The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/The Road to Accountable AI
The Road to Accountable AI artwork

Katie Fowler (Thomson Reuters Foundation): How 3,000 Companies Approach AI Governance

The Road to Accountable AI · 2026-04-30 · 38 min

0:00--:--

Key moments - from our scoring

Substance score

65 / 100

Five dimensions, 20 points each

Insight Density14 / 20
Originality11 / 20
Guest Caliber15 / 20
Specificity & Evidence13 / 20
Conversational Craft12 / 20

Katie Fowler, Director of Responsible Business at the Thomson Reuters Foundation, discusses findings from the largest corporate dataset on AI adoption to date. The Foundation used LLMs with carefully designed prompts to analyze publicly available corporate disclosures from 3,000 companies across 13 sectors and multiple regions, building on their existing Workforce Disclosure Initiative and UNESCO's recommendations on AI ethics. The research reveals a striking governance gap: while 44% of companies claim an AI strategy, only 13% have formal AI governance frameworks. Companies excel at articulating AI principles but struggle with operationalization and implementation infrastructure. Critical gaps emerge across human oversight (only 12.5% have explicit policies), workforce preparedness (universally lacking training and awareness programs), and data safety practices (only 25% assess training data provenance). The report highlights how experts driving responsible AI adoption sit within operational teams rather than leadership, creating misalignment between governance intentions and board-level accountability. For investors and stakeholders, transparency gaps proxy risk exposure - what companies don't disclose matters as much as what they do. The Foundation plans annual updates using both AI-assisted analysis and direct corporate disclosure as methodologies evolve.

Key takeaways

  • →44% of companies have AI strategies but only 13% have formal governance frameworks, indicating adoption focus over governance infrastructure.
  • →Only 12.5% of companies have explicit human oversight policies for AI systems, though many likely practice oversight without public disclosure.
  • →Workforce preparedness is universally lacking across sectors, with employees often unaware of AI impact, deployment timelines, or company policies on ethical considerations.
  • →Only 25% of companies analyze training data provenance, despite data governance being foundational to responsible AI and heavily informed by existing GDPR compliance experience.
  • →Responsible AI experts typically operate deep within organizations rather than at board level, creating a structural gap between operational best practices and leadership accountability.

In this episode

  1. 1Thomson Reuters Foundation's Mission and Responsible Business Work
  2. 2Evolution to AI Governance: From Workforce Disclosure Initiative to Corporate AI Data
  3. 3Methodology: Using LLMs to Analyze 3,000 Companies' AI Disclosures
  4. 4The Governance Gap: AI Strategy vs. Formal Governance Frameworks
  5. 5Key Findings: Workforce Preparedness and Human Oversight Gaps
  6. 6Data Protection and Privacy Assessments Versus Ethics and Human Rights
  7. 7Bridging the Gap: Transparency, Disclosure, and Investor Expectations

Mentioned

Thomson Reuters FoundationUNESCOWharton SchoolReutersWestlawTrustLawWorkforce Disclosure InitiativeGDPRKevin WerbachKatie Fowler

Guests

Katie Fowler

Topics in this episode

AI governance frameworksUNESCO recommendations on AI ethicsWorkforce Disclosure Initiative (WDI)Thomson Reuters FoundationTraining data provenance analysisHuman oversight in AI systemsGDPR compliance and AICorporate AI strategiesLLM-based disclosure analysisAI ethics operationalization

Questions this episode answers

What percentage of companies have formal AI governance frameworks?

Only 13% of the 3,000 companies surveyed have formal AI governance frameworks, despite 44% claiming to have AI strategies, revealing a significant gap between stated intent and operational implementation.

How did Thomson Reuters Foundation analyze 3,000 companies' AI practices?

They used LLMs with carefully designed prompts to extract information from publicly available corporate disclosures, supplemented by extensive human oversight and validation to ensure accuracy and traceability back to source documents.

What are the main AI governance gaps identified across companies?

Key gaps include human oversight policies (only 12.5% have explicit policies), workforce preparedness (universally lacking training and awareness), assessment of training data provenance (only 25%), and lack of operational infrastructure to implement stated governance principles.

What is the relationship between Thomson Reuters Foundation and Thomson Reuters the company?

The Foundation is an independent registered charity and the corporate foundation of Thomson Reuters, with a mission to strengthen free, fair, and informed societies, separate from the for-profit company's operations.

How does the UNESCO AI ethics framework inform this research?

The Foundation used UNESCO's recommendations on AI ethics - globally ratified by 193 countries - as a benchmark framework to assess corporate practices, organizing it into governance and oversight, human capital, and data safety and security categories.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

14 / 20

The episode delivers solid substantive value with concrete findings (44% have AI strategy, 13% have formal governance, only 12% have human oversight policies) and discusses meaningful gaps between aspiration and implementation. However, the insights are somewhat limited in density - much time is spent on methodology explanation and foundational context about Thomson Reuters and the UNESCO framework rather than deep exploration of novel patterns or surprising findings. The conversation touches important themes but rarely pushes into unexpected territory or counterintuitive analysis.

44% of organizations say that they have an AI strategy...only 13% of companies are publicly committing to a formal AI governance framework
there is a, a mismatch and the gap is suggesting that probably most companies, AI strategies are focusing on accelerating adoption and extracting value rather than on establishing robust governance and ethical commitments

Originality

11 / 20

The work itself is original (first large-scale dataset on 3,000 companies), but the conversational insights largely stay within well-trodden territory: the governance-execution gap is widely acknowledged in responsible AI circles, the regulatory clarity point echoes common industry sentiment, and the regional differences (Europe more mature on labor standards) are largely expected. The analysis rarely ventures into contrarian or first-principles thinking; it mostly confirms existing concerns.

there's a, a governance gap...how much onus and imperative companies do feel to be talking about their AI strategies, but how little that is translating into operationalization
just tell us what the rules are, and we struggle with an environment where we don't know how what we do is going to be evaluated

Guest Caliber

15 / 20

Katie Fowler is a legitimate practitioner running a major research initiative (3,000-company dataset, partnership with UNESCO) at a credible institution. She has real operational experience building data infrastructure and engaging with corporations and investors. However, she is not a household name operator (founder, CEO scaling AI) and the Thomson Reuters Foundation, while legitimate, is primarily a research/advocacy body rather than a company deploying AI at scale. She brings knowledge of governance frameworks but limited deep operating experience in AI deployment itself.

director of Responsible Business at the Thomson Reuters Foundation
we have three key big work streams...One is around strengthening the resilience of independent media...Second is our access to law work stream...and then finally the responsible business work

Specificity & Evidence

13 / 20

The episode provides useful specific metrics (44%, 13%, 12%, one-quarter for data provenance analysis, over half cite EU AI Act) and names the UNESCO framework and EU AI Act as reference points. However, it lacks concrete company examples, dollar figures, or detailed case studies of how governance gaps manifest in practice. Much discussion remains abstract (e.g., "what does responsible AI look like") without naming specific implementations, failures, or success stories that would ground the findings.

44% of organizations say that they have an AI strategy and only 13% have a, uh, a formal AI governance framework
only about a quarter of the participating companies...could actually report on how AI was affecting their workforce

Conversational Craft

12 / 20

Host Kevin Werbach asks thoughtful, well-informed follow-up questions (clarifying the methodology rigor, probing the SME gap, asking about investor leverage) and shows genuine curiosity. However, he rarely pushes back on claims or explores contradictions deeply. When Katie offers explanations (e.g., disclosure problem vs. actual practice gap), Werbach validates rather than challenges. The conversation is collegial and substantive but lacks the productive tension that would deepen insights - he accepts her framing rather than testing assumptions.

How do you have confidence...that you can't necessarily have humans look at every single data point. How do you actually have confidence that the report meets the objectives?
Only about one eighth of the companies...had policies explicitly about human oversight. Did that surprise you?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

data40governance23organizations21katie20framework20werbach18course18responsible17corporate17human16interesting16report15workforce15world13oversight13point13

Episode notes

Good data about how companies are implementing AI governance programs is essential both for organizations to benchmark their efforts, and for observers to understand the state of development. In this episode, Katie Fowler, Director of Responsible Business at the Thomson Reuters Foundation, joins Kevin Werbach to discuss the findings of Responsible AI in Practice , a new report drawing on a global dataset of roughly 3,000 companies across 13 sectors. Fowler unpacks the report's central finding: an enormous gap between corporate AI ambition and operational governance, with 44 percent of companies reporting an AI strategy but only 13 percent publicly committing to a formal governance framework. She argues that the gap is structural rather than just a disclosure failure, noting that AI expertise often sits deep within technical teams rather than at the leadership levels responsible for organization-wide rollout. She points to striking regional variation in workforce protections, the EU AI Act's emergence as a de facto global reference framework even outside Europe, and pushes back on the narrative that regulation stifles innovation.

Full transcript

38 min

Transcribed and scored by The B2B Podcast Index.

This file was generated by Descript Werbach: Hi, I'm Kevin Warbeck, professor of Legal Studies and Business Ethics at the Wharton School of the University of Pennsylvania. For decades, I've studied emerging technologies from broadband to blockchain. Today, AI is promising to transform our world, but AI needs accountability mechanisms to ensure it's developed and deployed in responsible, safe, and trustworthy ways. On this podcast, I speak with the experts leading the charge for accountable ai.

One of the biggest challenges in responsible AI is the lack of sufficient data. What are companies actually doing? As an aside, this is something that the Wharton Accountable AI lab is working on. More on that later, but there are a number of important initiatives happening.

My guest is Katie Fowler, director of Responsible Business at the Thomson Reuters Foundation. It has just released a report based on the largest available dataset. Of corporate AI adoption, 3000 companies across 13 sectors all around the world. We talk about what they found about the gap between conceptualization and operationalization of AI governance, other striking findings about what companies are and aren't doing, and patterns about different adoption practices, uh, around the world and in different contexts.

And how we can move towards an environment where data helps inform both what organizations do internally as well as incentive structures from investors and other stakeholders to promote effective AI governance practices. Katie, so nice to have you with me on the road to accountable ai. Katie: :Thank you so much for having me. Werbach: Thomson Reuters is a, a major content and technology firm, which people may be familiar with from things like the Reuters News Service and Westlaw and, and other services.

You work for the foundation. So talk a little bit about the work that your organization does in general first, and how does it relate to the larger for-profit firm? Katie: Absolutely. Yeah, thanks again so much for having us.

It's such a great opportunity to talk about the Thomson Reuters Foundation which is an independent charity. Um, it's the c Corporate Foundation of Thomson Reuters, as you mentioned. Um, and our mission is really to strengthen free, fair, and informed society. We have three key big work streams.

One is around strengthening the resilience of independent media. Of course, we carry the Reuters brand and we take our commitment to the resilience of independent media really seriously. Second is our access to law work stream, where we actually run the world's largest corporate pro bono platform called trust Law. So we've been connecting, um, civil society organizations and, and.

For purpose organizations across the world with pro bono legal support for many years. Really, really proud of the work that we do in that area. And then finally the responsible business work, which is of course led by myself. I've got an amazing team of, um, data professionals and private sector engagement, um, professionals too.

And our work is really to. Drive responsible business practice through corporate transparency and really to advocate for good jobs worldwide and increasingly to advocate for the responsible adoption of ai as it pertains to the private sector. So a really broad mission in relation to the work that Thomson Reuters does. I think the best way to put it and to sort of explain the difference in our approaches is that Thomson Reuters is very much powering the world's most informed professionals through the services that you mentioned, of course and others.

So it provides fast, reliable, independent, verified news, data and tech that is informing decisions at the highest level. And contra contrary to that and complimentary to that and the foundation's work is empowering often those same professionals actually to use their skills, expertise, and know how to strengthen free, fair and informed societies. Because every day we are working with those same professionals, lawyers. In-house councils, journalists, corporate leaders, and investors, to really bolster the resilience of independent media and to strengthen access to law, as I mentioned, through the world's largest pro bono platform.

Mm-hmm. And also then to promote responsible business. Yes. But we're also connecting with civil society organizations and governments.

So we take a, a really whole ecosystem approach to the positive impact that we can have. Werbach: We're going to talk mainly about the new initiative you have on AI company data. How did that, uh, emerge out of the overall responsible business work that you do? Katie: So it was quite a natural evolution for me, not least, because ignoring what is probably the most seismic, um, issue that it's happening in the private sector would be slightly odd.

Um, and of course it's having a huge impact on business behavior currently. Um, but we already run, um, the Workforce Disclosure Initiative or WDI, which is a world leading plaque. Form, which collects survey data from companies on how they treat their workforce throughout their direct operations and supply chain. And of course, because we already have that foundation and infrastructure, it was quite a natural progression to be looking at how the impact of corporate AI adoption and in fact data from our 2020.

Four WGI initiative actually found that only about a quarter of the participating companies, which is around 250 of the world's largest companies, could actually report on how AI was affecting their workforce. Mm-hmm. Uh, really indicated to us this low awareness of AI's business and workforce impact. So we therefore thought that it was a a really huge gap really.

I wanted to provide a comprehensive framework through which companies could really start to to examine and report against this, this growing issue. And then of course, secondly, I'd be remiss to not mention that we have a longstanding partnership with UNESCO and the opportunity since they. Publish their recommendations on the ethics of AI to be able to apply that to a corporate setting mm-hmm. Was just, open for us.

It's such a huge comprehensive framework. As you probably know, it's been globally ratified by 193 countries, so very intentionally. It is the most globally accepted governance framework, so we really couldn't. Um, miss the opportunity to be able to translate that into something that the corporate sector could actually use as a framework itself.

Werbach: The report that you recently published, and we'll put a link in the show notes covers 3000 companies, lots and lots of data. And my understanding is that, uh, you did that partly using AI to analyze information that companies put out. So, so talk about, um, what that experience was like and you know, how you can have confidence in the accuracy of what you're producing in the report. Katie: Yeah, absolutely.

I really, I'm really pleased that you raised this actually, because naturally we couldn't go into this huge data collection exercise without acknowledging that we also had a responsibility to, to use ai appropriately and effectively in order to gather this information. So, I first do want to say how much consideration went into that approach? Um, you're right in saying we collected public publicly available disclosures and we used an LLM with very specific prompts to identify, um, the exact relevant information in line with the framework that we'd already established, which included then linking outputs back to original source text.

And I guess my T key takeaways from, um, using that approach was that the LM LLMs proved very effective at scale for passing large volumes of public dis. Corporate disclosures. Ultimately a really big underlying, um, objective for us was to build a large data set because of the global discourse that surrounds corporate AI adoption and the lack of that sort of volume of data to support a lot of the hypotheses that, that we're talking about. Um, and this was particularly the case for.

Identifying explicit evidence-based statements, um, consistently across a diverse range of formats, such as reports and policies, and also then web content. But the prompt design was absolutely critical. So outputs were really highly sensitive to how instructions were framed. Mm-hmm.

So making clarity, specificity, and traceability, and linking extracted information back to exact source. Text was essential mm-hmm. In order to avoid misinterpretation, which is actually really, really easy when it comes to, um, a lot of sort of ESG and governance data. So humans, human herbicide just remained totally indispensable throughout the whole process, and there was a lot of it.

So corporate disclosures obviously vary very, very widely. Mm-hmm. In the language and structure. A lot of organizations are voluntarily disclosing information, not necessarily using explicit frameworks.

So we had to be really considered mm-hmm. In the reach of our of our scraping. And, you know, look at that language and structure and modeling risk uh, or risk mitigation in terms of the inconsistency and incompleteness of the extraction. Mm-hmm.

Um, and unless that was obviously a guided by human oversight, we would've been yeah. Not doing very well in terms of the ness of the, of the dataset. Overall we are really, really pleased with the outcome and the approach that we deployed. Lots of lessons obviously we'll go in to this as as we're sort of brandishing this last first annual report, we're intending very much to, to release one next year as well.

And I'm sure that we'll be looking at exacting the process again. And of course, looking at the developments that AI get off, Werbach: yes, much will happen in the next year. No question. Yeah.

Well, it's an interesting, it's an interesting point that you make because this is something that, that many companies are struggling with. The, the LLMs are incredibly powerful, but we know they have accuracy issues. It's sensitive to the prompt hallucinations and so forth. So certainly human oversight is essential in this context.

How do you have confidence, uh, given something at this scale that you can't necessarily have humans look at every single data point. How do you actually have confidence that the report meets the objectives? Are there ways that you are able to measure and assess whether you're analyzing these disclosures in the right way? Katie: O other than sampling and testing mm-hmm.

Um, throughout the whole process, we are, we are looking at the coherency mm-hmm. Of the data. What are the trends telling us how many anomalies exist within the trends? There are lots of different tests models that we can deploy, and I think as our team and capability also grow in that area, as we become a little bit more familiar with the type of information that we're.

That accuracy will likely build over time. Mm-hmm. It's very much, I mean, there's a, there's a full kind of section in our report that outlines our methodology and our approach and, you know, we really want to be on a learning journey in developing this sort of data that's useful and usable for the corporate sector as much as they are, able to put it out into the, um, into the ether. And ultimately I might also.

Add that our goal is that a large proportion, a much larger proportion of the dataset is put together from direct disclosures in the future. Mm-hmm. So we can deploy LLMs to scrape data, we can pre-populate surveys for a really large proportion of companies who want to engage with with us. Mm-hmm.

But then allowing them to do, to also deploy the human oversight, not just also is like such a key part of this quality control. Werbach: There's a tremendous amount of fascinating data in this report. I want to get into it, but let me first just ask you a general question. You, you mentioned using the UNESCO AI ethics framework as a starting point.

Do you have any general insights that you gain from looking at what companies are doing versus that framework? Katie: I think the headlines for us were just this enormous governance gap. So we saw a couple of our key findings really highlighted and emphasized how much, how much onus and imperative companies do feel to be talking about their AI strategies, but how little that is translating into operate. Operationalization and being implemented within their organizations.

Our overall feeling is that there's a piece here where we're unable to unpick the extent to which it's fear and the extent to which actually companies are being slightly modest about the extent to which they're actually deploying ai because there is such a lack of public information about it. They are totally unaware of what their peers and competitors are doing. They're un unaware of what. Good looks like at an industry level or at a regional level.

And we really wanted to try and dispel some of those myths using that that framework. The recommendations on the ethics of AI that UNESCO publish cover such a wide breadth of issues? Yes. We tried to boil it down into governance and oversight, human capital and data safety and security.

And I think even then you can go a lot further, um, in terms of looking at how different, particularly. Particularly different industries need to look at AI governance more specifically. But certainly we, our overall feeling is that using the UNESCO recommendations did allow us to appeal to organizations, companies in all regions. It gave us a really great solid benchmark and foundation of what, theoretically good can look like.

Mm-hmm. And then really helping to build on that. And, you know, as our data. Increases.

But the other key kind of standout indicator that we've highlighted is just how lacking workforce preparedness is across all sectors. It's unanimously being ignored. And, um, my feeling sort of. Totally is that there's, again, there's a fear and a, and a trepidation amongst corporate leaders about the extent to which engage their, to engage their workforce.

Are their workforce actually going to be redundant or are they actually a key stakeholder in the success of AI deployment? And it's this sort of tension that is being fueled, I think a lot by. By sort of media coverage around mm-hmm. What AI is going to do for the workforce in the future.

And then sort of confusion about the lack of evidence that we have in at an individual company level about exactly the efficiencies that it is offering. Werbach: Right. With regard to workforce preparedness, what, what external data might we see that is evidence of that? Because it, it may well be that companies are doing a lot internally, but they're not necessarily putting a formal disclosure out about, say, their training policy.

So what, what would you look for to see indications of workforce preparedness for ai? Katie: That's really, that's a really good point. And ultimately our data is very much corporate disclosure data. So there are limitations on the extent to which we are able to to make huge assertions.

But what we can see say is that there are, there is enough evidence sort of out. In the broader kind of research landscape to be able to corroborate a lot of the trends that we were seeing around human capital and human capital risks whereby. Employees themselves are not undergoing training, for example, where, there's an, an assertion that training is available or com or employees themselves are not aware of specific company policy around AI adoption and, and even ethical, considerate considerations of ai.

And so those sorts of indicators are, are those that we can look for. And then just to also highlight that our Workforce disclosure initiative As I, as I mentioned at the start, we have seen a consistent lack of reporting around the impact of technology on work. Course and so just being able to highlight to companies the importance of being able to monitor and manage redeployment, upskilling, you know, all of the changes that they're hoping to make to their sort of their workforce over time is really, really critical.

Werbach: Mm-hmm. I wanna get back to the, the point that you made earlier about the governance gap, and I, I believe the numbers in your report were 44%. So nearly half of companies have an AI strategy and only 13% have a, uh, a formal AI governance framework that, that you were able to see. So I'm, I'm curious your take on that, uh, because, you know, one question is you know, there's obviously a difference in those two numbers, but in some ways both of those are pretty big numbers given that.

We're really only three years in since chat, GPT, when, when companies broadly were having to wrestle with AI across the organization in the way they are now. Uh, and in some ways that's, that's a lot. Both of those numbers seem like a lot in that short period of time. But anyway, I'm interested in your, your thoughts about that.

Katie: Yeah, I think that's a really a really useful pointer. And, and ultimately we are not here to emphasize any negative trends. We're, we are really wanting to spell out what we're seeing, um, in the data. So ultimately, yeah, you are absolutely right.

It's absolutely, it's an actual, it's a brilliant number that 44% of organizations say that they have an AI strategy. I think that. Because they may be a very good AI strategy. Well, indeed, indeed.

And of course, because only 13% of companies are publicly committing to a formal AI governance framework, we are then left to fill in the gaps. So what exactly does that tell us? And people like me are gonna tell you that. Ultimately I, my concern is that there is a, a mismatch and the gap is suggesting that.

Probably most companies, AI strategies are focusing on accelerating adoption and extracting value rather than on establishing robust governance and ethical commitments, um, or protecting their workers. And of course, without these guardrails, AI oversight may not actually be working in practice. And I also feel that it's important to look at this from a, an, the perspective of of other stakeholders. So a really large stakeholder group that back, our AI company data initiative are our investor signatory group, and transparency is often.

Used as a proxy for risk management. And where there's a transparency gap, they are then left to ask questions. So are there reputational, regulatory or other risks that might actually undermine all of that accountability? So I think that, that, for me, it's, uh, often it's not what you are telling, it's what you are not telling.

Leaves you exposed somehow. So really what we're trying to encourage is to identify these gaps and help companies appreciate that. That without further explanation, other External parties are then left wondering and trying to fill that gap with an explanation. Um, so fibs maybe be adopting ai.

Practices very responsibly in their day-to-day operations, but without transparency to their consumers or to their investors, they're actually risking, undermining trust. So that's my kinda key takeaway from that gap. Werbach: Absolutely let, let me ask about a, a few of the specific findings there. I, I think they're interesting and I'm curious how you reacted to them.

Only about one eighth of the companies. Uh, we, we talked, um, a minute ago about human oversight in terms of your own work in building this report and, and how important it's to have humans in the loop in various ways engaged with ai, but only, only about an eighth of the companies that you surveyed. Had policies explicitly about human oversight. Did that surprise you?

Katie: Yeah. Um, did it surprise me? I, I think that it's not a great it's not a great data point. And given how much we know about the importance of Hu human oversight, it, it is quite alarming to look at on, on a, an aggregate level.

Mm-hmm. And I think that you do have to question whether it is a disclosure problem or whether companies do genuinely lack that. Mm-hmm. Human oversight, of course.

Um, and is human oversight something that, you know, you would've publicly communicated about it? Are companies privy to how much an external stakeholder wants to know about the level of human oversight? I think those are all really key questions to ask. Stage that we're at in collecting this data.

I feel confident that a lot of companies do have internal practices. They're just simply not communicating externally. Mm-hmm. But the reports, broader findings do actually point to more of a structural problem, which goes a little bit beyond poor disclosure.

And I think it is important not to just dismiss it as a disclosure problem, because across the dataset where we are seeing consistent patterns emerging mm-hmm. Around organizations being able to describe governance at a concept. To level, but not really being able to demonstrate how it that functions on a day-to-day operational level. So a lot of companies felt much better at announcing governance intentions, perhaps, than building operational infrastructure to deliver them.

So human oversight is probably squarely falling in that sort of infrastructure category. Werbach: No. Interesting. And, and I, I see that a lot when I talk to organizations that it, it's fairly easy to, to say, okay, here's our principle, but then they sit around looking at each other about what it means to actually implement it.

And, and to your point before they say what's everyone else doing? And, and they don't even know. So this, this kind of information you're showing I think will be really valuable to help organizations start to, to benchmark in that way. And, Katie: and also I think another point.

For me that sort of resoundingly important to express is how, where our experts sit in this. So often our experts in, you know, the people who see the importance of human oversight are not sitting on the boards, they're not sitting in leadership. They're sitting deep. Within teams of people who've been hired to operationalize ai.

So they're not necessarily also the people who are responsible for, broad rollout of robust governance infrastructure. And I think that's a really important point to raise too, and something that we've been called on is to kind of demystify amongst leadership, you know. Directors, what, what does responsible AI actually look like and mean? Because I've been in my career for 30 years and I'm not exactly sure how to deploy that.

So, um, I think that's also another important point to raise and not to undermine actually the really amazing work that is happening deep within organizations and teams. And that's sort of the ethics that exist at that individual level. Werbach: Yeah. One of the, the antecedents for that responsible AI work is, uh, work on data protection and privacy that that many organizations, especially global organizations, have had to do with the adoption of GDPR in, in Europe and with, broader global, uh, implications.

And so I was, I was interesting that, you know, your report seemed to. Suggest that there were, many more companies that talked about doing assessments for privacy with AI than things like human rights and ethics, but even with regard to data, um, I believe the number was only about a quarter of the companies did analysis of the provenance of the training data that they're using for ai. Which you would think would be the kind of thing that, you know, if they're more attuned to.

Privacy and data protection, they would start there. So there's a couple different pieces there. I I, I wonder if you could elaborate more on some of those. Katie: Yeah, I mean, just with your, with respect to your point about that policy in GDPR, I think that is a really, really interesting perspective and something that you could apply to a lot of the findings of the report in lots of different ways.

Werbach: Mm-hmm. Katie: Um, the way that GDPR continues to influence AI governance through AI systems that process personal data and must comply with GDPR principles, including lawlessness purpose limitation. Data minimization, et cetera. So that's a, that is an interesting facet to this.

And I think that the def facto way that this global standard in the way that GDPR. Um, sort of applied to data protection at large. We are also potentially seeing a little bit of that with regard to the governance framework of the EU AI Act as well. Mm-hmm.

Um, so the, because the AI Act is re remains the most advanced. An atte advanced attempt to set clear legally binding standards for safe, transparent, and accountable AI across all sectors. The broader regulatory landscape covering digital technologies and shaping AI operations indirectly is sort of a lot more disparate. And so the way the fascinating takeaway from the report for me was that over half of the companies actually cite.

Governance site, the eu a act, AI act as their sort of governance framework, even those that exist outside of Europe. And I think that's a really an interesting reflection for a lot of policy makers worldwide. In fact, you know, the, the absence of a regulatory foundation actually leaves a lot of corporates a little bit paralyzed to know, you know what the. The where the goalposts are and.

You know, the environment in which they're operating. So contrary to this sort of rhetoric that regulation stunts innovation and growth, actually we might be seeing something that's quite contrary to that, where anti-regulation actually stunts you know, the pace of innovation and growth that a lot of organizations, um, sort of need that safety net around them in order to be able to operate and yeah. Werbach: Safely and without constraints. So I think that's, that's quite an interesting.

Perspective. Yeah, I, I hear that from a lot of companies too. Obviously they don't love regulation and they have particular objectives to certain legal rules, but really what they want is clarity. They, they keep saying to me, just tell us what the rules are, and we struggle with an environment where we don't know how what we do is going to be evaluated.

Katie: Yeah, absolutely. It's it's a really interesting, um, time and we are obviously mapping global, regulatory, um, jurisdictions across our framework as well. So throughout the survey framework, we're actually able to tell companies which data point that they're responding to. Mm-hmm.

What that's relevant for in terms of global regulation. We've mapped 23. Cybersecurity and AI regulatory frameworks, for example, including obviously the EU AI Act. But we are seeing, you know, a lot more pace in emerging economies to be able to provide that kind of.

Framework and environment for, for companies to thrive in. So, you know, the next couple of years gonna be really fascinating mm-hmm. To see what happens. Werbach: Yes.

Did you find any other interesting differences among regions in terms of how, uh, people were responding, who got companies from all over the world? Katie: Yes, we did. We found some quite stark differences, which probably won't surprise the readers an awful lot. European and UK companies disclose a lot more on AI safeguards for workers than those in Asia, Latin America, and Africa.

Of course, it's fairly reflective on on the. Uh, labor standards that exist across all those different regions anyway, but also potentially it's reflective of the the categories of workforce, which AI is most affecting at this time. So it's slightly to suggest, obviously, a more mature regulatory and governance expectations around workforce, of course, in the UK and Europe. Mm-hmm.

Um, but there's also greater institutionalization of formal reporting channels in that region. And of course, the data finds that. Although it's still really low, the presence of AI related compliant mechanisms are higher in the UK and Europe compared to the rest of the world. So that was quite an interesting, trend.

Werbach: One other finding that that isn't surprising is that larger companies were much more likely to have formal AI governance policies than, than smaller ones. Did. Did you get any sense about. How small medium enterprises can engage in AI governance in an effective way.

Katie: Yeah. I think this question's really interesting and actually one we want to do a lot more work on. We really struggled to engage with the the SME kind of sectors and naturally, because we did a lot of public data scraping, of course that information is more available from, um, from public markets. So there's.

There's a really obvious answer to that to some extent, which is reflected in our data. However, we do hear anecdotally that, um, small and medium enterprises are a lot more driven in order to be able to adopt responsible AI practices, and of course, a lot earlier. Phase organizations are being established around, AI operationalizing their business in the first place. So there is a sort of imperative.

Also what's really interesting is looking at, um, our different segments of investors who are you know, really driving for. Responsible decision making and practice around AI adoption. Um, organizations that are invested in really large established organizations. Pension funds and other asset owners are really, really motivated to understand what this looks like long-term.

Whereas, you know, when we're trying to look at. Um, the venture capitalist market, private equity, we are seeing a lot more more of a splattering of interest. Mm-hmm. Which is very much steeped in individual ethics rather than, corporate framework.

'cause of course, fast turnaround investments the longer term risks of AI for people's society and the environment aren't so interesting for them 'cause it's not really going to impact their, um, their kind of. Grace and turnover and, and yields in the short term. Mm-hmm. So I think that whole piece is really interesting.

The startup kind of network is, uh, one that we've had a lot of interest from. Um, and may well look at the possibility of adapting the AI company data initiative survey even further so that it's more accessible for smaller businesses. But I have to say that we we made a really considered effort to mm-hmm. Ensure that the survey was appropriate to be responded to by any company of any size and at any stage of their corporate adoption of ai.

And so we're, now looking at potentially making some updates to the survey so that it's as relevant as it can be for the next cycle of disclosure. And we're concerned about too many changes 'cause it may sort of damage the integrity of the, ethical framework that we want. Companies to be able to deploy. So whilst companies might not be able to actually answer all of the questions, we still want them to be there as prompts for business leaders to be able to take back to their organizations and have a think about and maybe respond to the following year.

Werbach: You mentioned a couple times the, the role of investors and, and obviously with regard to things like worker protection or broadly ESG. There there's been, you know, tremendous effort around the world to have metrics and have ways that investors can assess companies and, and make their decisions. Um, the kind of work you're doing obviously can contribute to doing that kind of assessment for responsible use of ai. How do you see, uh, US going forward in terms of investors being able to play a role in incentivizing companies?

Katie: So, um, I think our long-term goal would be to be able to deploy our data into more materiality, um, research. Ultimately there needs to be a link to financial materiality. We would love to think that we'd be able to contribute to a responsible AI index, for example. Mm-hmm.

Where we are actually matching the. The maturity and um, and growth of financial metrics to responsible AI practice. Obviously it's gonna take some years to be able to build a data set that is, comparable and established enough to be able to develop that sort of framework. But that's going to be a really key lever for investors ultimately, because they'll be able to really tangibly request that of their portfolio companies.

But in the meantime, as I mentioned, a lot of our investors are saying to us. That they are, you know, in the absence of any kind of governance framework that they can really hang their hat on, they're looking at transparency as a key proxy for risk management. And so we are able to offer a framework to companies to, um. To enhance their transparency around their corporate adoption.

And what we have seen through our Workforce disclosure initiative is that investor buy-in and investor engagement is such a key part mm-hmm. Of this theory of change. Ultimately, they are the people who are gonna be able to impress upon corporations to change their behavior. It's not little little.

You know, civil society organizations and their advocacy, you know, the money will talk. Mm-hmm. And where investors start to feel that they have enough evidence to be able to withhold investments on the grams of, responsible practice around, um, ai, where there's a materiality link. I think that's gonna be the absolute, you know, winning strategy in order to, to emphasize the importance of this.

And of course, as we. You know, move forward, we will start to see real impacts and, you know, it will become much more, um, of a reputational risk for organizations mm-hmm. Rather than an anecdotal one. Werbach: Absolutely.

I, I agree that this is the direction that the things are inevitably going to have to go. Uh, it's, it's a very useful report and, uh, very much look forward to seeing. What you do going forward with this line of work. Uh, we need to wrap up but Katie, it's really been a pleasure speaking with you.

Katie: Thank you so much. Appreciate it. Werbach: This has been the Road to accountable ai. If you like what you're hearing, please give us a good review and check out my substack for more insights on AI accountability.

Thank you for listening. If you want to go deeper on AI governance, trust and responsibility with me. Another distinguished faculty of the world's top business school. Sign up for the next cohort of Wharton's Strategies for Accountable AI Online Executive education program, featuring live interaction with faculty expert interviews and custom designed asynchronous content.

Join fellow business leaders to learn valuable skills you can put to work in your organization. Visit exec ed.warden.upen.

edu/acai for full details. I hope to see you there.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Auditing AImnemonic security podcast · on AI governance frameworks96 / 100
  • AI Is Ready for Government. Is Government Ready?The So What from BCG · on AI governance frameworks84 / 100
  • Beyond the Pilot: How AEC Firms Scale AI AdoptionAEC Business · on AI governance frameworks73 / 100
  • Steve Odland on governing AI in an age of uncertaintyHBS Managing the Future of Work · on AI governance frameworks72 / 100
  • How To Make Successful Decisions In AIData Analytics Chat · on AI governance frameworks70 / 100
  • Shift Left, Real Moats, and Where Your Data Actually Goes, with Chris BollerudCybersecurity Ecosystem Show · on AI governance frameworks69 / 100

More from The Road to Accountable AI

All episodes →
  • Harish Peri (Okta): When the Thing Accessing Your Systems Has a Brain77 / 100
  • Logan Kelly (Waxell): The Accidental Agent Governance Company82 / 100
  • Nadav Cornberg (Eve Security): Interrogating Agents Before They Act83 / 100
  • Venkat Siva (Compfly): Governing Agents at the Execution Boundary95 / 100
  • Munmun De Choudhury (Georgia Tech): Conversational AI and Mental Health83 / 100
Explore the best B2B AI & Data podcasts →
All The Road to Accountable AI episodes →