Squire Patton Boggs is telling compliance professionals and general counsels that the AI policies most companies wrote two years ago are already outdated, and the gap matters for any business that uses automation to touch consumers or their data. In a new advisory on AI deployment, the firm argues that governance has shifted from policing how employees prompt public chatbots to managing AI that is now embedded across SaaS platforms, customer-facing products, HR systems and vendor tools.
For the credit and collection industry, several of the firm’s warnings land close to home.
The first is the rise of agentic AI, systems that execute multistep tasks with little human oversight. These agents can triage customer requests, update records, draft communications and trigger transactions, which the firm says raises new questions about authority, supervision and accountability. Collection operations weighing AI voice bots or autonomous workflow tools face exactly this problem: delegation without a clear owner when something goes wrong. The advisory also flags that major insurers are moving to exclude losses caused by AI agents from coverage, prompting a recommendation that companies confirm where their policies stand.
Vendor risk is the second pressure point. The firm urges legal teams to assume AI is present in any SaaS product unless a vendor affirmatively rules it out, and to rewrite intake questionnaires and contract templates to address training use, output ownership, data retention and liability for AI-driven errors. It suggests negotiating an “AI circuit breaker” that pauses a system when it behaves unpredictably. Pricing is shifting too, away from per-seat licensing toward usage and outcome-based models that can change quietly in online terms long after a contract is signed.
The consumer protection section will resonate most with collectors. The advisory notes that the plaintiffs’ bar is already pursuing AI cases under communications-privacy statutes like the California Invasion of Privacy Act, alongside consumer protection and product liability theories. Attorneys general in California, Massachusetts, New Jersey, Oregon and Texas have issued guidance applying existing consumer protection and civil rights laws to AI, and state laws increasingly regulate automated systems that make “significant decisions” about individuals. The firm advises routing all consumer-facing AI through product counseling review.
On the regulatory horizon, the advisory describes a tug of war between a deregulation-minded federal government and states passing a growing patchwork of AI laws, with comprehensive federal preemption still uncertain.
The core message is that AI governance is not a one-time project but a living framework that must keep pace with how the technology is actually procured and deployed.
.




