No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Featured

Not Every Use of AI Needs a Governance Policy; How Can You Tell the Difference?

Ethics, data privacy & legal compliance all argue in favor of strong AI policies

by Sarah F. Hutchins and Robert M. Botkin
May 22, 2024
in Featured, Governance, Opinion
robot hand with gavel

The decision of whether to implement an AI governance policy depends on a range of factors, including how the company uses AI, how much risk is involved and how use will affect stakeholders. Sarah Hutchins and Robert Botkin of Parker Poe explore how to know when to establish an AI governance policy — and when companies might not need them.

In the complex landscape of technological advancements, the implementation of artificial intelligence (AI) is becoming commonplace across various industries.

As businesses integrate AI into their operations, they might ask themselves: Do I need a policy governing how I use and deploy this technology? The answer is not always a clear yes, as some industry experts might lead you to believe. Understanding when an AI governance policy is necessary is crucial for companies navigating this evolving terrain.

Generally, we can categorize businesses into three buckets: Creators, open-ended users and closed-end users. The AI policy for these three types of businesses will vary considerably.

Creators are businesses that either directly develop AI tools or are integrating an AI tool into an existing product to enhance functionality. A retail brand, for example, that integrates a generative AI chatbot into its mobile app to help consumers find the product they are looking for would fall into the creator bucket. 

Open-end users are those businesses that allow employees to use AI tools but do not necessarily configure the large language model (LLM) or have any control with what goes into the model.

Last, closed-end users are businesses without consumer-facing AI tools but that may still implement autonomous systems that aid in the productivity of the business. Clients of a warehouse robotics company that use robots in their warehouses would be closed-end users, as the AI systems have a different set of risks than those AI tools developed by creators and utilized by open-end users.

These three types of businesses will need drastically different AI governance policies. Here is how to help fit the policy to your business’ needs and when it makes sense to implement one.

two robots having a showdown in the wild west
Featured

AI Is the Wild West, but Not for the Reasons You Think

by Jennifer L. Gaskin
March 20, 2024

As Europe moves closer to blanket rules regarding its use, CCI’s Jennifer L. Gaskin explores the evolving compliance and regulatory picture around artificial intelligence, the technology everyone seems to be using (but that we’re also all afraid of?).

Read moreDetails

When your company will likely need an AI governance policy

Data privacy and security concerns

In instances where AI systems handle sensitive user data, the implementation of a robust governance policy becomes imperative. This ensures compliance with data protection regulations and establishes guidelines for secure data handling.

Ethical considerations

AI systems often make decisions that impact individuals and society at large. An AI governance policy can help identify and mitigate ethical concerns by setting standards for responsible AI use, preventing biases and ensuring transparency in decision-making processes. For example, using AI software to evaluate candidates during the interview process could have a negative bias against minorities due to the underlying model’s training data.

Legal compliance

As AI technologies evolve, so do the legal frameworks surrounding them. Implementing an AI governance policy helps companies stay compliant with existing and emerging regulations, helping to reduce the risk of legal repercussions.

State lawmakers and federal regulators have started keeping a close eye on companies’ use of AI as the technology has made certain processes more efficient. States have moved forward on their own governance of data privacy and AI, both in the financial industry and beyond. California, Oregon, Florida, and New York are a few examples of states that have passed or are considering comprehensive data privacy laws or regulations focused on AI. 

Risk mitigation

Businesses operating in industries with high-risk consequences, such as health care or finance, should adopt AI governance policies to mitigate potential risks. These policies can outline risk management strategies and establish accountability measures.

Stakeholder trust

Demonstrating a commitment to responsible AI through governance policies builds trust among stakeholders. This includes customers, partners, and regulatory bodies who seek assurance that AI systems are used ethically and responsibly.

Customization of AI systems

Companies heavily reliant on AI may need governance policies to guide the customization and adaptation of AI models. Clear guidelines ensure that modifications align with the company’s values and objectives.

When you might not need an AI governance policy

Minimal AI integration

If a company’s use of AI is minimal and doesn’t involve substantial data processing or decision-making, a detailed governance policy may be unnecessary. In such cases, adherence to existing data protection and ethical guidelines may suffice.

Low-risk environments

Businesses operating in low-risk environments where AI applications have minimal impact on individuals or society may find that an extensive governance policy is not immediately required. However, periodic assessments are advisable to adapt to changing circumstances.

Temporary or experimental AI projects

Companies engaging in short-term or experimental AI projects with minimal long-term implications may opt for a more flexible approach. A concise set of guidelines during the project’s duration can be preferable to an exhaustive governance policy. This decision should be revisited at regular intervals depending on the project’s scope and implementation.

Outsourced AI services

If a company relies on third-party AI services with well-established governance policies, it may not need an additional policy. However, due diligence is essential to ensure alignment between the third-party policy and the company’s values. Furthermore, the agreement with the vendor should carefully address terms related to risk to the company. Read our article about the importance of businesses seeking assurances from their AI vendors on collecting, using, and disclosing data used to train the model.

Small-business operations

Smaller businesses with limited resources and AI integration may not immediately require an elaborate governance policy. However, as the business expands its AI usage, returning to evaluate the need for a comprehensive policy is advisable.


Tags: Artificial Intelligence (AI)
Previous Post

10 Questions to Ask About Generative AI

Next Post

LRN Benchmark of Ethical Culture 2024

Sarah F. Hutchins and Robert M. Botkin

Sarah F. Hutchins and Robert M. Botkin

Sarah Hutchins is a partner in Parker Poe's Charlotte office. Certified as a legal specialist in privacy and information security law by the North Carolina State Bar, she leads the firm's cybersecurity and data privacy team and helps clients navigate business litigation, government investigations and data privacy and cybersecurity.
Robert Botkin, an associate in Parker Poe's Raleigh, N.C. office, helps clients of all sizes — from Fortune 50 companies to startups — in a variety of industries navigate privacy and cybersecurity issues.

Related Posts

big data filtering concept

The $2 Billion ‘Free-Rider’ Problem: Why AI Scraping is Now a Boardroom Crisis

by Areejit Banerjee
January 6, 2026

If you're building data products today, you may subsidizing your competitor's offerings

cross functional team concept bridge between departments

Why Customer Experience Optimization Requires Cross-Functional Accountability

by Jim DeLoach
December 19, 2025

CX governance demands transparency in data collection, AI reliability in customer-facing applications and reputation risk management

ask an ethicist year in review_graphic

2025’s Unscientific Barometer: What Your Questions Revealed About Ethics & Compliance

by Vera Cherepanova
December 17, 2025

The collision of free speech, company reputation and political pressure was one of the hardest leadership tests of the year

roadblocks

Navigating APAC’s Mixed Approach to AI Regulation — Without Hitting Road Blocks

by Trevor Treharne
December 17, 2025

The average firm operating in Asia-Pacific faces two unworkable options in responsible deployment of AI: rebuilding governance for every jurisdiction...

Next Post
LRN Benchmark of Ethical Culture

LRN Benchmark of Ethical Culture 2024

reminder to speak up
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights