Create your own
Lesson illustration

Inferring Corporate Responsibility Boundaries in AI Ethics Statements

Hello, and welcome to the first lesson of the course. We will build toward a thesis that can examine how AI companies define “ethical AI,” communicate safety and responsibility, and potentially gain legitimacy through those communications. This first module establishes a necessary foundation: ethical AI is not simply a fixed technical checklist. It is a contested set of claims about harms, values, power, and responsibility.

Today’s focus is especially important for your proposed research questions. An AI ethics statement does not merely declare values such as fairness, safety, or transparency. It also draws a boundary around what the company accepts responsibility for, who else is expected to act, which harms count, and which questions remain outside the statement. By the end, you will be able to infer that constructed boundary systematically—without prematurely assuming that a company is either sincere or “ethics-washing.”


Corporate responsibility is a boundary, not a slogan

Consider two statements:

“We develop AI that is safe, fair, and transparent.”

“We assess foreseeable harms before release, publish limitations for intended uses, monitor serious incidents, and require high-risk customers to follow specified safeguards.”

Both may sound responsible. But the second tells us far more about the company’s claimed responsibility. It identifies activities, moments in the lifecycle, a class of harms, and at least some responsibility allocated to customers.

For analysis, treat corporate responsibility as an answer to six connected questions:

DimensionAnalytical questionWhat the statement may reveal
ActorWho is said to be responsible?The company, executives, engineers, customers, users, suppliers, governments, or “society.”
ObjectResponsible for what?A model, product, deployment, user outcome, data practice, or wider social impact.
LifecycleAt what stage does responsibility apply?Design, training, release, deployment, monitoring, incident response, or retirement.
Harms and valuesWhich risks count as ethical concerns?Bias, safety, privacy, security, misuse, human rights, labour, environmental costs, or political harms.
AuthorityWho has the power to decide, stop, alter, or limit use?Product teams, an ethics board, executives, customers, regulators, or affected communities.
AccountabilityWho must explain decisions, provide evidence, remedy harm, or face consequences?A named internal team, a customer, an external auditor, a regulator—or no one clearly.

The key word is constructed. You are analysing how responsibility is represented in communication, not yet establishing how responsibility operates in practice. That distinction will protect your future thesis from overclaiming.

A company can construct responsibility expansively—for example, by claiming obligations across the whole lifecycle and toward affected communities. Or it can construct it narrowly, perhaps presenting itself as responsible for the technical model but treating downstream deployment, social consequences, and remedy as someone else’s problem.


A benchmark: responsibility in a sociotechnical AI system

NIST’s AI Risk Management Framework is useful here not as a universal moral authority, but as a relatively detailed benchmark against which corporate claims can be read. It treats trustworthy AI as a set of context-dependent, interconnected characteristics: validity and reliability, safety, security and resilience, accountability and transparency, explainability and interpretability, privacy enhancement, and fairness with harmful bias managed.

NIST’s AI Risk Management Framework depicts AI risk management as a recurring cycle of Map, Measure, and Manage, with Govern at its centre. For corporate-communication analysis, it highlights that responsibility should extend beyond a one-off ethical principle to ongoing organisational governance across the AI lifecycle.

Artificial Intelligence Risk Management Framework (AI RMF 1

Read the selected pages of NIST’s Artificial Intelligence Risk Management Framework (AI RMF 1.0) as a benchmark for what a relatively expansive account of AI responsibility can include. Focus less on memorising every category and more on noticing how the Framework distributes responsibility across organisations, deployers, and affected people.

Begin with Section 3, “AI Risks and Trustworthiness,” on pp. 11–17. Read the overview and scan the subsections on safety, accountability and transparency, privacy, and fairness. Pay particular attention to context and tradeoffs: the Framework does not treat ethical AI as a single universal technical property. Then read Section 5.1, “Govern,” on pp. 20–23, including Table 1 and its continuation. Start with the role of governance. Notice the concrete expectations: policies, named roles, executive responsibility, monitoring, feedback, third-party risk, and safe decommissioning. Finally, return to the “Audience” section on pp. 8–10. Read the discussion of lifecycle actors and affected communities, especially collective responsibility. Ask which of these actors a corporate statement treats as decision-makers, advisers, users, or merely recipients of harm.

Two implications matter for your analysis.

First, AI responsibility is distributed, but it should not become diluted. Developers, deployers, buyers, users, suppliers, regulators, and civil-society actors can all have relevant duties. Yet a company should not be able to avoid responsibility simply by saying “AI is everyone’s responsibility.” Responsibility ought to track a party’s control, resources, expertise, foreseeable influence, and ability to prevent or remedy harm.

Second, responsibility is sociotechnical. A claim limited to technical accuracy, model robustness, or cybersecurity may matter greatly, but it cannot by itself cover questions such as whether the system should be used in a particular setting, who bears errors, whether an affected person can challenge a decision, or whether the deployment worsens an existing inequality.


From shared responsibility to accountable responsibility

A frequent corporate formulation is that responsible AI requires cooperation: developers must build responsibly, customers must deploy responsibly, and users must use systems appropriately. This can be accurate. It can also obscure who is actually empowered to decide.

IBM Technology’s short explanation of responsible AI makes this tension visible. It is a corporate educational video, so approach it as an example of a company articulating a governance model—not as independent proof that such a model is implemented everywhere.

What is Responsible AI? A Guide to AI Governance

Watch IBM Technology’s “What is Responsible AI? A Guide to AI Governance.” It usefully distinguishes a broad cultural aspiration from concrete accountability: named authority, resources, inventorying systems, training, and governance procedures.

Watch the accountability problem, where the speaker contrasts “nobody” and “everybody” being responsible with identifiable ownership. Then watch law and ethics for the claim that legal compliance can be insufficient when systems still cause harm. Finish with governance leadership, focusing on the proposed role, authority, budget, and cross-functional reach of a responsible-AI leader.

The video gives you a practical test for corporate statements:

  • A phrase such as “we are committed to responsible AI” describes a value.
  • A phrase such as “a named executive can halt deployment, has a budget, reports to senior leadership, and oversees incident review” describes a governance arrangement.
  • A phrase such as “customers are responsible for their use of our tools” allocates part of the burden outward. It becomes analytically important to ask what the company still controls: product design, access restrictions, contractual terms, documentation, monitoring, refusal of certain sales, and support for redress.

A company can reasonably distinguish between developer responsibility and deployer responsibility. For example, a general-purpose model provider may not control every customer’s application. But its statement becomes narrower when it treats downstream impacts as wholly external despite retaining meaningful control over product capabilities, pricing, distribution, safeguards, or eligibility.


A practical method for inferring a responsibility boundary

When you collect corporate materials later in the course, avoid coding an entire webpage as simply “ethical” or “not ethical.” Instead, isolate a meaningful unit: one sentence, paragraph, policy clause, or product-documentation section that makes a responsibility claim.

Use the following five-pass method.

1. Locate the ethical object

Identify what the statement calls “AI” and what is covered by the promise.

A company may refer to:

  • a foundation model;
  • a customer-facing product feature;
  • its own internal use of AI;
  • customer deployment of its tools;
  • an entire AI ecosystem.

This distinction is consequential. “We build safe models” places the focus on the technical artefact. “We seek safe outcomes in high-impact deployments” extends concern toward the social setting in which the artefact is used.

2. Mark agents and verbs

Underline who performs the action. Corporate language often conceals agency through passive phrasing:

  • Active and specific: “We test models before deployment and investigate reported incidents.”
  • Passive and vague: “Risks are carefully considered.”
  • Responsibility shifted outward: “Customers must ensure their use complies with applicable law.”
  • Responsibility transferred to an abstraction: “Society must decide how AI should be governed.”

Then classify each actor’s role:

RoleTypical wordingMeaning for boundary analysis
Decision-maker“We prohibit,” “we approve,” “we halt”The actor claims authority and control.
Implementer“Teams apply,” “customers configure”The actor carries out decisions or safeguards.
Adviser“Experts inform,” “stakeholders provide input”The actor may influence decisions without deciding.
Affected party“Users benefit,” “communities may be impacted”The actor is recognised as affected but may have no power.
External guarantor“Regulators set rules,” “auditors assure”Responsibility is located outside the company.

Recognition is not the same as empowerment. A statement may acknowledge affected communities while offering no mechanism for those communities to contest, revise, or halt a deployment.

3. Trace the lifecycle

Ask where responsibility begins and ends. A narrow statement may focus on pre-release model testing. A more expansive statement may include training-data choices, product design, deployment constraints, post-deployment monitoring, incident response, complaint handling, remediation, and retirement of a system.

The boundary is especially visible at handoff points:

  • developer to customer;
  • company to third-party data or model provider;
  • system output to human decision-maker;
  • voluntary company governance to public regulation;
  • one-time pre-release assessment to continuous monitoring.

Your experience of service blueprints can be helpful here. A responsibility boundary works rather like a boundary between frontstage and backstage service processes: the public-facing promise may look seamless, while critical decisions and handoffs occur elsewhere. In AI communication, map the handoffs rather than assuming that the organisation named in the statement controls the entire service journey.

4. Identify recognised harms—and meaningful silences

Do not treat an omission as proof that a company does not care. Corporate documents are written for specific audiences and purposes. But omissions still shape the ethical world that the text constructs.

For instance, a statement might make safety, security, and malicious misuse highly visible while saying little about:

  • discriminatory allocation of resources;
  • accessibility and digital exclusion;
  • worker surveillance or labour conditions;
  • environmental impacts;
  • political manipulation;
  • surveillance, policing, or military applications;
  • remedy for people harmed by an AI-supported decision.

The relevant question is not, “Did the company list every conceivable risk?” It is, “Which harms are made central, which are peripheral, and which fall outside this account of responsibility?”

5. Look for accountability rather than aspiration alone

A responsibility claim becomes more operational when it identifies mechanisms that could make the company answerable. Look for:

  • a named owner, committee, or executive;
  • decision rights, escalation routes, and authority to stop a release;
  • documented policies or use restrictions;
  • evaluation methods and their limits;
  • independent review, external audit, or stakeholder challenge;
  • monitoring after deployment;
  • incident reporting and remedies;
  • transparent disclosure of tradeoffs, uncertainty, and failures.

These are not automatic proof of substantive governance. They are evidence that a statement constructs a broader and more testable responsibility boundary than a pure values declaration does.


Reading narrowness critically, without jumping to intent

Critical scholarship warns that corporate ethics can become a language of self-regulation, reputation protection, and depoliticisation. This critique is relevant because a statement may present manageable technical improvements as a complete response to deeper political or structural problems.

SciOpen From Ethics Washing to Ethics Bashing: A Moral Philosophy View ...

Read Elettra Bietti’s discussion as a critical lens for analysing the limits of corporate ethics programmes. The aim is not to label every corporate ethics claim as deceptive. It is to develop precise questions about whether ethics communication narrows what can be contested and what remedies appear possible.

In Section 8, “A Critique of Ethics Washing from Within Moral Philosophy,” pp. 276–279, begin with the three-part critique. Follow the first and second arguments, particularly the discussion of internal constraints on ethics work and the difficulty of challenging an employer’s business model from within. Then read the final argument, beginning with the legitimacy-buffer concern. Focus on the claim that ethics rhetoric can redirect attention from structural questions toward narrower, procedural, or technically fixable issues.

Bietti’s argument suggests three warning signs of a narrow responsibility boundary:

  1. Ethics is confined to what preserves the existing business model.
    The company promises to reduce bias or improve documentation but rules out questioning whether a system should be sold, deployed, or used in a particular domain.

  2. The company controls both the ethical process and the final decision.
    An internal board or advisory group may have value, but the key question is whether it can influence high-stakes decisions, challenge leadership, or make its reasoning public.

  3. Ethics language makes alternatives harder to imagine.
    A statement can frame the issue as one of better safeguards, making public regulation, non-deployment, restrictions on certain use cases, or structural redistribution of power seem unnecessary or unrealistic.

These are interpretive concerns, not findings about intent. In a thesis, write cautiously:

  • Stronger: “The statement constructs the company as responsible for technical mitigation while leaving the legitimacy of the underlying deployment largely unaddressed.”
  • Weaker and usually unjustified from communication alone: “The company deliberately uses ethics to deceive the public.”

The first claim is grounded in text. The second requires evidence about motives and internal decision-making that corporate communication by itself rarely provides.


Worked close reading: who should govern AI?

The following interview segment gives you a short, real corporate-facing communication artifact. Sam Altman is speaking as OpenAI’s CEO, but an interview statement should not automatically be equated with a formal company policy. It is still useful for analysing how corporate leadership publicly constructs responsibility.

OpenAI CEO Sam Altman on AI governance, ethics, and innovation | A conversation with BiGS

Watch the selected segment of Harvard Business School’s conversation with OpenAI CEO Sam Altman. Treat it as a close-reading example of how a frontier-AI leader distributes authority between the company, government, and people affected by AI.

Watch governance and public voice. Note three elements: the rejection of the idea that OpenAI alone should set its own rules; the claim that people most affected by technology should have a strong voice in governance; and the unresolved issue of how collective preferences would be balanced with safeguards for minorities and rights.

A compact boundary analysis of this segment could look like this:

DimensionInference from the communication
Company authorityOpenAI is not represented as the sole legitimate setter of AI rules; unilateral self-governance is explicitly questioned.
External actorsGovernment, society, users, and especially people most affected by technology are positioned as relevant governance actors.
Ethical objectThe focus is broad: governance of AI systems and their alignment with human values, rather than a single product feature.
Responsibility allocationResponsibility is distributed across corporate developers, public institutions, and affected people.
Boundary left unclearThe statement does not specify representation, how affected groups would be identified, whether participation is binding, how minority rights would be protected, or which corporate decisions remain non-negotiable.
Appropriate conclusionThe communication expands the rhetorical circle of legitimate participants, but leaves the institutional mechanism of accountability underspecified.

Notice the analytical discipline here. The conclusion is neither “this is clearly ethical” nor “this is clearly ethics-washing.” It identifies an expansive principle—affected people should have a strong role—and an underspecified operational boundary—how that role changes actual corporate decision-making.


A compact coding memo for your future corpus

For each AI ethics statement, create a short responsibility-boundary memo. It can be only five to eight sentences, but it should include these fields:

  1. Claim: Copy or accurately paraphrase the ethical/responsibility claim.
  2. Responsible actor: Identify who is active, who advises, who is affected, and who is absent.
  3. Scope: Specify the AI system, use case, lifecycle stage, and harm categories covered.
  4. Control and mechanisms: Record concrete tools such as policies, evaluations, monitoring, use restrictions, governance bodies, or remediation.
  5. Boundary inference: State what the company accepts, shares, delegates, or leaves unaddressed.
  6. Evidential caution: Note whether this is a claim about communication only or whether evidence of implementation is supplied.

A useful sentence template is:

“This statement constructs the company as responsible for ___ during ___, primarily in relation to ___ harms. It assigns ___ to customers/regulators/users, while leaving ___ unclear or outside the stated scope. The claim is supported by ___ mechanisms, although the text does not establish ___.”

This format will later make comparisons across OpenAI, Anthropic, Microsoft, and different audiences much more defensible.


Key takeaways

Corporate AI ethics communication is boundary work. It defines not only values but also:

  • which actors are responsible and which merely participate;
  • which parts of the AI lifecycle are covered;
  • which harms become ethically visible;
  • who has the authority to make decisions;
  • whether responsibility is backed by accountability, evidence, remedy, and meaningful external input.

Distributed responsibility can be appropriate in AI systems, but it is not the same as diffuse responsibility. Pay particular attention to handoffs between developer, deployer, user, third-party supplier, regulator, and affected community. A statement that celebrates collaboration while leaving control, authority, and remedy vague may construct a narrower responsibility boundary than its ethical language initially suggests.

In the next lesson, we will move from analysing a company’s ethical claims to applying consequentialist and duty-based reasoning to an AI deployment scenario. That will give you normative tools for evaluating what is ethically at stake before examining how companies frame it.

Can't find a good explanation? Sign up and we'll make it for you

Sign up