GeoAI and the Law Newsletter
Tracking Developments in AI Laws and Regulations for Geospatial Professionals
GeoAI and the Law is not legal advice. The reader should consult with a trained lawyer on legal matters associated with GeoAI.
Editor’s Note
I published the first issue of this newsletter in March 2024. While the pace of change in artificial intelligence of both the technology and its adoption since then has been obvious to even the most casual of observers, developments in law and policy have been less obvious. But it would be a mistake to think that there has been none, or that AI is unregulated. After reviewing the past 49 issues of this newsletter, it is clear that while the legal landscape for AI is fragmented, it is becoming more concrete and is beginning to affect the geospatial sector.
This special edition does two things. First, it identifies five news items since March 2024 that I believe have, or will have, the most defined impact on geospatial AI from a legal standpoint. Second, it reviews the Deep Dive series and the arcs it traced.
Part 1: Top 5 Articles
1. EU Passes Comprehensive AI Rules (March 18, 2024) (European Parliament News)
In March 2024, the EU passed a comprehensive law regulating AI. The EU’s passing of the AI Act is certainly one the most significant legal and policy developments over the past two years. The AI Act is intended to balance innovation with perceived risk, but raises a number of questions. Companies that sell GeoAI products and services in Europe should determine whether they will be subject to the AI Act provisions that regulate 'high-risk AI systems', as these are the most onerous, and consequential.
2. DOJ’s Bulk Data Transfer Rule Applied to AI (September 4, 2025) (Federal Register)
The U.S. Department of Justice's Bulk Data Transfer Rule (the “Rule”) places unprecedented national-security controls on the collection, processing, storage, and disclosure of certain location-enabled data that is linked or linkable to a U.S. person. Companies that develop or deploy artificial-intelligence models trained on certain types of geospatial information capable of being linked to a person, should consider how the Rule applies to them. The Rule covers both certain types of demographic data (including addresses) and precise geolocation data, defined as any information (historical or real time) that identifies the position of an individual or device within 1,000 meters. Because only 1,000 U.S. devices' worth of precise geolocation data meets the 'bulk' threshold, even modest training and validation datasets can trigger the Rule. 'Transfer' is defined far beyond the traditional sale of data. For example, licensing an AI model (e.g., a chatbot) to third parties that can be used to access the training data, or hiring engineers who reside in a country of concern can each constitute a covered data transaction.
3. California AB-2013 — Generative AI Training Data Transparency Act (October 3, 2025) (California Legislative Information)
California's new AI Training Data Disclosure Law requires developers of generative AI systems to publish detailed information about the datasets used to train generative AI models. For GeoAI companies, this means they will need to reveal whether geospatial datasets include personal or proprietary information, raising compliance, intellectual property, and privacy considerations.
4. GSA's Proposed AI Contract Clause 552.239-7001 (March 24, 2026) (GSA.gov)
The U.S. General Services Administration (GSA) released a draft contract clause designated 552.239-7001, Basic Safeguarding of Artificial Intelligence Systems, that if finalized, will be inserted into every GSA solicitation and contract for AI capabilities. For geospatial companies selling AI-powered products and services to the federal government, this proposed clause represents a consequential shift in the procurement landscape. The clause touches upon many aspects of a geospatial AI vendor;s products and pipelines, including strict data ownership rules to an outright prohibition on foreign AI components.
5. European Commission Draft Guidelines on High-Risk AI Classification under Article 6 (June 4, 2026) (European Commission)
On June 4, 2026, the European Commission published draft guidelines for stakeholder consultation on the classification of high-risk AI systems under Article 6 of the EU AI Act (Regulation (EU) 2024/1689). Issued pursuant to Article 6(5) of the Act, the package consists of a general-principles document and two annex-specific chapters addressing the two routes by which an AI system becomes 'high-risk'. One such route is Article 6(1), covering AI that is itself a product, or a safety component of a product, regulated under the legislation listed in Annex I. The other route is Article 6(2), covering the eight use-case areas listed in Annex III (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border control, and the administration of justice).
For geospatial organizations, the draft offers something the Act itself did not: concrete examples, several of which specifically reference satellite imagery, drones, thermal sensors, and spatial-analytics platforms. The most important takeaway for geospatial professionals is that classification turns on the intended purpose a provider assigns to a system, not on the technology used or where it is deployed.
Part 2: Review of the Deep Dive Series
Most of the issues featured a Deep Dive on a specific legal topic. But two threads run longest and matter most for practitioners: how the EU AI Act's high-risk framework reaches geospatial systems, and how contracts are becoming the primary mechanism for allocating GeoAI risk. Part 2 traces those two arcs through the Deep Dives that built them.
Theme 1: High-Risk Systems Under the EU AI Act — What It Means for Geospatial
The high-risk thread opened in March 2024 with coverage of the AI Act’s passage and an early flag that “high-risk AI systems” would be the regulatory category most critical for geospatial vendors to track. A July 2024 Deep Dive then walked through what “high-risk” actually means under the Act, particularly the Annex III categories most likely to capture GeoAI applications: critical infrastructure, law enforcement, migration and border control, and essential public services.
By September 2024, the analysis became concrete: how does the Act apply when a geospatial business fine-tunes a foundation model such as NASA/IBM’s Prithvi? That fine-tuning question was revisited in November 2025 under Article 3(2), with attention to the compute thresholds that determine provider status, because who counts as the “provider” determines who bears the bulk of the compliance burden under the Act.
By March 2026, the focus shifted to operational compliance. A Deep Dive walked through what a high-risk geospatial AI vendor needs to have in place before the high-risk obligations begin (e.g., technical documentation under Annex IV, post-market monitoring, conformity assessment, quality management systems, and registration in the EU database). In May 2026, the EU Digital Omnibus reform pushed several of these deadlines back but did not change the substantive obligations.
And in June 2026, the Commission’s draft Article 6 guidance gave the clearest answer yet to the foundational question for any geospatial vendor: when is a system actually high-risk? The Commission’s illustrative examples (i.e., satellite imagery for search-and-rescue versus border-control surveillance; thermal sensors detecting human presence in uninhabited areas versus at frontiers) read like a glossary of geospatial practice.
The arc has a clear message: high-risk classification is not a single yes/no determination but a chain of judgments. Factors to consider include the system’s intended purpose, whether the vendor is acting as a provider or a downstream deployer, and which Annex III use case (if any) applies. Two years of Deep Dives have moved the field from “watch the EU AI Act” to “manage your high-risk classification as a live document, with the Commission’s guidance as your starting framework.”
Theme 2: Allocating GeoAI Risk Through Contracts
A separate but converging thread is the emergence of contract law as driving the most significant legal obligations associated with GeoAI. The first Deep Dive on this theme, in early 2025, made an argument that has continued to hold up. For most geospatial buyers and vendors, contract law would do more practical regulatory work than statutes. (Of note, this was often the case with privacy and cybersecurity - contractual requirements, particularly from large enterprises - predated comprehensive legal frameworks.) Limitation-of-liability clauses, liability caps, and accuracy disclaimers would be where GeoAI adoption was actually shaped or stalled. AI vendors were marketing performance parity claims while disclaiming any liability for failures in the systems. Even then, the gap between contractual risk allocation and marketing language was an issue.
By late 2025, the analysis became specific. A Deep Dive enumerated the AI-specific contract clauses geospatial counsel should consider drafting or negotiating. These included data rights (separating training-data inputs from derivative outputs), accuracy service-level commitments, bias-testing obligations, privacy and data-residency provisions, and national-security clauses (particularly where federal or defense contracts are in play). Each clause maps to a specific GeoAI risk, an imagery model that drifts, a routing model that misclassifies a sensitive site, a fine-tuned model whose outputs leak protected data.
Insurance entered the picture in early 2026, when carrier appetite for AI risk narrowed. A Deep Dive documented the new exclusions, sublimits, and deepfake-specific carve-outs that firms could expect to encounter on renewal. Contract counterparties cannot simply assume that residual risk allocated under indemnities or liability caps will actually be backed by an insurance recovery, if it materializes. The contract has to do more work because the insurance is doing less.
By March 2026, the contract story became a procurement story. A Deep Dive on GSA’s proposed clause 552.239-7001 showed how a single federal acquisition clause was poised to vest broad ownership of “Government Data” and any “Custom Development” in the United States, prohibit use of customer data to improve commercial models, and impose strict data-localization and segregation requirements. For many geospatial vendors, that one clause is more consequential than any U.S. AI statute. In April 2026, the California Executive Order N-5-26 Deep Dive showed the same pattern at the state level: procurement, not legislation, was leading the substantive governance work.
The arc’s message for geospatial professionals is that today’s operative legal framework for most GeoAI risk allocation is the contract, not the statute. The questions to consider in every deal include who owns the inputs and outputs, who is the “provider” for downstream regulatory purposes, what accuracy and bias guarantees are being made (and at what liability cap), and whether insurance will actually respond to the risks the contract assigns. And, for sales to government customers, what procurement clauses apply.
Closing
Fifty issues is a small number against the time horizon of the legal questions this newsletter tracks. The EU AI Act will be revised and reinterpreted for years. State patchworks will strengthen, conflict, and be litigated. Procurement clauses will be incorporated into laws. New foundation-model architectures (i.e., world models) will raise new issues.
But if you work in geospatial, my advice after fifty issues is the same as it was in Issue #1: the legal exposure from AI in your work is real, and the rules aren’t waiting for you to catch up. Read your contracts. Read the procurement clauses. Keep an eye on state bills and EU AI Act implementation. And where you can, get involved by contributing to the policies, standards bodies, and Bodies of Knowledge that are moving faster than legislators.
Edited by Kevin Pomfret
Partner at Pierson Ferdinand, Author of Geospatial Law, Policy and Ethics: Where Geospatial Technology is Taking the Law | LinkedIn



