Principled Practice: A Playbook for Operationalizing Responsible AI
Also authored by Beba Cibralic, Associate Fellow, Leverhulme Centre for the Future of Intelligence, University of Cambridge
CDT brief, entitled “Principled Practice: A Playbook for Operationalizing Responsible AI.” White document on a grey background.
Introduction
For many organizations, rapid advancements in machine learning has outpaced the creation of robust governance mechanisms. This problem became particularly acute in late 2022 when the popularization of large language models (LLMs) produced a slew of new governance challenges and put a spotlight on existing gaps. As artificial intelligence (AI) diffuses across the economy, an increasing number of organizations — from large to small, from public to private, and across a range of sectors, from finance and technology to education and healthcare — are trying to address both legacy and emerging governance problems. Previously, the work of developing responsible AI was concentrated in a handful of technology companies; today, it is relevant to all organizations using AI in order to prevent clear harms as well as foster consumer trust.
“Responsible AI” (RAI) is an umbrella concept that typically refers to an array of principles, practices, and standards that help ensure AI technologies and products are developed and used safely, ethically, and in line with societal expectations. Responsible AI practitioners are those individuals who work toward these goals, and can range from computer scientists to ethicists, UX researchers, legal professionals, and beyond.
Although attention to responsible AI has ballooned and shape-shifted over the years, consistent practitioner work in this domain contributed to a small-but-growing well of community knowledge — practices, tools, and lessons learned — that can be drawn from by both new practitioners seeking to build effective RAI practices as well as by seasoned ones aiming to enhance their own systems. To capture these learnings from the field, the Center for Democracy & Technology (CDT) brought together over 30 practitioners in the summer of 2024 for a workshop and interviews; the group included socio-technical researchers, designers, policy experts, technical leaders, and compliance and legal personnel, with experience working on efforts related to responsible AI, AI ethics, and AI safety. Practitioners came from a range of organizations across industry, civil society, and government, and their insights revealed five building blocks — conceptual and technical infrastructure — needed to operationalize responsible AI. While many practitioners developed their expertise in the technology sector, we expect the contours of their experiences to be broadly transferrable to other domains, and to be illuminating for professionals who are confronting similar issues at an earlier stage of organizational maturity. Those five building blocks (the five “P”s), are:
People: Empower your experts Responsible AI goals are best served by multidisciplinary teams that contain varied domain, technical, and social expertise. Rather than seeking “unicorn” hires with all dimensions of expertise, organizations should build interdisciplinary teams, ensure inclusive hiring practices, and strategically decide where RAI work is housed — i.e., whether it is centralized, distributed, or a hybrid. Embedding RAI into the organizational fabric and ensuring practitioners are sufficiently supported and influential is critical to developing stable team structures and fostering strong engagement among internal and external stakeholders.
Priorities: Thoughtfully triage work For responsible AI practices to be implemented effectively, teams need to clearly define the scope of this work, which can be anchored in both regulatory obligations and ethical commitments. Teams will need to prioritize across factors like risk severity, stakeholder concerns, internal capacity, and long-term impact. As technological and business pressures evolve, ensuring strategic alignment with leadership, organizational culture, and team incentives is crucial to sustaining investment in responsible practices over time.
Processes: Establish structures for governance Organizations need structured governance mechanisms that move beyond ad-hoc efforts to tackle emerging issues posed in the development or adoption of AI. These include standardized risk management approaches, clear internal decision-making guidance, and checks and balances to align incentives across disparate business functions. Processes should layer formal methods (e.g., audits, review checkpoints) with informal ones (e.g., ethical norms, internal culture) to support consistency and institutional memory required for effective AI governance.
Platforms: Invest in responsibility infrastructure To scale responsible practices, organizations will be well-served by investing in foundational technical and procedural infrastructure, including centralized documentation management systems, AI evaluation tools, off-the-shelf mitigation methods for common harms and failure modes, and post-deployment monitoring platforms. Shared taxonomies and consistent definitions can support cross-team alignment, while functional documentation systems make responsible AI work internally discoverable, accessible, and actionable. Infrastructure that balances automation with the need for human oversight is particularly crucial for navigating high-stakes contexts.
Progress: Track efforts holistically Sustaining support for and improving responsible AI practices requires teams to diligently measure and communicate the impact of related efforts. Tailored metrics and indicators can be used to help justify resources and promote internal accountability. Organizational and topical maturity models can also guide incremental improvement and institutionalization of responsible practices; meaningful transparency initiatives can help foster stakeholder trust and democratic engagement in AI governance.
In discussing each building block, we explore practical and procedural questions responsible AI practitioners will need to navigate as well as challenges they’ll likely face in building, adapting, or scaling up responsible AI efforts. Although there is no one-size-fits all approach and the “right” answers will differ for each organization, this report aims to articulate those tradeoffs and their implications so that practitioners can make informed decisions. Others in the field have already mapped out values that drive responsible AI. Building on this work, we help translate these into concrete, actionable organizational considerations.
Throughout this report, we include illustrative, deidentified reflections that responsible AI practitioners shared during our workshops and conversations.
CDT Comment Welcomes NIST Effort to Develop Zero Draft
Drawing on CDT’s previous comments on this NIST effort and our prior research on documentation, our submission welcomes NIST’s effort to develop the zero draft, which provides a much-needed step toward more standardized, high-quality guidance on how developers of AI system components should document key properties and potential sources of AI risk. This guidance will be a valuable resource for organizations to improve interoperability, build more performant AI products, and more effectively identify and mitigate AI risks.
Coalition Urges Senate Not to Let Companies Waive Financial Regulations for AI
CDT joined AI Now Institute, American Civil Liberties Union, and several organizations dedicated to tech policy, consumer protection, and civil rights in a letter to Senate leadership and the Senate Banking, Housing, and Urban Affairs Committee opposing the “AI Innovation Labs” language in Sec. 10509 of the CLARITY Act.
As concern about risks and harms related to AI systems continue to grow, a growing chorus of policymakers, industry leaders, and advocates have called for independent AI assessments. This explainer provides an overview of recent proposals for third-party assessment in the United States, including state and federal legislation, executive actions, and industry proposals.
Having third parties assess AI systems might seem like common sense, but crafting effective policies toward this goal can be devilishly tricky. A poorly-constructed ecosystem for third-party assessment could easily fail to consider the most consequential mechanisms of risk, neglect the AI harms that most impact people, or do more to protect AI companies than people.