AI Governance Lawyer for Boards and Deployers
Astraea Counsel builds AI governance that survives scrutiny — board oversight structures, deployment policies, vendor diligence, and the audit trail that shows who authorized an agent to act.
Lead attorney: Chanté Eliaszadeh, Founder & Principal
- Licensed in California · State Bar No. 335803 — verify
- Consultations scheduled directly with the attorney, not an intake desk
When boards and general counsel call us
- Your board wants an AI oversight structure that would hold up against a Caremark-style challenge, and nobody can say today what the agents in production are authorized to do
- You are adopting the NIST AI Risk Management Framework and need it mapped to obligations that actually bind you rather than adopted as a document
- An agent takes action on the company’s behalf and no named human principal, defined scope of authority, or audit trail sits behind it
- You are buying an AI product and the vendor diligence has to reach the model and the training data, not just the software
- Your D&O carrier is asking what AI oversight the board exercises, and the honest answer is not yet written down
- An internal AI use policy exists, but no one has tested it against what employees are actually running
What engagement gets you
- A board-level oversight structure analyzed under Delaware Caremark doctrine — the reporting lines, escalation triggers, and minutes that evidence informed oversight rather than an after-the-fact policy
- Agent authorization architecture built on the firm’s Know Your Agent (KYA) framework: a named legal person who answers for the transaction, a defined scope of authority, disclosure to counterparties, and a durable audit trail
- AI vendor diligence and procurement terms drafted around what an assignment can actually reach, since a third-party foundation model and open-source components need carve-outs and licenses rather than a blanket assignment
- Internal AI use policies written against what your teams are deploying, with the acceptable-use boundaries tied to the regimes that bind the company
- A NIST AI RMF implementation mapped onto your actual obligations, so the framework produces evidence of governance rather than a shelf document
Recognition
- Quoted throughout "AI Agents Can Move Money – Lawyers Say Nobody Knows Who's Liable," part four of Sandmark's seven-part Agentic AI series (August 6, 2026), Chanté Eliaszadeh
- Author, "Complying With Calif. Crypto License Law's 11th-Hour Rewrite," Law360 Expert Analysis (August 13, 2026) — Chanté Eliaszadeh and Brandon Orewyler
- Astraea Counsel ranked in Chambers USA: Spotlight 2026 — Fintech (Los Angeles)
- Lawdragon 500 X — The Next Generation: Crypto Regulation, Disputes, Blockchain (2026), Chanté Eliaszadeh
- 2024 Law360 Distinguished Legal Writing Award, The Burton Awards — Chanté Eliaszadeh, co-author (White & Case)
- Panelist, American Bar Association Business Law Section 2026 Spring Meeting — Financial Services Technology Joint Subcommittee, on use cases tied to agentic-AI payment flows
Common Questions
What does board-level AI governance actually require?
Delaware’s Caremark line asks whether the board made a good-faith effort to implement an oversight system and then monitored it. Applied to AI deployment, that turns on unglamorous evidence: whether the board knows which agents are in production, what those agents are authorized to do, who receives exception reports, and what escalation looks like when an agent acts outside its scope. A policy adopted after an incident is not an oversight system. The defensible posture is a reporting structure that existed before it was needed and minutes that show the board used it.
What is Know Your Agent (KYA)?
AI agents can now initiate real payments, and the technical identity standards — Visa, Mastercard, Google, NIST — build cryptographic identity for agents without answering the question the law actually asks: which legal person answers for the transaction. Know Your Agent is the compliance standard Astraea Counsel publishes to answer it. In practice it means a named human or entity principal behind every agent, a defined and documented scope of authority, disclosure to counterparties that they are dealing with an agent, and an audit trail good enough to litigate from.
Do we need AI governance if we only buy AI, not build it?
Deploying is where most liability lands. Existing doctrines — agency, negligence, product liability, unfair practices — already reach companies that put an AI system into service, and they do not wait for AI-specific legislation. A deployer also cannot inherit a vendor’s compliance posture by contract alone: if the agent acts on your behalf, the authorization question is yours to answer. Buying rather than building changes the diligence, not the exposure.
Book a Call With Chante Eliaszadeh
Pick a time that works for you — a 15-minute introductory call, no forms, no waiting.
Pick a date and time
Prefer to send a message instead?
Get your AI governance structure reviewed
Schedule a consultation on board oversight, agent authorization, or AI vendor terms.
Talk to an AttorneyAttorney advertising. Each case result described on this page was dependent on the facts of that case, and the results will differ if based on different facts. No attorney-client relationship is formed by visiting this page or submitting the contact form.