top of page
Search

Why Responsible AI is the Corporate Governance you Already Trust, Just Extended.

  • 2 days ago
  • 4 min read

By Steven Hill, Managing Partner, OakTruss Group LLC




Boards and c-suites have been governing judgment since anyone reading this has been alive. They just haven’t been calling it that. Every officer who signs a contract, every manager who approves a budget, every clinician who authorizes a treatment, and every banker who approves a loan is exercising judgment on the company’s behalf. Every professionally managed organization built a complete apparatus to oversee judgment long ago: ledgers that record what happened, budgets that bound what may happen, approval matrices that say who can decide what, and auditors who verify all of it. That apparatus was built around capital allocation because capital was where consequential judgment left a trail. The age of AI changes exactly one thing, and it’s a big one. For the first time, consequential judgment has moved into software.


A new kind of employee.


An AI system that approves loan applications, flags transactions, screens candidates, or drafts client communications is not a tool in the sense a spreadsheet is a tool. It exercises discretion. It makes decisions. It is, functionally, a new kind of employee. But unlike humans, AI works at machine speed, around the clock, at whatever scale you deploy it, or it deploys itself.

And it is an employee unlike any other. It cannot be deposed. It doesn’t attend the ethics training like other employees (not yet). It can be replicated ten thousand times overnight. When it errs, it errs consistently and at volume. This is why AI has compelled the evolution of corporate governance. A governance model designed for human decision-makers (hired one at a time, reviewed quarterly, promoted on track records) cannot simply be pointed at software and expected to hold.


The values carry over. The enforcement cannot.


Here is the part most “AI governance” conversations get wrong: nothing about the values is new. Fairness, accuracy, transparency, accountability: these are the same principles boards and c-suites already apply to human conduct. No director needs a philosophy seminar to know that decisions should be explainable, and someone should own the consequences.


What must change is enforcement. A person making decisions is reviewed periodically with quarterly check-ins, annual audits, occasional escalations. A machine making ten thousand decisions an hour has produced a quarter’s worth of activity before lunch. Periodic attestation must become continuous oversight because the actor being governed now operates in milliseconds.


That yields a working definition of responsible AI that fits on an index card: the discipline of making AI’s behavior observable, its risks proportionately controlled, and its humans accountable.


You have built this before.


The reassuring news is that the machinery required to govern AI is not exotic. Every artifact of AI governance is an existing corporate governance structure, re-instantiated for a new kind of decision-maker: software that decides. By artifact, we mean something concrete and durable that you can point to and hand to an auditor: a register, a log, a report, a signed approval. At a summary level, there are nine such artifacts, in three familiar categories:


·         Making behavior observable. You cannot govern what you cannot see. Start with a list of every AI system that exercises judgment, the way you already keep a register of your assets. Add a running record of what each system decided and why, a general ledger for decisions instead of dollars. Then report on it to the board on a set schedule, likely a faster one than your financials.


·         Controlling risk proportionately. A chatbot that schedules meetings does not need the scrutiny of a system that denies credit. So you sort your AI systems by how much damage they could cause and how freely they act, the same move enterprise risk management already makes when it rates a risk. That sorting is what a tool like the OakTruss Group AI Cube™ is built to do. Each tier then carries a matching set of controls, and no system gets built, deployed, changed, scaled, or shut down without clearing an approval gate, exactly the way a capital request has to clear one.


·         Keeping humans accountable. No consequence should ever trace back to “the algorithm.” Write down who is allowed to put AI to work on what, the way a delegation of authority does for people. Give every system one named owner who answers for it. Then have someone outside the team that runs it verify the work, which is what internal and external audit already do.


Capital allocation has a ledger, a budget, an approval matrix, and an auditor. Judgment now needs the same, at machine speed.


The question for your next board or leadership meeting


Regulators are converging on the same logic. The NIST AI Risk Management Framework organizes itself around governing, mapping, measuring, and managing AI risk. The EU AI Act scales what it requires of a system to how much harm that system could cause, which is exactly what boards already do when they rank enterprise risks by consequence. Bank regulators anticipated all of this fifteen years ago when model risk guidance (SR 11-7) required inventories, validation, and independent review of decision-making models.


But you don’t need a regulation to act. You need one discussion prompt: of the nine artifacts, which do we already have for AI today and which of the three categories is weakest?


AI didn’t ask corporate governance to invent something new. It asked governance to do what it has always done: follow consequential judgment wherever it moves. For a century, judgment lived in people, and we governed it through capital allocation. Now it also lives in software. The evolution isn’t optional. But it also isn’t unfamiliar. You have built all nine of these before, for capital allocation. Building them for judgment will take new tools and far closer collaboration across risk, IT, and the business, but not a new theory of governance.


 
 
bottom of page