Gridex research library

AI Compliance Answers for Workflow Controls

Direct, sourced answers to the AI compliance questions businesses actually search for: state AI laws, AI hiring rules, AI insurance exclusions, and AI agent liability. Each answer cites the statute or filing it relies on, then maps the issue to the workflow controls a business can document: notices, consent, human review, audit trails, and escalation points.

Published answers
48
Research areas
6
Publishing rule
Referenced records must meet each answer’s review threshold.

From answer to operating control

These pages answer what the rule or filing says. The next step is to decide what the workflow must log, disclose, approve, retain, or escalate before AI is allowed to operate inside the business.

State Regulations

21 answers
  • Do AI-driven adverse actions require fair lending notices? Yes. Federal fair lending laws require adverse action notices regardless of whether the decision was made by AI. Under ECOA and Regulation B, lenders must provide written adverse action notices with specific reasons for credit denials — regulators have clarified this applies even when an AI model is the proximate decision-maker. FCRA similarly requires adverse action notices when a consumer report influences a credit or employment decision. Colorado's AI Act (SB 26-189, which repealed and reenacted SB 24-205) adds a state-level layer: financial services is a consequential decision, so lenders using an automated decision-making technology (ADMT) must give interaction notice, explain an adverse decision within 30 days, allow correction of inaccurate personal data, and provide meaningful human review — creating overlapping obligations for Colorado lenders.
  • Are there regulations on AI in insurance underwriting? Yes. Colorado's AI Act (SB 26-189, which repealed and reenacted SB 24-205) treats insurance as a covered 'consequential decision' area: a carrier using automated decision-making technology in underwriting or claims must give interaction notice, disclose an adverse decision in plain language within 30 days, let consumers correct inaccurate personal data, and provide meaningful human review — replacing the prior high-risk impact-assessment model. The Colorado Division of Insurance has separately issued guidance requiring carriers to demonstrate that AI underwriting models do not produce unfairly discriminatory outcomes. Multiple other state insurance departments — including California, New York, and Illinois — have issued AI guidance bulletins, and the NAIC has adopted model AI governance principles that many states are incorporating into their regulatory frameworks.
  • Which states require disclosure when AI screens resumes? Illinois is not currently a general applicant-facing resume-screening disclosure regime. HB-3773 requires notice to an employee when an employer uses AI for covered employment decisions; broader prospective-employee notice details appeared in proposed IDHR rules that were not final as of August 13, 2026. The separate Illinois Artificial Intelligence Video Interview Act applies only to AI-analyzed video interviews and requires notice, explanation, and consent — not written consent. Colorado's SB 26-189 will require interaction notice, adverse-outcome disclosure, data correction, and meaningful human review when ADMT makes or substantially influences consequential employment decisions beginning January 1, 2027. Texas does not currently impose a general private-sector candidate disclosure rule for resume screening.
  • What AI rules apply to financial services in Colorado? Under Colorado's AI Act (reenacted by SB 26-189; obligations begin 2027-01-01), financial services is an enumerated consequential-decision category — meaning ADMT used in lending, credit underwriting, or insurance decisions triggers the full set of deployer duties: (1) interaction notice at the point of consumer contact; (2) adverse-outcome disclosure within 30 days of an adverse decision; (3) allow correction of factually incorrect personal data used by the ADMT; and (4) meaningful human review and reconsideration after an adverse decision. Impact assessments and 'high-risk AI system' classification from SB 24-205 no longer apply in Colorado.
  • What are California's AI content watermarking requirements? California SB-942 requires developers of large generative AI systems to embed machine-readable provenance data — commonly called watermarks — into AI-generated images, audio, and video. The watermarks must conform to established provenance standards such as the Coalition for Content Provenance and Authenticity (C2PA) specification. The requirement is intended to make AI-generated content identifiable even after it has been shared or downloaded from the originating platform.
  • Does California require AI detection tools? Yes. California SB-942 requires covered generative AI developers to make publicly accessible detection tools available that can identify content produced by their systems. The detection tool must be free to use, available without an account, and capable of assessing whether a given piece of content was generated by the developer's AI system. This requirement exists alongside the watermarking obligation and is intended to give journalists, researchers, and the public independent means of verifying AI provenance.
  • Who must comply with the California AI Transparency Act? California SB-942 applies to developers of generative AI systems that are made available to consumers in California and that generate text, images, audio, or video. Covered developers must implement provenance standards (such as C2PA) to embed machine-readable watermarks in AI-generated content, provide publicly accessible tools for detecting AI-generated content from their systems, and disclose when users interact with AI. The law applies to developers with 1 million or more monthly users.
  • Does the Colorado AI Act give consumers appeal rights? Yes, under Colorado's AI Act as reenacted by SB 26-189 (obligations begin 2027-01-01). When an ADMT makes or substantially influences an adverse consequential decision, the deployer must provide meaningful human review and reconsideration — and must disclose the adverse outcome to the consumer within 30 days in plain language. The prior 'high-risk AI system' and formal appeal-process-posting requirement from SB 24-205 are gone; the replacement is the human-review and timely-disclosure duty.
  • What are the Colorado AI Act consumer notice requirements? Under Colorado's AI Act as reenacted by SB 26-189 (obligations begin 2027-01-01), ADMT deployers have two distinct notice duties: (1) interaction notice — clear notice at the point of interaction when a consumer interacts with an ADMT; and (2) adverse-outcome disclosure — a plain-language explanation delivered within 30 days when an ADMT makes or substantially influences an adverse consequential decision. The prior SB 24-205 'proximate cause' and pre-decision notice framing no longer applies.
  • What is the difference between developer and deployer obligations under the Colorado AI Act? Colorado's AI Act (reenacted by SB 26-189; the statute formally takes effect 2026-08-12 but all obligations begin 2027-01-01) splits obligations between deployers and developers. Deployers — businesses using ADMT to make or substantially influence consequential decisions — have 4 duties: interaction notice, adverse-outcome disclosure within 30 days, data-correction rights for consumers, and meaningful human review after an adverse decision. Developers — those who build ADMT — must supply technical documentation (intended uses, training-data categories, known limitations), notify deployers of material updates, and retain compliance records 3+ years. Both deployer and developer duties begin 2027-01-01. Impact assessments and risk management programs from SB 24-205 are gone. A company can be both developer and deployer if it builds and uses the same system.
  • Does Colorado require AI impact assessments? No longer. SB 26-189 (signed 2026-05-14) repealed and reenacted Colorado's AI Act, eliminating the impact-assessment requirement entirely. Colorado now instead requires deployers of automated decision-making technology (ADMT) to: give consumers clear interaction notice, disclose adverse consequential decisions within 30 days, allow correction of incorrect personal data, and provide meaningful human review and reconsideration. The statute formally takes effect 2026-08-12, but all compliance obligations — for deployers and developers alike — begin 2027-01-01.
  • What are the penalties for violating Illinois AI hiring law? Illinois has no single AI-hiring penalty schedule. HB-3773 made covered AI conduct a civil-rights issue under the Illinois Human Rights Act; the amendment has no bespoke AI fine, but current §8A-104 permits cease-and-desist relief, actual damages, hiring or reinstatement, promotion, backpay and fringe benefits, attorney and expert fees and costs, other make-whole relief, and civil penalties tiered by prior adjudicated violations. The Artificial Intelligence Video Interview Act (820 ILCS 42) contains no standalone monetary penalty or enforcement section; its §20 is a demographic reporting duty, not an enforcement mechanism. If a hiring tool captures biometric identifiers, BIPA separately provides a private right of action for actual or statutory damages, plus fees, costs, and other relief including an injunction. Public Act 103-769, effective August 2, 2024, treats repeated collection from the same person by the same method as one violation and applies a parallel rule to repeated disclosure to the same recipient by the same method.
  • Can Minnesota consumers opt out of AI profiling? Yes, for profiling of covered consumer data. Minnesota §325M.14 lets a consumer opt out of personal-data processing for profiling in furtherance of decisions that produce legal or similarly significant effects. That consumer right does not create an employment opt-out: §325M.11 excludes a natural person acting in an employment or commercial context from the definition of consumer, and §325M.12 excludes job-applicant and employee-role data when it is collected and used solely within that role. Covered private controllers must still honor the opt-out for qualifying non-employment consumer profiling.
  • When is a data protection assessment required in Minnesota? Minnesota §325M.18 requires a covered private controller to conduct and document a data privacy and protection assessment for personal-data processing involving targeted advertising, sale of personal data, sensitive data, any heightened risk of harm to consumers, or profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment, disparate impact, financial, physical or reputational injury, offensive intrusion, or other substantial injury. The assessment must weigh benefits against risks and account for safeguards. These duties cover qualifying consumer data, not ordinary employment data: §325M.11 excludes people acting in an employment context from the definition of consumer, and §325M.12 excludes job-applicant and employee-role data used solely within that role.
  • Does the Minnesota Consumer Data Privacy Act cover employment AI decisions? Generally no. The Minnesota Consumer Data Privacy Act applies to covered private controllers processing consumer data, but §325M.11 excludes a natural person acting in an employment or commercial context from the definition of consumer, and §325M.12, subdivision 2(13), excludes data collected or maintained about a job applicant, employee, owner, director, officer, medical staff member, or contractor when the data is collected and used solely within that role. Ordinary resume screening, candidate scoring, and employee evaluation therefore do not receive the MCDPA's consumer opt-out or assessment protections. The same business may still be a covered controller for non-employment consumer data if it meets the Act's thresholds.
  • Does New York's AI law apply to the private sector? New York S7543-B (the LOADING Act) primarily applies to state government agencies that use automated decision systems, requiring inventories, impact assessments, and public transparency reports. Private sector employers are not directly covered by S7543-B. However, private sector employers in New York City who use AI in hiring are subject to NYC Local Law 144, which requires annual bias audits and candidate disclosure for automated employment decision tools.
  • What does the New York LOADinG Act cover? New York S7543-B (the LOADinG Act — Legislative Oversight of Automated Decision-making in Government) was signed into law on December 21, 2024, making New York the first state to impose comprehensive oversight on how state agencies use automated decision-making systems and AI. The law requires state agencies to: (1) publicly disclose every automated decision-making system in use, including vendor, purpose, start date, and the extent to which the system replaces human judgment; (2) obtain authorization before using any automated decision-making system and ensure meaningful human review; (3) publish impact assessments for any new or substantially modified system; and (4) maintain human oversight — no agency decision-making process may be fully delegated to an automated system. Enforcement is through legislative reporting obligations. The LOADinG Act applies to New York state agencies only; it does not directly impose obligations on private businesses. Private-sector firms in New York should monitor pending bills like S4394 (employment decision tools) and NYC Local Law 144 for automated employment decisions.
  • Does the Texas TRAIGA require biometric consent? For private-sector employers, no — TRAIGA itself does not impose the biometric consent obligation. Texas HB-149's (TRAIGA) prohibition on identifying individuals from publicly available biometric data without consent applies to government entities only. The controlling biometric consent law for private-sector employers is Texas's CUBI statute (Capture or Use of Biometric Identifier Act, Tex. Bus. & Com. Code §503.001): before capturing a biometric identifier — such as face geometry or a voiceprint in an AI video interview — for a commercial purpose, an employer must inform the individual and obtain consent, protect the data, and destroy it within a set period after the collection purpose ends. TRAIGA's 2025 amendments to CUBI, effective January 1, 2026, add an AI-model-training exception and clarify that media appearing publicly online does not by itself constitute consent unless the individual made it public. Enforcement of both TRAIGA and CUBI is exclusive to the Texas Attorney General; CUBI carries civil penalties up to $25,000 per violation. Employers already compliant with a strict biometric regime such as Illinois BIPA will generally meet CUBI's consent requirements.
  • What are the Texas TRAIGA private sector AI obligations? Texas HB-149 (the Texas Responsible Artificial Intelligence Governance Act, or TRAIGA) — effective January 1, 2026 — is structured as a prohibition-based statute, not an affirmative-obligation regime like Colorado's AI Act. Private-sector businesses that promote, advertise, or conduct business in Texas, produce products or services for Texas residents, or develop/deploy AI systems in the state are prohibited from: (1) using AI designed to incite self-harm, harm to others, or criminal activity (behavioral manipulation); (2) intentionally deploying AI to discriminate against protected classes (disparate impact alone is insufficient to prove intent); and (3) using AI to infringe constitutional rights or target individuals based on constitutionally protected characteristics. Two further TRAIGA prohibitions — biometric identification from publicly available sources, and social scoring — apply to government entities only; for private-sector employers, biometric consent for AI tools is governed by Texas's CUBI statute (Tex. Bus. & Com. Code §503.001), not TRAIGA. TRAIGA's consumer-disclosure duty (telling a person they are interacting with AI) applies to government agencies; healthcare-provider AI disclosure to patients is governed separately by SB 1188, not TRAIGA. There is no statewide mandate for risk assessments, governance policies, or high-impact-system recordkeeping. Enforcement is exclusive to the Texas Attorney General; no private right of action. A 36-month regulatory sandbox allows approved companies to test AI systems with certain requirements waived.
  • What AI rules apply to hiring in Texas? Texas does not currently have a private-sector AI hiring law that forces employers to disclose AI use, run bias audits, or let candidates opt out — there is no Texas equivalent of Illinois's AI Video Interview Act, Colorado's AI Act, or NYC Local Law 144. HB-2060 was a state-agency AI inventory and advisory law, not an employer hiring rule. TRAIGA (HB-149), effective January 1, 2026, is the main Texas AI statute for private employers, but for hiring it bites mainly when a tool is intentionally deployed to discriminate against a protected class or otherwise hits TRAIGA's prohibited-practice categories; TRAIGA does not create a general private-sector hiring disclosure mandate. TRAIGA's biometric-identification and social-scoring prohibitions apply to government entities only — biometric consent for private-sector AI tools, such as video-interview face or voice capture, is governed by Texas's CUBI statute (Tex. Bus. & Com. Code §503.001), not TRAIGA. Federal Title VII still applies, so an AI tool that produces a disparate impact on protected groups is a legal risk even without a Texas disclosure law. Practically, Texas employers should document each tool, its bias controls, any biometric-consent process, and a human-review checkpoint before any adverse hiring decision.
  • What is a high-risk AI system under Colorado law? The 'high-risk AI system' classification no longer exists in Colorado law. SB 26-189 (signed 2026-05-14) repealed and reenacted the Colorado AI Act, replacing the high-risk-AI-system model with a new framework centered on 'automated decision-making technology' (ADMT) that makes or substantially influences 'consequential decisions' — covering education, employment, housing, financial services, insurance, healthcare, and government services. The focus shifted from system classification to disclosure and consumer-rights obligations at the point of use.

Multi-State Comparisons

4 answers
  • Which states require AI disclosure to consumers? Several states require AI disclosure, but the scope differs sharply. Colorado's AI Act (SB 26-189, obligations from January 1, 2027) requires deployers to give consumers notice when automated decision-making technology is used in a consequential decision, plus a plain-language explanation after an adverse outcome. California's AI Transparency Act (SB 942, operative January 1, 2026) requires large generative-AI providers to offer an AI-detection tool and to watermark AI-generated content. Illinois HB-3773, effective January 1, 2026, requires notice to an employee when an employer uses AI for covered employment decisions; the enacted provision does not state a general applicant-notice duty. Separately, the Artificial Intelligence Video Interview Act requires notice, explanation, and consent before AI analyzes an applicant video interview. Connecticut SB-1103 governs state agencies' own AI use rather than private-sector consumer disclosure.
  • Which states actively regulate AI in employment as of 2026? Illinois and Colorado have the most direct state-level AI employment regimes as of 2026. Illinois HB-3773 prohibits discriminatory AI and zip-code proxies in covered employment decisions and requires notice to an employee; the separate AI Video Interview Act governs AI-analyzed applicant video interviews. Colorado's SB 26-189 obligations begin January 1, 2027. Texas TRAIGA applies prohibited-practice rules, including intentional discrimination and certain biometric identification, but does not create a general private-employer hiring disclosure rule. Connecticut SB-1103 governs state agencies, while Connecticut's private-controller privacy amendments and Minnesota's consumer privacy act exclude data used solely within ordinary job-applicant or employment roles; neither should be presented as a general private-employer AI hiring law.
  • How do Colorado and Minnesota AI privacy requirements compare? The two states take different approaches. Colorado's AI Act (SB 26-189, which repealed and reenacted SB 24-205 and whose obligations begin January 1, 2027) is a disclosure-and-notice framework: it does not require data protection assessments or high-risk AI classification. Instead, deployers of automated decision-making technology (ADMT) that makes or substantially influences consequential decisions must give consumers interaction notice, disclose adverse outcomes within 30 days, allow data correction, and provide meaningful human review. Minnesota HF-4757 takes the opposite approach, embedding AI governance within broader consumer data privacy protections and requiring data protection assessments before processing that presents foreseeable risk — including automated profiling producing legal or significant effects.
  • Which states require AI impact assessments? Connecticut has two distinct assessment regimes. SB-1103 / Public Act 23-16 requires Connecticut state agencies to assess AI before implementation. Separately, Connecticut General Statutes §42-522, as amended by Public Act 25-113, requires covered private controllers to assess profiling used for decisions with legal or similarly significant effects for processing activities created or generated on or after August 1, 2026; employment-role data is excluded. Minnesota §325M.18 requires covered private controllers to conduct data privacy and protection assessments for targeted advertising, data sales, sensitive data, heightened-risk processing, and certain profiling, but ordinary job-applicant and employee-role data is excluded. Colorado's SB 26-189 repealed its prior AI impact-assessment model, so Colorado is not on this list.

Insurance & Carriers

9 answers
  • Are D&O and E&O policies affected by AI endorsements? Yes. Berkley PC 51380 specifically targets D&O, E&O, and Fiduciary liability policies with an absolute AI exclusion. Any claim arising from AI use, including board-level AI governance decisions, can be excluded.
  • How do AI endorsements affect EPL policies? Berkley PC 51380 can attach to EPL policies, excluding claims where AI contributed to employment decisions. This is critical for companies using AI in hiring, performance reviews, or termination decisions.
  • How do I know if my policy has an AI exclusion endorsement? Check your policy's endorsement schedule or declarations page for forms CG 40 47 (Verisk/CGL), PC 51380 (Berkley/Professional), or similar AI-specific endorsements. Your broker can run an endorsement audit across all your policies.
  • Do AI exclusions cover shadow AI? Yes. AI exclusion endorsements like Verisk CG 40 47 and Berkley PC 51380 use broad language covering any AI use, including unsanctioned shadow AI tools used by employees without authorization.
  • What is the difference between AI exclusions and AI sublimits? AI exclusions (like Verisk CG 40 47) eliminate coverage for AI claims. At the other end, affirmative or sublimited AI coverage — such as the standalone AI liability products that launched in 2025-2026 — provides protection for AI-related losses rather than removing it, sometimes capped or conditioned on governance controls.
  • Does Verisk CG 40 47 apply to my CGL policy? If your CGL insurer has adopted the Verisk CG 40 47 endorsement, it excludes all AI-related claims from your general liability coverage. Check your policy declarations page for this endorsement number.
  • Which states have adopted Verisk CG 40 47? Verisk CG 40 47 has been adopted in multiple states including Illinois, Colorado, California, New York, and Connecticut, with additional states having pending filings. Check the endorsement tracker for current filing status.
  • What does Berkley PC 51380 exclude? Berkley PC 51380 is an absolute AI exclusion for professional and management liability (D&O, E&O, Fiduciary) that eliminates coverage for any claim based upon, arising out of, or attributable to AI use.
  • What is Verisk CG 40 47? Verisk CG 40 47 is a CGL policy endorsement that excludes coverage for bodily injury, property damage, or personal/advertising injury arising out of AI systems.

Industry Guides

6 answers
  • What AI compliance requirements apply to insurance brokers? Insurance brokers using AI for quoting, risk assessment, or client recommendations fall under Colorado's AI Act (SB 26-189, which repealed and reenacted SB 24-205), which treats insurance as a consequential decision: brokers must give interaction notice, explain adverse AI-driven decisions within 30 days, allow data corrections, and provide meaningful human review — plus potential E&O exposure if AI exclusion endorsements affect their own coverage.
  • What AI compliance risks affect education institutions? Educational institutions using AI for admissions, grading, or student monitoring face FERPA data obligations and emerging concerns about algorithmic bias in educational opportunity decisions. Where state AI law applies — such as Colorado's AI Act (SB 26-189, which repealed and reenacted SB 24-205) — education is a covered 'consequential decision' area, so a school using automated decision-making technology must give interaction notice, disclose adverse decisions within 30 days, allow data correction, and provide meaningful human review, rather than the repealed impact-assessment model.
  • What AI risks do marketing agencies face? Marketing agencies using AI for content generation, targeting, and analytics face risks from California's AI watermarking requirements, state consumer protection laws, and potential E&O claims if AI-generated content causes client harm.
  • Do AI tools in real estate create fair housing risks? Yes. AI tools used for property valuation, tenant screening, or marketing targeting can create fair housing violations if they produce discriminatory outcomes. Housing is a covered 'consequential decision' area under Colorado's AI Act (SB 26-189, which repealed and reenacted SB 24-205): a firm using automated decision-making technology must give interaction notice, disclose an adverse housing decision within 30 days, let consumers correct inaccurate personal data, and provide meaningful human review — replacing the prior high-risk-classification model.
  • What AI compliance issues affect healthcare organizations? Healthcare organizations using AI for diagnostics, treatment recommendations, or patient data analysis face HIPAA obligations for AI-processed data plus state-level AI rules. Healthcare is a covered 'consequential decision' area under Colorado's AI Act (SB 26-189, which repealed and reenacted SB 24-205): an organization using automated decision-making technology must give interaction notice, disclose an adverse decision within 30 days, let consumers correct inaccurate personal data, and provide meaningful human review — replacing the prior high-risk impact-assessment model.
  • What AI governance do financial services firms need? Financial services firms need AI governance covering model risk management, fair lending compliance for AI-driven decisions, and documentation of AI decision-making processes for regulatory examination. Financial services is a covered 'consequential decision' area under Colorado's AI Act (SB 26-189, which repealed and reenacted SB 24-205): a firm using automated decision-making technology must give interaction notice, disclose an adverse decision within 30 days, let consumers correct inaccurate personal data, and provide meaningful human review — replacing the prior impact-assessment requirements.

Governance

5 answers
  • Who is liable when an AI agent causes harm? Liability for an AI agent's actions tends to resolve in layers. Default — deployer or operator: the business that puts the agent into operation is generally answerable for the harm it causes, much as it would be for an employee or a tool it chose to use, under established agency, vicarious-liability, and negligence principles. Vendor or developer: responsibility can extend upstream through product-liability, professional-liability (E&O), or misrepresentation theories where the harm traces to a defect or an overstated capability rather than the deployer's own setup. Contract and indemnity: master service agreements, warranties, limitation-of-liability clauses, and indemnities reallocate that risk between the parties and often decide who actually bears a loss. Insurance and exclusions: a policy may respond, but AI-specific exclusions such as Verisk's CG 40 47 can strip coverage a deployer assumed it had — changing who pays without changing who is legally liable. Human review and audit trail: where a person reviews the agent's decisions and every action is logged, that record shapes whether the deployer is found negligent and whether coverage responds. Outcomes vary by jurisdiction and the agent's degree of autonomy, and newer rules such as Colorado's AI Act (SB 26-189, deployer and developer duties effective January 1, 2027) can add obligations whose breach supports a claim. This is general business and insurance-risk analysis, not legal advice.
  • What should an AI governance framework include? An AI governance framework should include an AI use policy, an inventory of where AI makes or substantially influences consequential decisions, documentation requirements, incident response procedures, and regular audit mechanisms. Note that Colorado's AI Act (SB 26-189, which repealed and reenacted SB 24-205) dropped the old impact-assessment and high-risk-classification model in favor of disclosure, consumer-notice, and human-review duties — so a framework should map to those obligations rather than the repealed assessment regime.
  • What is the difference between an AI governance policy and procedure? An AI governance policy defines the organization's principles and risk tolerance for AI use. Procedures are the specific steps employees follow to comply — approval workflows, documentation templates, and review cadences required by state regulations.
  • What should an AI risk register include? An AI risk register should catalog each AI system, its risk classification, applicable regulations, data inputs, decision scope, last assessment date, responsible owner, and insurance coverage status — critical for both compliance and claims documentation.
  • How do you discover shadow AI tools in your organization? Shadow AI discovery requires network traffic analysis, SaaS management platform audits, browser extension inventories, and employee surveys. Most organizations find 3-5x more AI tools in use than officially sanctioned.

Shadow AI

3 answers
  • How many shadow AI tools does the average enterprise have? Industry surveys indicate the average enterprise has 40-60 AI-enabled tools in use, with only 10-15 formally sanctioned. The gap represents shadow AI exposure that most insurance policies now explicitly exclude.
  • What is the difference between shadow AI and sanctioned AI? Sanctioned AI is officially approved, documented, and governed by the organization's AI policy. Shadow AI bypasses all governance controls, creating unmanaged regulatory and insurance risk because AI exclusion endorsements apply to all AI use regardless of authorization.
  • What is shadow AI? Shadow AI refers to artificial intelligence tools and services used by employees without IT department knowledge or organizational approval — including ChatGPT, AI writing assistants, and AI-powered browser extensions.