72% of AI Firms Lack Ethics in 2026

Listen to this article · 8 min listen

Despite the rapid advances in artificial intelligence, a striking 72% of global AI companies still operate without a formal ethical AI policy in place, according to a 2025 survey by the AI Ethics Institute. This statistic reveals a significant gap between technological progress and the establishment of strong governance, raising critical questions about how we ensure responsible AI development. How do we bridge this chasm to foster innovation while safeguarding societal well-being?

Key Takeaways

  • Only 28% of AI companies have a formal ethical AI policy, highlighting a substantial governance deficit.
  • The European Union’s AI Act, effective from mid-2025, mandates risk-based compliance for AI systems, setting a global precedent for complete AI regulation.
  • U.S. federal agencies, like the National Institute of Standards and Technology (NIST), are prioritizing voluntary AI risk management frameworks over direct legislative mandates as of 2026.
  • Global harmonization of AI regulatory standards remains a distant goal, with significant divergence in approaches between major economic blocs.
  • Companies must proactively integrate ethics into their AI development pipelines, moving beyond mere compliance to genuine responsible innovation.

The Startling Gap: 72% of AI Companies Lack Ethical Policies

The figure of 72% of AI companies operating without a formal ethical AI policy is not merely a number. It represents a systemic oversight that has real-world consequences. This absence means that decisions embedded within AI algorithms, from hiring tools to credit scoring systems, often lack explicit ethical guardrails. When I consult with organizations on their AI strategies, this is the first area we address. Companies frequently focus on technical performance and scaling, deferring ethical considerations until a problem arises. This reactive stance is insufficient for technologies with the potential to impact fundamental rights and public trust. The lack of a codified policy often translates into an absence of clear internal guidelines for data privacy, algorithmic bias detection, and transparency. Without these foundational elements, AI systems can perpetuate or even amplify existing societal inequalities, often unintentionally. The challenge is not just about compliance. It’s about embedding a culture of responsibility from the initial design phase through deployment and ongoing maintenance.

EU’s AI Act: A Regulatory Blueprint

In a significant legislative move, the European Union’s AI Act became effective in mid-2025, establishing a complete, risk-based regulatory framework for AI systems. This landmark legislation categorizes AI applications into various risk levels, imposing stringent requirements on “high-risk” systems, which include those used in critical infrastructure, law enforcement, and employment decisions. For instance, AI systems designed to assess creditworthiness are subject to rigorous conformity assessments, human oversight requirements, and strong data governance practices. This act represents a proactive attempt to manage the societal implications of AI, forcing developers and deployers to consider ethical implications from the outset. The EU’s approach stands as a powerful counterpoint to the prevailing lack of internal policies in many companies, demonstrating that external regulatory pressure can drive significant shifts in corporate behavior. While some argue that such extensive regulation could stifle innovation, the intent is to foster trustworthy AI, thereby potentially accelerating adoption by building public confidence. The fines for non-compliance are substantial, creating a strong incentive for adherence across all member states.

U.S. Approach: Frameworks Over Mandates

Across the Atlantic, the United States has largely favored a different path. As of 2026, federal agencies, particularly the National Institute of Standards and Technology (NIST), have prioritized the development of voluntary AI Risk Management Frameworks rather than direct legislative mandates similar to the EU’s AI Act. NIST’s AI RMF 1.0, released in early 2025, provides detailed guidance for organizations to identify, assess, and manage risks associated with AI. This framework emphasizes concepts like transparency, accountability, and validity, offering a structured approach for companies to self-govern. The U.S. strategy banks on industry-led adoption and the flexibility of non-binding guidelines to encourage innovation while addressing risks. For example, a company developing AI for medical diagnostics might use the NIST framework to establish clear protocols for data provenance, model validation, and human review processes, even without a direct legal obligation. This approach reflects a belief that overly prescriptive laws could hinder the rapid evolution of AI technology. My view is that while frameworks provide excellent guidance, their voluntary nature means adoption can be inconsistent, leaving significant gaps in accountability for less scrupulous actors. The market alone, I believe, will not solve these complex ethical dilemmas.

The Slow Pace of Global Harmonization

Despite the global nature of AI development and deployment, international efforts to harmonize AI regulatory standards remain fragmented and slow. The divergence between the EU’s prescriptive legislation and the U.S.’s voluntary frameworks illustrates this challenge clearly. While organizations like the OECD have issued principles on AI, translating these high-level ideals into actionable, globally recognized regulations has proven difficult. China, for instance, has implemented its own set of rules, particularly focusing on data security and algorithmic recommendations. This patchwork of regulations creates significant compliance burdens for multinational corporations developing AI. A company operating in all three regions must navigate distinct requirements for data governance, bias mitigation, and transparency. This lack of a unified global approach hinders the free flow of innovation and creates potential for regulatory arbitrage. Achieving true global harmonization would require unprecedented levels of international cooperation, something that has been elusive even on less complex issues. We see this with the ongoing discussions at the UN and G7, where consensus on specific regulatory mechanisms remains elusive, despite broad agreement on the need for responsible AI.

Beyond Compliance: The Imperative for Integrated Ethics

The conventional wisdom often suggests that regulation is a necessary evil, a hurdle to innovation. I disagree fundamentally with this premise, especially concerning AI. The real challenge is not simply to comply with emerging regulations, but to integrate ethical considerations directly into the AI development lifecycle. This means moving beyond a checkbox mentality. Consider the development of a large language model. It’s not enough to run a bias audit post-deployment. Ethical integration requires diverse teams, continuous stakeholder engagement, and clear ethical design principles from the project’s inception. This proactive stance, which I advocate for all my clients, transforms ethics from a compliance burden into a competitive advantage. Companies that genuinely prioritize fairness, transparency, and accountability will build greater trust with users and regulators alike, in the end fostering more sustainable innovation. This integrated approach, for example, might involve using privacy-preserving AI techniques like federated learning or homomorphic encryption by default, rather than as an afterthought. It acknowledges that responsible innovation is not a separate track. It is the track.

The journey toward responsible AI is complex, marked by differing regulatory philosophies and the urgent need for internal ethical frameworks. Companies must move beyond reactive compliance to proactively embed ethical considerations into every stage of AI development.

What is the primary goal of AI regulation?

The primary goal of AI regulation is to ensure that artificial intelligence systems are developed and deployed in a manner that benefits society, respects fundamental rights, and mitigates potential risks such as bias, discrimination, and privacy violations. It seeks to balance innovation with public safety and ethical considerations.

How does the EU’s AI Act differ from the U.S. approach to AI governance?

The EU’s AI Act adopts a prescriptive, risk-based legislative approach, mandating specific requirements and conformity assessments for AI systems, particularly those deemed “high-risk.” In contrast, the U.S. primarily relies on voluntary frameworks, such as NIST’s AI Risk Management Framework, encouraging industry self-governance rather than direct legislative mandates.

What are the consequences for companies that do not adhere to AI regulations?

Consequences for non-adherence vary by jurisdiction but can include significant financial penalties, reputational damage, legal liabilities, and even restrictions on deploying or selling AI systems. The EU’s AI Act, for example, includes provisions for substantial fines for non-compliance.

Why is ethical AI policy important for businesses?

An ethical AI policy is important because it provides internal guidelines for developing and deploying AI responsibly, addressing issues like data privacy, algorithmic bias, and transparency. It helps build trust with users, ensures compliance with emerging regulations, and mitigates risks that could lead to financial penalties or reputational harm.

Can AI regulation stifle innovation?

While some argue that regulation can slow down innovation due to compliance burdens, proponents contend that thoughtful regulation encourages trustworthy AI, which can actually accelerate adoption and encourage more sustainable, responsible innovation. By setting clear boundaries, it can guide development towards beneficial applications and prevent costly mistakes.

Christopher Briggs

Senior Policy Analyst MPP, Georgetown University

Christopher Briggs is a Senior Policy Analyst with over 15 years of experience dissecting complex legislative initiatives for news organizations. Currently at the Institute for Public Discourse, she specializes in the socio-economic impacts of healthcare reform, offering incisive analysis on how policy shifts affect everyday citizens. Her work has been instrumental in shaping public understanding of the Affordable Care Act's long-term effects. She is widely recognized for her groundbreaking report, 'The Hidden Costs of Deregulation: A Five-Year Review of State Health Exchanges.'