Assistant General Counsel - Ai, Privacy & Governance

Baseten Baseten · Data AI · San Francisco, CA · G&A

This role is for an Assistant General Counsel focused on AI, Privacy, and Governance. The primary responsibilities include owning the company's legal and regulatory positioning under AI regulation, leading export and trade compliance, building and running the privacy program, and managing the governance and controls layer for certifications. The role requires a JD, active bar membership, and 8+ years of experience in AI/tech regulatory, privacy, export/trade controls, and compliance/governance work, with in-house experience at a technology, cloud, or infrastructure company. Experience with data protection frameworks, AI governance frameworks, and security/assurance regimes is necessary. The role also involves translating regulatory obligations into operational controls and partnering with cross-functional teams.

What you'd actually do

  1. Own Baseten's legal and regulatory positioning under AI regulation — the EU AI Act, U.S. state AI laws, NIST AI RMF, and emerging frameworks
  2. Lead export and trade compliance, including BIS / EAR advanced-computing and semiconductor controls, end-use / end-user diligence, and sanctions screening as they apply to compute access and model distribution — owning the policy and screening framework that Commercial and Infra & Compute apply in their deals
  3. Build and run the privacy program: GDPR / CCPA compliance, the DPA and sub-processor framework, data-subject requests, cross-border transfer mechanics, and Baseten's posture as a processor
  4. Own the governance and controls layer for certifications — SOC 2, ISO/IEC 42001, HIPAA-eligible configurations — partnering with Security and Compliance on policy lifecycle, controls testing, evidence, and audit / regulator readiness
  5. Translate regulatory obligations into operational controls, documentation, and training that engineering, product, and GTM teams will actually adopt

Skills

Required

  • JD and active bar membership in good standing
  • 8+ years across some combination of AI / tech regulatory, privacy, export / trade controls, and compliance / governance work, with in-house time at a technology, cloud, or infrastructure company
  • Working command of data-protection frameworks (GDPR, CCPA) and the operational mechanics of a privacy program — not just the doctrine
  • Familiarity with AI governance frameworks (EU AI Act, NIST AI RMF, ISO/IEC 42001) and security / assurance regimes (SOC 2, ISO 27001)
  • Demonstrated ability to operationalize a regulatory regime end to end — controls, documentation, testing, reporting — in genuine ambiguity
  • Strong cross-functional skills: you can partner credibly with Security, Engineering, and Compliance and turn obligations into controls
  • Commercially grounded; comfortable supporting live deals and making measured, informed risk calls
  • The ability to learn, build, and master AI tooling and systems to self-serve and operate at breakneck speed

Nice to have

  • Direct experience with BIS / EAR export controls, CFIUS, or trusted-supplier / country-of-origin programs
  • Experience standing up or scaling a privacy or compliance program from an early stage
  • Relevant certifications (CIPP/E, CIPM, IAPP AIGP, or comparable)
  • Exposure to AI-specific contracting — model licensing, data provenance, training-data representations
  • Experience at an AI, ML, or developer-infrastructure company

What the JD emphasized

  • AI regulation
  • privacy program
  • export and trade compliance
  • governance and controls layer
  • operationalize a regulatory regime end to end