The rapid integration of artificial intelligence across industries has catapulted AI governance from a niche policy concern into a critical operational imperative for businesses worldwide. From sales teams leveraging chatbots with client data to hiring managers deploying AI screening tools and board members scrutinizing AI policies, the footprint of AI is expanding at an unprecedented pace. This pervasive adoption necessitates a robust regulatory framework, yet governments globally are charting distinctly different courses, creating a complex and fragmented landscape for enterprises. Dr. Cornelia C. Walther, a visiting scholar at Wharton and director of global alliance POZE, whose research focuses on leveraging AI for social good after two decades at the United Nations, highlights this critical divergence, underscoring that business leaders cannot afford to await legal certainty; proactive engagement is paramount.
The Urgent Need for AI Governance Amidst Rapid Deployment
The acceleration of AI development and deployment has outpaced the traditional legislative cycle, leaving a significant gap between technological capability and regulatory oversight. This disparity creates both opportunities and substantial risks. On one hand, AI promises unprecedented efficiencies, innovation, and problem-solving capabilities across sectors like healthcare, finance, logistics, and communication. On the other hand, the unbridled deployment of AI systems, particularly those involving sensitive data or critical decision-making, raises profound ethical, legal, and societal questions concerning bias, privacy, accountability, job displacement, and even fundamental human rights.
For a CEO, understanding the nuances of AI law isn’t about memorizing statutes but recognizing their manifestations in daily operations. The queries from board members about AI policy, the data handling practices of AI-powered customer service, or the fairness implications of AI in recruitment are all direct reflections of a maturing regulatory environment. The challenge is magnified by the lack of global consensus on how to effectively govern AI, leading to a patchwork of approaches that business leaders must decipher and navigate.
Divergent Regulatory Philosophies: A Global Snapshot
The world’s leading jurisdictions are approaching AI regulation with distinct philosophical underpinnings, each carrying unique implications for businesses operating within or interacting with these markets.
Greece: Embedding AI in Constitutional Bedrock
Greece provides a compelling example of a foundational approach to AI governance. In May 2026, Prime Minister Kyriakos Mitsotakis proposed a constitutional revision aimed at ensuring AI serves individual freedom and social prosperity. This move signifies a profound commitment to embedding human-centric principles at the highest legal level. Constitutional changes are inherently slow and deliberate processes, requiring extensive deliberation, successive parliamentary votes, and significant political consensus. However, their value lies precisely in their enduring nature; they establish fundamental principles that transcend technological cycles and serve as an immutable guide for future legislation, judicial interpretations, and public expectations.
For companies developing or deploying AI in critical sectors such as credit assessment, insurance underwriting, healthcare diagnostics, employment screening, or public communication, this constitutional signal is incredibly potent. It telegraphs a long-term societal commitment to prioritizing human agency and well-being over purely technological advancement. While the immediate legal ramifications may take time to materialize, the constitutional language will inevitably shape subsequent ordinary laws, influence litigation, and elevate public scrutiny. What might be considered an ethical dilemma today could very well become a stringent legal test tomorrow. Moreover, this approach subtly raises the bar for organizational transparency and accountability. To demonstrate that AI serves human freedom, organizations must possess a deep understanding of how their AI systems impact human attention, judgment, and choice, and be able to articulate and prove these insights. Legal scholars and civil society groups have largely lauded this move as a forward-thinking attempt to future-proof human rights in the age of AI.
California: Agile Governance Through Executive Action and Procurement Power
In stark contrast to Greece’s foundational approach, California exemplifies a rapid and practical regulatory rhythm driven by executive action and strategic procurement policies. Recognizing that the state could not wait for lengthy legislative processes while AI companies, workers, public agencies, and consumers were already experiencing AI’s effects, Governor Gavin Newsom issued a landmark executive order in 2023. This initial order directed state agencies to comprehensively study generative AI, identify beneficial public-sector applications, and thoroughly assess associated risks. This pragmatic, iterative approach has defined California’s strategy ever since.
Building on this foundation, California has continued to roll out targeted executive orders. In March 2026, a new executive order significantly strengthened AI procurement standards. Companies seeking state business are now required to demonstrate robust safeguards across multiple critical dimensions: privacy protection, system safety, data security, algorithmic bias mitigation, civil rights adherence, and prevention of misuse. This means vendors must provide transparent answers to questions about model training data, error detection mechanisms, human oversight protocols, and incident response in cases of harm. Just two months later, in May 2026, another executive order addressed AI’s potential for workforce disruption, focusing on worker training initiatives, exploring innovative ownership models, and devising mechanisms for employees to share in productivity gains generated by AI.
This "regulation by leverage" strategy is powerful. By dictating what it buys, the government effectively shapes the market, turning procurement requirements into de facto industry standards. Companies selling to state entities, healthcare providers, educational institutions, or other regulated industries in California will increasingly face detailed inquiries about their AI systems. Who trained the model? What data was used? How are errors detected? Where is human oversight mandated? What recourse exists when harm occurs? These are not trivial questions. The implication is that businesses must have a systematic way to map their AI systems against dimensions like privacy, bias, explainability, human oversight, environmental footprint, employee agency, and user dignity. Tech companies operating in California have expressed a mixture of compliance challenges and recognition of the necessity for these standards, while labor unions have largely welcomed the focus on worker protections.
The European Union: A Risk-Based Framework for Comprehensive Oversight
The European Union’s AI Act, which formally entered into force in August 2024, represents a third distinct regulatory philosophy: a comprehensive, risk-based approach. Drawing parallels to its globally influential General Data Protection Regulation (GDPR), the EU AI Act classifies AI systems into different risk categories, assigning corresponding obligations and compliance requirements.
The Act categorizes AI systems based on their potential to cause harm:
- Unacceptable Risk: AI systems that manipulate human behavior, exploit vulnerabilities, or are used for social scoring by governments are prohibited outright.
- High-Risk: This category includes AI systems used in critical infrastructure, education, employment, access to essential services (e.g., credit, healthcare), law enforcement, migration management, and the administration of justice. These systems face stringent requirements, including robust risk management systems, high-quality data governance, mandatory human oversight, high levels of accuracy, robustness, and cybersecurity, and clear transparency obligations.
- Limited Risk: Systems like chatbots or emotion recognition systems must comply with specific transparency requirements, such as informing users they are interacting with an AI.
- Minimal Risk: The vast majority of AI systems fall into this category and face minimal or no specific legal obligations beyond existing legislation.
This model resonates with many business leaders accustomed to enterprise risk management frameworks. It logically dictates that an AI system determining access to housing should bear a significantly heavier compliance burden than a social media caption generator. However, the operational challenge for many organizations lies in transitioning from "AI enthusiasm to AI discipline." As McKinsey’s 2025 State of AI survey found, while AI use is widespread, its enterprise-scale impact remains uneven. High-performing organizations distinguish themselves by proactively redesigning workflows and explicitly defining where human validation is indispensable. The EU AI Act demands precisely this clarity: value from AI is derived not from mere deployment, but from clearly delineating responsibilities and ensuring human judgment remains actively engaged. Fines for non-compliance can be substantial, reaching up to €35 million or 7% of a company’s global annual turnover, whichever is higher, signaling the EU’s serious intent. European businesses, particularly those in high-risk sectors, have begun significant compliance efforts, recognizing the "Brussels effect" – where EU regulations often become a de facto global standard.
The Business Imperative: Why Waiting for Legal Certainty is Costly
The temptation for many executives to defer action until the legal environment for AI "settles" is understandable but ultimately costly. As Dr. Walther emphasizes, AI law will remain uneven for years to come because different jurisdictions are making fundamental, often divergent, choices about freedom, safety, labor, and democracy. This waiting period is, in fact, the risk period, characterized by escalating financial, reputational, and operational exposures.
Growing Consensus on Trustworthiness and Measurable Governance:
Despite the divergence in regulatory approaches, a consistent signal emanates from leading global bodies regarding the future of AI governance. The Stanford 2025 AI Index, a comprehensive report tracking AI trends, consistently highlights the increasing societal impact of AI and the urgent need for robust ethical frameworks. Similarly, the OECD’s updated AI Principles underscore responsible innovation, human-centered values, robust and secure AI systems, transparency, and accountability as cornerstones of effective governance. The NIST Generative AI Profile provides a practical risk management framework, focusing on critical aspects like fairness, privacy, security, and transparency in generative AI applications. These convergent recommendations all point in the same direction: AI governance is rapidly becoming measurable, and trustworthiness is transitioning from an aspirational ideal to a concrete operational requirement.
Strategies for Building AI Agency: Dr. Walther’s Framework
To navigate this complex landscape and build enduring value, organizations need a minimum layer of "AI agency," independent of current legal mandates. Dr. Walther proposes two critical moves:
1. Cultivating "Double Literacy": Human and Algorithmic
Double literacy is the ability to understand both our human faculties and the mechanisms of AI systems.
- Human Literacy: This involves a deep understanding of our own cognitive processes – our aspirations, emotions, thoughts, sensations – including inherent biases, how attention is captured and manipulated, and the dynamics of social influence. It recognizes that humans are not perfectly rational actors and that AI systems can exploit or enhance these human traits.
- Algorithmic Literacy: This is the ability to comprehend how AI systems function – how they process data, make decisions, learn, and influence our perceptions, beliefs, and choices. It involves understanding the limitations, potential biases, and opaque nature of complex algorithms.
Together, these literacies are crucial for preserving human agency in an AI-saturated world. They must be fostered at every organizational level: board members asking incisive questions about AI’s impact, managers redesigning workflows to optimize human-AI collaboration, and employees using AI tools without surrendering critical judgment. This dual understanding empowers individuals to identify potential risks, challenge assumptions, and ensure AI remains a tool serving human objectives.
2. Integrating the Prosocial AI Index
The Prosocial AI Index offers organizations a structured and systematic methodology to assess whether their AI systems are "tailored, trained, tested, and targeted to bring out the best in and for people and planet." It provides measurable indicators across critical dimensions, including:
- Human Oversight: Ensuring meaningful human control and intervention capabilities.
- Bias Testing: Rigorous evaluation and mitigation of algorithmic bias.
- Explainability: The ability to understand and communicate how AI systems arrive at their decisions.
- Privacy: Robust protection of user data and adherence to privacy principles.
- Environmental Footprint: Assessing and minimizing the energy consumption and environmental impact of AI.
- Employee Agency: Empowering workers and ensuring AI enhances rather than diminishes their roles.
- User Dignity: Designing AI to respect and uplift human dignity.
Implementing such an index proactively allows organizations to build credibility and demonstrate responsible AI practices before external scrutiny intensifies. Retrofitting AI systems after regulations arrive is invariably more expensive and disruptive. Prosocial AI, with its focus on measurable agency and governance, has the potential to become the new ESG (Environmental, Social, and Governance) framework, offering sharper substance and a tangible pathway to responsible innovation, rather than merely serving as a branding exercise. Companies that embrace this proactive approach will emerge as "hybrid pioneers"—fluent in cutting-edge technology yet deeply committed to human-centric values—and will be strategically positioned for a legal environment that will increasingly demand proof that AI serves human freedom.
The Rise of Hybrid ROV: Return on Values
In an economy increasingly shaped by AI, the traditional metric of narrow ROI (Return on Investment), focused solely on short-lived efficiency gains, is insufficient. Dr. Walther advocates for a shift towards "Hybrid ROV"—Return on Values. This broader framework captures the profound, long-term benefits derived from ethical and responsible AI practices, including:
- Trust: Building confidence among customers, employees, and the public.
- Resilience: Creating robust systems that can withstand scrutiny and adapt to evolving ethical standards.
- Talent Attraction and Retention: Drawing in and retaining skilled professionals who seek purpose-driven work.
- Legitimacy and Social License: Earning societal acceptance and permission to operate.
These "intangible" assets are rapidly becoming the foundational conditions under which future value can be created and sustained in the AI era. Pioneering companies will be those that not only leverage AI for efficiency but also integrate it in a manner that upholds human dignity, fosters trust, and demonstrates a clear commitment to societal well-being. This strategic foresight will define leadership in the complex, regulated, and human-centric future of artificial intelligence.
