AI Is Now a Business & Human Rights Issue. Are Corporate Governance Frameworks Catching Up?


For some time, the business conversation around artificial intelligence has been dominated by innovation, productivity, cybersecurity and data protection. But as AI becomes part of how companies make decisions, another issue is becoming harder to ignore: what happens when those decisions affect people’s rights?
On 7 September, UN High Commissioner for Human Rights Volker Türk warned about the risks posed by advanced AI, the concentration of power over its development and the need for stronger safeguards and internationally agreed red lines. It is an important intervention but businesses don’t need to wait for some future version of AI to start thinking about human rights. The issue is already here. Companies are using AI to recruit people, monitor workers, assess performance, evaluate suppliers, interact with customers and support decisions that can have very real consequences for the people affected by them. The technology may be new. The responsibility that comes with using it isn’t and this is where there is a gap.
Many companies have already put some form of AI governance in place. There are policies, technical controls, cybersecurity assessments, data protection requirements and legal reviews. What is much less clear is whether those arrangements are actually looking at AI through the lens of its impact on people. Take recruitment. A company buys an AI-enabled recruitment system. Procurement assesses the supplier, IT looks at security and integration, Legal considers the contract and data protection, while HR looks at whether the system does what it was bought to do. All seems perfectly reasonable but the fact that a system works doesn’t tell us whether it treats people fairly. Could it disadvantage certain candidates? What was the system trained on? Does the company understand how recommendations are being produced? Can somebody challenge a decision influenced by it? And if there is a discriminatory outcome, is the company prepared to take responsibility for it, or does responsibility disappear somewhere between the company and the technology provider?
This is where business and human rights has something useful to bring to the AI debate.
We already have a framework for thinking about corporate impacts on people. The UN Guiding Principles on Business and Human Rights ask companies to identify actual and potential human rights impacts, act to prevent or mitigate them and understand whether those actions are working. There is no reason why AI should sit outside that thinking.
Human rights due diligence changes the question from simply whether a company is legally or technically able to use a particular technology to what happens to the people affected when it does. Distinguishing these steps is important because an AI system doesn’t have to malfunction to cause harm. It may perform exactly as designed and still produce an outcome that creates or contributes to an adverse human rights impact. Many may think that this is a simple technology issue but this actually a governance issue.
There is another part of this discussion which deserves more attention: most companies aren’t building the AI systems they use. They are buying them. AI is increasingly embedded in HR software, procurement platforms, customer management systems and other tools businesses use every day. In some cases, companies may not have much visibility at all over how the underlying model works, what information shaped it or where its limitations lie.
For anyone working in business and human rights, this problem should sound familiar.
We have spent years telling companies that outsourcing production doesn’t automatically outsource responsibility for what happens in their supply chains. Buying technology shouldn’t create a different principle. If an AI system affects a company’s workers, customers or other stakeholders, the fact that another company developed the technology doesn’t make the impact irrelevant to the company using it.
That also means procurement has a bigger role here than is sometimes recognised.
Buying AI cannot only be about capability, cost, cybersecurity and data protection. Companies need to know what they are buying. That includes understanding how systems have been developed, what risks have already been identified, how they have been tested, what happens when something goes wrong and whether the promised “human oversight” exists in practice rather than simply appearing in a policy. A contractual clause transferring responsibility to the supplier may manage part of the legal relationship. It doesn’t necessarily manage the human rights risk.
There is also a wider issue. We tend to talk about AI as though it exists somewhere in the cloud, disconnected from the physical economy. It doesn’t. There is a supply chain behind AI: data centres, energy, semiconductor manufacturing, critical minerals and, importantly, human labour. People train models, label data, moderate content and perform other work that remains largely invisible to the end user. So when companies think about AI and human rights, they need to look in both directions: at what happens because they use AI and at what sits behind the AI they are using. Regulation is beginning to catch up. The EU AI Act, for example, recognises that some AI applications can present serious risks to fundamental rights, particularly where systems are used in areas such as employment, education, essential services, migration and biometrics. But there is a danger in waiting for regulation to define the entire perimeter of corporate responsibility. Compliance tells a company what the law requires. Human rights due diligence asks something broader: where could our activities and business relationships affect people, and what are we doing about it?
For boards and senior management, this leaves a fairly immediate governance problem.
AI cuts across organisational structures, IT understands the technology, HR may own workforce applications, procurement manages suppliers, legal and compliance deal with regulatory exposure, sustainability teams may understand impact assessment. The risk sits across all of them, though. If nobody has visibility across those functions, a company can have several perfectly respectable controls and still fail to understand the overall impact of the technology it is deploying. Boards don’t need to become AI specialists. But they do need to know where AI is being used in the business, where it can materially affect people and whether the company has a credible way of identifying and addressing those impacts.
This is why AI now belongs firmly within the business and human rights conversation.
The technology will continue to change, and regulation will continue trying to catch up with it. But the underlying responsibility is not particularly new. Companies need to understand how their decisions affect people. Using AI to make or influence those decisions doesn’t remove that responsibility. If anything, it makes understanding where that responsibility sits more important.
