“[A]dept at handling state and global data privacy law compliance for various companies.”
Chambers USA 2026
Data Is Power. AI Is the Frontier. We Navigate Both.
Baker Botts Privacy, Cybersecurity, and AI Governance practice helps clients lead with confidence, turning regulatory complexity into a strategic advantage across the established data privacy landscape and the emerging frontier of AI law. As global privacy regulations tighten and AI governance frameworks rapidly take shape, the legal stakes have never been higher. At Baker Botts, we know that data is power—and artificial intelligence is reshaping how that power is exercised.
We are built for this moment. Our practice brings together seasoned privacy and cybersecurity lawyers alongside dedicated AI governance counsel—a fully integrated team advising on the full spectrum of data, cyber, and AI matters. Whether a client is building an enterprise AI governance program, responding to a General Data Protection Regulation (GDPR) enforcement action, or navigating a multi-jurisdictional data breach, we deliver coordinated, authoritative counsel across every dimension of the engagement.
What jurisdictions does our experience cover?
AI governance is not a future consideration. It is a present legal obligation. The EU AI Act is already in effect. U.S. federal and state AI legislation is accelerating. Regulators in the UAE, UK, Singapore, and beyond are moving quickly. Baker Botts advises clients globally on AI compliance, risk frameworks, governance program design, AI transactions, and enforcement defense—helping companies meet today's requirements while building structures to adapt to future challenges.
With boots on the ground across key jurisdictions, our U.S. teams — spanning Houston, Dallas, New York, Austin, Washington D.C., and beyond — work closely with our practitioners in London and Dubai to deliver seamless counsel across American, European, and Middle Eastern regulatory frameworks. Clients receive tailored advice wherever their business operates, with our international offices providing dedicated coverage of UK, EU, and Gulf region matters. Our team doesn't just follow regulatory developments — we help shape them.
We are also proud members of the Lex Mundi network of firms, enabling us to call on trusted legal partners around the globe for complex, multi-jurisdictional privacy, cybersecurity and AI governance matters.
What types of companies do we support in our Privacy, Cybersecurity, and AI Governance practice?
Baker Botts represents a diverse set of industry leaders across verticals where data and AI drive business—technology and SaaS companies, financial institutions, healthcare providers, energy giants, retailers, life science innovators, and telecom and internet providers, each facing distinct and evolving regulatory obligations.
How do we help organizations address privacy, cybersecurity, and AI governance challenges?
Baker Botts’ full-spectrum privacy, cybersecurity, and AI governance practice helps clients address evolving risks, maintain compliance, respond to incidents, and implement governance frameworks that support innovation while protecting their business. Our capabilities include:
01 Artificial Intelligence Governance & Compliance
- Compliance counsel on the EU AI Act, NIST AI RMF, ISO/IEC 42001, and U.S. federal and state AI legislation
- Enterprise AI governance program design, risk assessments, and compliance audits
- AI use policies, acceptable use standards, and board-level AI governance charters
- AI vendor agreements, data licensing, and technology transaction counsel
- Algorithmic accountability, bias and fairness obligations, and CPPA ADMT compliance
- Agentic AI and generative AI deployment counsel
- AI incident response, regulatory investigation defense, and enforcement actions
02 Privacy Regulatory & Compliance
- Full-spectrum guidance across CCPA/CPRA, HIPAA, GLBA, GDPR, ePrivacy, PIPEDA, LGPD, DOJ DSP, and beyond
- Scalable compliance program design, gap analysis, and operationalization
- State privacy law monitoring and multi-jurisdictional compliance coordination
03 Data Governance & Risk Mitigation
- Enterprise data governance framework design for AI, biometrics, and emerging technologies
- Data mapping, classification, retention policy, and cross-border transfer mechanisms
- Third-party vendor risk management and data exposure assessment
04 Privacy Auditing & Impact Assessment
- Privacy impact assessments and data flow mapping
- Cyber insurance coverage review and gap analysis
- Policy and procedure development and targeted employee training programs
05 Privacy, Cybersecurity, and AI Transactions
- Privacy and cyber due diligence in M&A, joint ventures, divestitures, and carve-outs
- SPA privacy and security representations, warranties, indemnities, and post-close obligations
- AI vendor agreements, data licensing, and technology contract negotiation
- Cloud, SaaS, IT infrastructure, and cybersecurity vendor contracts and DPAs
- Business process outsourcing and complex multi-party data and AI arrangements
06 Cyber Incident Preparedness
- Incident response plan development and tabletop exercise facilitation
- Crisis simulation wargaming and regulatory notification protocol design
- Board training on cybersecurity and AI obligations under SEC rules
07 Cyber Incident Response · 24/7
- Around-the-clock incident response across all industries and geographies
- Forensic investigation coordination and multi-jurisdictional breach notification
- SEC Form 8-K materiality determination and law enforcement engagement
- Parallel litigation strategy and regulatory defense
08 Litigation, Regulatory Enforcement & Investigations
- Defense of privacy, data breach, and AI-related class actions in federal and state courts
- Regulatory enforcement proceedings before the FTC, state AGs, UK ICO, and EU DPAs
- Government investigations and agency inquiry response — from CID through resolution
09 Board-Level Governance & SEC Disclosure
- Cyber risk committee advisory and board training on privacy, AI, and cybersecurity obligations
- Annual Form 10-K cyber and AI risk factor drafting and audit committee engagement
- SEC Form 8-K disclosure strategy following cyber, privacy, and AI incidents