Legal & Governance
What the change means for legal and compliance, and the privacy, security, risk and AI-governance responsibilities the corpus has not yet addressed.
This page reorders the material of the other two sections for Legal / Compliance. (Privacy, Security, Risk and AI Governance belong to this bucket by the project’s function map, but the corpus does not yet contain substantive content on them — flagged as a gap to fill later, not invented here.)
What changes for legal & governance
- Three regulatory items are now product decisions. Disclosing that a response is AI-generated, that a quote is a non-binding estimate, that advice does not replace a professional, and that a datum was not found — several of these became mandatory in 2026. The margin for discretion is narrowing; the threshold above the legal minimum remains a decision. See The regulatory perimeter.
- Liability in case of error. Who signs the disclosure and who answers for the error is a legal and product decision together. See Who signs, and who answers.
- Agentic exposure. Opening to agents exposes the organisation to prompt injection and commoditisation; closing means leaving the channel where comparison happens anyway. See Making a traditional product usable by an agent.
What you cannot decide alone
- How much the product discloses about its limits above the legal minimum is shared with Product & Design and Content & Editorial.
- The trust budget allocation is a leadership and product decision — see Leadership & Strategy.