The Business Case for Responsible AI: Enabling Growth by Going Beyond Compliance

Responsible AI governance is far more than a compliance requirement.

Published

17 September, 2026

Type

WBCSD insights

Share:

Together with CMS, the Principles for Responsible Investment (PRI), the Thomson Reuters Foundation and WBCSD members, we explored why Responsible AI governance is far more than a compliance requirement. It is a business imperative: enabling companies to deliver safe and secure AI-powered services, protect and strengthen workers’ skills and knowledge, maintain oversight of their operations and value chains, and make deliberate choices about where and how AI is embedded across the business. Through a lively discussion, we discussed why companies should invest in AI governance now.

AI adoption is outpacing oversight

Thomson Reuters Foundation’s AI Company Data Initiative (AICDI) highlights a critical challenge facing businesses today: AI adoption is advancing faster than the governance structures designed to manage its risks. Grounded in UNESCO’s Recommendation on the Ethics of AI, the initiative assesses the AI adoption and governance maturity of almost 3,000 companies.1 Key findings of the research point out that:
  • 43.7% of the companies publicly communicate that they have an AI strategy but of those companies, only 27% report adherence to a governance framework
  • 40% report Board oversight of AI, but only 3.8% have an AI Ethics Committee
  • 31% have an AI governance team but of those companies, only 11% have a Data Protection Officer
The Foundation’s Head of Data Insights and Investor Stewardship, Joy Zhang, highlighted that when we look beyond headline governance commitments, many companies appear to lack policies for AI training data quality, evidence of a formal AI model registry, AI literacy trainings for employees, AI impact assessments or policies to ensure human oversight of AI. As companies review these gaps, the opening of the latest AICDI disclosure window offers a timely opportunity to assess and strengthen responsible AI governance practices. Meanwhile, the board-level accountability for AI continues to evolve, thereby emphasising the role that directors play in oversight of AI-related risks. For boards looking to further develop their approach to AI governance, the Foundation offers a Responsible AI training programme, aimed at strengthening oversight capabilities and supporting effective stewardship of AI-related opportunities and risks.

AI governance is more than just a policy document

CMS supports clients worldwide to design, deploy and continuously assess AI governance framework. Their experience points to a critical aspect of responsible AI governance: it is practical, embedded in day-to-day processes and goes well beyond a static policy document or monthly committee meeting. It also needs to be proportionate and agile, enabling innovation rather than slowing it down. Responsible AI Governance entails:
  • Governance: establishing decision-making structures, such as AI governance boards, executive oversight and delegated authorities across business divisions
  • Use: defining how different business functions can use AI
  • Adoption: training and upskilling of your staff, managing AI procurement, deployment and lifecycle monitoring
  • Risk: integration of AI related risks in the Enterprise Risk Management system and active monitoring and addressing of issues
  • Data: quality and type of the data that is used for AI solutions and alignment between existing data governance frameworks and AI governance

Why do I need AI governance, I have IT Governance

CMS shared concrete examples and evidence of the risks when companies are not sufficiently investing in AI Governance:
  • Breaching the EU AI Act
  • Breaking existing IP laws
  • Failing to ensure good quality output and traceability
  • Dealing with confidentiality concerns
The experts of CMS, John Buyers, Markus Kaulartz and Catalina Panoiu further stressed the relevance of AI governance for securing the success of your business. Agentic AI only further accelerates the need for good governance that establishes human oversight over AI autonomy. Can a business afford to deal with the ripple effects of an AI agent that would refuse to obey a human command? With agentic AI humans need to be “on the loop” rather than only “in the loop”. Some organisations are using AI to ‘police’ AI. Specialised AI agents monitor actions and trigger alarms, or even block non-compliant or dangerous actions and prompts. As AI systems become increasingly autonomous, effective governance will depend on combining human judgement with technological safeguards that can monitor, intervene and enforce policies in real time.

Investors care about AI risks

Toby Sparwasser Soroka from the PRI shared how the PRI’s investor signatories are dealing with idiosyncratic, portfolio, and systemic AI risks as they intersect with sustainability themes across the AI value chain. Many of these sustainability issues are becoming financially material in real time, such as the estimated 130bln USD stalled in data center projects due to community opposition, water permitting, and connection ques. There are also material concerns about energy costs and availability and labor displacement at scale. Other highlighted investor concerns include energy costs and availability, workforce disruption, regulatory risk, and competition for resources with the energy transition. A significant portion of PRI’s signatory base are highly concerned with AI risk. Many are developing processes to assess AI risk, and are increasingly asking their portfolio companies to evidence accountability, demonstrate robust processes for risk management, and disclose transparently on AI risks and impact from their investees.

Start now

You may be at the start of your AI adoption journey, you may not have enough capacity or lack the proof points of how material AI risks are, but the clear signals from investors and evidence of increased costs, reputational issues, and business disruption are starting to mount up. We would like to invite WBCSD members to further deep dive into best practices on AI Governance in our upcoming co-hosted webinar with CMS on October 27 & 29. Please reach out to vandervelden@wbcsd.org for more details. For companies interested in exploring participation in the AICDI, or for boards looking to learn more about the Responsible AI training programme for Non-Executive Directors, please contact rbtrf@thomsonreuters.com.

About CMS’s TMC practice

CMS’s Technology, Media & Communications (TMC) practice is at the forefront of AI law, governance and regulatory developments, advising organizations on the responsible adoption and deployment of artificial intelligence. Drawing on extensive experience across industries and jurisdictions, CMS helps clients design practical AI governance frameworks that align legal compliance, risk management, innovation and business objectives. Our multidisciplinary teams support organizations throughout the AI lifecycle, from strategy and procurement to governance, deployment and ongoing oversight. The thought leadership materials below provide further insights into emerging AI risks, regulatory developments and practical approaches to building robust and future-ready AI governance frameworks.

Read more:

Footnote:

1. Companies are adopting AI faster than they are governing it