Preparing your company for AI regulation

Preparing your company for AI regulation

Preparing your company for AI regulation

 

Keeping up with the pace of change

The pace of change in the evolution of AI is relentless. Regulators across the world are trying to keep up. And taking a variety of approaches. Boards recognise the challenges, but often struggle to know how to address them.

In the UK, as with other aspects of regulation and corporate governance, the preference is for principles over rules. But across the EU the AI Act has come into force. This sets the benchmark for global AI regulation, prohibiting what are deemed to be harmful AI practices.

While on the surface the UK is outside of this requirement, in practice the regulation applies to all AI systems used in the EU – so many UK companies trading in Europe will feel its reach. Penalties are significant – up to Euro35m or 7% of global annual turnover.

Certain AI applications will be prohibited. Perhaps more significantly, within 24 months, high-risk AI systems, such as credit assessment and job candidate evaluations will need to be risk assessed, monitored and strong cyber-security controls implemented.

An issue that affects us all

We believe AI is an issue for all organisations. While the technology may be new and innovative, the mechanism for embedding it within existing business operations feels substantially similar to previous technology. Data has to be built into the system, directors have to have confidence in the inherent algorithms, judgements are applied that require human oversight, and there is a need for strong security controls at all stages and levels.

We believe in embedding good governance within the organisation. AI is an area where directors will not be able to suggest they did not understand the need for this. We understand that it is challenging – few of us really know how the technology works. Risks are emerging that have not been anticipated.

So what should you do?

Using the normal principles of good governance, we recommend organisations:

  1. Create an inventory of all of the use cases of AI across the organisation and their status. This needs to be dynamic to build additional aspects and use cases as they emerge.
  2. Conduct a regulatory impact assessment to determine which uses are caught in the EU AI Act or other forms of regulation.
  3. Perform a gap analysis to compare the existing controls over technology and processes with those required to have confidence in the AI use cases.
  4. Assess the human interventions necessary to have appropriate oversight and develop judgements around the use of algorithms. Does the necessary capability and capacity exist?
  5. Develop a plan to move your governance and wider AI capabilities to be within your risk appetite.
  6. Assess the quality of data flow into and out of the AI technologies, using standard data assessment techniques. This includes consideration of data protection rules.

Failures in oversight over AI have been around for some time. You only have to consider the A-level fiasco of 2020 when inbuilt algorithms marked down the results of some students, while facilitating grade inflation amongst other groups – with the impacts felt over a period of several years.

Getting this right is more than just applying a regulatory lens. Its about ethical and responsible business practices.

To assist our clients we are collaborating with a leading expert in AI Ethics and Governance, Annabel Gillard. If a conversation would be helpful please do reach out.

Carolyn Clarke

26th July 2024

AUTHOR.

CAROLYN CLARKE

Share on
Related Posts