Back Icon Return to blog

What Companies Need to Know About the OECD’s New Guidance on Responsible AI

Neil Bradley Neil Bradley September 3, 2026

Key Highlights

  • The OECD's new voluntary guidance offers the first global framework to help companies manage responsible AI use and due diligence across the entire AI value chain.
  • The six-step framework asks companies to identify, prevent, and remediate AI-related risks, from embedding policy commitments through to remediation.
  • Corporate AI investment more than doubled from about $253 billion in 2024 to over $580 billion in 2025, driving both opportunity and regulatory risk.
  • With regulations fragmented across the EU, U.S., China, and other regions, the OECD Guidance gives multinational companies a common, interoperable starting point.

Earlier this year, the Organisation for Economic Co-operation and Development (OECD) published guidance on responsible use of artificial intelligence (AI) – the first framework of its kind, designed to help companies navigate the global patchwork of AI-related regulations.

G&A has now developed a resource to help companies translate the OECD’s guidance into internal policies and process improvements around due diligence for responsible AI use. Our issue brief also provides a geographical map showing the current regulatory environment.

If your company uses AI — whether you’re building it, deploying it, or just using it to enhance day-to-day operations — it will likely face increasing regulatory scrutiny as responsible AI regulations proliferate worldwide. The OECD Guidance can serve as a high-level reference for companies as they embark on managing AI more responsibly. Here’s how.

What does the OECD’s guidance entail?

The Guidance is a voluntary, six-step due diligence framework that helps companies identify, prevent, and remediate risks tied to the AI value chain. Rather than treating AI governance as a single compliance step, it walks companies through a comprehensive cycle, including: embedding responsible business conduct into policy, identifying and assessing risks, ceasing or mitigating harm, tracking results, communicating externally, and providing remediation when needed.

G&A-Blog-Graphic-OCED-AI-1

The framework applies across the entire AI value chain, which the OECD divides into three groups:

  • Upstream suppliers (data providers, cloud service providers, hardware manufacturers, financial backers)
  • Companies actively building and operating AI systems
  • Downstream end users, including businesses that use AI tools but are not AI companies themselves

The OECD framework is designed to interoperate with frameworks for a range of other environmental, social, and corporate governance topics, so companies don’t have to start from scratch.

 

Why was it developed?

AI adoption by multinational enterprises has exploded in recent years. Corporate AI investment more than doubled from roughly $253 billion in 2024 to over $580 billion in 2025.

AI adoption by multinational enterprises has exploded in recent years. Corporate AI investment more than doubled from roughly $253 billion in 2024 to over $580 billion in 2025, while the risks associated with that growth also have multiplied. Among these, researchers found that at their current growth rate, AI system deployment and data center developments in the U.S. alone could contribute up to 44 million metric tons of CO2 emissions (MTCO2e) in the next four years[1]. This is equivalent to the amount of CO2 emitted from consumption of nearly 5 billion gallons of gasoline.

At the same time, regulation has struggled to keep pace. Major economies have moved forward with their own approaches: the EU’s Digital Omnibus amendments to the AI Act, the U.S. White House’s National Policy Framework for Artificial Intelligence alongside over 100 state-level AI bills in 2026, new Chinese national standards on generative AI security, and separate frameworks from India, Australia, Brazil, and the African Union. The result is a fragmented, jurisdiction-by-jurisdiction landscape that’s difficult for global companies to navigate in any efficient way. The OECD Guidance aims to give companies a common, interoperable starting point that bridges divergent global requirements.

G&A-Blog-Graphic-OCED-AI-2

 

Who is it for?

The Guidance is built for any enterprise operating within the AI value chain, not just AI developers. In addition to the three main stakeholder groups identified in the Guidance, external stakeholders like nonprofits, advocacy groups, and trade organizations can also use the resource to better drive structured engagements focused on risks and impacts throughout the AI value chain.

It’s especially relevant for companies operating across multiple legal jurisdictions and those that publicly report on their environmental, social, and governance risks and impacts.

 

Looking ahead

While the Guidance remains voluntary for now, it offers companies a practical head start: a structured way to manage AI risk that’s likely to align well with regulations taking shape around the world. Companies that familiarize themselves with evolving AI governance frameworks will be significantly ahead of the curve once regulations become mandatory.

[1] ‘Roadmap’ shows the environmental impact of AI data center boom (2025): https://news.cornell.edu/stories/2025/11/roadmap-shows-environmental-impact-ai-data-center-boom

Globe

How G&A can help

Our team of climate and sustainability experts can help your company adapt internal policies and processes to ensure responsible AI governance through peer benchmarking, gap analyses, public disclosure support, and more. Click here to see our full list of services, and reach out to discuss how we can support your goals around responsible AI use.