Policy Positions
Where I stand on AI governance, deepfake regulation, and synthetic media harm β and how that shapes the advice I give clients.
AI & Deepfake Policy Positions
These are my working positions, grounded in research and case analysis. They inform how I frame risk and what I recommend to clients β not abstract opinions.
Current laws leave victims significantly underprotected
Most existing statutes β including many at the state level β were written before generative AI made synthetic media trivially accessible. Enforcement gaps remain wide: prosecution is difficult, civil remedies are slow, and platform takedown obligations are inconsistent.
Pending legislation like Pennsylvania SB1213 and SB1050 represents meaningful progress, but without clear evidentiary standards and cross-jurisdictional enforcement mechanisms, victims will continue to face delayed and incomplete relief.
Governance frameworks must be operational, not performative
Most organizations adopt AI governance language without translating it into defensible decisions, documented controls, or tested response procedures. A policy document that sits in a shared drive is not governance β it's liability.
Effective AI governance requires clear ownership, scenario-tested procedures, and documentation that holds up when something goes wrong. Organizations that treat governance as a compliance checkbox will face greater exposure, not less.
AI-generated CSAM requires specific legal classification β not just analog extensions
Applying existing child exploitation statutes to AI-generated content creates interpretive ambiguity that defense counsel can exploit. Jurisdictions need explicit statutory language that closes the "no real victim" argument before it becomes standard practice in litigation.
This is not a hypothetical risk. Case evidence already shows these arguments emerging in early prosecutions. The legislative window to address this proactively is closing.
Detection and removal obligations must have teeth
Voluntary takedown commitments from platforms have not proven sufficient at scale. Regulatory frameworks that establish minimum detection and removal timelines β with liability for non-compliance β are a necessary evolution.
This does not require government control of content moderation. It requires that platforms bear some responsibility when they knowingly host non-consensual synthetic media and fail to act within a reasonable timeframe.
Most organizations underestimate their deepfake exposure surface
The threat is not limited to public figures or media companies. Any organization with leadership, employees, or clients who communicate digitally has an exposure surface β whether through voice cloning for fraud, synthetic identity attacks, or reputational harm.
Risk assessment should start with the organization's specific profile, not a generic threat landscape. The question is not "could this happen to us" but "what would it cost us if it did, and do we have a response plan."
Have a question about one of these positions?
If something here doesn't align with how your organization is thinking about AI risk, I'm open to that conversation. These are working positions based on current evidence β not fixed doctrine.