Skip to main content
9 October 2026
Digital Inclusion Benchmark

2026 CIC for Ethical AI Investor Statement

From Principles to Practice: Investor Expectations on AI Governance

Artificial intelligence (AI) is advancing at unprecedented speed, scale, and sophistication, transforming economies, societies, and the way people and businesses operate. Generative AI has become embedded across products, services and business operations, while increasingly autonomous agentic AI systems are beginning to reshape how decisions are made and work is performed. 

The growing deployment of AI across critical and increasingly sensitive domains, including national security and military applications, amplifies risks relating to human rights, discrimination, privacy, misinformation, cybersecurity, labour impacts, market concentration and the misuse of capable AI systems. Effective AI governance is therefore an essential component of long-term corporate resilience and shareholder value creation.

Governments and international institutions have responded with an evolving landscape of AI governance frameworks, including the European Union AI Act, the OECD AI Principles, the G7 Hiroshima AI Process, NIST AI Risk Management Framework, ISO standards, among others. Together, these frameworks reinforce growing expectations that companies develop, deploy and govern AI responsibly, while providing greater transparency on how risks are identified, managed and mitigated throughout the AI lifecycle.

Background and Rationale

As a group of over 56 investor participants in World Benchmarking Alliance’s (WBA) Collective Impact Coalition (CIC) for Ethical AI with over USD$10.9 trillion in assets under management, we recognise the significant potential of AI to deliver economic and societal benefits. However, companies that fail to develop and deploy AI responsibly may face material legal, regulatory, operational, reputational and financial risks. Robust AI governance is therefore fundamental to protecting long-term shareholder value and maintaining customer, partner and wider societal trust.

Since September 2022, we have engaged 80 large technology sector companies, out of 200 companies assessed by WBA’s Digital Inclusion Benchmark on ethical AI. Following the inception of this initiative, 57 more companies have now published their AI principles.

While we acknowledge some progress, it remains too slow. For example, 62% of assessed technology companies still lack publicly disclosed AI principles, a baseline expectation for investors. Meanwhile, public disclosure on responsible AI often remains high-level or ad hoc, rather than providing evidence of consistent and effective implementation.

As companies continue to invest heavily in AI development, investors require greater transparency on how companies that develop, deploy or significantly rely on AI are doing so responsibly and effectively operationalising their human rights and sustainability commitments. We expect companies to implement responsible AI across the full lifecycle of these technologies and products.

In light of these gaps, investors need more consistent, decision-useful disclosure on how companies govern, oversee and manage AI-related risks.
 

Our expectations:

1. Responsible AI principles and policies

Companies should publicly disclose business-relevant principles and policies that guide the development, procurement, deployment and use of AI systems across their operations, products, and value chains.

These principles and policies should be aligned with internationally recognised standards and frameworks, including the UN Guiding Principles on Business and Human Rights (UNGPs), the OECD AI Principles and other relevant global governance initiatives. As relevant to a company’s business and operations, a responsible AI policy should be group-level and address the full range of relevant AI technologies, including generative AI, foundation models and autonomous agentic systems, while considering potential dual-use and military applications.

Public commitments should demonstrate how companies seek to prevent harms to people, respect human rights, promote fairness and non-discrimination, safeguard privacy and security, ensure transparency and accountability, and maintain meaningful human oversight of AI systems.

2. AI Governance and Oversight

Companies should establish robust governance structures that enable effective oversight of AI-related risks across the enterprise.

Investors expect executive leadership to be accountable for AI governance, supported by defined roles and responsibilities, internal communications and controls, and enterprise-wide risk management processes. Explicit board and committee-level oversight and performance criteria should also be clearly articulated. Companies should ensure directors have access to regular training to develop the expertise needed to oversee AI-related opportunities, risks, and strategic decisions. Governance frameworks should evolve alongside advances in AI capabilities and address the development, procurement and deployment of foundation models, generative AI and agentic AI systems, including those integrated through third-party providers.

3. Responsible AI Implementation

Companies should move beyond merely disclosing high-level commitments to demonstrating effective and systematic implementation of those commitments. Disclosures should address how responsible AI principles are embedded across the entire system lifecycle from product development, procurement, and deployment to ongoing operations (including third-party and open-source models). Companies should also disclose how responsible AI policies actively shape decision-making, resource allocation, and daily practices. Specifically, companies should detail:

  • Governance & Oversight: How AI governance spans business functions, including employee training, supplier expectations, internal assurance, and strengthened human oversight as technologies evolve.
  • Risk Management & Lifecycle Controls: How high-risk applications are identified and escalated, safety testing and continuous monitoring are conducted, incidents are managed, and independent assurance is obtained to verify the effectiveness of relevant controls.
  • Impact & Progress: Clear qualitative and quantitative progress metrics and case studies illustrating how risk controls, safeguards, and decision-making adapt over time.

4. Due Diligence and AI Impact Assessments

Companies should conduct and disclose robust AI-related due diligence and impact assessments proportionate to the risks posed by their AI systems.

These processes should assess actual and potential human rights impacts to stakeholders in a company’s value chain, including consumers, customers, workers, and society, throughout the lifecycle of AI systems. They should be integrated into broader enterprise risk management and human rights due diligence processes and reflect evolving regulatory expectations for high-risk AI systems.

Companies should disclose how identified risks are mitigated, how affected stakeholders are identified and engaged where appropriate, what mitigation measures are established, how those measures are monitored for effectiveness over time, and how findings from impact assessments inform product design and governance improvement. For wider adoption of such standards and metrics, we encourage companies to participate in industry-wide initiatives such as Frontier Model Forum, contribute to AI Incidents Database and NVD (National Vulnerability Database), and commission relevant research. This could facilitate the development of needed standards and comparable safety metrics.

For higher-risk, frontier, or autonomous AI systems, investors expect enhanced scrutiny and human rights due diligence. Investors expect companies to employ independent third-party verification or auditing to assess the effectiveness of their safeguards and risk management systems. Conducting an independent human rights impact assessment is one such tool. These assessments provide comparable and verifiable disclosures that investors can use in their analysis and companies in their progress blueprinting.

Through the WBA Ethical AI CIC, investors will continue to engage companies on their responsible AI practices aligned with this investor statement and evolving regulatory frameworks.
 

About the Collective Impact Coalition for Ethical AI

TheCollective Impact Coalition for Ethical Artificial Intelligence (AI CIC) seeks to ensure that digital technology companies integrate human rights and ethical considerations into the development, deployment, and procurement of AI. The AI CIC brings together investors and other stakeholders to press companies for stronger policies, governance structures, and disclosures that can shed light on their commitments and operationalisation of responsible AI.

Since 2022, the AI CIC has rallied dozens of new contributors, growing from 44 members at its inception to 78 today, including 64 investors and 14 civil society groups. Investors seeking guidance and dialogue with companies in their portfolios have driven the expansion of our coalition. As of October 2026, investors are actively engaging with 75 technology companies across several industries under the banner of the AI CIC. Our 2025 progress report captures the latest engagement outcomes in detail.

WBA Disclaimer: https://www.worldbenchmarkingalliance.org/disclaimer

Subscribe to stay informed on our work

Keep up to date with all the latest from World Benchmarking Alliance

Join our newsletter