AI news ·
Companies should use a four-dimensional framework to manage AI compliance obligations
Companies must map AI compliance to pipeline roles to handle regulations like California's 30 new statutes. This framework helps legal teams adapt without restarting.

AI regulation is multiplying faster than most compliance programs can track. For legal professionals, the pressing question isn't which rules apply today-it's whether their organization has a method for answering that question reliably as rules keep changing. Companies that stay ahead are the ones analyzing each new obligation through four stable dimensions: jurisdiction, industry, their role in the AI pipeline, and the risk category the regulation targets.
AI pipeline roles define regulatory exposure
Before mapping any obligation, an organization must identify its position in the AI pipeline. That position determines which regulations apply and which controls matter most. Four distinct stakeholder groups define the pipeline.
Input data owners supply the data used to train models. Their decisions about what gets collected and shared constrain everything downstream. Model developers design and train the systems. Their choices about how a model learns carry legal consequences that travel with the model.
Model deployers integrate AI into products and workflows. They frequently inherit risks they didn't create. End users provide inputs and receive outputs. They bear their own obligations tied to how they use the system. Organizations that occupy multiple roles carry the corresponding obligations simultaneously.
Seven risk categories for systematic compliance
Compliance obligations aren't driven only by legislative preference; they emerge from the risks AI systems create at each pipeline stage. Seven categories cover the landscape with enough granularity to support concrete controls: bias, privacy intrusion, intellectual property infringement, opacity, inaccuracy, deception, and complacency.
Biased training data produces biased models regardless of intent. Unlicensed data creates IP liability that travels. Privacy-intrusive data-more common as datasets grow larger and less curated-becomes a growing regulatory exposure. Opacity, the inability to explain how an AI system reached a decision, stops accountability cold.
Output failures such as hallucinations and synthetic media are the most visible failures, but they are often symptoms of earlier-stage problems. When issues accumulate across pipeline transitions, or when a single flawed decision is replicated millions of times daily, small defects escalate into cascading failures. Overreliance on AI erodes human scrutiny and turns minor flaws systemic.
California statutes show the framework in practice
California's regulatory model-roughly 30 AI-related statutes effective since 2025-spans multiple industries, all four stakeholder roles, and every risk category. It remains the nearest available preview of a mature, multi-layered regulatory model. Four statutes illustrate how the dimensions interact.
SB 361 (effective Jan. 1, 2026) requires data brokers to disclose in their annual registration whether they sold or shared consumer personal information with generative AI developers. The law targets input data owners and addresses privacy intrusion by making that data flow visible to regulators and the public.
AB 2013 (effective Jan. 1, 2026) compels generative AI developers to publish high-level summaries of training datasets, including whether personal or copyrighted data was used. It targets model developers and addresses IP infringement, privacy intrusion, and opacity. SB 1120 (effective Jan. 1, 2025) regulates AI use in healthcare utilization review by requiring AI-based determinations to rest on a patient's individual clinical history rather than group datasets. The law targets model deployers in healthcare and tackles inaccuracy and bias directly.
AB 2876, signed into law in October 2024, requires the state to incorporate AI and media literacy into K-12 curriculum frameworks. It targets end users-students and teachers-and responds to overreliance on AI and the risk of deception from AI-generated content. Each statute shows that the same compliance dimensions surface across different contexts and regulatory approaches.
Building a portable compliance program
A compliance program anchored to this framework produces three concrete capabilities that conventional approaches can't replicate. First, role-based obligation mapping assigns every applicable requirement to the specific stakeholder responsible for it-developer, deployer, data owner, or end user. This prevents the failure mode of treating compliance as an undifferentiated legal department responsibility.
Second, full risk-taxonomy coverage ensures that all seven risk categories receive attention. Deception and privacy generate litigation, but opacity, bias, and complacency are routinely underinvested until an enforcement action makes them expensive. Inaccuracy can go undetected until significant harm has occurred. A program built against the complete taxonomy prevents that asymmetry.
Third, portability across jurisdictions and over time keeps the program stable. When a new rule arrives, the right questions are already built in: Which risk categories does it address? Which roles does it target? Which industries does it affect? A compliance program organized around these dimensions absorbs new obligations without restarting.
This portability is why acting now, rather than waiting for a settled federal framework, is the correct strategy. Organizations building programs against these dimensions demonstrate to regulators that they understand the technology, have assessed its risks, and are acting in good faith. That demonstration carries concrete value in enforcement decisions, regulatory relationships, and litigation defense. For legal professionals overseeing AI governance, additional practical resources are available through AI for Legal and the AI Learning Path for Regulatory Affairs Specialists.
Why this matters for legal professionals
For legal teams, the core lesson is structural. A framework built around the pipeline roles and risk categories turns a shifting regulatory landscape into a manageable compliance program. It identifies exactly which obligations attach to your organization's place in the AI pipeline, which risks remain underinvested, and what a new rule changes-before an examiner asks. Deployers carry the largest share of obligations in California, but every role has distinct, enforceable duties. Covering all seven risk categories, not just the ones generating headlines, protects against surprise enforcement. Most practically, the same framework works across industries and state lines, making it a durable investment for in-house counsel and compliance officers.