29 January 2024
Companies need rules when using AI. But what should they be? We have worked through the most important requirements of current law and future AI regulations and drafted 11 principles for a legally compliant and ethical use of AI in the corporate environment. We have also created a free one-page AI policy. This is part 3 of our AI series.
Many call for more regulation of artificial intelligence, even if opinions differ as to what really makes sense in that regard. You should be aware, though, that a lot of rules already exist and further regulations are to be expected. If a company wants to use AI in a legally and reputationally sound manner, it should take into consideration the following three elements:
Applicable law: In daily business, the focus will be on data protection law, with some aspects of copyright law and laws against unfair competition. Depending on the industry, there are also rules concerning official and professional secrecy and industry specific regulations dealing with the outsourcing of business functions to IT service providers (which is the case for most AI applications). Contracts may contain further restrictions, for example on what a company may use the data from a customer project for, even if data protection does not apply due to the lack of processing of personal data.
Future regulation: Most nowadays focus on the European Union's AI Act. It provides that a number of activities are prohibited (e.g. emotion detection at the workplace), it sets forth a number of rules for providers of "high-risk" AI systems (e.g. concerning risk management, quality assurance and product monitoring) and contains some obligations for certain other AI systems (e.g. transparency requirements re deep fakes). For most companies, it will be of less importance, at least if they do not offer or develop AI systems, but certain obligations will also be imposed on users. Companies in Switzerland should also take a look at the Council of Europe's planned AI Convention, as it will likely also have to be implemented in Switzerland one day; it will probably have a significant influence on AI regulations in Switzerland. We believe it concisely sums up the key principles that also underlie the AI Act and that are really important (the second draft is currently available). We will have a separate post on the AI Act as part of our blog series.
Ethical standards: We refer to them as supra-legal requirements to which companies submit themselves when dealing with AI, for example by going further in terms of transparency than the law (especially data protection law) currently requires. These requirements are naturally different for every company, as there are no universal ethics for AI. In practice, it is ultimately all about the expectations that the various stakeholders (employees, customers, the public, shareholders, etc.) of a company have as to how it should behave in certain matters. Each company must discuss, establish and define for itself what is appropriate here. What may be expected from a large corporation is not necessarily required for a start-up or SME. Advice on how to operationalize AI ethics in the context of a compliance system this can be found here (only in German) and a webinar here; both relate to data ethics, but the approach is the same in the case of AI.
We have put together the most important points from all three areas in 11 principles. These include not only guidelines on how AI can be used correctly in the company, but also measures to ensure compliance with the rules and the related management of risks (we will address the assessment of the risks of AI projects and issues of AI governance in further articles in this series, i.e. the procedures, tasks, powers and responsibilities that should be regulated in a company to keep developments and related risks under control).
These 11 principles are:
Each of these principles is described above only in an abbreviated manner. For each of them, we explain in a separate paper for our clients what this means in more detail and in more specific terms and how the company should behave accordingly and why. We have described the individual underlying legal sources with references to the applicable Swiss law, the GDPR and the draft of the AI Convention so that it is clear what already applies today and what is still to be expected. The AI Act will follow.
The paper can be obtained from us. We use it when we work with our clients in workshops to develop their own AI frameworks and regulations, i.e. it serves as a basis for an internal discussion about the appropriate guidelines that the company wants to set for its own use of AI in everyday life and in larger projects. For such a discussion, we recommend holding a workshop with various stakeholders in the company in order to define a common understanding of the use of AI in the company. This is important because, in our experience, guidelines are needed according to which AI projects are implemented and also to ensure predictability for those who want to carry out these projects. Our paper can then be incorporated directly into a more detailed directive or strategy paper with the necessary adjustments. This usually occurs in three steps:
Of course, the standards and rules include not only substantive issues (i.e. which behavior, functions or other aspects should be allowed in the context of AI projects), but also formal issues (i.e. how can AI projects be assessed and approved as quickly as possible in terms of law, safety and ethics). We already cover them in our 11 principles.
Alongside these regulations for AI projects, an organization should not simply prohibit its employees from using AI tools, but should actively make them available where possible. In this way, it can control and regulate their use much better. As we showed in part 2 of our blog series, even the popular tools come in very different flavours, for example in terms of data protection, and a company must check very carefully what it offers to its employees (click here for part 2 of our blog series).
In our view, a AI policy paper does not have to be complicated. To inspire people, we have created a template AI directive for all employees that only takes up one page. It contains a summary of the 11 principles on the one hand, and on the other hand it instructs employees which AI tools they are allowed to use in the company and for which purposes and also, above all, with which categories of data (here, data protection as well as confidentiality obligations, own confidentiality interests and copyright restrictions on the use of content must be taken into account). Alongside this, we provide employees with only three core rules for using these AI tools:
This policy complements the short video that we presented in Part 1 of this series, which is available for free in three languages (see here).
This article is part of a series on the responsible use of AI in companies:
We support you with all legal and ethical issues relating to the use of artificial intelligence. We don't just talk about AI, we also use it ourselves. You can find more of our resources and publications on this topic here.