How do AI ethics, governance and compliance differ?
AI ethics sets the principles a company wants its use of AI to follow, AI governance sets the roles, processes and decisions that put those principles into practice, and compliance means meeting specific requirements, such as those in law. The three overlap, but each answers a different question, and a company needs all of them because the law does not cover every risk.
Three questions, three layers
- Ethics: what should we do? Principles such as fairness, transparency and accountability. International frameworks like the OECD AI Principles describe values for trustworthy AI that governments and organisations use as a reference.
- Governance: who decides, and how? The roles and processes that turn principles into decisions: who approves a new AI tool, who checks its output and who can stop it. It starts with deciding who is responsible for AI in the company.
- Compliance: what must we do? Meeting specific requirements from laws, contracts or standards the company has committed to. For example, a legal requirement in the EU: providers and deployers of AI systems must take measures to support the development of AI literacy (AI Act, Art. 4, applies since 2 February 2025). The full timeline is in what the EU AI Act requires.
Why AI ethics matters beyond compliance
Laws address selected risks, not every risk. Hypothetical example: a small agency uses a generative AI tool to draft blog posts for clients. Beyond AI literacy measures and, in some cases, transparency duties, the AI Act sets few specific obligations for this use. Yet an invented statistic in a published post can still damage a client’s reputation. Ethics says accuracy matters; governance makes an editor responsible for checking facts before publication.
Principles without governance, in turn, stay on paper. Which rules do apply depends on your markets and your role; see which AI laws apply to your company.
How to tell a legal requirement from a recommendation
Guidance on AI often mixes binding rules with advice. Before acting on a statement, check which kind it is:
- Legal requirement. You can name the jurisdiction, the act and the article; the rule covers your role and your use case; and it applies from a stated date. If any of these is missing, find the source before relying on it.
- Voluntary standards and frameworks. It comes from a standard or framework such as ISO/IEC 42001 or the NIST AI Risk Management Framework. You follow it by choice, or because a customer asks you to.
- Recommendation. Practical advice, like most of this library. It is often worth following, but it is not a legal obligation.
Next step: start an AI inventory, a list of the AI tools your company uses. All three layers depend on knowing what is in use.
Sources and further reading
- OECD AI Principles
- Regulation (EU) 2024/1689 (AI Act) — Article 4
AI Horizon Conference
The AI Horizon Conference returns to Lisbon, once again bringing together entrepreneurs, investors and industry leaders to discuss the future of AI.