The compliance calendar is now concrete. From 2 August 2026, providers and deployers of high-risk AI systems must meet the EU AI Act's core obligations, with penalties reaching €35 million or 7% of global turnover for the most serious breaches. In the United States, the NIST AI Risk Management Framework has become the de facto standard even though it remains voluntary. A General Counsel can read every article of both and still not have answered the question that actually determines whether the company is governed: who owns what.

AI governance fails as an organizational-design problem before it fails as a legal one. The useful contribution a GC makes in 2026 is not a longer policy. It is a clear division of decision rights — including an explicit decision about what legal should not own.

What the GC should own — and deliberately not own

The recurring failure is a GC who is handed “AI governance” as a whole and becomes accountable for risks legal cannot actually control. The corrective is to separate the decision rights explicitly.

The GC's value is in drawing these lines and then holding them — refusing the risks that belong to security or the business, so that the ones that genuinely belong to legal actually get governed.

The GC's job is to design who owns which AI risk — not to become the owner of all of it.

Two regimes the GC has to hold at once

A GC operating in 2026 has to run two frameworks in parallel. The NIST AI RMF is voluntary, US-centric and useful as an internal structuring tool — it helps map where AI risk concentrates and what controls respond to it. The EU AI Act is binding, extraterritorial and deadline-driven: its high-risk obligations apply from August 2026, and they reach any company placing a qualifying system on the EU market regardless of where it is headquartered.

The practical implication is a classification discipline, not a compliance binder. For each material AI system the GC needs a defensible answer to one question — is this prohibited, high-risk, or limited-risk under the EU framework, and what does that classification require? Most enterprise systems are not high-risk, and saying so clearly is as valuable as flagging the ones that are.

Agentic AI changes the legal question from advice to action

Generative AI produces information; a human decides what to do with it. Agentic AI takes actions. That shift is where the legal exposure changes character. As DLA Piper and other firms have set out, an agent introduces execution risk — software that can autonomously breach a privacy obligation, a contractual term or a financial control at machine speed, without a human in the moment of the act.

That changes what legal must specify in advance: which actions an agent is authorized to take, on whose authority, with what audit trail, and who is accountable when it acts wrongly. The governing questions move from “what did the model say” to authorization, accountability, recordkeeping and incident response. A policy written for generative assistants does not cover a system that can transact.

Where the GC and the CISO divide

The GC/CISO boundary is where governance most often falls through, because both assume the other has it. The clean split is that the CISO owns the technical controls that keep an agent inside its authority, and the GC owns the policy and liability question of what that authority should be and who answers for a breach of it.

Open Future Forum's security research shows why this seam is dangerous right now. Securing AI agents and their access is the single biggest AI security problem CISOs name, at 62% — yet 69% of security leaders have no dedicated AI-security budget, and not one of the AI founders surveyed named security or legal as their buyer. Agents are arriving in the enterprise without either the CISO or the GC in the purchase. The GC's job is to make sure legal review is a gate the business cannot route around, precisely because the vendors are not routing it in.

What legal should clear before a system reaches production

The most useful thing a GC can install is a short, non-negotiable pre-production gate — the legal questions that must be answered before an AI system goes live, not after an incident.

None of this requires the GC to become a technologist. It requires the GC to own the questions that are legal in nature and to insist they are answered before deployment. The article is general information, not legal advice; specific systems and jurisdictions need specific counsel.

Last updated: August 19, 2026

Murray Newlands
Murray Newlands
Founder, Open Future Forum

Murray Newlands has been building executive communities in Silicon Valley since 2019. Open Future Forum runs role-specific forums and curated gatherings for senior executives and investors, grounded in a give-first philosophy.

Frequently Asked Questions

What is the General Counsel's role in AI governance?
The General Counsel's role is to design and hold the decision rights for AI risk — deciding what legal owns (regulatory exposure, policy, contracts, privilege, classification) and what belongs to the CISO, CIO/CTO, AI lead, business and board. It is an organizational-design responsibility more than a policy-drafting one.
Should the General Counsel own AI governance?
The GC should own the legal dimensions of AI governance and the design of the overall decision-rights structure, but not the whole of it. Making the GC accountable for technical controls, architecture or business outcomes they cannot control produces governance on paper and a vacuum in practice.
What changes for legal when AI becomes agentic?
Generative AI produces information; agentic AI takes actions. That introduces execution risk — a system that can autonomously breach privacy, contractual or financial obligations at machine speed. Legal must specify in advance which actions an agent may take, on whose authority, with what audit trail, and who is accountable when it acts wrongly.
How should General Counsel and CISO responsibilities differ on AI?
The CISO owns the technical controls that keep an AI system and its agents inside their authority; the GC owns the policy and liability question of what that authority should be and who answers for a breach. The seam between them is where governance most often fails, so legal review should be a gate the business cannot bypass.
What should legal review before an enterprise AI system goes into production?
A short pre-production gate: data rights, model and IP provenance, decision consequence and human-oversight thresholds, contractual liability allocation, auditability, and regulatory classification under frameworks such as the EU AI Act. This is general information, not legal advice.
Open Future Forum

Where General Counsel compare AI governance in practice

Open Future Forum's General Counsel Executive Forum convenes senior legal leaders on AI governance, agentic risk and the decision rights that make it work. Global, founded in Silicon Valley.