Closing the Responsible AI Gap
The purpose and necessity of Responsible AI is generally well understood and agreed upon among organizations. The struggle of moving from an ethical aspiration to an operational imperative is often attributed to the lack of appropriate methodology, governance framework, and cross-functional literacy to implement it.
Organizations typically have these functions in place; the challenge is to close the conventional gap to accommodate the requirements specific to AI.
The gap is most significant across two areas — the GRC framework, which establishes the governance, risk and compliance guardrails; and the methodology, which provides the vehicle for embedding governance into AI development and deployment — both of which require AI-specific provisions, tailored to the organization’s context, to be effective.
The Methodology Gap
Organizations will often use conventional approaches to develop or implement AI applications, which have been proven to be inadequate for AI requirements. Fundamentally, conventional approaches are designed to deliver applications that are deterministic in nature, whereas AI applications are probabilistic and require a different approach.
Agile is often the default choice for managing AI because of its iterative nature; while it can partially be applied across the AI lifecycle, it is insufficient as a standalone methodology for AI development and deployment — particularly given that AI applications can never meet the Definition of Done (DoD), and Agile was never designed to embed governance in the application lifecycle.
Several AI methodologies were developed prior to the emergence of Responsible AI as a requirement, leaving fewer options for organizations. CPMAI™ stands as a strong candidate for AI development and deployment; it is structured to accommodate AI governance for Responsible AI throughout its lifecycle.
Unlike conventional applications, the process for implementing an AI application (Deployer) is similar to that for developing the AI application (Provider). Using the CPMAI™ Lifecycle as an example, deploying an AI application goes through every phase except for Phase 4 — Model Development. What differentiates the two is the organization’s responsibilities and accountability under the EU AI Act.
The GRC Gap
Selecting the right methodology addresses only part of the challenge; the governance framework supporting it must equally be appropriate for AI. One way of looking at it is that the AI Lifecycle provides the structure for Responsible AI, with placeholders to integrate governance within each phase; GRC provides the substance to fill those placeholders.
Both are necessary and neither can be used in isolation. The AI Lifecycle without governance will only succeed at developing a technical solution, leaving the AI application exposed to risk and liability. Unlike conventional GRC, which is predominantly used as a tool for periodic audits, AI GRC must be embedded into the AI Lifecycle to support Responsible AI by design and continuous monitoring.
This integration provides a consistent methodology across AI applications, while accommodating different contexts through Governance, Risk and Compliance provisions that are highly dependent on the organization’s sector or industry, and the purpose of the AI systems being implemented.
Cross-functional Literacy
The challenge with traditional roles in most organizations is that project managers and GRC managers require deeper cross-functional knowledge to effectively manage AI initiatives.
It would be difficult for a project manager without explicit knowledge of GRC to successfully embed GRC into the AI Lifecycle; similarly, it would be difficult for a GRC lead without explicit knowledge of the AI Lifecycle to do the same, or even perform audits.
Implementing a comprehensive AI Framework requires, at minimum, training to increase AI literacy across the organization.
AI Centre of Excellence (AI CoE)
Similar to how AI GRC is an expansion of the Enterprise GRC to address AI related governance requirements, the AI CoE is an expansion of the PMO to enforce and provide oversight for the implementation of AI GRC into the AI Lifecycle.
The rationale is that many conventional project management principles still apply to AI initiatives, the same way conventional GRC is still applicable to AI initiatives. Since the PMO is already designed to provide governance and oversight, its function is simply extended to enforce the integration of AI GRC.
The AI CoE is also responsible for enforcing an Acceptable Use Policy (AUP) for AI applications used internally to support employees’ productivity. The use of Agentic AI carries significant risk — an agent accidentally revealing personal information when querying the HR system to generate a report could infringe privacy laws.
The AI CoE is the organizational vehicle for developing and sustaining this cross-functional capability.
The EU AI Act
While the EU AI Act is a binding legal force limited to organizations operating within or serving the EU market, it has become a de facto global reference for AI regulation in many countries.
In fact, Canada has signed an MOU with the European Union in December 2025, aligning on trustworthy AI principles and signaling intent toward regulatory convergence. In jurisdictions where AI-specific legislation has yet to be enacted, AI applications must comply with existing laws and regulations.
One aspect of the EU AI Act worth highlighting is the responsibilities assigned to various AI actors in the chain of custody. The Act established that every AI actor bears some degree of accountability, whether the actor is designated as a Provider, an Importer, a Distributor or a Deployer. Understanding your role as an AI actor is essential to establishing the necessary provisions and avoid unexpected liability.
If you deploy an AI system in your organization, you are the Deployer and therefore Deployer accountability applies. This is a significant shift from traditional systems implementation, where accountability is primarily borne by the Provider.
If you make substantial changes to a Provider’s AI system, you are de facto assuming both Deployer and Provider responsibilities in the process.
Because agentic systems can autonomously expand their own scope of action during execution, an agent initially designed for a narrow purpose may begin profiling individuals or materially influencing a decision — creating a compliance blind spot and potential liability.
Accountability under the EU AI Act is dynamic — it shifts with behaviour, modification, and use, reinforcing the need for continuous monitoring as a core component of any AI governance framework.
Conclusion
Organizations are under significant pressure to integrate AI into their operations. In attempts to fast-track implementation, they may prioritize the technical aspects of AI deployment over governance — leaving themselves exposed to liability that courts and regulators are increasingly unwilling to overlook.
Closing the Responsible AI Gap requires closing three interconnected gaps simultaneously — the right methodology for AI development and deployment, a governance framework with AI-specific provisions, and the cross-functional literacy to bring both together. Addressing these gaps not only reduces risk and liability exposure, but establishes a structured approach that leads to increased efficiency, consistency, and confidence in AI delivery.
References
OECD AI Principles
https://oecd.ai/en/ai-principles
General Data Protection Regulation (GDPR)
https://gdpr-info.eu
NIST AI RMF
https://airc.nist.gov/RMF
UNESCO — Recommendation on the Ethics of AI
https://www.unesco.org/en/artificial-intelligence/recommendation-ethics
ISO/IEC 42001
https://www.iso.org/standard/81230.html
ISO/IEC 42005
https://www.iso.org/standard/44545.html
ISO/IEC 22989
https://www.iso.org/standard/74296.html
EU AI Act
https://artificialintelligenceact.eu