Senior Counsel, Digital Regulations

Box Box · Enterprise · US - Washington, DC · Remote · Legal

This role is for a Senior Counsel, Digital Regulations at Box, an AI-first company focused on Intelligent Content Management. The position requires navigating the global regulatory landscape for digital platform services and AI, translating complex legislation into actionable strategies and scalable guardrails. The counsel will drive regulatory leadership, architect compliance, perform horizon scanning for emerging regulations, orchestrate cross-functional delivery using DACI models, and transition projects to operational owners. The ideal candidate has 5+ years of experience in digital regulations, engaging with regulators, synthesizing enterprise-wide impacts of global rules like the EU AI Act and NIST AI Risk Management Framework, and a JD or equivalent. They should be adept at translating legal requirements into internal processes, leading cross-functional programs, and collaborating with stakeholders. While the company is AI-first and the role interacts with AI regulations, the core function is legal and regulatory strategy, not AI/ML development.

What you'd actually do

  1. Drive regulatory leadership: Draft internal and external policy positions and responses for comment periods. Translate shifting standards, rules, and frameworks into positions that can be defended as they become legally enforceable.
  2. Architect compliance: Convert high‑risk digital obligations into clear business impacts and partner with legal and other cross-functional stakeholders to implement controls that support compliance and operational teams, such as monitor new and evolving incident reporting and notification requirements like EU NIS2 and US state-level laws, assess their applicability, and work with teams to design and implement processes.
  3. Horizon scan: Identify emerging regulatory proposals such as, in the U.S., E.U., CN, JPN, and U.K. early, before they become law.
  4. Orchestrate delivery: Lead cross‑functional workstreams (Legal, Product, Engineering, Governance, Risk, Compliance) using DACI models to ensure smooth regulatory implementation.
  5. Hand off to operations: **Transition completed regulatory projects to steady‑state owners that are responsible for maintaining compliance and audit readiness.

Skills

Required

  • 5+ years of experience engaging with regulators and elected officials specifically in digital regulations
  • Skilled at presenting and negotiating proposed legislation, rules, and standards with regulators and policymakers
  • Master of horizon scanning and cutting through ambiguity
  • Capable of quickly synthesizing the enterprise-wide impact of global rules like the NIST AI Risk Management Framework, EU AI Act, Colorado AI Act, and the EU Digital Services Act
  • JD or equivalent with significant experience in digital regulation
  • Deep familiarity with translating digital regulatory legal requirements into internal processes
  • Proven track record of leading complex, cross-functional programs across Legal, Product, and Engineering
  • Executive presence to brief leadership
  • Build deep working relationships with domain-specific counsel
  • Maintaining deep trusted relationships with subject matter experts and technical stakeholders

Nice to have

  • AI-First Thinker: You see emerging tech as a strategic opportunity, not just a risk. You have a growth mindset and use AI to make smarter, faster decisions.

What the JD emphasized

  • digital regulations
  • AI Act
  • EU AI Act
  • NIST AI Risk Management Framework
  • Colorado AI Act
  • EU Digital Services Act
  • regulatory strategy
  • regulatory leadership
  • regulatory preparedness
  • digital regulatory legal requirements
  • cross-functional programs