When considering an artificial intelligence (AI) strategy, often the first things that jump to mind are operational considerations: how should the product be designed, the algorithms developed, and the technology deployed into the broader enterprise? However, there is an important governance process that should precede the operational framework of an AI strategy.
The Industry Relations and Corporate Governance Committee of CFA Society Toronto hosted three subject-matter experts to discuss AI and corporate governance on March 12, 2021. The session was moderated by Monique Morden, founder and advisor of Judi.ai, with guest panellists Laila Paszti, partner at Norton Rose Fulbright Canada LLP; Dr. Bahar Sateli, manager in AI and analytics at PwC Canada; and Dr. Christine Chow, executive director, global head of strategic governance and ESG integration at IHS Markit.
Legislation for AI exists, but the regulatory framework is fragmented
In many parts of the world, including Canada, there is no single regulatory framework to deal with AI. Rather, AI is governed throughout its whole life cycle by a fragmented regulatory framework that includes sector-specific regulation, consumer protection laws, human rights codes, and privacy legislation. This makes the corporate governance of AI multidimensional and often complex.
Data privacy and intent of use are two major areas that need careful consideration. A corporate governance framework should ensure that consent is obtained when using personal information to develop AI, even if the information is publicly available. The intended use of the data is equally important; individuals should understand what they consent to when their data is used and know that their data will not subsequently be used for other purposes.
Keep it narrow and document the process
To build a successful AI strategy, a clear, narrow objective should be defined. A broad, vague objective cannot be easily translated into code, which could result in low accuracy and spurious results. In contrast, a well-defined, narrow objective that guides the development stage will ultimately result in higher accuracy and a better understanding of the AI’s decision-making process. This should ease the governance process significantly.
Further consideration should be given to documenting all decisions made while developing and implementing the AI. Specific effort should also be made to analyze and document the performance of the AI and understand its decision-making process. From a governance and regulatory perspective, it is important to know why the AI reached certain conclusions in order to avoid undesirable outcomes, such as unintended discrimination against groups or individuals.
In this regard, some trade-off between complexity, accuracy, and an ability to explain the decision-making process may be necessary. The recommendations of more complex processes, such as deep-learning models, may be more accurate, but it is often difficult to explain why the AI reached certain conclusions. A governance process for AI needs to carefully consider how to balance this trade-off.
Understanding the risks and the limitations of AI
There are many risks to adopting AI in an enterprise, and the governance process needs to constantly monitor those risks. Specifically, the AI’s performance poses a key risk, so it is essential to understand the accuracy of the AI. Conclusions reached through AI could potentially be life changing, both for an enterprise and for individuals. Such life-changing scenarios could arise if, for example, AI technology were to incorrectly diagnose an individual and consequently suggest the wrong treatment, or if AI technology were to misclassify potential customers for a business, leading the firm in the wrong direction.
In-house AI or third-party products?
As AI technology develops and becomes more widely adopted, many enterprises may decide to use third-party products instead of developing their own AI technology. While third-party products may offer benefits such as lower costs, enterprises should consider which data the AI was trained on, assess the AI’s accuracy, and understand its decision-making process to ensure there are no unintended biases in its recommendations. The same regulatory framework that governs in-house AI is likely to govern third-party AI.
Good AI governance leads to successful implementation
There is no one-size-fits-all solution to AI governance, and an enterprise’s approach will need to be multidimensional. Fortunately, this field is advancing quickly, and there is increasing recognition of the key issues surrounding AI and corporate governance. Good AI governance goes a long way in mitigating risks to an enterprise and ensuring the successful implementation of an AI strategy.