AI Law, Compliance & Emerging Technology
AI law for real-world business.
Sections
overview
focus areas
depth of practice
team
insights
industries served
representative matters
testimonials
contact us
overview
focus areas
depth of practice
team
insights
industries served
representative matters
testimonials
contact us
Overview
Organizations adopting artificial intelligence face growing legal risk tied to privacy, security, automated decision-making laws, and emerging state and federal regulation. Whether you’re deploying third-party systems, building proprietary models, or exploring generative AI internally, you need clarity on risk, regulation, and how to move forward responsibly.
Our AI Law attorneys and in-house technical team provide practical guidance that helps organizations adopt AI responsibly, document decisions defensibly, and scale innovation with confidence. This is not theoretical counsel. It is real-world guidance designed to help your organization move faster, with fewer surprises.
We help organizations adopt and leverage AI confidently with practical, business-focused legal guidance that supports innovation without stepping into avoidable legal trouble. Alongside our attorneys, we have an internal team of AI engineers, data architects, and developers who support clients with education, adoption strategy, and technical execution.
Helping Organizations Use AI Responsibly
Companies turn to us when they need straightforward answers about what AI tools they can use, how they can use them, and what they need to document along the way. We advise on compliance with emerging state and federal rules, including when a tool qualifies as an automated decision system. We also help clients navigate disclosure and transparency requirements, data governance, training-data rights, and privacy considerations when building or buying AI tools.
Beyond compliance, we provide education and hands-on training so teams understand what AI can do, where its limits are, and how to integrate it into everyday work. Whether you’re experimenting with generative tools or building custom solutions, we develop the playbooks, guardrails, and adoption strategies that make AI practical across your organization. Our technical team supports this work by designing internal workflows, piloting generative tools, and helping you understand how these systems fit into your operational landscape.
Managing Risk in Automated Decision-Making
Using AI introduces new commercial, privacy, and operational risks. We help organizations strengthen vendor agreements, clarify ownership and IP rights in generated content, and build internal governance and approval workflows that support defensible decision-making.
For organizations scaling AI beyond simple use cases, our attorneys and in-house technical team work together to guide model development, training-data strategy, privacy by design, lifecycle governance, and evaluations of accuracy and bias. Whether you’re enhancing a foundation model or creating proprietary tools, we help ensure your innovation roadmap stays aligned with legal requirements and operational realities.
Support Across Regulated Industries
AI adoption is accelerating in industries where compliance already matters most. We support organizations across New York State and nationwide, including companies operating in highly regulated environments such as healthcare, finance and insurance, HR and workforce management, and lending and underwriting. We also provide legal certification that AI tools align with major U.S. regulatory frameworks, including:
- HIPAA
- CCPA/CPRA
- FCRA
- GLBA
- Sarbanes-Oxley
- PCI DSS
- FERPA
- FDA AI guidance
EEOC and FTC enforcement standards
We Answer Your Questions
- What rules apply to the AI tools we’re using?
- Can we train models with customer or employee data?
- What belongs in an AI vendor contract?
- How do we manage the risk of inaccurate or biased outputs?
- What documentation should we keep in case regulators ask?
- How do we educate our teams so they can use AI safely and effectively?
- What should leadership know before adopting or building AI?
- If we’re building our own models, what privacy, IP, and governance steps should we take now?
- What technical guardrails should we have in place to support responsible model development?
- How do we get our AI systems certified?
- Do we need an AI policy for internal staff use of ChatGPT or Copilot?
- What AI disclosures are required for customers, patients, or employees?
If AI is creating new questions inside your organization, we help you find clear, practical answers.
Focus Areas
AI Adoption & Change Management
Training, staff education, risk-benefit guidance, and rollout strategies that help teams use AI effectively at scale.
AI Compliance & Governance
AI policies, internal approval workflows, documentation standards, audit readiness support, and strategic frameworks that keep your organization aligned with evolving laws.
Automated Decision-Making & High-Risk Tools
Regulatory analysis, bias mitigation, documentation requirements, and governance for tools used in hiring, lending, healthcare, and other sensitive areas.
AI Development & Model Training Support
Counsel for organizations building or customizing models, supported by our in-house AI developers and data engineers and architects who assist with technical planning, data strategy, and responsible development practices.
Vendor Contracts & Third-Party Systems
Negotiation, risk allocation, transparency requirements, and oversight when deploying external AI solutions. Includes contract review for data use, IP ownership, indemnification, transparency obligations, and regulatory risk allocation.
Industry-Specific Compliance
Guidance tailored to highly regulated industries with unique AI considerations.
Depth of Practice
Our depth of practice includes experience with:
- AI tool evaluation and risk assessment for internal and customer-facing use cases
- Automated decision system analysis, documentation, and defensibility planning
- AI governance programs, internal controls, disclosures, and transparency practices
- Data governance, privacy-by-design workflows, and training-data strategy
- Vendor contracting for AI and automation tools, including oversight and accountability frameworks
- Ownership and IP considerations related to AI-generated outputs and model development
- Accuracy, bias, and model risk evaluations aligned with operational realities
- Internal education, training, and change-management programs for responsible use
- AI adoption playbooks and technical guardrails supported by in-house engineers, developers, and data architects
- AI policy development for internal staff use, customer-facing tools, and executive governance
- Legal certification alignment with U.S. regulatory frameworks including HIPAA, CCPA/CPRA, FCRA, GLBA, Sarbanes-Oxley, PCI DSS, FERPA, FDA guidance for AI technologies, and federal standards enforced by the EEOC and FTC
- Our team combines legal guidance with technical support so recommendations can actually be implemented.
Team
Burge-B

Benjamin
Burge
Partner
Buffalo, NY
Miller-M

Matthew
Miller
Partner
Buffalo, NY
Muto-D

Dominick
Muto
COO
Buffalo, NY
Pakkiri-K

Kimay
Pakkiri
Associate
Buffalo, NY
Rupp-T

Tony
Rupp
Founding Partner
Buffalo, NY
Szczepanski-M

Matthew
Szczepanski
Project Manager
Buffalo, NY
Wacker-J

Jacob
Wacker
Senior Developer
Buffalo, NY
Weber-C

Cory
Weber
Partner
Buffalo, NY
Insights
New York May Soon Require Large Employers to Report Annually on AI’s Impact on Jobs
New York May Soon Require Large Employers to Report Annually on AI’s Impact on Jobs August 4, 2026 Home / By Matt Miller New York’s Legislature has passed a bill that would require large employers…
Rupp Pfalzgraf Featured in Buffalo Business First on In-House AI Development
Rupp Pfalzgraf Featured in Buffalo Business First on In-House AI Development July 7, 2026 Home / Rupp Pfalzgraf was recently featured in Buffalo Business First for our development of an in-house…
California’s Expanding AI Laws: What Businesses Need to Know
California’s Expanding AI Laws: What Businesses Need to Know July 7, 2026 Home / By Amedeo Zmarandoiu California has quickly become one of the most active jurisdictions in the U.S. for regulating…
Rupp Pfalzgraf Launches AI Law, Compliance & Emerging Technology Practice
Rupp Pfalzgraf Launches AI Law, Compliance & Emerging Technology Practice July 7, 2026 Home / The rise of artificial intelligence is rapidly reshaping how businesses operate, creating both new…
Industries Served
Banking & Finance
Insurance
Energy, Environment & Sustainability
Construction & Real Estate
Professional & Business Services
Health Services
Transportation & Aerospace
Advanced Manufacturing & Materials
Information Technology & Software
Consumer Products & Retail/Hospitality
Agriculture & Food
Education
Related Practice Areas
Business Law
Representative Matters
Drafted AI policies and consulted with multiple organizations on how to better leverage existing AI tools and where internal AI education and tailored workflow development could benefit their organizations.
Testimonials
Rupp Pfalzgraf’s AI Lunch & Learn was one of the most practical and eye-opening sessions we’ve attended — not a vendor pitch, but a candid look at how a forward-thinking firm is actually operationalizing AI across real workflows. They didn’t just talk strategy; they showed us proprietary tools they built in-house and sent us home with a framework we could immediately apply to our own work.



