AI launch blocked

Legal is nervous about your AI launch

Legal usually is not blocking the feature. It is blocking the absence of a record it can rely on. The fix is a completed assessment, not a longer wait.

What legal is actually waiting for

Legal usually is not blocking the feature — it is blocking the absence of a record it can rely on. What unblocks it is a completed assessment covering the use case, the personal data involved, the legal basis, and whether there is automated decision making or profiling with significant effects, along with a risk classification against the applicable regime.

Assembled properly, this takes weeks rather than months. The delays usually come from the vendor answering diligence questions rather than from the assessment itself.

What the assessment covers

The assessment starts with the use case itself: what personal data is involved, what legal basis applies, and whether the system involves automated decision making or profiling with significant effects. That is paired with a risk classification against the applicable regime — the same tool can carry very different risk depending on whether it is drafting marketing copy or screening job applicants.

Risk classification applied to the vendor rather than to the use case is one of the most common failure points. The assessment fixes that by anchoring classification to what the tool actually does in your context.

The vendor position

The assessment also covers what the contract actually permits regarding training on your data, retention, and sub-processing. Many organizations lean on vendor assurances without reading what the contract says. Those are not the same thing, and legal needs the contract position on record, not the sales deck.

Controls and oversight

The controls section documents human oversight, what the model can and cannot decide alone, testing evidence, and the fallback if it fails. These are the operational commitments that turn an assessment from a paper exercise into something the business can actually stand behind.

Disclosure position

Finally, the disclosure position: what the privacy notice tells users and whether any consent or opt-out applies. Getting this right before launch means the notice reflects what the system actually does rather than being retrofitted after the fact.

Questions about the assessment

Why does the same AI tool get treated differently depending on the use case?

Risk classification should be applied to the use case, not to the vendor. The same tool carries very different risk whether it is drafting marketing copy or screening job applicants — treating them identically because they share a vendor is where assessments go wrong.

How long does this take?

Assembled properly, the assessment takes weeks rather than months. The delays usually come from the vendor answering diligence questions rather than from the assessment itself.

Is a vendor's assurance enough, or do I need to read the contract?

You need to read the contract. Many organizations rely on vendor assurances without reading what the contract actually permits regarding training on their data. Those are not the same thing, and the assessment documents the contract position specifically.

How Applied Privacy Consulting Supports AI Risk Assessment

  • Use Case Intake And Inventory

    A register of where AI is actually in use across the business, including tools adopted by individual teams without central approval, with each entry recorded at the use-case level rather than the vendor level.

  • Standard Assessment Criteria

    A single assessment template applied consistently across use cases, covering the personal data involved, the legal basis, whether automated decision making or profiling with significant effects is in scope, and the disclosure position, so two reviewers reach the same conclusion on the same facts.

  • Risk Classification Matrix

    Tiering criteria anchored to what the tool does in your context rather than to the vendor supplying it. The same model may be classified differently when it drafts marketing copy than when it screens job applicants, with defined thresholds for what each tier requires before launch.

  • Regulatory Applicability Assessment

    Mapping each use case against the regimes that reach it, including the EU AI Act, GDPR and UK GDPR automated decision-making provisions, US state AI and profiling rules, and sector requirements, with the analysis documented rather than assumed.

  • Vendor And Contract Position

    Review of what the contract permits on training with your data, retention, sub-processing, and audit rights, separating the contractual position from sales assurances, with a diligence question set to run at procurement.

  • Controls And Human Oversight

    Documentation of what the system can decide alone, where a human sits in the loop, the testing evidence behind that decision, and the fallback if the model fails or degrades.

  • Disclosure And Notice Review

    Alignment of privacy notices, in-product disclosures, and any consent or opt-out mechanism with what the system actually does, addressed before launch rather than retrofitted after.

  • Governance Structure And Intake Workflow

    The routing that decides which use cases need full assessment, who approves each risk tier, how exceptions are recorded, and when a use case returns for review.

  • Monitoring And Reassessment

    Triggers for revisiting a completed assessment, including model changes, expanded use, new jurisdictions, and vendor terms updates, so the record stays current between formal reviews.

  • Team Training

    Onsite or remote training for legal, product, procurement, and business teams on when to route a use case for assessment and how the classification criteria apply.

Explore

Ready to unblock your launch?

Start the assessment

A completed assessment covering the use case, data, legal basis, vendor position and controls is what legal needs. Assembled properly, this takes weeks rather than months.

Write to us

Prefer email? Start here.

A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.