protection assessments for profiling and other higher-risk processing. If your AI tools profile consumers or make decisions about them, the AI inventory and risk assessment feed directly into that work, so the two engagements can share effort.
Ulyx Advisory provides non-legal governance consulting using published frameworks. We do not provide legal advice or representation, and we do not interpret laws or rules of professional conduct for clients.
On a 30-minute call we'll map where AI shows up in your organization today and which engagement fits.
Schedule an AI Governance Call