Hire an AI Consultant · Seattle, WA
Seattle's enterprise AI problems are governance problems before they are technology problems. Microsoft ISVs and Amazon suppliers operate in procurement environments where customers ask detailed questions about AI security controls. Boeing contractors process technical data that may be ITAR-controlled or subject to program-specific security requirements. Healthcare operators face HIPAA obligations that extend to the AI tools their employees use.
The common failure: a company approves an AI tool without a formal assessment, employees use it with proprietary customer data, and the exposure surfaces 12 months later in a vendor security review. The corrective action costs more than the original assessment would have.
Fixed scope, flexible pricing based on complexity. Three to four weeks. Written deliverables yours to keep.
Tell us about your AI governance or vendor risk question.
AI governance is not a policy document. It is a set of operational controls that prevent specific, identifiable harms. The document is only as effective as the controls it establishes.
Without a written policy, employees use their judgment about which AI tools to use with which data. That judgment is not consistent. An engineer at a Microsoft ISV feeding customer source code into an unapproved AI coding tool has created IP exposure for the company and potentially violated the customer's contract terms. A written policy with a specific approved tool list removes the ambiguity. Building the policy requires 2 to 4 weeks of stakeholder input and review. It is not a legal document. It is an operational one.
Enterprise procurement of AI tools requires a security assessment before contract signature. After signature, the options are limited: renegotiate the DPA (difficult), accept the risk (problematic for enterprise customers), or terminate the contract (expensive). A 5-day pre-signature assessment reviews the vendor's SOC 2 report, data processing agreement, subprocessor list, model training opt-out status, and incident notification terms. Most Amazon supplier relationships require the supplier to represent that their own AI tools meet specific security standards. A vendor who fails that standard creates a downstream compliance problem.
Seattle's healthcare operators and financial services companies face model risk management obligations that go beyond acceptable use. An AI model supporting a clinical or credit decision must have documented validation, ongoing performance monitoring, and a defined review process for model updates. These requirements apply even if the model is a vendor product. The organization deploying the model is responsible for its outcomes, not the vendor.
A policy that employees haven't read doesn't exist operationally. A 30-minute annual training covering what employees are and are not authorized to do with AI tools, with a completion attestation, satisfies most customer AI security questionnaire requirements. The training content should be specific to your approved tool list, not generic AI awareness content.
A structured 5-day assessment that tells you whether an AI vendor meets the security requirements for your data classification and customer obligations, before the contract is signed.
01
Document exactly what data the tool will process, how it is transmitted to the vendor, where it is stored, and whether it is used in model training. Most exposures come from training data use that employees don't know about.
02
Review the vendor's SOC 2 report against your data use pattern. Confirm that model training and inference pipelines are in scope. Identify complementary user entity controls the vendor assumes you have in place.
03
Review the data processing agreement for customer data rights, retention limits, model training opt-out, incident notification timelines, and subprocessor obligations. Flag terms that conflict with your customer contract requirements.
04
For Microsoft ISVs and Amazon suppliers: confirm that the vendor's DPA is compatible with the AI security representations you make in your customer contracts. Gaps must be resolved before procurement.
05
A one-page risk summary suitable for procurement approval, with any required remediation conditions documented. The document can be shared with your customer if requested.
06
AI vendors update their terms and model infrastructure without prominent notice. A quarterly monitoring checklist ensures the original assessment stays current.
Boeing contractors and aerospace suppliers process technical data that may be EAR or ITAR controlled. The standard commercial AI tool approval process is not sufficient.
Before an AI tool can be approved for use with technical data, the data must be classified. EAR-controlled technical data has different handling requirements than ITAR-controlled technical data, and some data is CUI but not subject to either. An AI tool approved for CUI processing may still be prohibited for ITAR-controlled inputs. The classification determination should be made by the organization's export control function, but the AI consultant's job is to frame the right question and ensure the procurement process includes that review.
For ITAR-controlled inputs, the AI vendor's infrastructure must be accessible only by US persons. This requirement applies to the vendor's engineering and operations teams, not just to the customer-facing API. Many AI vendors have non-US-person engineers with access to model training infrastructure. A compliant configuration typically requires the enterprise version of the AI product with specific contractual commitments about personnel access. General-purpose consumer tiers do not provide these commitments.
We do not resell AI tools. Vendor assessment outcomes are based on your requirements, not on whether we have a referral relationship with the vendor. If a vendor fails the assessment, we say so.
Discovery call, written scope document, fixed price. The scope is agreed before work starts. No open-ended retainer, no hourly billing, no monthly invoice where the amount varies.
Deliverables are written to be shared with your legal, compliance, and procurement teams. Risk assessments include the evidence behind the conclusion. Policy documents include the rationale for each requirement. Not slide decks.
Describe your AI tool procurement question or governance gap. We reply within one business day with a rough scope and price range. No commitment required.