When a firm publishes its AI ethics principles, is it building guardrails — or building a defence against being regulated?
The module's set case is EY's “responsible AI transformation,” taught with IBM's governance framing. This case teaches the examinable governance content — and audits the case the way the course teaches you to audit everything.
EY case: EY.ai (US$1.4B), the EYQ assistant, AI-powered audits and talent management, governed by AI Principles and an Ethics Review Board. The five reflection questions: client privacy/security; preventing algorithmic bias; transparency to build trust; the role of top managers; balancing efficiency with ethics.
AI governance (IBM video) = guardrails for responsible AI. Four risks: bias (latent in human data), privacy/copyright (data seeps into outputs), lack of transparency (black-box vs glass-box), model deterioration (needs continuous monitoring). Regimes: NIST AI RMF (Govern/Map/Measure/Manage) and the EU AI Act (penalties for non-compliance).
Four AI-governance risks: bias, privacy/copyright, transparency, model drift. Two regimes: NIST (guidance), EU AI Act (law with teeth).
The course's EY narrative cites a single EY URL and lists four principles; EY actually publishes nine Responsible AI principles. “EY Helix” is EY's audit-analytics platform and pre-dates the AI branding. And the reputational context the case omits: the US$100M SEC fine (2022) for ethics-exam cheating, with PCAOB audit-deficiency rates around 37% (2023) improving to 28% (2024).
Voluntary “AI principles” and internal ethics boards can become ethics-washing — the appearance of governance without external accountability. The counterweight is enforceable regimes. Note the live update the deck can't have: under the EU's 2026 Digital Omnibus, the AI Act's high-risk obligations were postponed to December 2027 — so any claim they bite in August 2026 is now out of date.
Self-written principles are a start, not a safeguard. The question for any “responsible AI” claim is: who audits it, and what happens if it's breached?
Name IBM's four AI-governance risks and the two governance regimes.
What does auditing the EY case reveal?
What 2026 change affects the EU AI Act timeline?