AI Governance Library

Governing Intelligence: Law, Privacy, Security, and Compliance in the Age of Artificial Intelligence

No universally accepted definition of artificial intelligence exists — a gap that carries direct consequences for regulation, compliance obligations, and regulatory scope. This textbook proposes the AI Governance Stack as its central organizing framework: a five-layer operational model.
Governing Intelligence: Law, Privacy, Security, and Compliance in the Age of Artificial Intelligence

⚡ Quick Summary

Governing Intelligence: Law, Privacy, Security, and Compliance in the Age of Artificial Intelligence by Noah M. Kenney provides a comprehensive operational textbook for establishing auditable AI governance. Anchored by the author's proprietary five-layer AI Governance Stack—spanning Data Governance, Model Governance, System Integration, Control & Monitoring, and Audit & Evidence—the text establishes how organizations can translate high-level legal mandates into executable engineering controls. Through detailed statutory analyses, technical specifications, and end-to-end implementation walkthroughs, the document examines cross-jurisdictional compliance across the EU AI Act, US federal and state statutes (including Colorado SB 24-205, CCPA/CPRA, and BIPA), cybersecurity attack vectors, intellectual property doctrines, and sector-specific privacy regimes across healthcare, education, and finance.

🧩 What's Covered

Kenney organizes modern AI risk management into a structured curriculum addressing foundational theory, comparative regulation, technical security, and operational compliance:

  • The AI Governance Stack: Formulates a five-tier operational hierarchy governed by the Layer-Failure Propagation Principle (failures cascade upward and cannot be resolved solely at higher layers). It provides RFC 2119 implementation specifications, decision rules, audit criteria, and a five-stage Governance Maturity Model (Ad Hoc to Optimized).
  • Global Regulatory Regimes: In-depth comparative review of the EU AI Act (Regulation 2024/1689) risk taxonomy, Annex III high-risk requirements, conformity assessment pathways, and systemic risk GPAI thresholds (≥10^25 FLOP). It also contrasts the US fragmented landscape—featuring FTC Section 5 unfairness enforcement, algorithmic disgorgement, state legislation (Colorado SB 24-205, NYC Local Law 144, Illinois BIPA/AIVIJA)—with UK pro-innovation sectoral oversight and China's state-centric content moderation and generative AI measures.
  • AI Privacy & Privacy Engineering: Reconciles GDPR requirements (Article 5 principles, Article 22 automated decision-making restrictions, Article 35 DPIAs, Schrems II cross-border transfers) and US privacy statutes with technical privacy engineering solutions, including local and central differential privacy (ε, δ budgeting), k-anonymity, synthetic data generation via GANs/VAEs, and federated learning.
  • AI Cybersecurity & Threat Defense: Technical deep dive into model extraction, data poisoning (clean-label and backdoor attacks), evasion techniques (FGSM, PGD, Carlini & Wagner), membership inference, model inversion, and supply chain security across training infrastructure.
  • Intellectual Property & Commercialization: Analyzes the human authorship requirement (Thaler v. Perlmutter, Naruto v. Slater), fair use litigation over training data, patent eligibility under the Alice/Mayo framework, trade secret protections, and open-source licensing models (RAIL, Apache 2.0, Llama Community License).

💡 Why it matters?

Most AI governance resources remain stranded at the level of abstract ethical principles or legal commentary. Governing Intelligence bridges the gap between regulatory theory and engineering execution by establishing concrete decision rules, metrics (such as Population Stability Index drift triggers and fairness disparity thresholds), and architectural specifications. By demonstrating how the five-layer Stack maps directly to international frameworks like NIST AI RMF 1.0, ISO/IEC 42001, and the EU AI Act, the text provides practitioners with a single unified architecture capable of handling multi-jurisdictional compliance while mitigating technical debt.

❓ What's Missing

While the volume covers broad legal and technical ground, certain operational artifacts remain at a high level. The text references specific toolchains (e.g., MLflow, Collibra, Immuta) and includes checklist outlines, but omits complete, line-by-line programmatic code samples or complete regulatory filing documentation packages. Furthermore, while frontier AI systemic risks and FLOP thresholds are covered, extended guidance on autonomous agentic workflows and multi-agent coordination governance is left for future exploration.

👥 Best For

AI governance officers, data protection officers (DPOs), enterprise risk managers, AI/ML engineers, corporate legal counsel, and compliance professionals who need an actionable, technical blueprint for designing and auditing enterprise-grade AI risk programs across multiple jurisdictions.

📄 Source Details

  • Author: Noah M. Kenney (Founder & Principal Consultant, Digital 520; President & Chief Scientist, Disruptive AI Lab; President, Ethical Tech Forum)
  • Publication Date: 2026 (First Edition)
  • Publisher: Digital 520
  • Format: Textbook / Monograph (486+ pages)
  • Key Frameworks Cited: AI Governance Stack, EU AI Act, NIST AI RMF 1.0, ISO/IEC 42001:2023, GDPR, CCPA/CPRA, Colorado SB 24-205, FTC Act Section 5, MITRE ATLAS, OWASP ML Top 10.

📝 Thanks to

Authored by Noah M. Kenney and published by Digital 520.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.