Logo
FrontierNews.ai

How Companies Should Actually Build AI Governance Before Regulators Come Knocking

AI governance isn't about having the right policy document; it's about demonstrating you made thoughtful decisions before problems happened. That's the critical distinction emerging from updated federal guidance that's reshaping how organizations should approach artificial intelligence oversight. Rather than treating AI as a novel legal frontier, regulators and compliance experts now view it as a new factual context where longstanding legal principles like fiduciary duty, privacy protection, and corporate accountability apply.

Why Regulators Are Scrutinizing AI Governance Now

The Department of Justice's September 2024 revisions to its Evaluation of Corporate Compliance Programs (ECCP) signal a significant shift in how federal prosecutors will assess corporate conduct. Prosecutors are now instructed to examine whether companies have assessed how artificial intelligence impacts their ability to comply with criminal laws, whether AI-related risks are integrated into enterprise risk management, what governance structures exist around AI use, and how organizations mitigate both deliberate and unintended misuse of these technologies.

This matters because governance is almost always evaluated retrospectively. When regulators investigate corporate misconduct, they examine the compliance program that existed before the alleged violation occurred. When shareholders challenge board oversight, they look at what information directors received before a crisis. When juries evaluate corporate conduct, they ask what management knew and what management did before harm occurred. The same pattern will apply to AI.

What Does Effective AI Governance Actually Look Like?

Organizations frequently make a critical mistake by starting with an AI policy. That's understandable but often misguided. Policies govern known activities; governance begins by identifying those activities. The National Institute of Standards and Technology's Artificial Intelligence Risk Management Framework (AI RMF 1.0) emphasizes this approach, beginning not with technology controls but with organizational understanding.

Steps to Building a Defensible AI Governance Program

  • Conduct a Legal Risk Inventory: Organizations should identify which business units employ AI, whether systems are internally developed or procured from third parties, what categories of information are submitted to those systems, whether AI influences customer-facing or employment decisions, and who is responsible for legal oversight of each implementation. This inventory should be a legal risk assessment, not merely a technology or software inventory.
  • Assign Clear Accountability: Mature compliance programs routinely identify individuals responsible for cybersecurity, export controls, anti-corruption compliance, and privacy. AI frequently lacks comparable organizational ownership. The DOJ's ECCP repeatedly emphasizes responsibility, accountability, and management oversight as hallmarks of effective compliance. Organizations should be able to identify who evaluated legal risks, who approved deployment, and who retained continuing oversight.
  • Integrate AI Into Existing Compliance Systems: Rather than creating an isolated "AI office," many organizations find greater success by integrating AI review into existing governance processes. Procurement should evaluate AI vendors using existing third-party risk management procedures; information security should assess AI systems through existing cybersecurity review processes; privacy officers should evaluate AI systems processing personal information under existing privacy governance; and employment counsel should review AI-assisted hiring tools through established employment law processes.
  • Write Policies Around Principles, Not Products: One of the quickest ways for an AI policy to become obsolete is to write it around today's software. Technology will change; underlying governance principles will not. Organizations should avoid policies that simply identify approved or prohibited AI platforms. Instead, policies should establish decision-making principles that remain applicable regardless of technological evolution, such as what categories of information may be submitted to external AI systems and when legal review is required before implementation.

"Much of today's AI conversation is focused on models, chips, and compute. Our research suggests that long-term AI advantage is increasingly determined by a country's ability to deploy AI effectively, cultivate talent, build trusted institutions, and leverage global ecosystems," said Emmanuel Benhamou, Managing Director of the Ethical AI Governance Group.

Emmanuel Benhamou, Managing Director, Ethical AI Governance Group

How Are Governments Approaching AI Governance?

Beyond corporate compliance, governments are developing their own AI governance frameworks. New Zealand's Labour Party recently unveiled a comprehensive AI Action Plan that includes establishing an Office of AI to coordinate policy across government, creating an online safety regulator, developing a copyright framework for creators, and setting clear rules for data centers. The plan emphasizes that AI should help people make better decisions but should not make decisions about people's lives on its own, with clear expectations for human oversight and accountability in the public service.

Australia has pursued a similar approach, and New Zealand's Labour Party has indicated alignment with Australia would create more certainty for creative and business communities working across the Tasman. These government frameworks reflect a broader recognition that AI governance requires coordination across multiple policy domains rather than isolated regulation.

What About National AI Competitiveness?

A new research report from the Ethical AI Governance Group and Draup introduces the "AI Sovereignty Paradox," arguing that long-term AI advantage depends on maintaining strategic control and choice while participating in global AI ecosystems. The report challenges the assumption that AI sovereignty requires complete national control over critical AI assets, instead framing sovereignty around strategic control and optionality: ensuring countries maintain enough choice across models, infrastructure, talent, data, and partnerships that no single provider or geopolitical shift can dictate their AI future.

The research identifies a growing AI deployment gap as one of the defining challenges facing governments and enterprises worldwide. This is the disconnect between AI capability and large-scale operational adoption. Closing that gap requires more than access to advanced technology; it requires the talent, institutions, organizational readiness, and operating models needed to translate AI capability into economic value at scale.

"The layer of talent that makes the AI models work in a tangible way for enterprises, which is a combination of technologists and domain experts, will be the most crucial talent to accelerate AI adoption in enterprises," said Vijay Swaminathan, CEO of Draup.

Vijay Swaminathan, CEO, Draup

The report examined five leading AI ecosystems: the United States, Israel, France, India, and Japan. Key findings indicate that AI competitiveness extends beyond frontier model development and infrastructure ownership; national AI advantage increasingly depends on ecosystem coordination and deployment readiness; human capital, workforce adaptation, and institutional capacity are becoming critical AI assets; and countries can strengthen AI sovereignty through strategic specialization and architectural optionality rather than attempting to own every layer of the AI stack.

For organizations navigating this evolving landscape, the message is clear: governance is not optional, and it's not something to defer until after a problem emerges. The organizations best positioned to succeed in an increasingly regulated AI environment are those that can demonstrate they exercised reasonable judgment, conducted thorough risk assessments, assigned clear accountability, and integrated AI oversight into existing compliance structures before regulators, shareholders, or courts came calling.

" }