By Tishkoff PLC, Ann Arbor, Michigan
Artificial intelligence is no longer a moonshot or a marketing slogan. It is a set of data-driven systems that increasingly determine which customers see your offers, how your products are priced, what your employees are recommended to do next, and even how your supply chain adjusts in real time. As adoption has accelerated, regulators have moved from curiosity to scrutiny. What felt like a distant policy debate is fast becoming a practical compliance reality. For business owners across Michigan and beyond, that means artificial intelligence must be managed with the same rigor you apply to financial reporting, workplace safety, and consumer protection. The question is not whether rules are coming, but how ready you are for a regulatory environment that expects documentation, accountability, and meaningful oversight of the algorithms you use or buy.
The emerging legal landscape has a familiar structure even if the technology is novel. Governments are combining old tools like consumer protection statutes, civil rights laws, and product safety obligations with new AI-specific frameworks that center on risk management, transparency, and human oversight. That layered approach is important to understand. Your company can face liability under existing rules that were never written with machine learning in mind, such as unfair or deceptive practices laws if your AI marketing claims overpromise, equal employment rules if automated screening treats candidates differently on protected grounds, or health and financial privacy laws if models ingest regulated data without permission. At the same time, dedicated AI frameworks at the federal, state, and international levels are defining responsibilities for “deployers” and “developers,” setting expectations for testing and monitoring, and creating breach or incident reporting duties for high-risk use cases. The result is not a single AI statute to memorize but a web of obligations that together push organizations toward governance by design.
The most consequential shift for business leaders is the move from ad hoc experimentation to auditable governance. Regulators have learned that policing outputs alone is a losing game when models adapt, scale, and sometimes behave unpredictably. They are therefore asking companies to show their work: how models were selected and trained, which datasets were used, what risks were considered, and what controls were implemented to mitigate foreseeable harms. That emphasis turns AI from a purely technical project into a cross-functional program that touches legal, compliance, security, HR, and the business units that rely on the models. If you have ever built a quality management system for manufacturing or a privacy program for data protection, the rhythm will feel familiar. Policies must be written, procedures must be followed, evidence must be kept, and senior management must be accountable for the system’s effectiveness.
One of the most practical organizing concepts is risk tiering. Policymakers increasingly distinguish between low impact uses, such as content recommendations for an internal knowledge base, and high-risk uses that can significantly affect people’s rights or safety, such as credit underwriting, employee hiring, medical decision support, or autonomous control of physical equipment. For low impact tools, the regulatory ask is often light-touch transparency and reasonable safeguards. For high-risk systems, the expectation is a formal lifecycle approach that begins with a well-scoped use case, continues through data curation and validation, includes pre-deployment testing and bias analysis, and ends with post-deployment monitoring, incident handling, and decommissioning criteria. Business owners should not wait for a statute to assign a label to their use. Perform your own risk assessment grounded in the stakes of the decision, the populations affected, and the model’s failure modes, and then scale your controls accordingly.
Data remains the beating heart of AI regulation. Most of the risks that draw legal attention bias, privacy violations, IP misuse, and opaque decision-making begin with what goes into the system. From a compliance perspective, you should be able to answer straightforward questions about your training and inference data. Where did it come from? What rights do you have to use it? What does it contain about individuals, especially sensitive attributes that could trigger sectoral laws or anti-discrimination rules? How was it cleaned, labeled, and checked for representativeness? Those are legal questions as much as technical ones. If your data vendors cannot provide contracts that address provenance, consent, and lawful basis, or if your internal processes cannot document quality controls, your models may function today but become indefensible tomorrow. Treat your datasets as regulated assets and your documentation as the evidence that keeps those assets compliant over time.
Transparency and explainability are not merely academic ideals; they are tools that reduce regulatory risk. Courts and agencies repeatedly ask the same questions when an automated decision harms someone: who can explain what happened, who can reverse or override the decision, and who will be accountable for fixing the underlying issue, so it does not happen again. If your systems are optimized only for accuracy or speed, you may discover too late that you cannot reconstruct the logic behind a denial or adverse outcome. That does not mean every model must be interpretable in a strict, white-box sense. It does mean your deployment of any model must be paired with an explanation strategy. That can include local explanation techniques, policy-level rationales that describe how the system is used, notices that inform users about automation, and recordkeeping that ties specific outputs to model versions, datasets, and thresholds. The more consequential the decision, the stronger that explanation strategy needs to be.
Procurement and vendor management have quietly become the frontline of AI governance. Many organizations use models embedded in software-as-a-service tools, off-the-shelf APIs, or integrated platforms rather than building systems in-house. From a regulator’s perspective, outsourcing does not outsource accountability. If your business benefits from an automated decision, your business must ensure that decision complies with applicable law. That reality makes your contracts as important as your code. Demand clear descriptions of the AI capabilities, documented testing results for relevant use cases, commitments about training data provenance, security and privacy obligations, audit rights where appropriate, and notification requirements for material model changes or incidents. Align those terms with your internal governance so obligations do not sit on paper while your teams remain unaware of how to operate the tool safely.
Employment and workplace applications deserve special attention because they bring together multiple sensitive obligations. Automated screening and employee monitoring tools can inadvertently amplify disparities or intrude on privacy in ways that draw fast regulatory action and reputational harm. Before adopting AI in hiring, performance evaluation, scheduling, or discipline, ensure that your HR, legal, and DEI stakeholders have a shared framework for fairness, transparency, and notice. Run pilot tests with representative data, look for differential error rates across protected groups, and set conservative thresholds with human review capable of catching edge cases. Provide candidates and employees with clear channels to contest decisions and to request human reconsideration. Above all, avoid deploying tools that you are not prepared to defend with data, documentation, and a repeatable review process.
The interplay of AI and consumer protection will shape how you market AI-enabled products and services. Marketing claims about “AI-powered” capabilities can create implied warranties and expectations, particularly when they describe safety or effectiveness. If your advertisements or sales materials suggest that a system can solve a problem autonomously with high reliability, regulators may interpret that statement as a promise requiring substantiation. Align your public messaging with your internal risk assessments and your documented testing results. If limitations or human oversight are necessary, say so plainly. Consumer deception is judged not by your intent but by the impression on a reasonable consumer, and AI hype is increasingly recognized as fertile ground for overstatement.
Privacy and security remain inseparable from AI governance. Models trained on personal or proprietary data can leak sensitive information through poorly controlled prompts, updates, or outputs. They can also create new attack surfaces, from data poisoning to adversarial inputs that force unintended behavior. Regulators view these risks through familiar legal categories: reasonable security, purpose limitation, data minimization, and breach notification. From a practical standpoint, embed your privacy program into model development. Map data flows into and out of AI services, set access controls and retention schedules, restrict sensitive attributes unless strictly necessary, and stress-test how models respond to prompts seeking confidential information. When your AI workload is hosted by a third party, insist on security representations that match your standards, not theirs, and verify compliance through independent attestations where feasible.
The cross-border reality of digital business means you cannot plan for AI regulation in one jurisdiction at a time. Even if your company is Michigan-based and serves U.S. customers, you may work with vendors that process data in Europe or train models on global datasets. International frameworks are converging on common principles risk management, transparency, human oversight, and red-team testing even as their enforcement mechanics differ. Businesses that anchor their programs in those widely recognized principles will be better positioned to adapt to local variations without reengineering their approach for every new rule. Consider the baseline of governance practices as your operating system and individual jurisdictional requirements as applications you install when needed.
Incident response for AI deserves its own planning cycle. Traditional security incidents involve unauthorized access or exfiltration. AI incidents can also include model hallucination that produces harmful outputs, drift that degrades performance over time, bias that emerges only after deployment to new populations, and integration failures that cascade across automated systems. Design your response plan to detect, triage, and remediate these categories with the same discipline you bring to cybersecurity. Define what counts as an AI incident in your environment, specify who is authorized to disable a model in production, identify what evidence must be preserved for legal review, and practice the handoffs between engineering, legal, communications, and customer success. Regulators often judge organizations more by how they respond to problems than by the fact that problems occurred at all.
Insurance will likely evolve as a meaningful tool in AI risk transfer, but coverage gaps are common today. Traditional technology errors and omissions policies may not contemplate algorithmic bias claims, regulatory fines for AI-specific violations, or the cost of large-scale model recall and retraining. Early conversations with your broker can surface how your current policies would treat AI risks and what endorsements are available. At the same time, insurers increasingly expect to see evidence of governance as a precondition to favorable terms. A written AI policy, a risk inventory, vendor diligence, security controls, employee training, and a tested incident plan can all influence whether you are seen as a good risk.
Small and midsize businesses sometimes assume AI regulation will land only on large enterprises. That assumption underestimates how rules travel through supply chains and customer contracts. If your product plugs into a larger company’s workflow, or if you provide services to regulated sectors like finance, health, or education, you will be asked to meet the standards of your customers even before statutes name you directly. Preparing now is therefore a growth strategy as much as a compliance strategy. Demonstrable governance can help you win deals that require assurances, pass vendor risk assessments, and stand out in competitive procurement processes that are increasingly scoring AI responsibility alongside price and features.
No governance program succeeds without people who know how to operate it. Investing in training is one of the highest-leverage steps you can take, and it should aim at fluency rather than coding proficiency. Executives need to understand what they are signing when they approve AI-related contracts or risk registers. Product managers must learn how to translate business objectives into technical guardrails. HR teams require awareness of the boundaries around automated screening and monitoring. Customer-facing staff should recognize when a complaint or outcome signals a model that needs attention. And your legal and compliance teams must keep pace with regulatory developments while developing practical checklists that business units can actually use.
Documentation is the connective tissue across everything described above. Policies and procedures matter only to the extent they can be demonstrated. In practice, that means maintaining model cards or system sheets that describe purpose, inputs, outputs, constraints, and performance; keeping version histories that let you tie particular outcomes to specific models and datasets; and capturing the results of pre-deployment testing, bias audits where appropriate, and signoffs by accountable owners. Good documentation keeps projects on track, streamlines due diligence with customers and investors, and provides essential evidence if a regulator asks how your system came to be deployed. Poor documentation, by contrast, forces leaders to rely on recollection and leaves you vulnerable to claims that you never considered foreseeable risks.
As counsel to Michigan businesses, we also see the local dimension of AI readiness. Midwest manufacturers are experimenting with predictive maintenance and robotic vision, professional services firms are adopting generative tools to accelerate client work, and retailers are tuning pricing and personalization. These are precisely the domains where the line between efficiency and exposure can be thin. A maintenance model that misclassifies defects could create safety risks; a drafting tool that incorporates confidential client data could trigger privilege or confidentiality concerns; and a personalization engine that uses proxy signals for protected classes could raise discrimination questions. Preparing for regulation means conducting use-case-specific reviews, not generic signoffs. When we guide clients, we center the conversation on the concrete decision being automated, the humans affected by that decision, and the legal duties that already apply to that context.
Looking ahead, enforcement patterns will likely prioritize a few themes. First, regulators tend to act where harms are visible and repeatable, which points to employment, credit, health, housing, and consumer deception as early hot spots. Second, agencies will use their existing authority aggressively while formal AI rules roll out, which means investigations framed under unfair practices, discrimination, or data security are more likely than citations under brand-new AI statutes in the near term. Third, transparency obligations will rise as a low-cost, high-impact lever. Expect to see requirements for notices, documentation, and disclosures that do not ban AI but make its use legible to those affected. Finally, companies that can demonstrate a culture of responsible AI evidenced by governance artifacts and responsive remediation will have more opportunities to resolve issues cooperatively rather than through litigation or penalties.
For many leaders, the hardest step is moving from abstract awareness to a clear plan. The most effective programs we see share a simple arc. They begin with an inventory of where AI is already in use and where it is being considered, capturing both proprietary models and third-party tools. They evaluate those uses for risk and prioritize the highest-impact projects for deeper controls. They set written policies that explain how AI will be selected, tested, approved, and monitored, with named owners and escalation paths. They align vendor contracts with those expectations and refresh templates, so new purchases do not recreate old gaps. They train teams on how to follow the program and why it matters. And they practice incident response so the first real problem is not also the first rehearsal.
Tishkoff PLC’s advice to Michigan business owners is to treat AI regulation as an opportunity to professionalize your use of powerful technology rather than as a barrier to innovation. The same structures that regulators want clarity of purpose, disciplined testing, strong data hygiene, measured transparency, and defined accountability are the structures that make AI projects succeed and scale. By building them now, you reduce the risk of costly course corrections later, reassure customers and partners who are asking hard questions, and improve your readiness for whatever formal rules arrive. We can help translate these principles into tailored policies, contracts, and training that fit your industry, your risk tolerance, and your growth plans. The choices you make today will determine whether tomorrow’s rules feel disruptive or simply confirm the good practices you already put in place.
The path forward is not about predicting every detail of future statutes but about aligning your operations with durable principles that regulators, courts, and customers consistently reward. Understand your use cases, respect your data, document your decisions, empower your people, and prepare for incidents. Do those things well, and you will be ready for the next phase of AI’s evolution—one where trust, accountability, and performance travel together.
Contact Tishkoff
Tishkoff PLC specializes in business law and litigation. For inquiries, contact us at www.tish.law/contact/. & check out Tishkoff PLC’s Website (www.tish.law/), eBooks (www.tish.law/e-books), Blogs (www.tish.law/blog) and References (www.tish.law/resources).
Sources
- National Institute of Standards and Technology, “AI Risk Management Framework (NIST AI RMF 1.0).” https://www.modulos.ai/nist-ai-rmf/
- Executive Order 14110, “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence,” The White House (October 30, 2023). https://www.federalregister.gov/documents/2023/11/01/2023-24283/safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence
- European Union, “Artificial Intelligence Act,” Official Journal of the European Union (2024). https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
- ISO/IEC 42001:2023, “Artificial Intelligence Management System — Requirements.” https://pecb.com/en/education-and-certification-for-individuals/iso-iec-42001/iso-iec-42001-lead-implementer
- Federal Trade Commission, “Aiming for Truth, Fairness, and Equity in Your Company’s Use of AI” and related business guidance. https://www.predictiveanalyticsworld.com/machinelearningtimes/aiming-for-truth-fairness-and-equity-in-your-companys-use-of-ai/12104/
This publication is for general informational purposes and does not constitute legal advice. If you would like counsel specific to your business and use cases, Tishkoff PLC is available to help.
