AI governance & legal

Use AI with clear rules, not crossed fingers.

Your team already uses AI, with or without permission. This practice turns that fact into an advantage: an inventory of what runs where, a usage policy people actually follow, contracts that protect you, and LFPDPPP compliance reviewed by lawyers. The technical side is ours; the legal side is Alarcón Law, our allied firm.

Printed AI governance framework, annotated, on a wooden desk next to a fountain pen
AI governance & legal
Governance is the permission slip, not a brakeContext

Most companies are in one of two bad places with AI: banned on paper and used in secret, or allowed without rules and nobody knows what client data ended up in which model. Both end the same way, with an incident nobody can explain to a client, a regulator or a board.

AI governance is the middle path: knowing which systems your company uses, deciding which uses are allowed at which level, writing it down in a policy your team can actually follow, and backing the sensitive parts (data protection, contracts, liability) with real legal work.

We run this as a joint practice. Lizardi maps your systems, designs the technical controls and trains your people. Alarcón Law, our allied firm in Mexico City, handles the legal substance: LFPDPPP compliance, AI contracts and regulatory questions. One project, both halves covered.

In alliance with Alarcón LawAlliance
Alarcón Law, problema resuelto

The legal half of this practice is Alarcón Law, our allied corporate firm in Mexico City. Together we also cover what comes next in legal practice: influencer and creator legal management, and AI-powered legal resources for firms.

What a governance project coversThe practice
G-01

AI system inventory and risk map

We find every AI system your company actually touches, the official ones and the shadow ones, and map each to its risk level: what data goes in, where it is processed, who depends on the output. You cannot govern what you have not listed.

G-02

An AI usage policy your team will actually follow

A written policy that says which tools are allowed for which work, at which level: public models for non-sensitive drafting, enterprise deployments for client work, on-premise for the regulated core. Short enough to be read, specific enough to be enforced, and rolled out with training instead of a memo.

G-03

LFPDPPP and personal data in AI projects

When personal data meets AI, Mexican data protection law has opinions: legal basis, privacy notices, transfers, ARCO rights against automated decisions. Alarcón Law reviews your flows and closes the gaps before an authority or a counterparty finds them.

G-04

AI contracts: vendors, development and licensing

The clauses that matter when you buy, build or license AI: data retention and training carve-outs, confidentiality, IP over prompts and outputs, liability when the model is wrong. Alarcón Law drafts and negotiates the legal side; we translate the technical claims so nothing important hides in the annex.

G-05

AI committee and executive training

Governance survives when someone owns it. We help you stand up a small AI committee, define who approves new uses, and train your leadership so decisions about AI stop being delegated to whoever shouts the loudest about it.

What you walk away withWhat you keep
01

A written inventory of the AI systems your company uses, each mapped to a risk level

02

An AI usage policy your legal and compliance areas can sign, rolled out with training

03

LFPDPPP gaps in your AI flows identified and closed with real legal work by Alarcón Law

04

AI vendor and development contracts with the clauses that actually protect you

05

A committee and a decision path, so the next AI question has an owner

AI governance, brieflyQuestions
What is AI governance?

The set of rules and controls that let a company use AI on purpose: knowing which systems run, deciding which uses are allowed with which data, writing it into a policy, and backing the sensitive parts with legal work. It is what separates "our team uses AI" from "our team uses AI and we can prove it is under control".

Do I need this if we only use ChatGPT?

That is usually when you need it most. A single consumer tool, used by many people without rules, is the highest-risk setup: client data in personal accounts, no retention guarantees, no record of what went where. A short policy and the right tier of deployment fix most of it quickly.

Who does the legal work?

Alarcón Law, a corporate law firm in Mexico City and our allied firm in this practice. Lizardi does the technical mapping, controls and training; Alarcón Law signs the legal deliverables: LFPDPPP compliance, contracts and regulatory analysis. You get one project with both halves covered by the right professionals.

What does the LFPDPPP require if my AI uses personal data?

Among other things: a valid legal basis and a privacy notice covering that use, care with transfers to providers, and respect for ARCO rights, including objection to automated decisions. The exact obligations depend on your flows, which is why the project starts with the inventory rather than a template.

How does this relate to the training program?

They complete each other. Training teaches your team to use AI well on their real work; governance defines the rules of the game they play by. Many clients start with one and add the other once the first gaps show up.

Related practicesVerticals
Let's begin

Put rules around your AI

Tell us how your team uses AI today, even if the honest answer is "we are not sure". The inventory is exactly for that.