- Most organisations have an AI ethics policy and almost none actively manage AI ethics. A 2021 framework, the Ethical Management of AI, reframes it as a leadership practice rather than a document.
- The gap is not intent but management. As AI takes on more autonomous decisions that affect real people, managers get little practical support for handling the ethics day to day.
- Recognition is not action. Stanford's 2025 AI Index found organisations widely name AI's risks, with 64% citing inaccuracy, 63% regulatory compliance and 60% cybersecurity, yet not all of them act.
- Ethics shows up in the ordinary: who a model rejects, what it optimises, whose data it uses. The framework puts three lenses on it: the manager's decision, the ethical considerations, and the wider environment.
- Treat ethics as a capability you build and practise, not a principle you publish. It is becoming a trust asset, not a compliance cost.
The AI ethics policy you approved is real. It is on the intranet, and it has the right words in it: fairness, transparency, accountability, human oversight. And yet, if you are honest with yourself, you could not say who actually applies it in the moment a model quietly declines a loan, ranks one candidate above another, or decides what a customer sees. The values are written down. The decisions are happening somewhere else, made by people and systems who have very likely never opened the document.
Here is the distinction that matters. Having AI ethics and managing AI ethics are different things, and almost every organisation has done the first without the second. A 2021 paper in the journal Sustainability makes the point precisely: as AI is granted more autonomy over decisions that influence individuals and societies, managers who want to embed ethical thinking receive very little practical support for how to do it, even as everyone agrees it matters. Its answer is a framework, the Ethical Management of AI, that treats ethics as an active management practice built from three perspectives: the decision in front of the manager, the ethical considerations at stake, and the wider environment shaping both. Ethics, in that light, is something you do, repeatedly, not something you sign once.
Why does an AI ethics policy change so little on its own?
Because a policy names values; it does not make decisions. And the ethical weight of AI lives in ordinary, distributed choices: which applicants a hiring model advances, what a recommendation engine is told to maximise, whose data trains it and who was never asked. A statement on the intranet does not reach those moments, because nobody consults a principle mid-workflow.
The evidence for the gap is stark. Stanford's 2025 AI Index found organisations broadly recognise the risks, with 64% naming inaccuracy, 63% regulatory compliance and 60% cybersecurity, yet not all of them take active steps to address what they name. Recognition without management is exactly where harm hides, and it is the same shape as why so many AI strategies quietly fail: the intent is sound, and the operating practice underneath it is missing.
What does it look like to manage AI ethics, not just declare it?
It looks like a small set of habits, practised on the real decisions rather than described in the abstract. The framework's three lenses translate into things a leader can actually do.
- Name an owner for every consequential AI decision. Deloitte found only 21% of organisations have a mature model for governing autonomous AI, so start where most have not: a named human accountable for each material decision the system makes.
- Look before you assume. Audit what a model learned from. Amazon's recruiting AI excluded women because it trained on a decade of mostly male CVs, and nobody examined that history until the damage was visible.
- Decide what is genuinely at stake, explicitly. Name which considerations apply to each use, whether fairness, privacy, transparency or dignity, rather than gesturing at "responsible AI" and moving on.
- Read the environment. Regulators, your market and your own people all set expectations, and ethical management aligns to them on purpose. These are precisely the questions a board should be asking before an incident forces them.
- Make it recurring. Review the ethics of your AI on a cadence, the way you would a financial control, rather than signing it once and filing it. Systems drift; a model that was fair in March can be quietly unfair by June.
Move from an AI ethics policy to an ethics practice
The AI Strategy Session helps you turn stated principles into the small set of decisions, owners and reviews that make AI ethics real in the day-to-day, in ninety minutes.
Book your Strategy SessionWhy is this a leadership question rather than a compliance one?
Because compliance asks whether you wrote the policy, and leadership asks whether you live it. The distinction is not pedantic. AI has moved ethical choices out of the annual review and into thousands of automated decisions a day, and no compliance function can be present for all of them. What can be present is a culture in which the people building and running these systems know which questions to ask and feel expected to ask them. That is made, not mandated.
It also connects to something quietly practical. The scarce human skill in an AI-saturated business is judgement, the ability to tell a technically valid answer from a right one, which is the same reason you cannot out-hustle the machine. Managing AI ethics is judgement made routine, and it compounds in the same way trust does.
Having AI ethics and managing AI ethics are different things. One is a document. The other is a decision you make, again and again, when it counts.
What does this ask of me as a leader this quarter?
It asks for coherence, the alignment between what you say you value and what your systems actually do. An organisation becomes what it repeatedly does, not what it publishes, so if the ethically loaded decisions happen unmanaged, your real values are simply whatever the models default to. Managing AI ethics is how your stated values and your actual behaviour stay in one piece, and it is the difference between a principle that reassures and a practice that protects.
The reward is not only avoided harm. The organisations that people come to trust to act well with AI, staff, customers and regulators alike, are the ones who will be trusted with more of it. The policy was the easy part. The practice is the leadership, and it is available to start this quarter, one owned decision at a time.
| Source | Finding on managing the ethics of AI |
|---|---|
| Brendel et al., Sustainability (2021) | Proposes the Ethical Management of AI framework across three lenses, managerial decision-making, ethical considerations and the macro and micro environment; finds managers get limited support to actually manage AI ethics |
| Stanford HAI, 2025 AI Index | Organisations widely recognise AI risks (inaccuracy 64%, regulatory compliance 63%, cybersecurity 60%) but not all take active steps to address them |
| Deloitte, State of AI in the Enterprise (2026) | Only 21% of organisations have a mature governance model for autonomous AI agents |
| Dastin (2018), reported | Amazon's recruiting AI down-ranked women after training on a decade of mostly male CVs, and was discontinued |
Frequently asked questions
Isn't an AI ethics policy enough?
How do you actually manage AI ethics day to day?
Why is AI ethics a leadership issue and not just compliance?

About the author
British technology futurist, AI keynote speaker and advisor. Thirty years across enterprise technology and AI strategy, helping leaders navigate the future of work. The futurist who died.