
By Chuck Gallagher — Business Ethics Keynote Speaker and Trainer
TL;DR: Most AI ethics frameworks stop at fairness, transparency, privacy, and accountability — the four pillars Thomson Reuters and others have outlined as the foundation for responsible AI use. Chuck Gallagher, AI speaker and author, argues those pillars are necessary but not sufficient: what organizations keep skipping is the human decision to rationalize, and that gap is where AI ethics failures are actually born. Governance documents don’t fail. People do — and until leaders treat AI ethics as a human behavior problem, the four pillars will sit on unstable ground.
A compliance officer at a mid-sized financial firm spends six months building an AI governance policy. It covers data privacy, algorithmic fairness, explainability requirements, and a review board sign-off process. She presents it to the executive team, gets applause, and files it in the company’s policy repository. Three months later, a business unit head deploys a vendor AI tool that bypasses the review board entirely — because the quarter-end deadline was too close, the deal was too important, and the workaround felt justified. The policy never changed. The behavior did.
That is the story Thomson Reuters’ Future of Professionals Report 2025 is quietly telling, even if it doesn’t frame it that way. The report — which surveyed more than 2,000 legal, risk, compliance, tax, accounting, audit, and trade professionals — found that nearly two-thirds of respondents’ organizations lacked a clearly spelled-out AI adoption plan. It also found that 37 percent cited ethics as one of their main concerns about AI investment, and 50 percent pointed to a lack of demonstrable accuracy as a major barrier. Those numbers describe organizations that know they have a problem but haven’t connected the problem to its actual source.
What the Four-Pillar Framework Gets Right — and What It Misses
As an AI ethics speaker and author, I want to be clear: the four-pillar framework that Thomson Reuters and similar organizations have articulated is sound. Fairness and non-discrimination, transparency and explainability, privacy and data protection, accountability and responsibility — these are the right categories. They give organizations a structure for thinking about the risks that come with AI deployment, and they mirror the principles baked into frameworks like the EU’s AI Act, which became the world’s first comprehensive legal framework for regulating artificial intelligence when it was established in 2024. Anyone dismissing these pillars as bureaucratic box-checking is underestimating how much discipline it actually takes to implement them properly.
But frameworks don’t make choices. People do. And people have a remarkable capacity to decide, in the moment, that a policy doesn’t quite apply to this situation — that the stakes are too high, the timeline too short, the benefit too obvious to let a governance process slow things down. I have spent thirty years studying how otherwise reasonable, credentialed professionals end up crossing ethical lines they swore they’d never cross. The pattern is almost always the same: a perceived need, an available opportunity, and a rationalization that makes the compromise feel justified. That three-part sequence — need, opportunity, rationalization — doesn’t disappear just because an organization has an AI ethics policy. It gets applied to the policy itself.
The rationalization sounds like this: “We have the framework in place, so we’re covered.” Or: “We’re using a reputable vendor, so the ethics question is their problem, not ours.” Or my personal favorite: “Everyone in our industry is doing this the same way.” The Thomson Reuters report found that many professionals remain uncertain about how to balance technical innovation and professional ethics. That uncertainty is not primarily a knowledge gap. It is a rationalization gap — the space between knowing what the right process requires and deciding, in a specific moment of pressure, that this particular situation is different enough to justify skipping it.
What Does Responsible AI Governance Actually Require From Leaders?
The Thomson Reuters piece correctly identifies three best practices for implementing AI governance: understanding the technology, instructing employees about ethical and legal implications, and maintaining ongoing monitoring. I would add a fourth that the compliance world almost always leaves out — training people to recognize rationalization in real time. The EU’s AI Act and Colorado’s AI Act, which goes into effect in February 2026 to regulate high-risk AI systems, can mandate process requirements. They cannot mandate the moment when a vice president decides that the process doesn’t apply to his deal. That moment is where AI ethics is won or lost, and it is not a regulatory problem. It is a human behavior problem.
I have watched organizations build beautiful governance frameworks and then culture their way right past them. The Thomson Reuters report notes that 91 percent of professionals believe computers should be held to higher standards than humans. That statistic is fascinating for what it reveals about the human side of this equation: we are willing to demand ethical performance from machines while giving ourselves considerably more latitude. That asymmetry is exactly where the rationalization lives. If we hold AI to a standard we are unwilling to apply to the humans deploying it, we have not built an ethics framework. We have built a liability shield.
At ChuckGallagher.com, I argue consistently that compliance is downstream of ethics — that policies capture what ethical behavior looks like after the fact, but they do not create the conditions that produce ethical behavior in the first place. AI governance is no different. The audit trails, the explainability requirements, the review board sign-offs — those are all downstream artifacts. The upstream question is whether the people in your organization have internalized the principle that AI is not a shortcut past accountability, that deploying a tool does not transfer the moral weight of a decision to the tool, and that “the algorithm decided” is not an ethical defense. It is a rationalization.
As an AI ethics speaker and author, what I tell every leadership team I work with is this: your AI ethics program is only as strong as the decision your most pressured employee makes at 4:45 on a Friday afternoon when the quarter is ending, the vendor is ready to go live, and the governance review is going to take two more weeks. Build for that moment. Not just for the policy document.
Frequently Asked Questions
Q: What are the four core principles of AI ethics in professional services?
A: The four core principles are fairness and non-discrimination, transparency and explainability, privacy and data protection, and accountability and responsibility. Thomson Reuters’ Future of Professionals Report 2025, which surveyed more than 2,000 professionals across legal, risk, compliance, and tax fields, identified these principles as the foundation for responsible AI use in regulated industries. Organizations that implement all four still need to address the human decision-making patterns — particularly rationalization — that can undermine even well-designed frameworks.
Q: Why do AI ethics frameworks fail in practice?
A: AI ethics frameworks most commonly fail not because they are poorly designed but because of the human tendency to rationalize exceptions under pressure. Research consistently shows that need, opportunity, and rationalization are the three factors that lead otherwise ethical people to cross ethical lines — and those same forces are applied to governance processes themselves. The Thomson Reuters Future of Professionals Report 2025 found that nearly two-thirds of organizations lacked a spelled-out AI adoption plan, creating the exact ambiguity that makes rationalization easier.
Q: What is the EU AI Act and how does it affect AI governance?
A: The EU’s AI Act, established in 2024, is the world’s first comprehensive legal framework for regulating artificial intelligence. Its risk-based approach categorizes AI systems by the potential harm they could cause, with the strictest requirements applied to high-risk systems that make decisions about employment, financial access, legal services, or healthcare. Colorado’s AI Act, which goes into effect in February 2026, takes a similar approach at the state level in the United States. Both frameworks set process requirements but cannot substitute for the cultural and behavioral conditions that produce ethical decision-making.
Q: How should organizations handle AI accountability when something goes wrong?
A: Accountability for AI failures must be anchored to the humans who made deployment decisions, not the systems themselves. Chuck Gallagher, AI speaker and author, argues that “the algorithm decided” is a rationalization, not an ethical defense — and governance frameworks must make that clear before failures occur. The Thomson Reuters framework points to audit trails and human oversight as essential mechanisms, and 91 percent of professionals in the Future of Professionals Report 2025 believe computers should be held to higher standards than humans — a belief that must be matched by human accountability structures, not just technical ones.
Q: What is the difference between AI compliance and AI ethics?
A: Compliance captures what ethical behavior looks like in documented policies and processes; ethics is the condition that produces ethical behavior in the first place. An organization can be fully compliant on paper and still have employees who rationalize shortcuts around every control in place. The ABA’s Model Rules of Professional Conduct, for example, do not address AI usage directly but require lawyers to maintain competence — meaning the ethical obligation exists regardless of whether a specific AI rule does. Building a culture where people internalize ethical principles, rather than just follow checklists, is the distinction that separates organizations that handle AI responsibly from those that merely appear to.
I want to hear from you. Has your organization moved beyond the policy document — are you actively training people to recognize rationalization when it shows up in AI deployment decisions? Or have you found that governance frameworks mostly get bypassed when the pressure is high enough? Drop your experience in the comments below, and I will respond personally. And that question leads directly into what I think are the most important reflection prompts for leaders navigating this right now.
Five Questions for Further Thought and Consideration
1. If you asked your most pressured employee to describe your organization’s AI governance process right now, what would they say — and how close would that description be to the actual written policy?
2. In the last twelve months, has your organization ever deployed or continued using an AI tool while a governance review was still pending? What was the rationalization for that decision?
3. When your AI system produces an outcome that harms a client or employee, who in your organization is personally accountable — and does every person on your leadership team know that answer today?
4. How does your organization train people to recognize rationalization in real time, and how would you know if that training was actually changing behavior?
5. If 91 percent of professionals believe AI should be held to higher standards than humans, what does that belief actually require of the humans who deploy, oversee, and are accountable for AI systems?
Related Articles:
Healthcare and Ethics: Is “Fail Fast” the Ethically Responsible Approach?
