

You already answer to HIPAA, GDPR, or CCPA. What changed is that a tool nobody reviewed can now send the data somewhere nobody approved, and make a decision you have to be able to explain. Same duties, new surface.
“Someone pasted a client record into a chatbot.”
Whether that's a breach depends on which tool, what agreement is in place, and what the vendor does with it — three facts your inventory should already hold.
“A customer asked us to delete everything.”
You have 30 or 45 days depending on the law, and the answer has to include whatever went into the AI tools too.
“Explain how the system decided that.”
GDPR Article 22 and the CCPA ADMT rules both ask. The impact assessment you already completed is the explanation.
Each of these gets its own crosswalk showing where your program addresses it — and, just as usefully, where it doesn’t yet.
Notice before collection, deletion on request, an opt-out of automated decision-making, and knowing which vendors received what. The ADMT rules share Colorado's January 1, 2027 date.
A lawful basis, a stated purpose, and the ability to explain an automated decision to the person it was made about. Article 22 is the one AI keeps walking into.
If patient data could reach an AI tool, the business associate agreement and the safeguards have to be in place first — before the tool is switched on, not after.
Each requirement sits next to the clause in your own program that answers it, and the ones nothing answers are listed as gaps rather than quietly omitted.
Generated from your own answers and grounded in the same cited control library as everything else. Pro plan and above.
A request arrives, the clock starts. 30 days for GDPR, 45 for CCPA, counted for you, with the overdue ones surfaced before they are overdue.
Written in advance, with the notification deadline on it, because the afternoon of a breach is the worst possible time to be drafting one.
Privacy frameworks are included in the plans noted above — CCPA on Pro and above, GDPR and HIPAA on Agency. A defensible starting point that you review and approve, not legal advice.
Two decades directing large-scale technology portfolios, enterprise risk management and applied machine learning — which is why the control library is authored and versioned the way it is, rather than assembled from templates.
Gradient Descent LLC is an independent company. GOVERNBOX.ai is not affiliated with, endorsed by, or produced on behalf of any government agency.
The free scorecard asks what data your team puts into AI tools, and shows you the gaps.
Take the free scorecard →