Ideas Made to Matter

Artificial Intelligence

AI ethics and governance: Where will you draw the line?

Beth Stackpole
5 minute read

What you’ll learn: 

  • Enterprises must address complex ethical issues surrounding AI or risk exposure to myriad financial, legal, and reputational risks.
  • A framework called Boundaries of Tolerance includes a set of performance measures to help organizations assess their position on the AI ethics maturity spectrum.
  • Organizations should strive to go beyond minimum compliance requirements and continuously adapt AI systems to evolving risks and uncertainties.

In companies’ rush to capitalize on artificial intelligence, ethics and governance considerations often take a back seat. The impulse to move fast can undermine firms’ ability to launch a responsible AI program that delivers measurable business value, says Jeffrey Saviano, an MIT Sloan School of Management senior lecturer with three decades of experience at EY. 

When applied together, AI ethics and responsible governance can help ensure that AI systems are safe, fair, and aligned with human, organizational, and societal values. AI ethics shines a light on key principles such as fairness and transparency, while AI governance typically refers to the practices and policies put in place to drive accountability and compliance.

Presenting recently as part of the MIT Sloan speaker series “AI + X: How AI Is Changing Management Practice,” Saviano estimated that ethics and governance practices lag AI adoption by at least a couple of years. “Execs see the potential AI can have on organizations, and it’s creating a chaotic frenzy to quickly launch new solutions,” he said. “It’s pushing some companies to not focus as much on governance.”

That’s a concern, because enterprises that don’t actively consider those complex issues as an early and integral part of their AI deployment strategies could expose themselves to myriad financial, legal, and reputational risks. 

“Companies need to do the hard work to determine what they want to stand for in their AI programs,” said Saviano, who addresses the issue in depth in his forthcoming book, “Boundaries of Tolerance: A Foundational Model for Ethical AI Strategy and Governance.” 

“For example, they need to determine how much human oversight to require, how transparent they want to be about the organization’s use of AI, and which principles matter to them,” Saviano said. “Until they do, they won’t know how to respond when faced with a real AI-related problem.”

A trifecta of AI ethics failures

As more workers are empowered to use AI in their day-to-day roles, including many using unsanctioned tools in the workplace, it’s necessary to establish and promote responsible AI practices. 

Saviano recounted a trio of scenarios that spotlight what can happen when companies are ill-prepared to deal with the fallout of irresponsible or ethically challenging AI systems:

  • An AI solutions development team at a large bank, operating in beta, discovers a systemic bias affecting 5% of its target customer base. Management struggles to find a solution and brings the issue to the board of directors for input. The board can’t reach consensus on a resolution, so the issue remains unaddressed. If the company ultimately deploys a solution at scale, it will be exposed to potential lawsuits, negative press, financial risks, and other repercussions.
  • A global consulting firm delivers a report on welfare compliance to the Australian government that includes fabricated cities and incorrect quotes. The firm discloses its use of generative AI only after the failures have been discovered. The firm fixes the issues and refunds payment, but after a hundred-plus negative media reports, the damage has already been done.
  • A chatbot at a major airline provides a customer with inaccurate information about the company’s bereavement policy, triggering a lawsuit and causing the firm financial harm. The courts reject the airline’s creative defense that AI was a separate actor. As a result, the airline is held liable and faces stiff penalties and fines.

These examples and legal precedents from shareholder derivative suits should serve as fair warning to boards and corporate leadership that they can’t ignore potential harm to stakeholders. “If you are producing AI systems that could cause global harm, you have an obligation to act,” Saviano said.

AI agents doing various jobs

Agentic AI: Business Implications and Applications

In person at MIT Sloan

A framework for AI ethics and governance

Saviano and his research team developed a framework called Boundaries of Tolerance that includes a set of performance measures to help organizations assess their position on the AI ethics maturity spectrum and determine what’s required to advance to a higher level. Recommended best practices include the following: 

Create a formal board-level technology or AI-focused committee. In addition to AI leadership groups or councils at the management level, establish a dedicated board-level structure with formal responsibility for the governance and oversight of AI systems. This ensures that the organization meets legal standards that require the board of directors to assume responsibility for mission-critical areas of risk. Those directives stem from shareholder suits, including a case brought against Boeing after a series of 737 Max crashes. “There’s a direct line from [the Boeing suit] to how companies need to think about their AI systems,” Saviano said. “It’s waking up board members and corporate officers to the fact that they have a fiduciary duty to protect their stakeholders and will be held accountable.”

Make AI ethics and governance a cross-functional effort. The issue is too large for any single corporate domain. Convene experts from technology, legal, risk, operations, and other key functions to collaboratively shape ethical AI practices and effective risk management. This approach aims to break down silos, establish accountability, and embed oversight across the entire AI life cycle.

Adopt professional AI ethics standards. This is common practice across many professions, including law and medicine. Adopting policies and practices that support responsible AI innovation provides leaders and employees with guideposts for acceptable conduct. It also sets clear expectations for the company’s interpretation of ethical AI and integrates those values directly into AI systems. “The law is grounded in ethics, but it’s incomplete,” Saviano said. “We can’t just leave this to chief ethics and compliance officers. They need support from across the enterprise to address these issues appropriately.”

Embrace proactive compliance. Organizations should go beyond minimum compliance requirements to build a buffer of additional safeguards. This will minimize their exposure to legal and ethical risks and help prevent adverse AI incidents.

Practice prudent vigilance. Innovation and growth leaders are pushing to rapidly develop and launch new AI solutions, while enterprise risk management professionals remain cautious, prioritizing protecting the organization. This often creates a binary question within companies: Do we proceed with the new solution or not? 

Prudent vigilance offers a middle ground. Organizations should continuously monitor and adapt AI systems in response to evolving risks and uncertainties; they may then proceed, but with effective guardrails. Doing so shifts the emphasis to early detection and responsive action, ensuring that the innovative solution moves forward responsibly.

Ultimately, enterprise AI governance strategies and practices will reflect the personal choices and boundaries of company leadership, Saviano said. With the right performance measures and adherence to best practices, engaged leaders can continuously advance AI ethics maturity and inspire their organizations to improve amid rising risks.


Jeffrey Saviano is a senior lecturer in AI strategy, governance, and ethics at the MIT Sloan School of Management who recently completed a three-year research appointment at Harvard University. Over more than three decades at EY, Saviano developed and commercialized some 25 businesses and solutions, generating over $400 million in annuity revenue. He led EY’s research collaboration with MIT Connection Science, focusing on enterprise AI strategy, risk, and new governance models for senior executives. His forthcoming book, “Boundaries of Tolerance: A Foundational Model for Ethical AI Strategy and Governance,” will be available in October 2026.

For more info Tracy Mayor Senior Associate Director, Editorial (617) 253-0065