Business Management Tutor (APA, NO PLAGARISM, GREAT WORK, ON TIME)
T hi s do cu m en t is co py ri gh te d by
th e A m er ic an
P sy ch ol og ic al
A ss oc ia tio
n or
on e of
its al lie d pu bl is he rs .
T hi s ar tic le
is in te nd ed
so le ly
fo r th e pe rs on al
us e of
th e in di vi du al
us er
an d is no t to
be di ss em
in at ed
br oa dl y.
SPECIAL ISSUE ARTICLE
ARTIFICIAL INTELLIGENCE AND ORGANIZATIONAL STRATEGY: ETHICAL AND GOVERNANCE
IMPLICATIONS
Larry W. Norton GeNovo Consulting, Limited Liability Company, Flower Mound,
Texas, United States Naveen Jindal School of Management, The University of
Texas at Dallas
Artificial intelligence (AI) has the potential to impact organizational performance in ways unimagined even a few years ago. Although AI is not new, its rapid advancement has heightened the awareness of its strategic business value concurrent with the ethical implications and potential for harm that AI systems present. The article argues that businesses face ethical dilemmas in parallel with pressure to adopt AI as a business opportunity. It discusses AI’s growing impact on business model innovation, organizational strategy, and operational effectiveness in light of the need for ethical AI systems and practices. Calls for AI governance solutions are mounting and, within organizations, will involve structural, process, and policy considerations likely with ethics as central. These elements are discussed as specialized management practice components unique to AI. Several governance structures and organizational design considerations are discussed as means to enable disciplined, ethical, and responsible AI use. The article concludes with three recommendations for AI deployment that balance ethical considerations with financial profit motives and suggest that the two are not mutually exclusive.
This article was published Online First February 3, 2025. Larry W. Norton https://orcid.org/0000-0002-1755-6449 Larry W. Norton played a lead role in writing–original draft. Correspondence concerning this article should be addressed to Larry W. Norton. Email:
131
Consulting Psychology Journal © 2025 American Psychological Association 2025, Vol. 77, No. 2, 131–141 ISSN: 1065-9293 https://doi.org/10.1037/cpb0000280
A ll
rig ht
s, in
cl ud
in g
fo r t
ex t a
nd d
at a
m in
in g,
A I t
ra in
in g,
a nd
si m
ila r t
ec hn
ol og
ie s,
ar e
re se
rv ed
.
T hi s do cu m en t is co py ri gh te d by
th e A m er ic an
P sy ch ol og ic al
A ss oc ia tio
n or
on e of
its al lie d pu bl is he rs .
T hi s ar tic le
is in te nd ed
so le ly
fo r th e pe rs on al
us e of
th e in di vi du al
us er
an d is no t to
be di ss em
in at ed
br oa dl y.
What’s It Mean? Implications for Consulting Psychology
Artificial intelligence (AI) applications are becoming increasingly ubiquitous in organizations, prompting questions ranging from its importance to business strategy to its risks and responsible and ethical use. This article discusses AI’s function as a strategic necessity in today’s business organizations. It presents emerging forms of organizational governance structures as vehicles for disciplined decision-making for responsible and ethical AI use.
Keywords: artificial intelligence, business strategy, ethics, governance
Technological innovation has impacted human beings and their societies for millions of years. Since the StoneAge through the InformationAge, technological innovation has brought about social and economic change. It has improved human lives and advanced the collectivewell-being of the societies where people live and work (Ali et al., 2021). Indeed, the next technological evolution has arrived with artificial intelligence (AI), which some have characterized as the Fourth Industrial Revolution (Malomane et al., 2022). Unlike the technology of yesteryear, AI developments are proceeding much faster than previous innovations (Robles & Mallinson, 2023), profoundly disrupting domains ranging from economics to medicine, education, business, government, and others that humans depend on in modern society.
Thus, many refer to AI as a general-purpose and transformative technology because of its pervasive and far-reaching potential to shape much of what individuals experience in their personal and work lives (Crafts, 2021). Avoiding its impact is increasingly improbable. As such, questions about how AI will impact humans individually or through groups and organizations for better and worse are mounting. Calls for its regulation and governance—much of this ethically based—are growing, primarily driven by the potential to harm individuals and society.
Yet AI’s ability to disrupt business environments presents opportunities to create new business models and to improve legacy ones in equal measure. Consequently, new opportunities, as well as risks, emerge. This article explores AI’s impact on business models, strategy, and operations and argues that organizations using or intending to use AI must establish a new discipline of governance, risk management, and ethicality as essential elements of its responsible use.
AI’s Growing Importance to Business Organizations
Understanding AI’s impact on business organizations is in its infancy. Large platform-based technology companies (e.g., Google, Microsoft, Amazon, Uber) and large organizations (e.g., Capital One) are leading the way. However, most are still discovering how, where, and when to adopt AI, which is evolving. Important questions companies should ask at the outset are relatively straightforward and necessary: “How can AI help us differentiate our business from the competition?”How can it be used to make us more efficient?” “Where do we start?” “How do we use AI ethically and responsibly to avoid harm yet drive business value?” These questions are about running a business with AI and not about developing a strategy for AI. Both topics are important, but this article focuses on the former.
Although answers to these questions are as varied as the organizations that need to ask them, when vetted, they create focus. For example, establishing competitive differentiation might suggest using AI to give customers more value for their patronage than the competition (e.g., as large financial services companies did with AI-driven fraud detection). The need for efficiency, for example, might suggest using AI to screen job candidates, saving administrative time, or automating the use of hospital surgical suites to optimize asset productivity. Knowing where to start means identifying a business problem where AI presents a practical solution, and not all problems are appropriate for AI. Building a governance system means ensuring ethical and responsible practices are managed in parallel with value creation. Terms such as “AI first” and “AI-fueled” are increasingly part of strategy discussions, meaning that AI is becoming a key element of strategic planning processes and further underscoring its importance (Davenport & Mittal, 2023). The fundamental objective for a company is knowing where
132 NORTON
A ll
rig ht
s, in
cl ud
in g
fo r t
ex t a
nd d
at a
m in
in g,
A I t
ra in
in g,
a nd
si m
ila r t
ec hn
ol og
ie s,
ar e
re se
rv ed
.
T hi s do cu m en t is co py ri gh te d by
th e A m er ic an
P sy ch ol og ic al
A ss oc ia tio
n or
on e of
its al lie d pu bl is he rs .
T hi s ar tic le
is in te nd ed
so le ly
fo r th e pe rs on al
us e of
th e in di vi du al
us er
an d is no t to
be di ss em
in at ed
br oa dl y.
to improve its value proposition, help it grow, be more effective, or differentiate itself in the marketplace with AI.
AI’s designation as a general-purpose technology means that hundreds of business uses exist, ranging from operational cost reductions to, preempting cyberattacks, improving new product time-to- market, managing the workforce, and many proliferating others. Some are ethically benign, and others are fraught with concern (Deloitte Artificial Intelligence Institute, 2022). The arrival of foundational generative AI models has expanded use case possibilities considerably, suggesting that most companies will find it difficult not to build AI into their strategic planning discussions despite the risks involved. Table 1 illustrates example use cases and some of the advantages and disadvantages delineated by level of risk. In this context, risk can potentially impact humans adversely to varying degrees. These illustrations imply that not all AI uses are high risk, and some that are high risk can be used ethically and responsibly. Deepfake technology (a form of generative AI) can be used responsibly for applications that involve various realistic training scenarios, for example.
AI’s Relationship to Business Strategy
At its core, business strategy is about deciding how a firm will compete. Strategies define how, why, and where an organization intends to succeed in the markets it has decided to pursue. Any company’s strategic intent is to position itself to win in the marketplace by defining the business’s challenges, an overall approach to addressing them, and a set of coherent actions needed to overcome them (Rumelt, 2011). New product innovations, a new business model, improved customer value propositions, or any combination are usually in scope.
The concepts presented by strategist Michael Porter in the 1980s (Porter, 1985) have endured and suggest that successful companies compete by following three fundamental strategies combined or separately: product or service differentiation, cost leadership, and market focus. Differentiation means a firm’s products or services are superior to the competition’s and priced at a premium. Cost leadership means that a firm’s product or services are less expensive but of equal value and quality to the competition. Focus means that specific market segments are addressed effectively.
Davenport and Mittal (2023) reinforced this approach and suggested three archetypes when using AI to drive business strategy: create something new, transform operations, and influence customer behavior. Targeting one or all three is suggested to connect AI uses with business strategy, although probably not simultaneously. Accordingly, conversations that facilitate such clarity help answer the above question—“Where do we start?”—and also help inform answers to the others (e.g., “How can AI help differentiate our business from the competition?”). This presents a fundamental dilemma for many companies: selecting the right on-ramp. As a general practice, early AI adopters suggest starting small with an area that matters to one of the archetypes above yet is lower risk. For example, automating areas where employees spend time on repetitive or manual tasks (i.e., transform operations) is common. One health care network uses AI to read patient chart reviews across the enterprise and automates previsit planning and appointment scheduling. The system automatically enters appointments in the organization’s electronic health records system (Bruce, 2024).
Table 1 Example Artificial Intelligence Uses and Illustrative Advantages and Disadvantages Within Risk Profiles
Risk profile Example use Advantage Disadvantage
High risk Hiring and selection Credit scoring Health care diagnostics Autonomous vehicles Deepfake technology
Facilitated decision-making Advanced insights Efficiency gains Potential innovations
Unfair or harmful impact Complex regulatory compliance Ethical, privacy, and reliability concerns
User trust perceptions Low risk Supply chain optimization
Energy efficiency Traffic flow management Sales forecasting Customer communication
Cost savings Productivity gains User experience Scalability
Implementation costs Financial or operational setbacks versus human harm
Data dependency High maintenance
ARTIFICIAL INTELLIGENCE AND ORGANIZATIONAL STRATEGY 133
A ll
rig ht
s, in
cl ud
in g
fo r t
ex t a
nd d
at a
m in
in g,
A I t
ra in
in g,
a nd
si m
ila r t
ec hn
ol og
ie s,
ar e
re se
rv ed
.
T hi s do cu m en t is co py ri gh te d by
th e A m er ic an
P sy ch ol og ic al
A ss oc ia tio
n or
on e of
its al lie d pu bl is he rs .
T hi s ar tic le
is in te nd ed
so le ly
fo r th e pe rs on al
us e of
th e in di vi du al
us er
an d is no t to
be di ss em
in at ed
br oa dl y.
Business Model Innovation
New technologies often drive business model innovation in existing firms or through start-ups (Johnson et al., 2008). AI is viewed as a market-disrupting technology, foundational to both AI-based start-ups and legacy companies aiming to create innovative new businesses. Innovation in this regard suggests modifying how a firm creates or captures value and delivers it to customers (Jorzik et al., 2023). For example, health care is an industry in which AI-driven innovation is underway. Kulkov (2023) studied health care-related AI start-ups and found that much of the health care value chain, including patients, service providers, hospitals, pharma, and insurance companies, are seeing new market entrants with disruptive potential.
For example, one start-up, Hippocratic AI, was founded to fill the growing shortage of nurses, social workers, nutritionists, and other roles by training specialized large language model chatbot agents to provide interactive low-risk, nondiagnostic, and patient-facing services traditionally performed by humans (Mukherjee et al., 2024). Hippocratic AI’s business model creates a staffing marketplace where health care systems and payors can “hire” AI-powered agents to interact directly with patients around the clock, thus increasing the availability of services to more people. The business model is considered innovative for three reasons: (a) It has never been done before, (b) it has disruptive potential in an industry that resists change, and (c) the company will not release its system without safety testing by human experts (i.e., physicians and nurses), illustrating how AI ethics and profit motives can coexist as investors were willing to defer short-term profits in the interest of safety.1
AI’s ability to impact how companies create economic and societal value is significant. An early example of AI-based innovation in legacy companies comes from Google’s AI research laboratory, DeepMind, where a deep learning algorithm, AlphaFold, was used to discover new insights into complex protein structures. Proteins are large, complex molecules essential for the function of all living cells. They are composed of chains of amino acids that fold into unique multidimensional shapes. Understanding these shapes is crucial as they determine a protein’s function within an organism. AlphaFold predicted these structures with stunning accuracy and in far less time than previous methods (Callaway, 2022). The implication is far-reaching. A better understanding of diseases is possible, leading to the development of new drug therapies. The business connection is that pharmaceutical companies can accelerate the discovery of treatments and shorten the time-to-market of lifesaving drugs. In AlphaFold’s case, a pharmaceutical start-up, Isomorphic Labs, partnered with Eli Lilly and Novartis and leveraged AlphaFold’s findings. Other legacy pharmaceutical companies similarly use AI technologies to speed discoveries (Li et al., 2024).
What is required to use AI as a differentiator in one’s industry? First, the fundamental technologies that drive AI—algorithms, computer processing power, cloud computing, engineering expertise—are financially expensive but accessible by most companies of a size capable of disrupting markets. However, the most critical requirement for AI use is access to high-quality data at scale, which can be scarce. Those with robust and disciplined data governance practices that capture, organize, and use data in real time will have an advantage. Second, selecting use cases matters. One example is the financial services organization Capital One, which aims to disrupt the credit card industry by offering customers new services through its data and technology capabilities. Although the company started with machine learning (ML) to predict customers most likely to pay their credit card loans, it has since invested heavily in AI to enable agile and reduced time-to-market responses for new products. The Capital One case illustrates where AI can drive product market differentiation in ways that influence customer behavior (Davenport & Mittal, 2023).
Organizational and Business Operations
AI is unquestionably a powerful tool for improving the efficacy of business operations. Industries such as financial services, health care, consumer products, energy, media, and government have used AI to improve productivity, operational reliability, process efficiencies, and others (Deloitte
1 See Hippocratic AI press release, March 18, 2024. Hippocratic AI Raises $53 Million Series A at a $500 Million Valuation (https://www.globenewswire.com/).
134 NORTON
A ll
rig ht
s, in
cl ud
in g
fo r t
ex t a
nd d
at a
m in
in g,
A I t
ra in
in g,
a nd
si m
ila r t
ec hn
ol og
ie s,
ar e
re se
rv ed
.
T hi s do cu m en t is co py ri gh te d by
th e A m er ic an
P sy ch ol og ic al
A ss oc ia tio
n or
on e of
its al lie d pu bl is he rs .
T hi s ar tic le
is in te nd ed
so le ly
fo r th e pe rs on al
us e of
th e in di vi du al
us er
an d is no t to
be di ss em
in at ed
br oa dl y.
Artificial Intelligence Institute, 2022). Despite the appearance of objectivity and the types of data used in some of these systems, unfair treatment can occur, however unintentional.
For example, many large financial industry firms use ML systems to screen credit applications. Algorithmic processing can reduce a consumer’s application submission and acceptance time to a few days. An efficient process is created because fewer labor hours are required, more applications can be processed, and administrative errors are reduced. This makes economic sense as an operational intervention. But there is a downside. ML models require data sets for training. What if these data contain inadvertent bias against applicants who might be flagged unfairly as high risk, such as many in marginalized communities, but otherwise not be a high risk? In other words, a false-positive error. One study researched the development and use of a fairness tool to detect ML-based loan approval bias using disparate impact metrics similar to that used in test validation work. The study tested how to make loan application processing explainable and fair. Results showed that bias can be controlled by changing the ML-based decision process and retraining the model (Purificato et al., 2022).
Further, most companies use key performance indicator (KPI) metrics to measure business performance. Conventional practice suggests that optimizing collections of KPIs (e.g., metrics such as materials throughput, profit margin, customer engagement) is not a strategy but does inform strategy and reflects the success of its execution. In the age of AI, KPIs are becoming increasingly sophisticated. For example, ML techniques can evaluate lagging and leading KPIs, suggest diagnostic- type recommendations for improvement, and even identify new KPIs not directly apparent to humans (Kiron et al., 2023). Although valuable, practices such as these require clean data and a governance structure designed to monitor and evaluate the consequences of decisions informed by system- generated KPIs. Algorithms are designed to optimize business criteria, not identify possible harm. For example, social media platforms built to maximize user engagement may land in this category. Similarly, credit recommender systems can adversely impact underrepresented populations, as noted above, especially when developed using flawed training data. What might make strategic business sense may harm individuals and society, including a firm’s brand.
AI systems used internally by organizations are subject to similar ethical risks, especially when used to manage employees. Performance appraisals, selection and promotion systems, and training and development practices (e.g., coaching) are seeing AI applications in growing numbers. As with any AI system, biased training data can result in flawed management decision-making, potentially harming employees.
Approaches to AI Governance and Risk Management
Although AI’s potential benefits can be awe-inspiring, the risks can be equally as dangerous. AI ethics have been debated since the 1950s (Wiener, 1950), but the topic has recently gained mainstream attention, primarily out of concern for AI’s potential to create harm, mislead, or otherwise disrupt society. Benchmarking data support this concern. The number of AI incidents and controversies reported in the open-access AI, Algorithmic, and Automation Incidents and Controversies2 database was 26 times greater in 2021 than in 2012 (Maslej et al., 2023). Recent real-world examples such as deepfake images, facial recognition misuse, copyright infringement, political interference, natural language hallucinations, and dozens of others, some mentioned in this article, illustrate this new reality. The amount of exposure to harmful incidents seems to be expanding.
Yet AI’s capacity to transform business organizations is significant. Its adoption comes with threats and requires disciplined governance and risk management. Risk can be defined as “the composite measure of an event’s probability of occurring and the magnitude or degree of the consequences of the corresponding event” (Artificial Intelligence Risk Management Framework, 2023, p. 4). The operative concept is the event’s potential for harm and hence the relevance of ethical principles. AI governance is gaining traction on two levels—in society through laws and regulations and in organizations using
2 AI, Algorithmic, and Automation Incidents and Controversies is an independent, nonpartisan, public interest initiative that tracks, examines, and makes a case for AI and algorithmic transparency, openness, and ethical responsibility (https://www.aiaaic.org/).
ARTIFICIAL INTELLIGENCE AND ORGANIZATIONAL STRATEGY 135
A ll
rig ht
s, in
cl ud
in g
fo r t
ex t a
nd d
at a
m in
in g,
A I t
ra in
in g,
a nd
si m
ila r t
ec hn
ol og
ie s,
ar e
re se
rv ed
.
T hi s do cu m en t is co py ri gh te d by
th e A m er ic an
P sy ch ol og ic al
A ss oc ia tio
n or
on e of
its al lie d pu bl is he rs .
T hi s ar tic le
is in te nd ed
so le ly
fo r th e pe rs on al
us e of
th e in di vi du al
us er
an d is no t to
be di ss em
in at ed
br oa dl y.
various structural and management practices. This discussion focuses on the latter. Here, governance can be defined as:
A system of rules, practices, processes, and technological tools that are employed to ensure an organization’s use of AI technologies aligns with the organization’s strategies, objectives, and values; fulfills legal requirements; and meets principles of ethical AI followed by the organization. (Mantymaki et al., 2022, p. 604)
AI governance would suggest two questions for discussion: (a) What components are important for inclusion in a governance framework? and (b)What organizational structures are needed to manage it?
Framework Components and Ethical Implications
Conceptual articles on recommended components are abundant. Although much of the discussion is more relevant to society than business organizations, themes that are relevant to organizations are emerging. Birkstedt et al. (2023) published a review article concerning this topic. Results showed that several themes emerged, these being technology (e.g., computing infrastructure, algorithms, data governance), stakeholders (internal and external), context (e.g., political and social environments), regulation (laws, professional standards), and processes (e.g., audit, oversight, risk assessments).
Consistent with Birkstedt et al.’s (2023) taxonomy, ethical components differ along these dimensions. Regarding technology, biased training can adversely impact specific groups. Moreover, when biased training data are used in some patient-facing health care applications, some people may receive lower treatment priority if systems are trained to predict favorable outcomes (e.g., as with some types of surgery). This is because underinsured populations—many frommarginalized communities— frequently cannot afford treatment in sufficient numbers for adequate representation in training databases. Relevant ethical principles in these cases include the importance of system accountability and responsible and ethical use. More traditional ethical frameworks suggest that fairness and nonmaleficence are broadly applicable. In the case of the American Psychological Association’s Ethical Principles of Psychologists and Code of Conduct, two standards are relevant: Avoiding Harm (i.e., Psychologists take reasonable steps to avoid harming) and Unfair Discrimination (i.e., in their work-related activities, psychologists do not engage in unfair discrimination).
Regarding stakeholders within an organization, who is responsible for the ethical use of AI? A shared and cross-functional responsibility would make sense. For example, AI developers mediate ethics within the technology-related development of AI solutions, risk managers assess the potential for harm (internally and externally), and boards of directors and senior management provide oversight. For this model to work effectively, role clarity and lines of responsibility among the players are essential (Buhmann & Fieseler, 2021).
AI regulation concerns laws and other binding resolutions that operate in parallel with ethical principles, standards, and practices. This area is evolving, most notably led by the European Union’s (EU’s) adoption of the EU Artificial Intelligence Act (European Parliament, 2023) and concurrently with AI legislation underway or already enacted in the United States. For example, as of this writing, 17 states have enacted AI legislation around ethics-related principles such as protection from unsafe systems, data privacy, system transparency, protection from discrimination, and accountability (The Council of State Governments, 2023). At the time of this writing, in 2024, over 400 AI-related bills are proposed in U.S. state legislatures (Bedayn, 2024). Although these are societal-level governance mechanisms, the business implications are significant and interact locally with how organizations will, in due course, adjudicate ethical dilemmas. Practically speaking, this means that the development and deployment of AI systems will undergo increasing ethical scrutiny. The business implications are substantial. Aside from legal exposure, AI systems are significant strategic and financial investments. Some applications (or elements of them) could be banned (as in the EU) or possibly have limited use depending on local regulations, thus adversely impacting business investments.
Governance processes suggest using vehicles such as AI audits, various risk assessment metrics, and independent oversight to monitor AI’s use and impact. These processes are enormously complex. For example, industry agreement on how, when, and under what conditions an audit is necessary is a topic of debate with few generally accepted standards for guidance (Landers & Behrend, 2023).
136 NORTON
A ll
rig ht
s, in
cl ud
in g
fo r t
ex t a
nd d
at a
m in
in g,
A I t
ra in
in g,
a nd
si m
ila r t
ec hn
ol og
ie s,
ar e
re se
rv ed
.
T hi s do cu m en t is co py ri gh te d by
th e A m er ic an
P sy ch ol og ic al
A ss oc ia tio
n or
on e of
its al lie d pu bl is he rs .
T hi s ar tic le
is in te nd ed
so le ly
fo r th e pe rs on al
us e of
th e in di vi du al
us er
an d is no t to
be di ss em
in at ed
br oa dl y.
With the arrival of generative AI, especially multimodal models, the number and type of system assessment metrics have risen sharply. Most of these are system performance-related (e.g., system processing speed), although a growing number target ethical issues directly. Stanford University’s The AI Index 2023 Annual Report included a chapter on technical AI ethics (Maslej et al., 2023). It reported on model bias, fairness, toxicity, and poor demographic representation that are both diagnostic and benchmarking-oriented. The issue is complex because bias and fairness metrics tend to interact counterintuitively. For example, correlation analyses show that models performing better on certain fairness metrics can show worse gender bias, but less gender-biased models can show more toxicity. These dynamics interact and are hard to explain, underscoring the need to understand nuanced model characteristics before broad deployment. If issues emerge, mitigation can include human experts fine- tuning a model as a control measure. However, this requires oversight processes to monitor model performance and a willingness and resources to act as necessary.
Another body of work from the United States Department of Commerce’s National Institute of Standards and Technology presented a framework to help companies address AI-related risks. Developed with input from public and private sector representatives, the goal was “to offer a resource to the organizations designing, developing, deploying, or using AI systems to help manage the many risks of AI and promote trustworthy and responsible development and use of AI systems” (Artificial Intelligence Risk Management Framework, 2023, p. 2). Although its framework primarily addresses risk mitigation, it also encourages companies to maximize AI’s positive impacts.
The framework is built around characteristics that help reinforce trustworthy AI and includes system accountability, transparency, explainability, privacy, and fairness principles. Although these are emerging as foundational ethical principles within the AI industry, action recommendations are slower to emerge. A call for robust governance is one such action and is concerned with how AI aligns with organizational values, ethics, and strategy, including the need for policies, processes, and oversight. Other elements include continuously measuring and monitoring system risks and developing mitigation plans.
Both Birkstedt et al. (2023) and the National Institute of Standards and Technology works have many of the same concepts in common. For example, the needs of stakeholders—both internal and external—are mentioned in both models. There is also a common concern for society, and both mention the need to assess AI’s impact. Perhaps most importantly, both cite ethics and use common foundational principles of accountability, transparency, explainability, and avoiding bias. Both cite generally accepted information technology (IT) governance frameworks as resources to support AI governance specifically. Two of the most notable are the Institute of Electrical and Electronics Engineers 7000 series (Ethically Aligned Design, 2019) and the International Organization for Standardization 27000 family of standards (International Organization for Standardization 27000 Series, 2024).
Although these works are helpful, as a practical and nontrivial matter, a significant omission concerns the structural placement of AI governance within an organization. Accountability must reside somewhere in organizations and be made explicit and enforceable.
Organizational Structure Considerations
Whether AI requires a form of organizational governance is little doubted. The options available and the form they should take are relevant questions. First, how and where a firm uses AI are initial considerations. Not all uses pose risks or create ethical dilemmas, suggesting that degrees of risk may drive structural designs; less restrictive governance measures may suffice when low-risk applications are involved, and vice versa. Second, structural elements suggest combining traditional governance models (e.g., board of directors, CEO, and C-suite roles) with potentially new elements that address AI’s specialized nature, risk potential, and strategic value.
Board Level
AI has reached board-level attention primarily because of its potential to impact a firm in multiple ways. In public companies, boards of directors carry a fiduciary obligation to oversee the firm’s strategy, fiscal health, reputation, brand, legal compliance, risks, and ethics, all touched by AI applications. According to Gregory (2023), boards of directors, as part of these responsibilities, must
ARTIFICIAL INTELLIGENCE AND ORGANIZATIONAL STRATEGY 137
A ll
rig ht
s, in
cl ud
in g
fo r t
ex t a
nd d
at a
m in
in g,
A I t
ra in
in g,
a nd
si m
ila r t
ec hn
ol og
ie s,
ar e
re se
rv ed
.
T hi s do cu m en t is co py ri gh te d by
th e A m er ic an
P sy ch ol og ic al
A ss oc ia tio
n or
on e of
its al lie d pu bl is he rs .
T hi s ar tic le
is in te nd ed
so le ly
fo r th e pe rs on al
us e of
th e in di vi du al
us er
an d is no t to
be di ss em
in at ed
br oa dl y.
understand a company’s current or intended AI uses, its strategic implications, business impact, risks, ethical obligations, and the policies and controls needed to deploy responsible AI. This reasoning suggests that AI governance rests within traditional board-level oversight and is managed as needed. A question to consider is whether it should be structured as a separate board committee.
Board-level committees oversee specialized functions that warrant special attention, such as audits, executive compensation, and risk management. Accordingly, the level of board member AI expertise is a consideration. Members of these committees come from varied backgrounds and are selected for their independence, experience, and expertise. With AI’s rapid advancements, most are unlikely to possess basic AI literacy. However, AI educational programs for board members are emerging. For example, the National Association of Corporate Directors offers modules in AI governance as part of its educational offerings. Yet members are accountable for oversight. In such situations, many boards default to internal company experts. In the case of AI this may also be insufficient and possibly introduce an unintended element of risk in its own right.
The structural question, then, is not whether board-level involvement is needed. Instead, the question is whether forming a separate AI-dedicated committee is justified. In cases where AI presents high risk to the firm’s interests, broadly defined, such a committee is likely justified; where AI presents low risks, existing governance structures may suffice. The tipping point to the former will almost assuredly be a function of the extent to which AI adoption is integral to the firm’s strategy.
Independent Ethics Advisory Boards
The literature discusses these and other limits of traditional corporate governance structures specific to AI (Tallarita, 2023). The main point is that conventional corporate governance mechanisms are untested in this domain andmay be ill-suited to oversee AI safety. One suggestion is to use third-party ethics advisory boards for consultation on complex ethical issues (Liautaud, 2021), which appears to be a kernel of an idea. Its role should not be to enforce rules that executives find limiting. Instead, it should be to advise on building AI-driven business value within ethical parameters. Smaller companies with fewer resources, in particular, may benefit from this approach. Its engagement could be triggered when AI creates risks exceeding predefined criteria (e.g., when a use case involves legal, reputational, or brand risks).
A corollary to this idea is the adoption of an internal institutional review board first used in medicine and employed throughout academic institutions when human subjects are utilized in research. Outside of health care, institutional review boards are not commonly found in private corporations, if at all. However, it would be plausible to consider such a model to advise on AI risks, even if supplemental to established risk management functions. Membership could include data scientists, engineers, attorneys, psychologists, ethicists, and senior managers to provide a cross-discipline focus (Blackman, 2021).
Consulting psychologists could be ideal for such assignments for at least two reasons. First, proficiency in ethical matters that impact the well-being of humans is a core competency among psychologists. Generalizing to the risks posed by AI is not a stretch. Second, using theoretical concepts relevant to AI adoption, such as the linkage between individual attitudes, social norms, behavioral intentions, and actual behavior, as foundational to understanding user behavior, is within the purview of most consulting psychologists.
C-Suite and Functional Ownership
How AI is managed below the level of the board of director requires some thought. Is it an IT departmental subfunction or, given AI’s firm-level strategic purpose, a new C-suite role reporting to the CEO and separate from the chief information officer? Decision considerations involve firm size, business model and complexity, degree of centralization, AI use cases (current and planned), and IT infrastructure. Although structural configurations will vary, governance models will likely be driven by multidimensional risk assessments, including ethical factors not usually considered.
Emerging Alternatives
Given AI’s status as a general-purpose technology with broad applications, emergent structures are surfacing that redefine governance and seem to be unique. Departing from traditional governance is to
138 NORTON
A ll
rig ht
s, in
cl ud
in g
fo r t
ex t a
nd d
at a
m in
in g,
A I t
ra in
in g,
a nd
si m
ila r t
ec hn
ol og
ie s,
ar e
re se
rv ed
.
T hi s do cu m en t is co py ri gh te d by
th e A m er ic an
P sy ch ol og ic al
A ss oc ia tio
n or
on e of
its al lie d pu bl is he rs .
T hi s ar tic le
is in te nd ed
so le ly
fo r th e pe rs on al
us e of
th e in di vi du al
us er
an d is no t to
be di ss em
in at ed
br oa dl y.
balance more accessible, scalable, and innovative AI uses with management systems that mitigate risk. Structures that adopt this thinking are built to allow for AI adoption locally within business units. The caveat is that the system is under the direction of deep subject matter experts who understand the risks and are held accountable if something goes wrong. One such approach at theMayo Clinic has created a less centralized and more scalable system to take advantage of AI’s broad-based capability. Those in centralized functions (e.g., IT, regulatory and risk management) are tasked with partnering with physician groups and others cross-functionally, where each function plays a specialized role that collectively forms a self-governing system. The role of IT is to focus on the technology and essential AI infrastructure; physicians focus on use cases needed to leverage AI in line with the organization’s mission and objectives; other specialists focus on managing regulatory requirements such as Federal Drug Administration approvals (Davenport & Bean, 2024). This model makes sense for organizations willing to create a decentralized self-governing structure as an alternative to traditional top-down models. Although not a solution for all organizations, structural alternatives that provide autonomous decision-making and control are emerging.
Recommendations
Organizations using or considering AI face a dilemma: How are profit motives balanced with responsible AI when competitive pressures require risk-taking? The notion of striking an alliance between the two and making AI safety profitable is an exciting idea, although easier said than done. One approach is to make internal risk-mitigation practices a competitive differentiator and an integral part of business strategy. Consumers are increasingly attentive to AI’s dangers, and as laws and regulations take root, staying ahead of legal restrictions makes long-term strategic and financial sense.
Second, robust governance should not be optional, yet its form should vary by ethical, business, and societal risk assessments. Not all AI applications are risky, and others are hugely so. Governance models and practices should be commensurate with these assessments but flexible enough to accommodate additional risks presented by evolving AI use cases. Accordingly, legacy governance models will require updating in both structure and process. For those willing to experiment, the dividends may be worth the experimentation.
Third, none of the points in this article suggest that adopting AI technology is an all-or-nothing proposition. Companies further along on their AI journey started small and grew as they developed capabilities, managed risks, and learned lessons. The recommendation is to initially select a simple use case and expand in due course as one’s capabilities develop.
Last, encountering AI in client engagements is a new development for most consultants (psychologists included) and is likely to increase. A call for AI literacy among consultants should not go unheeded. Although proficiency in AI coding is not a requirement, understanding its uses, advantages, and appropriate application in organizations should be a competency objective. Understanding its limitations and ethical liabilities is also a necessity in equal measure. At a minimum, all consultants should be able to engage in informed conversations when encountering AI in organizations.
References
Ali, M. H., Hamdan, A., & Alareeni, B. (2021). The implementation of artificial intelligence in organizations’ systems: Opportunities and challenges. In B. Alareeni, A. Hamdan, & I. Elgedawy (Eds.), The importance of new technologies and entrepreneurship in business development: In the context of economic diversity in developing countries. ICBT 2020. Lecture notes in networks and systems (Vol. 194, pp. 153–163). Springer. https://doi.org/10.1007/978-3-030-69221-6_12
Artificial Intelligence Risk Management Framework (AI RMF 1.0). (2023, January). US Department of Commerce, National Institute of Standards and Technology. https://doi.org/10.6028/NIST.AI.100-1
Bedayn, J. (2024,March 4). States target AI’s hidden hand in Americans’ lives. Associated Press. https://apnews.co m/article/artificial-intelligence-ai-explained-policy-technology-regulations-discrimination-d3226c9139d3d06a f263e7ff467d0666
ARTIFICIAL INTELLIGENCE AND ORGANIZATIONAL STRATEGY 139
A ll
rig ht
s, in
cl ud
in g
fo r t
ex t a
nd d
at a
m in
in g,
A I t
ra in
in g,
a nd
si m
ila r t
ec hn
ol og
ie s,
ar e
re se
rv ed
.
T hi s do cu m en t is co py ri gh te d by
th e A m er ic an
P sy ch ol og ic al
A ss oc ia tio
n or
on e of
its al lie d pu bl is he rs .
T hi s ar tic le
is in te nd ed
so le ly
fo r th e pe rs on al
us e of
th e in di vi du al
us er
an d is no t to
be di ss em
in at ed
br oa dl y.
Birkstedt, T., Minkkinen, M., Tandon, A., &Mäntymäki, M. (2023). AI governance: Themes, knowledge gaps and future agendas. Internet Research, 33(7), 133–167. https://doi.org/10.1108/INTR-01-2022-0042
Blackman, R. (2021, April 1). If your company uses AI, it needs an Institutional Review Board. Harvard Business Review. https://hbr.org/2021/04/if-your-company-uses-ai-it-needs-an-institutional-review-board
Bruce, G. (2024, April 8). Indiana health system to automate chart reviews with AI. Becker’s Hospital Review. https:// www.beckershospitalreview.com/innovation/indiana-health-system-to-automate-chart-reviews-with-ai.html
Buhmann, A., & Fieseler, C. (2021). Towards a deliberative framework for responsible innovation in artificial intelligence. Technology in Society, 64, Article 101475. https://doi.org/10.1016/j.techsoc.2020.101475
Callaway, E. (2022). What’s next for AlphaFold and the AI protein-folding revolution. [London]. Nature, 604(7905), 234–238. https://doi.org/10.1038/d41586-022-00997-5
Crafts, N. (2021). Artificial intelligence as a general-purpose technology: An historical perspective.Oxford Review of Economic Policy, 37(3), 521–536. https://doi.org/10.1093/oxrep/grab012
Davenport, T. H., & Bean, R. (2024).Mayo Clinic’s healthymodel for AI success.MIT SloanManagement Review. https://sloanreview.mit.edu/article/mayo-clinics-healthy-model-for-ai-success
Davenport, T. H., & Mittal, N. (2023). All-in on AI: How smart companies win big with artificial intelligence. Harvard Business Review Press.
Deloitte Artificial Intelligence Institute. (2022). The AI Dossier-expanded: Managing risk and trust for the top uses for AI in every major industry. https://www2.deloitte.com/us/en/pages/consulting/articles/ai-dossier.html
Ethically Aligned Design (Version II). (2019). Electrical and Electronics Engineers. https://standards.ieee.org/indu stry-connections/
European Parliament. (2023, December 19).EUAI act: First regulation on artificial intelligence. https://www.europa rl.europa.eu/news/en/headlines/society/20230601STO93804/eu-ai-act-first-regulation-on-artificial-intelligence
Gregory, H. J. (2023, October 7). AI and the role of the board of directors. Harvard Law School Forum on Corporate Governance. https://corpgov.law.harvard.edu/2023/10/07/ai-and-the-role-of-the-board-of-directors/
International Organization for Standardization 27000 Series. (2024). International Organization for Standardization. https://www.iso.org/standards.html
Johnson, M. W., Christensen, C. M., & Kagermann, H. (2008, December). Reinventing your business model. Harvard Business Review. https://hbr.org/2008/12/reinventing-your-business-model
Jorzik, P., Yigit, A., Kanbach, D. K., Kraus, S., & Dabic, M. (2023). Artificial intelligence-enabled business model innovation: Competencies and roles of top management. IEEE Transactions on Engineering Management, 71, 7044–7056. https://doi.org/10.1109/TEM.2023.3275643
Kiron, D., Schrage, M., Candelon, F., Kohdabendeh, S., & Chu, M. (2023). Strategic alignment with AI and smart KPIs (1st ed.). MIT Sloan Management Review.
Kulkov, I. (2023). Next-generation business models for artificial intelligence start-ups in the healthcare industry. International Journal of Entrepreneurial Behaviour & Research, 29(4), 860–885. https://doi.org/10.1108/ IJEBR-04-2021-0304
Landers, R. N., & Behrend, T. S. (2023). Auditing the AI auditors: A framework for evaluating fairness and bias in high stakes AI predictive models. American Psychologist, 78(1), 36–49. https://doi.org/10.1037/amp0000972
Li, H., Sun, X., Cui, W., Xu, M., Dong, J., Ekundayo, B. E., Ni, D., Rao, Z., Guo, L., Stahlberg, H., Yuan, S., & Vogel, H. (2024). Computational drug development for membrane protein targets. Nature Biotechnology, 42(2), 229–242. https://doi.org/10.1038/s41587-023-01987-2
Liautaud, S. (2021, January 21). How to set up an ethics advisory board.Harvard Business Review. https://hbr.org/ 2021/01/how-to-set-up-an-ethics-advisory-board
Malomane, R., Musonda, I., & Okoro, C. S. (2022). The opportunities and challenges associated with the implementation of fourth industrial revolution technologies to manage health and safety. International Journal of Environmental Research and Public Health, 19(2), Article 846. https://doi.org/10.3390/ijerph19020846
Mantymaki, M., Minkkinen, M., Birkstedt, T., & Viljanen, M. (2022). Defining organizational AI governance. AI and Ethics, 2(4), 603–609. https://doi.org/10.1007/s43681-022-00143-x
Maslej, N., Fattorini, L., Brynjolfsson, E., Etchemendy, J., Ligett, K., Lyons, T., Manyika, J., Ngo, H., Niebles, J. C., Parli, V., Shoham, Y., Wald, R., Clark, J., & Perrault, R. (2023, April), The AI index 2023 annual report. AI Index Steering Committee, Institute for Human-Centered AI, Stanford University.
Mukherjee, S., Gamble, P., Markel Sanz, A., Kant, N., Aggarwal, K., Manjunath, N., Datta, D., Liu, Z., Ding, J., Busacca, S., Bianco, C., Sharma, S., Lasko, R., Voisard, M., Harneja, S., Filippova, D., Meixiong, G., Cha, K., Youssefi, A., … Miller, A. (2024). Polaris: A safety-focused LLM constellation architecture for healthcare. arXiv. https://doi.org/10.48550/arxiv.2403.13313
140 NORTON
A ll
rig ht
s, in
cl ud
in g
fo r t
ex t a
nd d
at a
m in
in g,
A I t
ra in
in g,
a nd
si m
ila r t
ec hn
ol og
ie s,
ar e
re se
rv ed
.
T hi s do cu m en t is co py ri gh te d by
th e A m er ic an
P sy ch ol og ic al
A ss oc ia tio
n or
on e of
its al lie d pu bl is he rs .
T hi s ar tic le
is in te nd ed
so le ly
fo r th e pe rs on al
us e of
th e in di vi du al
us er
an d is no t to
be di ss em
in at ed
br oa dl y.
Porter, M. E. (1985). Competitive strategy: Techniques for analyzing industries and competitors. Free Press. Purificato, E., Lorenzo, F., Fallucchi, F., & De Luca, E. W. (2022). The use of responsible artificial intelligence
techniques in the context of loan approval processes. International Journal of Human–Computer Interaction, 39(7), 1543–1562. https://doi.org/10.1080/10447318.2022.2081284
Robles, P., & Mallinson, D. J. (2023). Catching up with AI: Pushing toward a cohesive governance framework. Politics and Policy, 51(3), 355–372. https://doi.org/10.1111/polp.12529
Rumelt, R. P. (2011). Good strategy, bad strategy: The difference and why it matters (1st ed.). Crown Business. Tallarita, R. (2023, December 5). AI is testing the limits of corporate governance.Harvard Business Review. https://
hbr.org/2023/12/ai-is-testing-the-limits-of-corporate-governance?autocomplete=true The Council of State Governments. (2023, December 6). Artificial intelligence in the states: Emerging legislation.
https://www.csg.org/2023/12/06/artificial-intelligence-in-the-states-emerging-legislation/ Wiener, N. (1950). The human use of human beings: Cybernetics and society. Houghton Mifflin Company.
Received May 6, 2024 Revision received July 2, 2024
Accepted July 10, 2024 ▪
E-Mail Notification of Your Latest Issue Online!
Would you like to know when the next issue of your favorite APA journal will be available online? This service is now available to you. Sign up at https://my.apa.org/ portal/alerts/ and you will be notified by e-mail when issues of interest to you become available!
ARTIFICIAL INTELLIGENCE AND ORGANIZATIONAL STRATEGY 141
A ll
rig ht
s, in
cl ud
in g
fo r t
ex t a
nd d
at a
m in
in g,
A I t
ra in
in g,
a nd
si m
ila r t
ec hn
ol og
ie s,
ar e
re se
rv ed
.
Reproduced with permission of copyright owner. Further reproduction prohibited without permission.
- Artificial Intelligence and Organizational Strategy: Ethical and Governance Implications
- AI's Growing Importance to Business Organizations
- AI's Relationship to Business Strategy
- Business Model Innovation
- Organizational and Business Operations
- Approaches to AI Governance and Risk Management
- Framework Components and Ethical Implications
- Organizational Structure Considerations
- Board Level
- Independent Ethics Advisory Boards
- C-Suite and Functional Ownership
- Emerging Alternatives
- Recommendations
- References