1. Map the Risk Landscape
Effective AI governance begins with a comprehensive, clear-eyed assessment of where and how the company is using AI. Companies should inventory all of their AI systems, including both internally developed models and third-party tools embedded in vendor software, and classify each by its level and area of risk and, as applicable, opportunity. With a rigorous risk-scoring methodology, companies can produce a detailed, regularly updated profile for each AI deployment and use case, enabling the board and management to allocate risk-mitigation resources efficiently and weigh the risks against potential areas of strategic opportunity.
2. Designate Clear Accountability
Clear accountability is a cornerstone of credible AI governance. Companies should consider assigning ownership of critical AI-related areas to trusted, experienced executives — for example, a Chief AI Officer or a cross-functional management committee — and define rules and responsibilities for the business units deploying and using AI day to day. Embedding accountability at various levels positions the right people and teams to anticipate and resolve issues before they become problems, protecting the company and strengthening its ability to capture AI-generated efficiencies.
3. Elevate Board Engagement
AI’s capabilities have sparked a race among companies to integrate it into their operations. But directors should resist pressure to deliver perfunctory approvals of AI initiatives — and instead engage in substantive discussions about each particular initiative and its strategic implications, after becoming fully informed. This means insisting on regular, meaningful reporting from management on material AI deployments — not just one-time briefings or project updates — and applying thorough scrutiny to questions around use cases, data security, risk monitoring, compliance, opportunity maximization, and more. Engaged directors send an important signal to the organization and its employees about the company’s commitment to effective AI governance.
4. Establish Escalation Protocols
AI systems are not perfect. Material AI incidents — like discriminatory outputs, data breaches, or customer-facing system failures — can lead to financial loss, reputational harm, regulatory inquires, or legal liability. So, companies would be wise to develop escalation protocols that define how and to whom employees must report these incidents, specifying timeframes for escalation and requiring contemporaneous documentation of both the incident and the company’s response. A company’s ability to respond quickly to a challenge — and to do so in an organized, defensible manner — can mitigate harm and avoid a major crisis.
5. Invest in Continuing Education
Continuing education has long been important for overseeing a company’s integration of new technologies, but AI’s relentless evolution has made it particularly challenging. Keeping pace entails investing in robust and frequent AI training for directors, senior managers, and key personnel in legal, compliance, and risk functions, focused on AI’s capabilities and limitations, ethical considerations, legal and regulatory developments, and industry-specific issues. Periodic deep dives into the company’s own AI systems, led by internal subject-matter experts, are similarly essential. The board and management need not become technologists, but they must be fluent enough in both the company’s AI use and the broader AI landscape to provide effective oversight and guide responsible, value-creating use of the technology.
This information is provided by Vinson & Elkins LLP for educational and informational purposes only and is not intended, nor should it be construed, as legal advice.