Was ist ein KI-Ethikrat und braucht jedes Unternehmen einen?
An AI ethics council is an internal body that ensures a company uses artificial intelligence responsibly, transparently, and in compliance with regulations. Whether every company needs one depends on the intensity of AI use: if you only use AI sporadically, clear guidelines are sufficient. If you systematically integrate AI into decision-making processes, you need a structured body. The following questions clarify how such a council is set up and what the EU AI Act requires.
What tasks does an AI ethics council actually take on?
An AI ethics council evaluates, monitors, and steers the ethically responsible use of AI systems within a company. It reviews new AI projects for risks, formulates internal guidelines, and ensures that fundamental rights such as non-discrimination, data protection, and transparency are upheld when AI is used.
In concrete terms, this means: the council accompanies AI projects from planning through to operation. It identifies potential biases in training data, assesses high-risk AI systems in accordance with the requirements of the EU AI Act, and determines when human oversight is strictly necessary. It also documents decisions so that the company can be held accountable when approached by authorities or customers.
Typical tasks include:
- Risk assessment of new AI applications before rollout
- Development and maintenance of internal company AI guidelines
- Review of algorithms for non-discrimination and fairness
- Ensuring compliance with the EU AI Act and the GDPR
- Advising management on strategic AI decisions
- Communicating ethical AI principles internally and externally
The ethics council is therefore not a purely advisory body, but an active supervisory authority that brings AI governance to life.
Who typically sits on an AI ethics council?
An AI ethics council is made up of representatives from various areas of the company, because ethical AI questions simultaneously touch on legal, technical, and organisational dimensions. A purely technical composition is not sufficient.
A composition of at least five perspectives has proven effective:
- IT and data science: Technical understanding of AI systems, data quality, and model behaviour
- Legal and compliance: Knowledge of the EU AI Act, the GDPR, and liability law
- HR and employment law: Assessment of AI use in HR-relevant processes and co-determination rights
- Data protection: The data protection officer as a permanent member, since AI regularly processes personal data
- Senior management: Strategic involvement so that ethics decisions have real consequences
Larger companies also involve external specialists, such as ethicists, consumer protection experts, or representatives of affected stakeholder groups. It is important that the council has genuine decision-making authority, or at least a formal right of veto over high-risk AI projects. Without the power to enforce its decisions, it remains a fig leaf.
From what company size does an AI ethics council make sense?
A formal AI ethics council makes sense from the moment a company uses AI systems that influence decisions about people — for example in areas such as recruiting, lending, customer service, or quality control. Company size is less decisive than the intensity and risk level of AI use.
As a rule of thumb:
- Small companies (fewer than 50 employees): Written AI guidelines and one responsible person are sufficient in most cases.
- Medium-sized companies (50 to 500 employees): A small, interdisciplinary body of three to five people makes sense as soon as AI is used productively in core processes.
- Large companies (more than 500 employees): A fully formed AI ethics council with a clear charter, regular meetings, and reporting obligations to management is necessary.
The risk class of the AI systems in use under the EU AI Act is also decisive. Anyone operating high-risk AI — for example in the area of personnel decisions or critical infrastructure — must establish structured oversight mechanisms regardless of company size. For these companies, an ISO 42001 Audit is a sensible first step for assessing their own level of maturity.
What does the EU AI Act require in terms of ethical AI governance?
The EU AI Act does not explicitly require the establishment of an AI ethics council, but it does demand concrete governance structures that substantively cover exactly what such a council should deliver: risk monitoring, human oversight, transparency, and accountability.
Specifically, the EU AI Act obliges operators of high-risk AI systems to, among other things:
- Implement human oversight mechanisms
- Take measures for continuous monitoring of system behaviour
- Report serious incidents
- Inform those affected by automated decisions
- Retain automated logs for six months
- Cooperate with national authorities
In addition, many companies orient themselves by the European Union’s ethics guidelines for trustworthy AI, which define principles such as human agency, technical robustness, non-discrimination, and societal wellbeing. An AI ethics council is the organisational instrument through which these legal and normative requirements can be systematically implemented. Anyone who wants to implement AI regulation compliance cannot avoid a clear governance structure.
How does an AI ethics council differ from an AI governance framework?
An AI governance framework is the written set of rules: guidelines, processes, risk classes, and responsibilities. An AI ethics council is the human body that brings this framework to life, monitors it, and develops it further. Both belong together, but neither replaces the other.
The difference can be summarised as follows:
- AI governance framework: Defines the rules of the game. It determines how AI systems are assessed, deployed, and controlled. Standards such as ISO 42001 provide a recognised framework for this.
- AI ethics council: Enforces the rules of the game. It makes decisions on individual cases, resolves conflicts between commercial objectives and ethical requirements, and ensures that the framework does not become an empty formality.
In practice, many companies fail not because of a missing framework, but because of the missing body that applies it consistently. A well-structured AI management system based on ISO 42001 gives the ethics council the structural foundation on which it can operate. Both elements reinforce each other: the framework creates orientation, the council creates binding commitment.
How does a company introduce an AI ethics council?
Introducing an AI ethics council succeeds in five steps: first analyse the need, then appoint the body, formulate a charter, define processes, and embed the council in the existing governance structure. The entire process should be actively supported by senior management.
In detail, the following approach is recommended:
- Stocktaking: Which AI systems is the company already using? Which risk classes are affected? A gap analysis based on ISO 42001 helps to assess the current state.
- Assemble the body: Interdisciplinary composition from IT, legal, HR, data protection, and management level. Define clear roles and responsibilities.
- Develop a charter: Written foundation with mandate, decision-making authority, meeting schedule, and reporting obligations.
- Define assessment processes: How are new AI projects submitted and evaluated? What criteria apply for approval?
- Integration and communication: Embed the council in existing governance structures and inform employees about tasks and points of contact.
A common mistake is treating the ethics council as a downstream control body that merely rubber-stamps finished projects. More effective is early involvement, already in the conceptual phase. This avoids costly corrections after the fact and builds trust in AI systems from the very beginning.
How mITSM supports the development of AI governance expertise
We at mITSM offer practical training that empowers specialists and managers to build and operate AI governance structures such as an AI ethics council on a sound basis. Our courses combine regulatory knowledge with concrete skills for action.
Here is what we offer specifically:
- Fundamentals of AI application: Comprehensive knowledge of AI governance, the EU AI Act, ISO 42001, and AI compliance for those responsible within companies
- KIMS Auditor: Specialised training for people who introduce or audit an AI management system based on ISO 42001
- AI Compliance Officer: An overview of all relevant legal standards, from the EU AI Act to the GDPR, for multipliers within the company
- Certifications via ICO-Cert: Recognised personal certifications that concretely increase market value in the job market
- Flexible formats: In-person, online live, and e-learning at 11 locations throughout Germany
All our trainers are certified experts who know AI governance not only from theory, but from practical work with companies. Anyone who wants to take the next step will find the right offering on our training page or can find out more directly about our ISO 42001 audit offering. Get in touch with us and build AI governance expertise that truly delivers.
Dieser Inhalt wurde mithilfe von KI erstellt und kann Fehler enthalten.