Updated
Updated · The National Law Review · Aug 31
Companies Build Single AI Governance Programs for 2 U.S. Regulators
Updated
Updated · The National Law Review · Aug 31

Companies Build Single AI Governance Programs for 2 U.S. Regulators

2 articles · Updated · The National Law Review · Aug 31

Summary

  • A single AI governance framework is emerging as the practical answer to overlapping DOJ and SEC scrutiny, with companies mapping AI systems, controls and disclosures into one compliance structure.
  • DOJ prosecutors now test whether companies assess AI risks and prevent deliberate or reckless misuse under the Evaluation of Corporate Compliance Programs, including controls, human oversight, accountability and employee training.
  • SEC examiners are approaching the issue from the investor-protection side, targeting 2026 “AI washing” — false or exaggerated claims about AI capabilities in filings, earnings calls, marketing materials and presentations.
  • An accurate AI inventory, cross-functional ownership and documented testing sit at the center of both regimes, giving companies evidence for criminal-law compliance and support for public claims.
  • Companies that split AI oversight into separate legal and disclosure tracks risk duplicated work and compliance gaps, while internal reporting channels and shared documentation can reduce exposure to both agencies.

Insights

How are employees' hidden, unapproved AI tools exposing major corporations to severe SEC penalties?
Could your company's vague AI-powered marketing claims secretly trigger a federal criminal investigation?