The technical foundation under high-stakes AI decisions.
Some AI decisions carry legal, regulatory, or financial consequences that all turn on one thing: getting the technology right. Starrett Law and Advisory establishes — and defends — what an AI system actually is, where its value is created, and how it behaves. That technical foundation is what high-stakes governance, tax, and dispute matters rest on. We advise; and where a matter calls for it, we represent.
Three pillars, one discipline.
Governance, tax, and disputes each rest on the same thing: getting the engineering facts right, and building a record that survives scrutiny.
AI Governance & Risk
Building, deploying, and accounting for AI responsibly — governance frameworks, privacy program design, AI-risk and third-party/AI-vendor assessments, and regulatory defense — grounded in how the systems actually work, not in checklists.
Cybersecurity risk assessment · AI governance and compliance · Data privacy and protection · Third-party and AI-vendor risk
Tax Treatment of AI
The technical foundation under high-stakes AI tax positions: defining what the AI asset is, locating where its value is created, and building the record to defend it — for R&D tax credits, software and compute capitalization, transfer pricing, and M&A, down to the cloud and GPU compute, training pipelines, and model artifacts the numbers actually rest on.
Grounded in a Master of Laws in Taxation from a graduate tax program long ranked among the nation's best by the firms that recruit from it.
AI Disputes & Investigations
When AI systems, data, or outputs come under scrutiny — in litigation, regulatory inquiry, or internal investigation — we reconstruct what the technology did and produce a defensible technical record.
Decades of forensic-investigation experience, now applied to AI.
The unifying thread across all three: establish and defend what the technology actually is and does, under scrutiny.
Paul Starrett
Starrett Law and Advisory pairs deep legal and tax fluency with hands-on technical depth in AI and data systems — the rare pairing these matters require.
Why Advisory
The practice began in 2001 as a law firm and grew into a full-service advisory and consulting practice as technology risk moved to the center of our clients' hardest problems. The shift was deliberate: on AI questions, conventional legal work too often stops at citing frameworks, while the answers that hold up turn on getting the engineering facts right. We lead with that technical work — advisory by default — and provide legal representation where a matter calls for it.
Engineering Foundation
That fluency isn't secondhand — it starts with five years as a security software engineer at RSA Security, writing production encryption and authentication software before the forensic, governance, and tax work that followed. Reading the build is a habit that predates the law.
Experience
Founder Paul Starrett has served as General Counsel and Chief Risk Officer of a publicly held AI and data-management company, leading global legal, technology, and risk operations. He has led investigations and e-discovery on 45+ multimillion-dollar matters for AmLaw 50 firms and Fortune 100 clients.
Teaching
Teaches AI governance and cybersecurity law at Santa Clara University School of Law, and Law and Machine Learning in the M.S. in Data Science program at the University of the Pacific. A frequent subject-matter expert and CLE/CPE faculty instructor.
Leadership
Founding chair (2013–2020) of the ABA's Big Data Committee, and a contributor to the IAPP's AI Governance Certification as a practice-exam question writer and peer reviewer. Active in the IAPP, ACFE, and ISACA.
A rare stack of disciplines under one roof.
Most advisors bring either the law or the technology. Our advantage is the seam between them: we speak the engineering and the legal, regulatory, and tax rules with equal fluency — so the technical facts a high-stakes position depends on are established correctly and hold up under scrutiny.
Law
Attorney practice across AI governance, privacy, and regulatory matters — advisory by default, with representation where a matter calls for it.
Tax
The technical substantiation behind AI tax positions, especially R&D tax credits and software and compute capitalization; grounded in a Master of Laws in Taxation.
Artificial Intelligence
Working fluency in how models are built, trained, and deployed — the technical foundation under defensible AI positions of every kind.
Data Science
A Master of Science in Predictive Analytics: the ability to interrogate the data and the methodology, not just the summary.
Software Engineering
Five years as a security software engineer at RSA Security and Network Associates, building encryption, PKI, and authentication systems in Python, Java, and C. That hands-on foundation is what makes the AI work concrete — reading the actual model build, the training-versus-inference compute split, and the cloud and GPU infrastructure that R&D credits and compute capitalization turn on. Still hands-on today with generative-AI coding tools.
Forensic Investigation
Eight years in electronic discovery and information governance, with investigation and evidence experience that makes technical claims provable when challenged.
PrivacyLabs Compliance Technology Podcast
Conversations at the intersection of privacy, AI governance, tax, and compliance — for practitioners who have to make the technology and the law agree.
Listen on Buzzsprout →Let's discuss the matter.
Whether you need an advisory memo or representation through a regulatory inquiry or dispute, the first conversation is direct and confidential.