Part 4: What Companies Owe the People They Affect
Responsible AI and Social/Cultural Acceptance: A Series

Companies need two different muscles: the RAI discipline (governance structure, bias testing, transparency, human oversight, incident response…table stakes at this point) and a genuinely separate acceptance-building practice. A few concrete, often-skipped pieces of the second muscle:
Build an AI operating model, not just an AI policy. Ownership needs to be explicit: who approves high-risk use cases, who monitors deployed systems, who handles incidents, who talks to regulators or the public when something goes wrong. If the answer is "everyone," the real answer is "no one."
Maintain an actual AI inventory. This sounds obvious and rarely happens. AI enters organizations through procurement, shadow IT, embedded vendor features, and everyday employee adoption…not just deliberate build decisions. Without an inventory (owner, purpose, data used, people affected, risk tier, oversight requirements), you can't govern what you don't know exists.
Extend governance to vendors. "We didn't build the model" is not a defense your customers will accept. They experience your decision to deploy it, regardless of who built it. That means real vendor questions: what data trained this, where does our data go, is it used for further training, what audit rights do we have, can the system be disabled if something goes wrong.
Stand up AI incident management, the same way you already have one for cybersecurity! Covering harmful outputs, discriminatory outcomes, data leakage, model drift, and unauthorized use. The goal isn't pretending AI will never fail; it's making sure failures are detected, contained, learned from, and corrected.
Build a culture where employees can say "this creates too much risk" without being treated as obstacles to innovation. A company that only rewards deployment velocity quietly incentivizes people to stop flagging risk. A company that rewards spotting both opportunity and risk innovates more sustainably.
Start measuring acceptance, not just performance. Alongside accuracy, bias, and uptime, track trust (do affected users trust the system?), comprehension (do people understand what it's doing?), agency (do people feel they have meaningful choices?), perceived fairness, contestability, and actual adoption. These aren't traditional engineering metrics, but they often determine whether a system succeeds or gets quietly abandoned or publicly rejected.
Run the publicity test before deployment. Would you be comfortable explaining this specific use of AI publicly, in plain language? If the honest answer is no, that discomfort is data and it usually means there's a deeper problem worth resolving before launch, not after.



Comments