NIST AI RMF
2026-09-18California is advancing privacy and AI legislation that establishes new regulatory requirements for AI governance frameworks, while vendor management practices are emerging as critical control points for third-party AI risk mitigation. Practitioners must update procurement governance and contractual controls to align with evolving state-level AI regulations.
- →California Legislature Advances Privacy and AI Bills with Website Tracking Limits: Organizations must assess compliance obligations under new California AI and privacy requirements and update governance frameworks to address state-specific regulatory mandates.
- →Vendor Management Contractual Controls for Third-Party AI Systems: Procurement teams need to negotiate AI-specific clauses and risk allocation terms in vendor agreements to ensure third-party AI systems meet organizational risk management standards.
Review and update vendor management policies and procurement templates today to incorporate AI risk controls and prepare for California's new privacy and AI regulatory requirements.
Part 1 of this series explained why AI vendor relationships break the assumptions built into most standard software procurement templates, and where those legacy templates leave organizations exposed:...<BR />By: <a href="https://www.jdsupra.com/profile/michael_volkov/">The Volkov Law Group</a>
In the final weeks of California’s 2026 legislative session, lawmakers passed a series of bills that stand to significantly reshape the state’s privacy and AI regulatory landscape....<BR />By: <a href="https://www.jdsupra.com/profile/ropes_gray/">Ropes & Gray LLP</a>