We don't help you adopt AI —
we help you govern it.
Senior-led AI governance, risk and control advisory for regulated and mission-critical systems. Every engagement is delivered by the principal. No junior staff, no hand-offs, no discovery theater.
Most organizations cannot answer the first question a reviewer asks.
Not is the model accurate — that question comes later, and someone else usually owns it. The first question is simpler and harder: where does AI touch a determination you are accountable for, and who signed off?
Pilots produce demos. Vendors produce claims. Neither produces a record. When an oversight body, a contracting officer, or a resident asks how a decision was reached, the answer has to already exist in writing — assembled before it was needed, not after.
That record is what ArcPoint builds. We call it the AI Control Layer.
Four states. Each one is a question you should be able to answer today.
Every engagement below moves an organization from the failure state on the left to the record on the right. Nothing else is the point.
The AI Control Layer is what you get. The Weftline Framework is how it is produced.
Weftline builds on the NIST AI RMF and adds two things the baseline leaves to the practitioner: IEEE 7000 ethical value elicitation, and structured bias testing. Five movements — Strategic Intent, Decision Authority, Operational Integration, Workforce Enablement, Technical Infrastructure — with AI Influence Mapping running through all five to surface where controls are absent.
See how an engagement runs →Two buyers, two obligations, one control layer.
Every AI deployment needs a values-alignment record before it goes live.
The requirement is per-deployment and indefinite. The policy behind it is binding under D.C. Code and carries sanctions. And the support structure built to help agencies meet it expires at the end of 2026.
- Values alignment verified before deployment — MO 2024-028 §III
- Human accountability for every determination — §III.C
- OCTO AI/ML Governance Policy conformance
- CTO approval before funds are obligated — IT Procurement Policy §4.2
- Responsible AI training — employees and contractors
Your contract already carries AI obligations. And a subcontracting line to fill.
If any part of your scope touches AI, you have already signed clauses you may not be resourced to satisfy. One subcontract can close the compliance gap and the small-business requirement at the same time.
- Certified SBE — satisfies § 2-218.46(a)(2)(A), not the fallback
- 100% self-performed by the principal — no pass-through
- Proposal-ready AI governance sections on 48-hour notice, at no cost
- Federal: NIST AI RMF, OMB M-25-21/22, CMMC-adjacent programs
- Unclassified scope posture — no CUI required
An audit record, not an assurance.
A governance firm should be judged the way it asks its clients to be judged: on documentation that survived someone else's review.
Work sample — available on request
An independent AI Values Alignment Assessment of DC Compass (OCTO / Esri / Azure OpenAI), a live District AI deployment. Conducted entirely from public sources against MO 2024-028, the OCTO AI/ML Governance Policy, and standard clauses E.1–E.4. Twenty scored findings, every citation verified, principal-signed.
Why it was self-directed
Because a client should not have to take a methodology on faith. The assessment shows the intake instrument, the findings register, the scoring, and the full deliverable set applied to a real system — before anyone signs anything.
Request the work sample →Fixed scope. Fixed fee. Defined deliverables.
Fixed fee is risk transfer — overrun risk sits with ArcPoint, not with your program. Three of the most common entry points below; the full ladder runs deeper.
AI Governance Gap Assessment
An organization-wide diagnostic: where AI influences decisions, where oversight is missing, and what to fix in what order. The standard front door when the answer to "what do we even have?" is a shrug.
Details →DC AI Values Alignment Assessment
The full published obligation set for one deployment — the six §III values plus conformance testing against the OCTO AI/ML Governance Policy and clauses E.1–E.4. Assessing one instrument of three is not an assessment.
Details →AI Strategy Session
One working hour with the principal and a one-page memo. Flat fee, any lane. The lowest-friction way to find out whether there is a real engagement here — for either of us.
Details →The mandate survives.
The help does not.
Mayor's Order 2024-028 §III requires alignment with six AI values, verified before deploying any AI tool — every deployment, documented, indefinitely. Both the AI Taskforce and the Advisory Group expire December 31, 2026. Agencies are not losing the obligation. They are losing the structure built to help them meet it.
Six things a reviewer can ask for, in writing, today.
A jurisdiction's marquee AI order is rarely its entire compliance surface. In the District, the Mayor's Order sits alongside a binding OCTO policy and a standard clause set — and OCP's own clause E.2 requires conformance with all of it.
Agencies are not losing the obligation. They are losing the help.
The per-deployment values-alignment requirement is permanent — §III sets no end date. The AI Taskforce and the Advisory Group both sunset at the end of 2026 under §VI.J and §IV.J. Every deployment that goes live in 2027 carries the same duty with less institutional support behind it.
That is the case for standing capacity rather than episodic projects — someone retained who already knows your systems when the question arrives, instead of a procurement that starts after it does.
Registered, certified, and able to receive award today.
Set-aside eligible
Certified SBE, eligible for the mandatory set-aside of contracts at or below $250,000 under § 2-218.44 — the band ArcPoint's District services are scoped to sit inside, individually and in combination.
Maximum bid preference
Six CBE designations whose combined value exceeds the statutory cap, so ArcPoint qualifies for the most § 2-218.43(b) allows: 12 points on proposals, or a 12% price reduction on bids. No competitor can hold more — only match.
Never both sides of one procurement
ArcPoint does not represent a vendor bidding to an agency it advises, and takes no role in source selection. Where we support a procurement, recommended language is input to the Contracting Officer and counsel, who own the solicitation.
Vendor-neutral, and resident
No referral fees, no reseller relationships — findings serve the agency and nothing else. A DC resident with a direct stake in how the District governs AI, not a firm that flew in for the mandate.
Ready to execute: NDA · W-9 · CBE number. SAM.gov active · OCP eSourcing registered · Basic Business License and Clean Hands current.
Deliverables, not hours.
Your contract already carries AI obligations.
And a line to fill.
If any part of your scope touches AI — analytics, automation, a model inside a workflow, a vendor tool in a resident-facing system — you have signed clauses that require evidence you may not be resourced to produce. One subcontract can close the compliance exposure and the small-business requirement at the same time.
Can your program produce this today?
Each line below is a clause you have already signed. The question is not whether the obligation applies — it is whether the artifact exists before someone asks for it.
Why an SBE specifically — and why the distinction matters.
35% to small business enterprises
On government-assisted non-construction contracts over $250,000, § 2-218.46(a)(2)(A) requires 35% of dollar volume to go to small business enterprises. CBEs generally are the (a)(2)(B) fallback — available only where qualified SBEs are insufficient. ArcPoint is a certified SBE, which satisfies the primary requirement rather than the exception.
The plan is due before your proposal is accepted
§ 2-218.46(d) makes a bid nonresponsive on a deficient plan — and the plan is due before the District accepts your proposal, not after award. After award: executed subcontract returned for your (h) submission, and quarterly figures for your (i) reports, unprompted.
100% self-performed by the principal
Satisfies § 2-218.46(b-1). Independent advisors are used for surge capacity, never as a conduit. There is no second-tier subcontracting behind this certificate.
Preference does not pass through
§ 2-218.43 preference attaches to the bidder and does not flow through a subcontract. ArcPoint's six designations total 19 points against the 12-point cap — the statutory maximum — which applies where ArcPoint bids as prime or in a certified joint venture under § 2-218.39a. In a standard subcontract your benefit is (a)(2)(A) satisfaction and, at or below $250,000, § 2-218.44 set-aside eligibility.
Subcontract and teaming capability for federal work.
AI governance is arriving in federal scopes faster than programs are staffed for it. ArcPoint teams as a subcontractor against the instruments that already bind the work.
- NIST AI RMF — the methodology baseline, layered with program-specific requirements rather than applied generically.
- OMB M-25-21 and M-25-22 — agency use and acquisition of AI.
- Lifecycle controls — impact assessments, model and system cards, human-oversight procedures, change management, decommissioning.
- AI System IV&V — independent assessment of bias, traceability, and regulatory alignment in high-impact environments.
- OWASP LLM Top 10 — agentic and MCP-connected workflow risk in regulated environments.
- Scope posture: unclassified only — no CUI required, stated plainly up front so the fit question is settled in the first conversation.
Deliverables, not hours.
Proposal-ready governance sections
AI governance narrative written to the solicitation's evaluation criteria, on 48-hour notice, before any subcontract, at no cost. If you don't win, you owe nothing — that is the point.
The clause evidence set
AI Factsheet drafted then maintained annually and on change · values-alignment record per deployment in the form OCTO expects · bias-testing evidence package · incident response procedure · human-accountability procedure with named owners.
CTO approval package
Support assembling the approval package under OCTO IT Procurement Policy §4.2, so the money moves on schedule rather than stalling at a gate nobody staffed for.
A single practitioner is a continuity risk only if the work lives in one head.
Senior-led by the certificate holder means no staffing ramp, no substitution risk, and no second-tier subcontracting. That is the half everyone likes. Here is the other half: the method — intake instrument, evidence request list, scored findings register — keeps work transferable rather than held in one head, and every artifact ships in editable source form.
Committed availability of 40 hours per month per engagement, response within one business day. Fixed fee where scope allows — overrun risk sits with ArcPoint. Teaming is non-exclusive, and never against a partner on the same solicitation.
Quote returned in three business days.
Everything your § 2-218.46(d)(2) plan needs.
| Legal name | ArcPoint Consulting, LLC |
|---|---|
| Address | Washington, DC 20020Full street address on the capability statement, for your subcontracting plan |
| UEI | JE2DLNX4BVQ3 |
| CAGE code | 20CH5 |
| D-U-N-S | 144965471 |
| DC CBE No. | LSDZRE17604082029Valid to August 10, 2029 · LBE · SBE · DBE · DZE · ROB · EIE · verifiable with DSLBD |
| NAICS | 541611 · 541618 · 541690 · 541512 · 611430Small under all listed codes |
| Registrations | SAM.gov active · OCP eSourcing registered |
| Business size | Small Business |
| Scope posture | Unclassified only — no CUI required |
| Point of contact | Jermaine Leonard, AIGP — Founder & Principal Consultant |
Fixed scope. Fixed fee.
Defined deliverables.
Every engagement declares a boundary before it starts — what is in, what is out, and what ships. Fixed fee is risk transfer: overrun risk sits with ArcPoint rather than with your program. Pricing is scoped to the engagement and quoted in three business days.
District Agencies & Programs
Federal & GovCon
Commercial & Regulated SMB
Any Lane
Bring one AI deployment — in use or planned.
In thirty minutes you will know whether that deployment has an alignment record that would survive review, and — for District work — whether the engagement can be procured under the § 2-218.44 set-aside. No fee, no obligation.
Book the CallThe AI Control Layer is the outcome.
Weftline is how it's built.
Governance-first, with the NIST AI RMF as the baseline and jurisdiction-specific requirements layered on top. The framework exists so the work is repeatable, transferable, and legible to someone who was not in the room — which is the only kind of governance record worth having.
Five movements, with influence mapping running through all of them.
Builds on the NIST AI RMF and adds what the baseline leaves to the practitioner: IEEE 7000 ethical value elicitation, and structured bias testing.
AI Influence Mapping runs across all five — the technique that surfaces where AI shapes a determination and no control is present. It is what makes the difference between a governance program that covers the systems you remembered and one that covers the systems you have.
One dataset. Every artifact rendered from it.
Findings are structured records before they are prose — consequence × evidence confidence, named owner, effort, remediation wave. Which means the report, the workbook, the readout, and the submission set cannot disagree with one another.
Baseline, then jurisdiction.
A framework alone does not discharge an obligation. The baseline establishes the discipline; the binding local instrument decides what the record has to contain.
- NIST AI RMF — the methodology baseline across every lane.
- IEEE 7000-2021 — ethical value elicitation, added where the baseline defers to the practitioner.
- ISO/IEC 42001 — AI management system structure for commercial and multi-jurisdiction clients.
- DC: MO 2024-028 · OCTO AI/ML Governance Policy · AI Procurement Handbook and clauses E.1–E.4 · OCTO IT Procurement and IT Project Policy.
- Federal: OMB M-25-21 and M-25-22 · CMMC L2/L3 · NIST SP 800-171 · DFARS 252.204-7012.
- OWASP LLM Top 10 — agentic and MCP-connected workflow risk.
The constraints we accept before you ask.
Every citation verified at ship
Each regulatory citation in a client-facing deliverable is re-checked against the primary source before delivery, and the verification is documented citation by citation. A governance finding built on a misremembered section number is worse than no finding.
Principal-signed, principal-defended
The principal reviews and signs every deliverable, and defends every finding in the room. AI is used as back-office leverage in research and drafting; judgment and accountability are not delegated.
Editable source form
Every artifact ships in a form the client can maintain. Your governance record should not depend on our availability, and it should not be hostage to a file format.
Vendor-neutral, with nothing to disclose
No referral fees, no reseller relationships, no platform partnerships. Nothing a competitor can characterize as steering, and no finding that costs us revenue to make.
Senior-led means
exactly what it says.
ArcPoint Consulting is a solo, senior-led AI governance, risk and control practice in Washington, DC. Every engagement is delivered by the principal. There is no bench, no staffing ramp, and no junior consultant learning your program on your budget.
Jermaine Leonard, AIGP
Twenty-eight years governing regulated, mission-critical production systems — and the audit record to show what that produced.
From 1997 to 2025, Senior Principal Engineer at Hughes Network Systems (EchoStar), responsible for regulated production infrastructure spanning more than 30,000 remote sites at 99.9% uptime, including an 80% reduction in provisioning time through zero-touch orchestration. Across that tenure: eleven consecutive SOC 2 and PCI audit cycles carried with zero findings.
That is the relevant background for AI governance, and it is a deliberate claim. The hard part of governing AI is not the model — it is producing a control record that survives an outside reviewer, in a live system, under real operating pressure, without stopping the work. That is a discipline built over decades in regulated operations, not a framework certification earned in a weekend.
- AIGP — IAPP AI Governance Professional, and a member in good standing of the IAPP
- CDP Certified AI Consultant
- DC Certified Business Enterprise — LBE · SBE · DBE · DZE · ROB · EIE, certified through August 2029
- Washington, DC resident — with a direct stake in how the District governs AI
Five positions, held consistently.
Governance-first architecture
Governance built in before deployment, not retrofitted after an incident. Retrofitting is more expensive and produces a weaker record, because the decisions that needed documenting were made months ago by people who have moved on.
Decision accountability focus
We address how decisions are made, influenced, and defended — not only how a model performs. Model performance is a vendor's problem. Determinations are yours.
Operational AI risk expertise
AI behavior in real environments, under real constraints, with real consequences — assessed by someone who has carried production systems through outside audits rather than only read about them.
Senior-led engagements
Every engagement led by the principal. No junior staff, no hand-offs, no billable-hour padding. Fixed fee where scope allows, so overrun risk sits with ArcPoint.
Vendor-neutral
No referral fees, no reseller relationships, no platform partnerships. Our findings serve your interests, and there is nothing to disclose because there is nothing to disclose.
Skeptical of hype, by policy
Nothing in the fee structure rewards telling you to adopt more AI. Often the finding that matters most is that a control, an owner, or a written procedure is missing — not that a tool is.
Registered and able to receive award today.
Ready to execute: NDA · W-9 · CBE number. Basic Business License and Clean Hands current.
Professional references available on request, including a named reference to the regulated-systems and audit record described here.
| Legal entity | ArcPoint Consulting, LLC |
|---|---|
| Location | Washington, DC 20020 |
| UEI | JE2DLNX4BVQ3 |
| CAGE | 20CH5 |
| D-U-N-S | 144965471 |
| DC CBE | LSDZRE17604082029Certified 2026-08-10, valid to 2029-08-10 |
| NAICS | 541611 · 541618 · 541690 541512 · 611430 |
| Registrations | SAM.gov · OCP eSourcing |
| Scope posture | Unclassified only — no CUI |
Regulatory developments,
read as obligations.
Not news summaries. Each piece takes a development a client will hear about anyway and works out what it actually changes about someone's duty, evidence, or exposure — including the frequent answer that it changes less than the headline suggests.
Each article was originally published on LinkedIn; the version here is the same text with its source link. White papers are published here first. Regulatory positions are stated as of the publication date and are not updated in place — where a development has since moved, a later piece says so rather than a silent edit.
What Assurance Actually Tests. A Test Plan for Auditing the AI Control Layer.
An AI governance review that never selects a decision has audited the documentation of AI governance. It may have done that well. What it hasn't tested is whether anything in the organization would stop a consequential AI system that was producing bad outcomes.
The main audit guidance on AI tells you what to look at. It doesn't tell you what to sample, how many items to pull, or what evidence passes. This paper does. It adapts twenty years of Sarbanes-Oxley control testing to AI, where three things change: controls shift without a change ticket, human review decays as volume rises, and the most important control has usually never been used.
Inside the paper
- Why the sampling unit is the consequential decision, not the AI system
- The timestamp test: which evidence counts, and which is a reconstruction
- How to test human review, including when a falling override rate means trouble
- A severity scale for AI control findings, graded by reversibility and likelihood
- A first-year scope an audit function can actually deliver
- Where internal audit can work alone and where it needs an independent specialist
- A 21-test matrix covering Visibility, Validation, Control and Auditability
Six questions for your audit committee
- What was the sampling unit, systems or decisions?
- How was the AI inventory tested for completeness, and from which sources outside the governance team?
- How many consequential decisions were tested, from what population, at what confidence?
- How much of the evidence the organization supplied existed before the request?
- How many stop authorities have never been used?
- Who reviewed the validations, and what's their relationship to the people who built the system?
A report that can answer those has tested something. A report that can't has read something.
Written for chief audit executives and audit committees, and their public-sector equivalents: agency heads, inspectors general and oversight boards.
About the author. Jermaine Leonard, AIGP, is the principal of ArcPoint Consulting, a senior-led AI governance, risk and control advisory practice in Washington, DC. Every engagement is delivered and signed by the principal.
DC's AI Values Have Never Been Enforced. The Window to Fix That Is Closing.
Every governance framework works fine right up until the moment it actually costs someone something. Before that moment, nobody can tell you whether it's real or whether it's a mission statement with a mandate number attached.
DC's six AI values, in place since 2024 under Mayor's Order 2024-028, have not had that moment yet. That's the real question hanging over the framework — not whether the org chart names an owner for Accountability.
I'd call this the founding violation problem. A rule doesn't become credible because someone wrote a consequence into it. It becomes credible the first time that consequence actually lands on someone, and everyone watching adjusts their behavior because of it. Miranda warnings didn't change policing because a court described them well. They changed policing once departments started losing cases over ignoring them.
Until DC's six values produce their own version of that moment, they're operating on borrowed credibility.
A finding. A paused deployment. A factsheet rejected and made public. Until one of those happens, the framework rests on the assumption that it would hold up if tested — never actually tested.
Why this is urgent rather than academic
DC's AI Taskforce and Advisory Group sunset December 31, 2026. Whatever informal enforcement muscle exists right now mostly runs through that structure. If the first real test of the six values happens after these bodies are gone, it happens without the apparatus that would have made it a clean, citable precedent.
And a framework that misses its own founding-violation window doesn't get a second one on the same terms. Whatever comes next has to rebuild credibility from scratch, against a public record showing two full years of a mandate nobody was held to.
What to watch between now and year end
One specific thing: whether OCTO, an inspector general, or any agency points to an actual finding under the six values — not a policy citation, an enforcement action.
If that doesn't happen before the Taskforce sunsets, the framework doesn't fail. It just becomes permanently aspirational by default, and no later reorganization fixes that retroactively.
This is my read, not a compliance assessment of any specific agency's program.
Illinois Didn't Just Add an AI Law. It Changed Who Gets to Grade the Homework.
Every other state AI law runs on the honor system: a company writes its own safety framework and tells regulators to take its word.
Illinois' Artificial Intelligence Safety Measures Act (SB 315), signed July 6, breaks that pattern. Large frontier developers must publish a safety framework and hire an independent, conflict-free third party to audit it annually, with results going to the state and the Attorney General.
Why this shift matters
Self-attestation and independent audit look similar on paper. They produce opposite incentives. Under disclosure, the company grading its own framework has no cost for optimistic language. An audit moves the liability: a named auditor certifies the result under their own professional standing. That's the SOX playbook, run on catastrophic-risk claims instead of earnings.
One wrinkle shows real audit sophistication: SB 315 requires the auditor to both certify compliance and recommend improvements. That's the same independence conflict that ended Arthur Andersen and split audit from consulting after Enron. The statute hasn't resolved it. Neither has the auditor market, yet.
What the audit actually requires
- Independence — no financial interest between auditor and developer.
- Competence — demonstrated frontier-model safety expertise, not general IT audit credentials.
- Standard — "generally accepted auditing standards," which don't yet formally exist for this domain; expect early reliance on NIST AI RMF and ISO 42001.
- Access — auditors see unredacted documentation, not just the published framework.
- Disclosure — a redacted summary goes public in 30 days; the full report goes to regulators, trade secrets or not.
What to do about it, by tier
Near or above $500M and training frontier-scale models: the 18 months to January 2028 is short given how thin the qualified-auditor pool is. Scope your exposure, formalize catastrophic-risk assessment in writing, build the 72-hour incident playbook, and start auditor conversations before the market gets crowded.
Everyone else — most companies buying AI rather than building it — your compliance move is with your vendors, not Illinois:
- Ask vendors whether their compliance claim is self-reported or audited, in writing.
- Add audit-report access language to contracts and DPAs now.
- Build internal AI governance that survives outside review, even without a legal mandate yet.
Watch for who copies the auditor requirement. That's what turns AI governance into an assurance function.
States that follow Illinois won't copy the penalty figures. The companies treating that distinction as semantic now are the ones explaining it to a regulator later.
The CMMC Suspension Didn't Lower Your Risk. It Moved It.
On July 13, 2026, the Department of War suspended CMMC Phase II — the third-party assessment piece that was supposed to start this November. Most of the reaction treats this as a break. I'd argue it's the opposite.
Here's what actually happened. The suspension removed a verification step. It didn't touch the obligation underneath it. NIST 800-171 is still the baseline. DFARS 252.204-7012 hasn't changed. SPRS scoring and your annual affirmation are still required. And nothing about this action touches DOJ's separate authority to pursue False Claims Act cases against contractors who misrepresent their cybersecurity posture. DoW can suspend its own assessment program. It can't suspend DOJ's.
What's gone is the independent check. Your obligation to be right about what you attest isn't.
For two years, a C3PAO assessment meant someone outside your organization had looked at your controls before the government relied on your score. That check is paused now.
Why this is a governance issue, not just a cyber one
Every SPRS filing is now a claim to the federal government that nobody outside your walls has verified. Based on how DOJ's Civil Cyber-Fraud Initiative cases have generally been built, the exposure tends to come less from missing controls and more from a gap between what got attested and what an audit would have found. Self-attestation without an outside check widens that gap's room to hide.
So if your read on this suspension is "we can slow down," what you're actually doing is holding onto that gap without the buffer that used to make it smaller.
What I'd be doing instead
- Pull the evidence behind every control claim in your SPRS score, tied to what's actually running — not what a policy document says should be running.
- Get clear on who owns the affirmation, and make sure there's a record of what they checked before they signed it.
- Look hard at whether your CUI scope can shrink. Smaller footprint, easier to defend, easier to keep accurate.
- Run your own internal testing against the 110 controls, because nobody's scheduling that visit for you anymore.
The compliance calendar just got longer. The liability window didn't move at all. If you sit on a board or in GC and you're looking at cyber risk this quarter, that's the signal: tighten review, don't ease off it.
This is my read on where things stand, not legal advice. FCA exposure is a question for counsel. Note added since publication: the suspension was subsequently confirmed to cover CMMC Phases 3 and 4 and all future milestones, not Phase II alone. The argument above holds — the underlying obligation survives regardless of scope — but the original post understated how broad the suspension was.
Default-On Consent Isn't a PR Risk. It's a Compliance Case Study.
If your team is watching the AI image-generation consent fight play out and calling it a consumer problem, not yours, look closer. The consent design is what's worth studying.
Default-on, opt-out use of someone's likeness isn't a PR problem. It's exactly the kind of thing that lands on a risk register the moment a product touches someone's face, voice, or image without them actively saying yes first. Here's how I'd walk a client through it.
Start with the biometric statutes
They have the sharpest teeth. If any part of the pipeline extracts or matches facial geometry — not just displays a photo — Illinois BIPA, Texas CUBI, and Washington's biometric privacy law all require notice, and BIPA wants written consent before capture. "It was a public photo" doesn't get you out of that. Go find out what the model actually does with the input before anyone writes this off the risk register.
GDPR is right behind it
A facial image used to identify someone is special category data under Article 9, and legitimate interest won't cover you. You need an explicit lawful basis — and at scale, you're very likely triggering a DPIA under Article 35 whether you want one or not.
Minors need their own lane entirely
If a tagged or referenced account belongs to someone under 18, COPPA and a growing list of state minor-safety-by-design laws don't accept "there's an opt-out in settings somewhere" as good enough. That's a dedicated gate, not a shared toggle.
State AI law is the one I'd stop leaning on
Colorado's original AI Act would have required impact assessments for exactly this kind of automated processing. Then SB 189, signed May 14, gutted that in favor of a lighter disclosure and human-review framework that doesn't even start until January 2027 — and applies only to automated decision-making in employment, education, lending, insurance, healthcare, housing, and government services.
The real exposure sits in biometric and kids' privacy law, not general AI law. Most teams have that backwards.
The fix isn't complicated, even if the legal mapping is
- Default to opt-in.
- Get consent before generation, not after.
- Build provenance in at the point of creation, instead of bolting on a lookup tool once someone's already upset.
If you're building or buying anything with this architecture, run the DPIA before the sprint starts — not after the headline.
Bring one AI deployment.
In use, or planned.
Thirty minutes. You will leave knowing whether that deployment has an alignment record that would survive review, and — for District work — whether the engagement can be procured under the § 2-218.44 set-aside. No fee, no obligation, no slide deck.
Send a note
Or skip the form and book the call directly.
Accessibility Statement
A firm that sells governance should be willing to be measured by its own instrument. This page states what standard this site targets, what was done to meet it, what is known not to meet it, and how to tell us when we're wrong.
Conformance target
This site is built to conform to Web Content Accessibility Guidelines (WCAG) 2.1, Level AA. That standard is also the benchmark referenced by Section 508 of the Rehabilitation Act, which governs information and communication technology procured by federal agencies, and is used as a reference standard by District of Columbia agencies.
We state this as a target with known exceptions rather than as a certification. No third party has audited this site. Claiming certified conformance without an independent assessment would be the same self-attestation problem we advise clients against.
Measures taken
- Contrast. Primary text combinations were selected against measured ratios — cream on navy at approximately 13.8:1 and gold on navy at approximately 6.4:1, both exceeding the 4.5:1 AA threshold for body text. The lighter brand gold is deliberately never used for text on light backgrounds, where it fails; a darker gold is substituted for accents.
- Keyboard operability. Every interactive element is reachable and operable by keyboard, with a visible focus indicator at 3px and 2px offset. A skip-to-content link is the first focusable element on the page.
- Target size. Interactive targets are set to a 44px minimum.
- Semantic structure. Headings descend in order, navigation is marked as a landmark, the current page carries an
aria-currentstate, and the mobile menu button exposes its expanded state. - Form labels. Every field has a persistently visible label. Placeholders are never used as the only label, and validation errors are conveyed in text rather than by color alone.
- Motion. Transitions are limited to color and opacity at 150–250ms. There is no parallax, no scroll-jacking, and no entrance animation on body copy. The
prefers-reduced-motionsetting is honored. - Meaning without color. No information is conveyed by color alone.
Known limitations
Stated plainly, because an accessibility statement that lists only successes is marketing:
- No independent audit. Conformance has been assessed internally only. No assistive-technology user testing has been conducted.
- Client-side routing. Pages are rendered without a full page load. Focus is moved to the main region on each route change and the document title is updated, but screen reader announcement behavior across this pattern has not been verified with every assistive technology.
- Third-party scheduling. The booking tool linked from this site is operated by a third party. Its accessibility is outside our control and has not been assessed by us.
- Documents. Capability statements and other PDFs distributed by ArcPoint have not been individually tested for tagged-PDF accessibility. An accessible alternative format is available on request.
Feedback and alternative formats
If any part of this site or any ArcPoint document is inaccessible to you, write to jleonard@arcpointconsulting.com or call (240) 244-9850. Tell us the page or document and the barrier you hit. We aim to acknowledge within one business day and to supply the content in an accessible alternative format at no cost.
If a response is unsatisfactory, say so directly to the principal — there is no escalation tier above him, which is the point of the firm.
Privacy Notice
Short, because this site does very little. It describes what actually happens here, not what a generic template would allow us to do later.
What this website collects
No analytics. No cookies. No tracking pixels. No advertising technology. This site sets no cookies and embeds no third-party analytics or marketing scripts. We do not build profiles of visitors, and we cannot tell you which pages you read.
Two exceptions are worth naming precisely:
- Web fonts are currently loaded from Google Fonts, which means your browser makes a request to Google's servers and Google receives your IP address in the process. We are moving to self-hosted fonts to remove this.
- Hosting logs. Our hosting provider records standard server logs, which typically include IP address, timestamp, and user agent. We do not use these for analytics.
Information you send us
If you use the contact form, it opens a message in your own email client — the data is not posted to a server we control. If you email, call, or book a call, we receive what you send: typically name, organization, email address, phone number, and whatever you choose to describe about your situation.
We use that information only to respond to you and to carry out any engagement that follows. We do not sell it, rent it, or share it for anyone else's marketing, and we do not add you to a mailing list you didn't ask for.
The scheduling tool
Booking a call sends you to a third-party scheduling service. Information you enter there is handled under that provider's privacy terms, not ours.
What we ask you not to send
Please do not send Controlled Unclassified Information, procurement-sensitive material, pre-decisional documents, or personal information about third parties through this website, the contact form, or ordinary email. ArcPoint operates an unclassified-only scope posture. Sensitive material is handled under a non-disclosure agreement through a separate channel — ask and we will set one up before you send anything.
Retention and security
Enquiry correspondence is retained while a business relationship is reasonably in prospect and thereafter as required for tax, insurance, and professional-record purposes. Engagement records are retained under the terms of the applicable agreement. Access is limited to the principal.
Your choices
You may ask what we hold about you, ask for it to be corrected, or ask for it to be deleted, by writing to jleonard@arcpointconsulting.com. Where a legal obligation requires us to retain something, we will tell you that rather than quietly decline.
Changes
If this site later adds analytics, a hosted form handler, or any other data collection, this notice will be updated before that change goes live, and the effective date above will change with it.
Note: this notice describes current practice accurately. It has not been reviewed by counsel, and it is not tailored to GDPR, CCPA, or other specific regimes. If ArcPoint begins handling personal data at scale or for clients in those jurisdictions, it should be replaced with a reviewed instrument.
Terms of Use
The terms on which this website is offered. They govern the site only — engagements are governed by their own signed agreement, which controls wherever the two differ.
No advice, and no relationship formed
Everything on this site — including the Insights articles and every description of a regulation, mandate, policy, or contract clause — is general information, not advice. It is not legal advice, and ArcPoint is not a law firm. It is not a compliance assessment of your organization, your program, or any specific deployment. Reading it, emailing us, or booking a call does not create a consulting or advisory relationship. That begins only when a written agreement is signed by both parties.
Regulatory content is accurate as of its date
Citations to statutes, mayor's orders, agency policies, and contract clauses were verified against primary sources at the time of writing. Regulation moves. Articles carry a publication date and are not updated in place — where a development has since changed, a later piece says so rather than a silent edit to the original. Verify anything you intend to rely on against the current primary source, or ask us to.
No warranty
This site is provided as-is. We do not warrant that it is free of errors or omissions, or that it will be continuously available. To the fullest extent permitted by law, ArcPoint Consulting, LLC disclaims liability for loss arising from reliance on site content that has not been provided under a signed engagement.
Intellectual property
Site content, the Insights articles, the AI Control Layer descriptor as used here, and the Weftline Framework and its structure are the property of ArcPoint Consulting, LLC. You may quote briefly with attribution and a link. You may not reproduce substantial portions, or use this content to train a model or build a competing methodology, without written permission.
Names of statutes, agencies, standards bodies, and third-party organizations are used for identification and reference. Their use does not imply endorsement, affiliation, or approval by those parties in either direction.
Independence and conflicts
ArcPoint is vendor-neutral: no referral fees, no reseller relationships, no platform partnerships. ArcPoint does not represent a vendor bidding to an agency it advises, takes no role in source selection, and will not act on both sides of the same procurement. Nothing on this site should be read as an offer to do any of those things.
Do not send sensitive material
Do not transmit Controlled Unclassified Information, classified material, procurement-sensitive or pre-decisional documents, or third-party personal information through this site or by unsecured email. ArcPoint operates an unclassified-only scope posture. Unsolicited material sent contrary to this notice is not accepted in confidence.
Governing law
These terms are governed by the laws of the District of Columbia, without regard to conflict-of-law principles.
Contact
Questions about these terms: jleonard@arcpointconsulting.com.
Note: these terms have not been reviewed by counsel. They should be before the site goes live, particularly the limitation of liability and intellectual property sections.