top of page

The Board's New Responsibility: Managing AI Governance and Ethical Risk

Writer: Support Legal
Support Legal
12 minutes ago
8 min read

Artificial intelligence is becoming part of everyday business. From customer service and recruitment to financial analysis, decision-making and document automation, businesses are finding new ways to use AI to improve efficiency and reduce costs.

 

But as AI becomes more deeply integrated into business operations, the conversation is moving beyond what the technology can do. It is becoming a question of governance.

 

For boards and senior management, AI can no longer be viewed solely as a technology issue for the IT department. The use of AI can create legal, ethical, operational and reputational risks that may affect the business.

 

This is creating a new responsibility for boards. The question is no longer simply whether a business should use AI. It is whether the business has the right governance in place to use it responsibly.

 

AI Governance Is Becoming a Board-Level Issue

AI systems can influence important business decisions. They may help identify suitable job candidates, assess customer behaviour, detect fraud, generate reports or make recommendations that affect individuals and organisations.

 

As the role of AI expands, so does the potential impact of its failures. An AI system may produce inaccurate information, reflect bias in its underlying data, generate misleading content or expose confidential information. It may also operate in ways that are difficult for users or decision-makers to understand. These risks can affect the business in several ways.

 

There may be legal consequences where AI use results in discrimination, privacy issues or intellectual property disputes. There may be regulatory concerns where AI is used in regulated activities. There may also be significant reputational consequences where a business is unable to explain how an important decision was made.

 

For these reasons, AI governance is increasingly becoming part of wider corporate governance and risk management.

 

The board does not need to understand every technical aspect of artificial intelligence.

But it should understand how AI is being used within the business, the risks it creates and whether appropriate controls are in place.

 

The Risk Is Not Always in the Technology Itself

AI is often discussed as though the technology itself is either good or bad. In practice, the risk will usually depend on how it is being used.

 

A generative AI tool used to assist with basic administrative tasks may create a different level of risk from an AI system used to support recruitment, credit decisions or customer profiling.

 

The same technology can therefore create very different legal and ethical concerns depending on the context.

 

This is why an effective governance approach should focus on the use case rather than treating every AI system in the same way.

 

Businesses need to understand what the AI system is doing, what data it is using and how much influence it has over the final decision.

 

An important distinction may be whether the AI system is simply assisting a human decision-maker or whether its output is effectively determining the outcome. The greater the potential impact of the AI system, the greater the need for oversight.

 

Accountability Cannot Be Outsourced

Many businesses use AI systems developed by third parties. A business may subscribe to a generative AI platform, use an AI-enabled software product or integrate an external AI model into its own systems.

 

This can create the impression that responsibility rests with the technology provider.

That is not always the case. The business remains responsible for how it chooses to use the technology within its own operations. It may also remain responsible for decisions made based on AI-generated outputs.

 

This means businesses need to consider more than whether the provider is reputable. They should also understand how the technology works in practice, what limitations it has and what contractual protections are available.

 

The use of a third-party AI provider should therefore form part of the business's broader governance and risk management process. Contracts should be reviewed carefully, particularly where AI systems process confidential or personal information or play a significant role in business decision-making.

 

The key question is not simply:

 

Who developed the AI?

 

It is also:

 

Who is responsible for the decision to use it?

 

Managing the Ethical Risks of AI

 

Legal compliance is essential, but it is not the only issue. Some of the most significant AI risks may arise before there is a clear legal rule that addresses them.

This is where ethical governance becomes important.

 

AI systems may create concerns relating to fairness, transparency, privacy and accountability. A system may produce an outcome that is technically lawful but difficult to justify from an ethical or commercial perspective.

 

For example, an AI tool may reflect bias in historical data. A generative AI system may produce inaccurate information with a high degree of confidence. An automated system may make recommendations that are difficult for users to challenge or understand.

 

The Organisation for Economic Co-operation and Development's AI Principles reflect these wider concerns by emphasising fairness, privacy, transparency, security and accountability. They also recognise the importance of ongoing risk management throughout the AI lifecycle.

 

For businesses, this means that responsible AI governance should involve more than asking whether the business is technically complying with a particular rule.

 

It should also consider whether the use of AI is consistent with the organisation's values, commercial objectives and responsibilities to customers, employees and other stakeholders.

 

The Importance of Clear Responsibility

One of the greatest challenges in AI governance is determining who is responsible. AI may involve multiple teams across the organisation.

 

The technology team may select the system. A business department may use it. Legal and compliance teams may assess the risks. Data protection teams may review the use of personal information.

 

Without a clear governance structure, responsibility can become fragmented. This can create a situation where everyone is involved, but no one is clearly accountable. A business should therefore establish clear ownership of its AI governance framework.

 

The board and senior management should understand who is responsible for approving significant AI use cases, monitoring compliance and responding when an AI system creates an unexpected outcome. Clear responsibility does not mean that the board needs to approve every use of AI.

 

It means that there should be an appropriate structure for oversight, particularly where the technology creates significant legal, ethical or commercial risk.

 

The Dubai Government's Department of Finance provides a recent example of this approach, with its AI policy addressing legal compliance, ethical use, risk assessment, human and technical resources, lifecycle governance, transparency, accountability and regular review.

 

AI Risk Should Be Managed Throughout Its Lifecycle

One of the challenges of AI is that the risks can change over time. An AI system that performs effectively during initial testing may produce different results when used at scale. Changes to data, user behaviour or the wider business environment may also affect its performance.

 

AI governance should therefore not end once the system has been approved. The NIST AI Risk Management Framework takes a lifecycle approach to AI risk, with the aim of helping organisations consider trustworthiness during the design, development, deployment, use and evaluation of AI systems. Its framework identifies characteristics including validity, reliability, safety, security, accountability, transparency, privacy and the management of harmful bias.

 

For businesses, the practical lesson is straightforward. AI systems need ongoing oversight.

 

This may involve monitoring how the system is being used, reviewing its outputs, assessing changes to the underlying technology and responding to new risks as they emerge.

 

The board's role is not to monitor individual AI outputs. It is to ensure that the organisation has an effective process for doing so.

 

Human Oversight Still Matters

As businesses automate more processes, it can be tempting to assume that the technology will produce better decisions simply because it can process large amounts of information quickly. But automation does not remove the need for human judgment.

 

In some situations, human oversight can provide an important safeguard. This may involve reviewing an AI-generated recommendation, allowing a decision to be challenged or ensuring that a person has the authority to intervene where an AI system produces an unexpected or harmful outcome.

 

The appropriate level of human oversight will depend on the use of the system. A low-risk AI tool used to help draft internal documents may require a different level of oversight from a system that influences employment, financial or customer decisions.

 

The key is to avoid creating a system where the human role exists only on paper.

 

If an employee is expected to review an AI-generated decision, the organisation should ensure that the review is meaningful and that the employee has sufficient information and authority to challenge the output.


Data Is Central to AI Governance

AI governance is closely connected to data governance. AI systems depend on data to operate, whether that data is used for training, testing or generating outputs.

 

This creates important questions about where the data comes from, whether the organisation has the right to use it and how it is being protected. Businesses should also consider whether personal data is being processed and whether the proposed use of that data is consistent with applicable data protection requirements.

 

Confidential business information presents a separate concern. Employees may use publicly available generative AI tools to draft documents, analyse information or summarise materials without fully considering where that information is being processed.

 

A clear AI governance framework should therefore establish how employees can use AI and what information they are permitted to provide to AI systems.

 

The Board's Role in Setting the Framework

The board's responsibility is not to manage the technical development of an AI system.

Its role is to ensure that the organisation has an appropriate framework for managing the risks. This begins with understanding where AI is being used.

 

Many businesses may have formal AI projects, but employees may also be using AI tools independently as part of their everyday work. Without visibility, the business cannot properly assess its risks.

 

The next step is to establish a clear approach to AI use. This may involve determining which use cases require additional approval, what types of data can be used, when human oversight is required and how third-party providers are assessed.

 

The framework should also be reviewed regularly. AI technology is changing quickly, and a governance framework that is appropriate today may need to change as the technology, regulatory environment and business use cases evolve.

 

The objective should not be to slow down innovation. It should be to ensure that innovation takes place within an appropriate framework of responsibility and risk management.

 

AI Incidents Need a Response Plan

Businesses should also consider what happens when AI goes wrong. An AI system may generate false information, produce a biased outcome, disclose confidential information or be manipulated by a third party.

 

The business should know how to respond. Who should investigate the issue? Should the system be suspended? Does the incident need to be reported internally or externally? Are customers or other affected parties impacted?

 

An effective response process can help the business contain the problem and understand whether the incident reveals a wider weakness in its governance.

 

The same principle applies to serious cybersecurity or data incidents. Preparation can make a significant difference when decisions need to be made quickly.

 

The Future of Corporate Governance Will Include AI

The role of the board is continuing to evolve. Cybersecurity has moved from being a technical issue to a board-level concern. Data protection has followed a similar path.

 

AI is likely to do the same. As AI becomes more capable and more integrated into business operations, boards will need to consider how it affects risk, strategy, decision-making and accountability.

 

This does not mean that every board needs an AI expert. It means that boards need access to the right expertise and information to ask the right questions.

 

How is AI being used across the organisation?

 

What are the most significant risks?

 

Who is accountable for managing them?

 

How are AI systems monitored?

 

What happens when the technology produces an outcome that the business cannot accept?

 

The businesses that answer these questions early will be better positioned to benefit from AI while managing its potential risks.

 

Managing Innovation Responsibly

AI offers significant opportunities for UAE businesses. It can improve efficiency, support better decision-making and create new commercial possibilities.

 

But the benefits of AI will depend partly on the trust that businesses build around its use. Effective AI governance is not about preventing organisations from using new technology.

 

It is about ensuring that the technology is used responsibly. For boards, this is the new responsibility.

 

The question is no longer simply whether AI can be used. It is whether the business has established the governance, accountability and ethical safeguards needed to use it well.

 

As AI becomes a more important part of business strategy, managing these issues will become an equally important part of corporate governance.

 

The businesses that approach AI with the right balance of innovation and responsibility will be better positioned to manage both the opportunities and the risks that the technology creates.

 

Comments


bottom of page