CONTACT USarrow icon

"*" indicates required fields

Name*

OVERVIEW

Protecting the data that powers AI

Every AI system that touches your business also touches your data. The legal consequences follow regardless of whether you anticipated them. An employee may use personal information to train or improve a model. Another may enter confidential or proprietary business information into a public tool. A third-party model may retain or reuse data in ways you didn’t anticipate. If you’re a government contractor, putting controlled unclassified information into the wrong AI environment can trigger a 72-hour reporting obligation under DFARS 252.204-7012 and put your compliance representations at issue under the False Claims Act.

You can’t delete a prompt and expect the legal, confidentiality, or security consequences to go away. That’s why organizations must understand what information their AI systems collect, where it goes, how long it’s retained, whether vendors can use it for model training or other purposes, and what happens when the vendor relationship ends.

The attorneys at Dunlap Bennett & Ludwig help you work through these questions while you still have options, rather than after a disclosure, a contract dispute, or a regulator’s inquiry has narrowed them.

Our experience in AI privacy, data protection, and cybersecurity

Our attorneys work with AI developers, regulated businesses, and federal contractors to establish safeguards that protect sensitive information while allowing them to adopt and use AI technologies. We advise clients on state privacy and biometric laws, the Health Insurance Portability and Accountability Act (HIPAA), the Gramm-Leach-Bliley Act, the Fair Credit Reporting Act, children’s privacy requirements, and federal contractor cybersecurity obligations.

But our experience with AI privacy and cybersecurity goes beyond advising clients on the law. We develop, test, and deploy AI tools in our firm under confidentiality and governance controls, and we evaluate third-party platforms against confidentiality obligations. That means we evaluate AI privacy and security questions from both a legal and an operational standpoint, and we know which controls tend to survive contact with the engineers and business teams who have to implement them.

As a veteran-owned firm with a proud history of representing government contractors and defense-sector clients, we understand the heightened security, procurement, and data-handling requirements that apply when AI systems use government information. We’ve also confronted these issues from the client side. Our co-founder Tom Dunlap also co-founded a venture-backed biotechnology company whose work has been funded through NIH and CDC awards, so we have seen these obligations from the client side as well as the counsel side.

We are also equipped to handle cross-border AI data issues. We are the Washington, D.C. metropolitan area member firm of Alliott Global Alliance, an international alliance of independent professional firms. When a matter reaches regimes outside the United States, including the General Data Protection Regulation (GDPR) and the EU AI Act, we can bring in local counsel from legally independent member firms in those jurisdictions.

What we do

AI privacy and cybersecurity problems rarely begin and end with a privacy policy. We help organizations determine what information their AI systems ingest, where that information travels, what vendors are permitted to do with it, and how to respond when established safeguards fail.

    Privacy compliance and data use
    • Assess privacy obligations applicable to AI deployments under the California Consumer Privacy Act and the California automated decisionmaking technology regulations, which took effect January 1, 2026 but do not require ADMT compliance until January 1, 2027, and under the profiling opt-out and assessment provisions of the roughly twenty other state privacy statutes now in force, including consent requirements, data minimization, and purpose limitation
    • Prepare the assessments these deployments actually require on AI involving personal information, health data, financial information, and children’s data, including CCPA risk assessments, which are triggered by using personal information to train AI capable of making a significant decision, state data protection assessments, and Article 35 data protection impact assessments under the GDPR
    • Advise on cross-border data protection considerations affecting AI deployments, including the GDPR’s prohibition on decisions based solely on automated processing that produce legal or similarly significant effects, the duty to disclose meaningful information about the logic involved, and data subject rights

    Biometric data and automated decision-making
    • Develop consent, retention, disclosure, and destruction practices for AI systems processing biometric information to comply with the Illinois Biometric Information Privacy Act, still the only state biometric statute with a general private right of action and one with no AI training exemption, and other state laws governing facial recognition, voiceprints, and other biometric information, including the Texas statute, amended effective January 1, 2026 to carve out biometric data used to develop and train AI models
    • Evaluate privacy requirements affecting automated decisions involving employment, credit, insurance, and other consequential uses
    • Advise on emotion recognition and biometric categorization systems, including the uses the EU AI Act prohibits outright rather than merely requiring disclosure, among them inferring emotions in the workplace and in schools, and the disclosure duties that attach to the uses that remain permitted

    Cybersecurity and federal contractor data protection
    • Develop safeguards for confidential, privileged, personal, proprietary, and government-controlled information used with AI tools
    • Establish controls governing employee use of public and enterprise generative AI platforms
    • Counsel federal contractors and subcontractors on AI systems handling controlled unclassified information under DFARS 252.204-7012 and the 252.204-7019, -7020, -7021, and -7025 series, NIST SP 800-171 Revision 2, which DoD still requires notwithstanding the publication of Revision 3, and the Cybersecurity Maturity Model Certification program, whose Phase 2 requirements DoD suspended in July 2026
    • Address FedRAMP and other federal security requirements affecting AI systems deployed in or connected to agency environments
    • Evaluate cybersecurity and supply-chain risks involving third-party models, APIs, cloud infrastructure, and other components of an organization’s AI stack
    • Advise on export control exposure when foreign-national personnel access controlled model weights or technical data
    • Integrate AI-specific risks into existing cybersecurity and incident response programs

    AI vendor and supply chain risk
    • Conduct privacy and cybersecurity diligence on AI vendors, model providers, cloud platforms, and other technology providers, including their data-use terms, training practices, retention settings, confidentiality controls, security measures, and incident notification obligations
    • Determine whether AI vendors may retain or use client data, prompts, inputs, or outputs for training models or other purposes
    • Evaluate AI meeting, transcription, and similar tools for confidentiality, privilege, privacy, and data security concerns
    • Identify gaps between vendor terms and the privacy, security, confidentiality, and contractual commitments that clients have made to customers, regulators, or government agencies
    • Negotiate privacy and security provisions addressing data residency, processing restrictions, subprocessors, audit rights, incident notification, and data portability
    • Help clients respond to customer AI security questionnaires, AI security addenda, and related data protection requirements

    AI-related data incidents and regulatory response
    • Conduct privileged internal investigations when employees disclose confidential or privileged information, personal data, source code, or controlled unclassified information into unmanaged AI tools
    • Assess breach notification and regulatory reporting obligations when an AI system contributes to a data exposure
    • Develop response strategies for privacy and cybersecurity investigations involving AI systems
    • Respond to inquiries from privacy regulators, state attorneys general, supervisory authorities, and other agencies concerning AI-related data practices
    • Provide ongoing counsel as AI systems, vendors, privacy laws, and cybersecurity requirements evolve

Contact Us

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name*
Please do not include any confidential or sensitive information in this form.
Submitting this form does not create an attorney-client relationship.

Intern Program

As part of our effort to recruit, develop and retail the best and brightest attorneys, Dunlap Bennett & Ludwig offers a summer intern program for promising law school students who are looking to work as part of an innovative and incredibly successful team. With a global team of lawyers, selected candidates are able to work on high level projects in a collaborative space.

Paralegals and Legal Support Staff

At Dunlap Bennett & Ludwig, our team of paralegals and staff work together collaboratively along side our attorneys toward a common goal. We have created a positive work environment where our paralegals and legal assistants work to successfully reach firm-wide goals and support each other to combine individual strengths to enhance team performance. They regularly assist our attorneys with organizing and maintaining files, conducting legal research, and preparing documents.