Share with your CISO
California’s 30-plus AI statutes, most taking effect in 2025 and 2026, are the clearest preview of where U.S. AI compliance is heading, and Duane Morris partner Agatha Liu’s four-dimensional compliance framework offers the most operationally precise map of that terrain published to date. The framework organizes every AI obligation across jurisdiction, pipeline role (data owner, model developer, deployer, or end user), and seven risk categories including bias, opacity, and complacency. Model deployers carry the largest share of California’s obligations, even when they didn’t build the underlying model.
What this means for your business
The compliance failure mode that’s actually expensive isn’t missing a new statute. It’s having no durable method for absorbing new statutes without rebuilding the program from scratch each time. Most enterprise AI compliance efforts are organized around jurisdictions and legal counsel assignments, which means they’re reactive by design. The question this framework forces is structural: does your organization know which pipeline role it plays, and has that role been assigned concrete, auditable obligations rather than general legal department awareness?
The risk taxonomy Liu proposes is where the framework earns its keep. Deception and privacy intrusion get attention because they generate litigation and headlines. Opacity and complacency, meaning the erosion of human oversight as AI handles more decisions at scale, get systematically underinvested until an enforcement action or discovery request makes them expensive. That asymmetry isn’t an accident. It reflects where legal risk has historically been visible, not where AI risk actually concentrates. A CISO building a program against all seven categories is essentially buying insurance against the next regulatory priority, not just the current one.
The deployer accountability finding deserves a hard look before your next vendor contract cycle. California’s framework holds the entity putting AI into operational use primarily responsible for its effects, even when that entity can’t fully control the underlying model’s behavior. That’s not a California quirk, it’s the regulatory logic emerging across the EU AI Act and proposed federal frameworks. If your organization deploys third-party models without contractual controls over training data provenance, explainability standards, or bias audits, you’re carrying obligations you may not have priced into those agreements. I’d revise this read if a federal framework preempts state deployer liability, but nothing on the current legislative calendar suggests that’s coming soon.
Based on reporting from Companies Can Tackle AI Compliance by Using Multipart Framework, originally published 2026-06-18 03:00:00.

