The compliance calendar is now concrete. From 2 August 2026, providers and deployers of high-risk AI systems must meet the EU AI Act's core obligations, with penalties reaching €35 million or 7% of global turnover for the most serious breaches. In the United States, the NIST AI Risk Management Framework has become the de facto standard even though it remains voluntary. A General Counsel can read every article of both and still not have answered the question that actually determines whether the company is governed: who owns what.
AI governance fails as an organizational-design problem before it fails as a legal one. The useful contribution a GC makes in 2026 is not a longer policy. It is a clear division of decision rights — including an explicit decision about what legal should not own.
What the GC should own — and deliberately not own
The recurring failure is a GC who is handed “AI governance” as a whole and becomes accountable for risks legal cannot actually control. The corrective is to separate the decision rights explicitly.
- 01General Counsel owns — legal and regulatory exposure, enterprise AI policy, contractual allocation of liability with vendors, privilege, regulatory interpretation and classification (is this system high-risk under the EU AI Act?).
- 02The CISO owns — technical security controls, identity and access, monitoring, threat models for AI systems and agents.
- 03The CIO / CTO owns — architecture, integration, data dependencies and deployment.
- 04The CAIO or AI lead owns — AI strategy, the adoption operating model and enablement.
- 05The business owner owns — the workflow, the human-oversight design and the business outcome.
- 06The board owns — oversight of material AI risk and the accountability structure itself.
The GC's value is in drawing these lines and then holding them — refusing the risks that belong to security or the business, so that the ones that genuinely belong to legal actually get governed.
Two regimes the GC has to hold at once
A GC operating in 2026 has to run two frameworks in parallel. The NIST AI RMF is voluntary, US-centric and useful as an internal structuring tool — it helps map where AI risk concentrates and what controls respond to it. The EU AI Act is binding, extraterritorial and deadline-driven: its high-risk obligations apply from August 2026, and they reach any company placing a qualifying system on the EU market regardless of where it is headquartered.
The practical implication is a classification discipline, not a compliance binder. For each material AI system the GC needs a defensible answer to one question — is this prohibited, high-risk, or limited-risk under the EU framework, and what does that classification require? Most enterprise systems are not high-risk, and saying so clearly is as valuable as flagging the ones that are.
Agentic AI changes the legal question from advice to action
Generative AI produces information; a human decides what to do with it. Agentic AI takes actions. That shift is where the legal exposure changes character. As DLA Piper and other firms have set out, an agent introduces execution risk — software that can autonomously breach a privacy obligation, a contractual term or a financial control at machine speed, without a human in the moment of the act.
That changes what legal must specify in advance: which actions an agent is authorized to take, on whose authority, with what audit trail, and who is accountable when it acts wrongly. The governing questions move from “what did the model say” to authorization, accountability, recordkeeping and incident response. A policy written for generative assistants does not cover a system that can transact.
Where the GC and the CISO divide
The GC/CISO boundary is where governance most often falls through, because both assume the other has it. The clean split is that the CISO owns the technical controls that keep an agent inside its authority, and the GC owns the policy and liability question of what that authority should be and who answers for a breach of it.
Open Future Forum's security research shows why this seam is dangerous right now. Securing AI agents and their access is the single biggest AI security problem CISOs name, at 62% — yet 69% of security leaders have no dedicated AI-security budget, and not one of the AI founders surveyed named security or legal as their buyer. Agents are arriving in the enterprise without either the CISO or the GC in the purchase. The GC's job is to make sure legal review is a gate the business cannot route around, precisely because the vendors are not routing it in.
What legal should clear before a system reaches production
The most useful thing a GC can install is a short, non-negotiable pre-production gate — the legal questions that must be answered before an AI system goes live, not after an incident.
- 01Data rights — is the training and input data lawfully used, and does output create privacy or IP exposure?
- 02Model and IP provenance — what is the model, and who owns and indemnifies its output?
- 03Consequence and oversight — what decisions does the system influence, and where is a human required, at what threshold?
- 04Contractual liability — how is liability allocated with the vendor if the system causes harm?
- 05Auditability — is there a log sufficient to reconstruct what the system did and why?
- 06Regulatory classification — is it high-risk under the EU AI Act, and what does that trigger?
None of this requires the GC to become a technologist. It requires the GC to own the questions that are legal in nature and to insist they are answered before deployment. The article is general information, not legal advice; specific systems and jurisdictions need specific counsel.
Last updated: August 19, 2026
Frequently Asked Questions
Where General Counsel compare AI governance in practice
Open Future Forum's General Counsel Executive Forum convenes senior legal leaders on AI governance, agentic risk and the decision rights that make it work. Global, founded in Silicon Valley.