Every organisation we speak to has an AI ethics policy. It’s usually a well-meaning document, approved by the board, filed somewhere sensible, and largely ignored in the day-to-day scramble to ship products and hit targets.
That gap between policy and practice is where things go wrong. And with the EU AI Act’s high-risk obligations kicking in by August 2026, it’s a gap that can no longer be tolerated.
So what does responsible AI actually look like when it leaves the boardroom?
It Starts with Knowing What You’ve Got
You can’t govern what you can’t see. One of the most common issues we encounter with clients is a lack of visibility into the AI tools already in use across the business. Marketing has adopted one tool, operations another, and someone in finance is quietly running models in a spreadsheet plugin.
Building a living inventory of your AI systems, who owns them, what data they touch, and what decisions they influence, is the unsexy but essential first step. According to PwC’s 2025 Responsible AI survey, nearly half of executives said that turning AI principles into operational processes has been their biggest challenge. An inventory won’t solve everything, but it gives you a foundation to work from.
Bias Doesn’t Announce Itself
One of the most instructive lessons from the past few years comes from financial services. A bank automated its loan approvals with machine learning, only to discover through internal audit that the model was disproportionately rejecting applicants from historically underserved areas. The training data carried decades of human bias, and the algorithm faithfully reproduced it.
This isn’t unusual. Bias in AI systems is rarely intentional, which is precisely what makes it dangerous. It sits quietly in your data, compounding silently until someone thinks to look. Responsible AI means building in regular checks: fairness audits, explainability tools, and the habit of asking “who might this disadvantage?” before deployment.
Governance Needs to Be Woven In, Not Bolted On
The organisations getting this right are not those with the biggest compliance teams. They’re the ones embedding AI oversight into the workflows that already exist: procurement reviews, privacy impact assessments, change management processes.
If responsible AI is a separate committee that meets monthly, it will always lag behind the pace of adoption. We’ve seen far better results when governance is part of how teams work, not an extra hoop to jump through. When your vendor intake process already asks the right questions about AI, and your product launch checklist includes model risk, you don’t need to chase compliance. It happens naturally.
Transparency Builds Trust (and Saves You Later)
There’s a practical reason to be transparent about how your AI works, beyond the regulatory requirement. Customers and partners increasingly want to understand how decisions are being made, especially when those decisions affect them directly.
The same PwC survey found that 55% of executives reported improved customer experience from responsible AI practices. That makes sense. When people trust that your systems are fair and explainable, they’re more willing to engage.
Transparency also protects you when things go wrong, because they will. A system that can explain its reasoning is far easier to fix and defend than a black box.
The Regulatory Clock Is Ticking
With the EU AI Act’s transparency rules taking effect in August 2026, and high-risk system obligations applying from the same date, the window for preparation is narrowing. Separately, Colorado’s new AI law introduces obligations around algorithmic discrimination for high-risk systems.
This isn’t about panic. It’s about recognising that the “we’ll deal with it later” approach has a shelf life. Organisations that start now, even with imperfect processes, will be far better positioned than those scrambling at the deadline.
Where to Begin
If you’re wondering where to start, here’s what we’d suggest based on our experience working with data-driven organisations:
First, build that inventory. Know what AI you’re using and where. Second, assign clear ownership, because shared responsibility often means no responsibility. Third, embed governance into your existing processes rather than creating parallel ones. And finally, start monitoring for bias and fairness now, not after the first complaint.
Responsible AI isn’t a destination. It’s a discipline. And like most disciplines, the hardest part is simply starting.
If this is something your organisation is grappling with, we’d love to have a conversation. Sometimes an outside perspective is all it takes to turn good intentions into good practice.

