AI Law, Compliance & Emerging Technology

AI law for real-world business.

D

Sections

E

overview

focus areas

depth of practice

team

insights

industries served

representative matters

testimonials

contact us

overview active menu icon

overview

focus area active icon

focus areas

depth of practice active icon

depth of practice

team active menu icon

team

insights active menu icon

insights

industries served active menu icon

industries served

representative matters active menu icon

representative matters

testimonials active menu icon

testimonials

contact us active menu icon

contact us

Overview

Organizations adopting artificial intelligence face growing legal risk tied to privacy, security, automated decision-making laws, and emerging state and federal regulation. Whether you’re deploying third-party systems, building proprietary models, or exploring generative AI internally, you need clarity on risk, regulation, and how to move forward responsibly.

Our AI Law attorneys and in-house technical team provide practical guidance that helps organizations adopt AI responsibly, document decisions defensibly, and scale innovation with confidence. This is not theoretical counsel. It is real-world guidance designed to help your organization move faster, with fewer surprises.

We help organizations adopt and leverage AI confidently with practical, business-focused legal guidance that supports innovation without stepping into avoidable legal trouble. Alongside our attorneys, we have an internal team of AI engineers, data architects, and developers who support clients with education, adoption strategy, and technical execution.

Helping Organizations Use AI Responsibly

Companies turn to us when they need straightforward answers about what AI tools they can use, how they can use them, and what they need to document along the way. We advise on compliance with emerging state and federal rules, including when a tool qualifies as an automated decision system. We also help clients navigate disclosure and transparency requirements, data governance, training-data rights, and privacy considerations when building or buying AI tools.

Beyond compliance, we provide education and hands-on training so teams understand what AI can do, where its limits are, and how to integrate it into everyday work. Whether you’re experimenting with generative tools or building custom solutions, we develop the playbooks, guardrails, and adoption strategies that make AI practical across your organization. Our technical team supports this work by designing internal workflows, piloting generative tools, and helping you understand how these systems fit into your operational landscape.

Managing Risk in Automated Decision-Making

Using AI introduces new commercial, privacy, and operational risks. We help organizations strengthen vendor agreements, clarify ownership and IP rights in generated content, and build internal governance and approval workflows that support defensible decision-making.

For organizations scaling AI beyond simple use cases, our attorneys and in-house technical team work together to guide model development, training-data strategy, privacy by design, lifecycle governance, and evaluations of accuracy and bias. Whether you’re enhancing a foundation model or creating proprietary tools, we help ensure your innovation roadmap stays aligned with legal requirements and operational realities.

Support Across Regulated Industries

AI adoption is accelerating in industries where compliance already matters most. We support organizations across New York State and nationwide, including companies operating in highly regulated environments such as healthcare, finance and insurance, HR and workforce management, and lending and underwriting. We also provide legal certification that AI tools align with major U.S. regulatory frameworks, including:

  • HIPAA
  • CCPA/CPRA
  • FCRA
  • GLBA
  • Sarbanes-Oxley
  • PCI DSS
  • FERPA
  • FDA AI guidance
    EEOC and FTC enforcement standards

We Answer Your Questions

  • What rules apply to the AI tools we’re using?
  • Can we train models with customer or employee data?
  • What belongs in an AI vendor contract?
  • How do we manage the risk of inaccurate or biased outputs?
  • What documentation should we keep in case regulators ask?
  • How do we educate our teams so they can use AI safely and effectively?
  • What should leadership know before adopting or building AI?
  • If we’re building our own models, what privacy, IP, and governance steps should we take now?
  • What technical guardrails should we have in place to support responsible model development?
  • How do we get our AI systems certified?
  • Do we need an AI policy for internal staff use of ChatGPT or Copilot?
  • What AI disclosures are required for customers, patients, or employees?

If AI is creating new questions inside your organization, we help you find clear, practical answers.

Focus Areas

AI Adoption & Change Management

Training, staff education, risk-benefit guidance, and rollout strategies that help teams use AI effectively at scale.

AI Compliance & Governance

AI policies, internal approval workflows, documentation standards, audit readiness support, and strategic frameworks that keep your organization aligned with evolving laws.

Automated Decision-Making & High-Risk Tools

Regulatory analysis, bias mitigation, documentation requirements, and governance for tools used in hiring, lending, healthcare, and other sensitive areas.

AI Development & Model Training Support

Counsel for organizations building or customizing models, supported by our in-house AI developers and data engineers and architects who assist with technical planning, data strategy, and responsible development practices.

Vendor Contracts & Third-Party Systems

Negotiation, risk allocation, transparency requirements, and oversight when deploying external AI solutions. Includes contract review for data use, IP ownership, indemnification, transparency obligations, and regulatory risk allocation.

Industry-Specific Compliance

Guidance tailored to highly regulated industries with unique AI considerations.

Depth of Practice

Our depth of practice includes experience with:

  • AI tool evaluation and risk assessment for internal and customer-facing use cases 
  • Automated decision system analysis, documentation, and defensibility planning 
  • AI governance programs, internal controls, disclosures, and transparency practices 
  • Data governance, privacy-by-design workflows, and training-data strategy 
  • Vendor contracting for AI and automation tools, including oversight and accountability frameworks 
  • Ownership and IP considerations related to AI-generated outputs and model development 
  • Accuracy, bias, and model risk evaluations aligned with operational realities 
  • Internal education, training, and change-management programs for responsible use 
  • AI adoption playbooks and technical guardrails supported by in-house engineers, developers, and data architects 
  • AI policy development for internal staff use, customer-facing tools, and executive governance 
  • Legal certification alignment with U.S. regulatory frameworks including HIPAA, CCPA/CPRA, FCRA, GLBA, Sarbanes-Oxley, PCI DSS, FERPA, FDA guidance for AI technologies, and federal standards enforced by the EEOC and FTC 
  • Our team combines legal guidance with technical support so recommendations can actually be implemented.

Team

Burge-B

Benjamin Burge

Benjamin

Burge

Partner

Buffalo, NY

Miller-M

Matthew Miller

Matthew

Miller

Partner

Buffalo, NY

Muto-D

Dominick Muto

Dominick

Muto

COO

Buffalo, NY

Pakkiri-K

Kimay Pakkiri

Kimay

Pakkiri

Associate

Buffalo, NY

Rupp-T

Tony Rupp

Tony

Rupp

Founding Partner

Buffalo, NY

Szczepanski-M 

Julie Krapinski

Matthew

Szczepanski

Project Manager

Buffalo, NY

Wacker-J

Julie Krapinski

Jacob

Wacker

Senior Developer

Buffalo, NY

Weber-C

Cory Weber

Cory

Weber

Partner

Buffalo, NY

Insights

Representative Matters

Drafted AI policies and consulted with multiple organizations on how to better leverage existing AI tools and where internal AI education and tailored workflow development could benefit their organizations.

Testimonials

Rupp Pfalzgraf’s AI Lunch & Learn was one of the most practical and eye-opening sessions we’ve attended — not a vendor pitch, but a candid look at how a forward-thinking firm is actually operationalizing AI across real workflows. They didn’t just talk strategy; they showed us proprietary tools they built in-house and sent us home with a framework we could immediately apply to our own work.

– Venture Capital Firm

Contact Us

AI Law and Compliance