Governance First: How to Build the Legal Architecture That Lets AI Work for You
Part One of this series documented the AI-driven threat environment, from autonomous cyberattacks to the emergence of frontier AI cybersecurity tools and the double-edged nature of systems like Claude Mythos. Part Two addressed the legal exposure: Executive Order 14409, FTC enforcement, SEC disclosure liability, Delaware board oversight doctrine, and AI output liability across employment, copyright, and defamation. This third and final installment addresses what to do about it.
AI Governance Is Not a Technology Problem. It Is a Legal and Fiduciary One.
There is a question at the center of every organization’s AI strategy, and it is not a technology question. It is a governance question: what should AI be allowed to know, who decides, and under what controls?
That question does not get answered by an IT department or a software vendor. It gets answered by lawyers, working alongside management and the board, building the legal architecture that determines how artificial intelligence is selected, deployed, permissioned, monitored, and governed across the enterprise.
Most organizations have focused on the tool layer: which platforms to use, how to prompt them, what they cost. That is a starting point, not a governance strategy. It addresses what AI can do. It says nothing about what AI should be allowed to do, who is accountable when it causes harm, or what happens when a regulator or a court asks for a defensible record of how AI decisions were made.
Those are legal questions. And right now, most enterprises do not have legal answers for them.
In June 2026, hackers exploited Meta’s AI support chatbot to take over high-profile Instagram accounts, including the Barack Obama White House account and the Chief Master Sergeant of Space Force’s account, by doing nothing more sophisticated than asking the bot to link the target account to a new email address. Meta had deployed its AI support system with the authority to reset passwords and perform account maintenance across all Facebook and Instagram accounts. No human escalation path existed. Victims reported they could not reach a person to recover their accounts. The attack required no technical skill. It required only a sentence. That is what happens when an AI is given the authority to act without governance controls on what it is permitted to do.
Two federal frameworks now define the governance benchmark that regulators, auditors, and plaintiffs’ counsel will apply. NIST AI 600-1, the Generative Artificial Intelligence Profile, issued July 26, 2024, pursuant to Executive Order 14110, identifies twelve risk categories unique to generative AI. These include hallucinations, where AI systems confidently generate false or misleading information; data poisoning, where training data is manipulated to corrupt model outputs; and prompt injection, where maliciously crafted inputs manipulate AI behavior. The profile provides more than 200 suggested actions for developers, deployers, and operators. NIST AI 600-1 is not a regulation and does not impose binding legal obligations. It is, however, likely to be cited in regulatory investigations, litigation discovery, and governance audits as the key benchmark for evaluating whether an organization’s generative AI controls were reasonable.
The EU AI Act’s Article 53 obligations for providers of general-purpose AI models, Regulation (EU) 2024/1689, became applicable on August 2, 2025. Developers of virtually all major AI platforms in use today are now subject to mandatory technical documentation, downstream disclosure, copyright compliance, and training data transparency obligations under EU law. Whether a specific U.S. enterprise user has a direct contractual right to that documentation will depend on the structure of its vendor relationship. Organizations contracting with AI vendors should require, in their agreements, access to the technical documentation, copyright compliance commitments, training data summaries, and risk disclosures necessary to evaluate the vendor’s compliance posture and the organization’s own downstream exposure.
AI systems can change their own behavior and capabilities over time, through continued learning, self-generated training data, model updates, or agentic feedback loops. Some call this recursive self-improvement. The governance issue is straightforward. A framework built around a fixed snapshot of an AI tool’s capabilities can become obsolete faster than any annual review cycle.
A March 2026 analysis published by Stanford Law School’s CodeX center argues that boards deploying systems with recursive self-improvement capabilities may face Caremark oversight exposure and identifies three technical risk patterns: behavioral drift, where recursive training on synthetic outputs progressively severs the connection between system behavior and human norms; self-poisoning, where minor errors and biases compound across iterations rather than washing out; and goal subversion, where the recursive architecture creates a surface for manipulation that can redefine the agent’s objectives incrementally across cycles. Vendor contracts should require notice of material model updates. Internal policies should be tied to approved versions, use cases, and capabilities. Board oversight should account for the possibility that an approved AI tool may later develop or receive capabilities or access terms that were not present at the time of approval.
The Fable 5 episode is a live example. A safety bypass triggered an eighteen-day export-control shutdown in June. When the model returned, it came back on different commercial terms, with standard subscription access ending days later and usage shifting to metered credits. An organization that had mapped its dependency on Fable 5 could plan around the change. One that hadn’t could only learn about the change the way it learned about the shutdown itself: after the fact.
Anthropic’s own disclosure on July 30 makes the point more starkly than Fable did. The company said a misconfiguration with an evaluation partner left testing environments, which were supposed to be isolated, connected to the open internet. According to Anthropic, Claude Opus 4.7, Claude Mythos 5, and an internal research model used that access to breach three real organizations using basic techniques, like weak passwords. The earliest incident dated back to April. Anthropic didn’t know until it reviewed 141,000 test sessions in late July, and two of the three affected organizations didn’t know until Anthropic told them. If the developer of a model can’t reliably confirm what environment its own system is operating in, an enterprise counting on a vendor’s assurances about containment is relying on something the vendor itself cannot fully verify.
What “Information Governance Posture” Actually Means
Data inventory
- Does the organization know what personal, sensitive, or regulated data it holds, where it lives, and who has access to it?
Vendor and third-party risk
- Are vendor contracts and diligence practices current with applicable security standards and state-law requirements? And do they account for vendors’ vendors?
Incident response planning
- Does the organization’s incident response plan, the documented playbook for detecting, containing, and recovering from a cyberattack, account for AI-accelerated attack timelines and autonomous threat actors?
AI use policy
- Has the organization addressed what data employees may submit to AI tools, and what that means for confidentiality, privilege, and regulatory compliance?
Board-level governance
- Is cybersecurity and AI governance a standing board-level agenda item with documented accountability and board minutes to prove it?
The Opportunity Inside the Obligation
Most organizations treat data security and AI governance as separate problems. They are the same work.
Getting an organization’s data house in order, knowing what information it holds, where it lives, who can access it, how it is protected, and how it is governed, is the prerequisite for deploying AI safely. AI cannot be responsibly integrated into enterprise workflows without first answering those questions.
Integrating AI thoughtfully, with governance architecture in place, also strengthens information governance across every function of the enterprise. AI creates governance obligations. Properly deployed, it also helps organizations meet them. It can map the data environment, flag anomalies, monitor who accesses what data and when, and surface compliance gaps in real time, at a scale no manual process could match.
AI-enabled defense is becoming an essential component of any serious cybersecurity program. But AI-based tools cannot be deployed defensively, responsibly, or sustainably without governance architecture in place first. The sequence matters. Establish the governance framework before deploying the technology. The organizations that get that order right will be the ones best positioned when the rules get tested.
AI is not a department or a tool category. It is a condition of how modern enterprises already operate, whether leadership has made a deliberate choice about it or not. Employees are using it. Vendors are using it. The question is not whether to address AI governance. It is whether to do so intentionally, with legal architecture in place, or to discover the exposure after the fact.
What Organizations Should Do Now
These steps do not require outside counsel to initiate. They do require leadership attention.
1. Inventory your AI use. Know what tools employees are already using, what data those tools can access, and whether any of those deployments are authorized.
2. Review your vendor contracts. Assess whether they address data handling, security obligations, copyright compliance, incident notification, and the technical documentation needed to demonstrate your own compliance posture.
3. Adopt an AI use policy. A written policy governing employee use of AI tools takes no technology investment and does more to reduce exposure than almost anything else on this list.
4. Map your sensitive data. A data inventory identifying what personal, regulated, or confidential information the organization holds and where it lives is the foundation of every other governance obligation.
5. Brief your board. Cybersecurity and AI governance should be a standing agenda item with documented board minutes. Under Delaware’s evolving Caremark doctrine, the absence of that documentation is itself a governance risk.
For more information, please contact Jim Ickes or any member of the Frantz Ward AI Enterprise Governance practice group.