AI sits on the board: from experiment to corporate governance
Artificial intelligence is no longer a topic confined to innovation labs or technical teams; it has taken center stage in the business discourse. The Madrid Bar Association (ICAM) hosted today the conference 'Towards Responsible AI: Governance, Trust, and Responsible Management under ISO/IEC 42001', an event that gathered legal professionals, businesses, and technology specialists to address a challenge that is no longer solely technological but also pertains to regulatory compliance, oversight, and corporate governance.
Among the participants in the conference were Alejandro Touriño, president of the TIC Section of ICAM; Jesús Heredero; Irene Agúndez from Iberdrola; Miriam Oñoro from Banco Santander; representatives from Amadeus; and specialists from Numintec, SesameHR, and the Institute of Knowledge Engineering, in a meeting that confirmed that AI governance is now a central part of the corporate agenda.
The event stems from a growing conviction in legal and business circles: artificial intelligence has entered a phase of organizational maturity. As Alejandro Touriño, president of the TIC Section of ICAM, summarizes, 'artificial intelligence is no longer the future. It is the present.' This present, he warns, requires a shift from enthusiasm to responsibility, from isolated pilot projects to genuine integration into the governance structures of companies.
Touriño clearly outlined the change in landscape: just two years ago, the debate centered on whether companies should use AI; subsequently, the conversation focused on its ethical implications; now, the key question is different. 'We have moved from experimentation to corporate governance, from pilot projects to large-scale implementation, and from enthusiasm to responsibility,' he asserts. This evolution means that the conversation must shift from being purely technological to becoming a governance issue, with a direct impact on management bodies and legal advisory teams.
The key issue is no longer simply deploying tools, but rather knowing who is responsible when a system makes a mistake, how to oversee the AI assistants already used by staff, how decisions are documented, and how regulatory compliance is demonstrated. For Touriño, 'the conversation is no longer about technology but about governance.' This shift opens up a particularly relevant area for the legal profession, which must apply the accumulated experience in corporate governance, data protection, cybersecurity, and regulatory compliance to artificial intelligence.
Along the same lines, the approach highlighted throughout the ICAM conference is that an organization cannot transfer to an algorithm a responsibility that belongs to it. European regulation and management norms precisely advocate this direction: identifying systems, classifying risks, assigning responsibilities, reviewing decisions, and leaving verifiable proof of compliance.
The first round table, dedicated to the transition 'from the AI Act to corporate governance', focused on translating the European Regulation on Artificial Intelligence into the internal practices of companies. In highly regulated sectors, the challenge lies not necessarily in creating a parallel architecture but in integrating AI into existing mechanisms of inventory, oversight, risk management, and internal control. In other words, the objective is to avoid managing artificial intelligence as a silo within the organization.
The second round table, focused on 'implementation' and the architecture of controls, highlighted the role of ISO/IEC 42001, described as the first international reference standard for artificial intelligence management systems.
The value of this standard lies in its ability to facilitate the establishment, implementation, maintenance, and continuous improvement of an AI management system, a crucial step in transforming general principles into verifiable internal processes.
In this context, the concept of 'responsible AI' ceases to be a rhetorical phrase and begins to be measured in terms of concrete procedures. Systems inventories, risk assessments, traceability, human oversight, supplier controls, and periodic review of decisions are part of a single trust infrastructure. It is no coincidence that the conference emphasizes the linkage of AI governance with other established disciplines, such as data protection, information security, or regulatory compliance.
Touriño summarized this change with a phrase that also serves as a strategic warning. 'Companies that use more AI will not succeed. The winners will be those capable of demonstrating that they use it better: responsibly, explainably, auditable, and securely.' This statement shifts the focus of competition: the advantage will no longer solely reside in the adoption of technology but in governing it judiciously and with evidence.
This is, ultimately, the message that underpins the ICAM conference. Artificial intelligence has ceased to be an abstract promise and has become a reality that demands standards, structures, and responsibility. And in this new era, trust is no longer taken for granted: it must be earned.
Continue reading the article at Cinco días