As generative artificial intelligence (AI) tools like ChatGPT, Gemini, and Claude become core components of daily business operations, AI is no longer merely a technological means to improve efficiency. Its influence now extends deeply into marketing, credit assessment, investment, customer service, and even executive decision-making. This makes AI governance an urgent priority. Yet, while many companies actively invest in AI adoption, only a minority have truly established and implemented comprehensive AI governance frameworks. The real risk for companies is not "lacking AI," but "having AI without governance." Currently, many corporate AI applications already touch on customer rights, personal data protection, credit decisions, and internal confidentiality, yet overall governance remains at the level of "letting the IT department test it." This is no longer a technical issue—it is a breakdown in corporate governance.

To assist financial institutions in securely and effectively managing emerging technologies, the securities and futures market-related industry associations released the "Guidelines for Information Security Control of Emerging Technologies by Securities and Futures Market-Related Associations" on December 27, 2024 (113th year of the Republic of China calendar). Chapter 8 of these guidelines contains 13 articles specifically addressing "Security Controls for AI Usage." This article argues that although these guidelines are designed for the financial sector, they effectively serve as an AI governance textbook for all organizations, offering valuable lessons for every industry.

The core principles of the guidelines can be distilled into eight governance pillars: governance accountability, risk classification, third-party oversight, fairness, data privacy, security and robustness, transparency and explainability, and a warning against blind trust in generative AI and the risk of data leakage. Below, these principles are translated into eight actionable AI governance lessons that any enterprise can understand and begin to implement.

Lesson One – Governance Accountability: Ask "Who is responsible?" before asking "How do we implement it?"

The typical path for AI adoption in companies today is for the IT department or a business unit to first purchase tools and run models, with governance frameworks added only afterward as a formality. The guidelines require organizations to designate senior executives or establish dedicated committees responsible for overall AI oversight, and to build clear internal governance structures and talent development mechanisms. In other words, governance should be a prerequisite for technology adoption, not an afterthought.

In practice, a simple but harsh test is: "If an AI error leads to a major customer complaint or legal violation, who within the company is accountable?" If there is no clear answer to this question, the AI governance structure is not yet in place.

Lesson Two – Risk Classification: Different risk levels of AI cannot be measured with the same yardstick

The guidelines adopt a risk-based governance approach, requiring organizations to conduct risk assessments and classifications based on use cases, considering factors such as impact on customer rights, extent of personal data usage, degree of AI autonomy, and system complexity. Only then can appropriate control measures and periodic review mechanisms be designed according to the risk level.

For example, an AI tool that summarizes meeting notes carries a fundamentally different risk profile than an AI system that directly provides investment advice or credit decisions. If a company applies the same level of scrutiny to both, it either over-regulates low-risk operations or leaves high-risk applications in a regulatory vacuum. The first step should be to inventory all internal AI use cases, classify them by impact, autonomy, and data sensitivity, and create a "risk map" before determining how to manage them.

Lesson Three – Third-Party Oversight: Outsourcing AI is not outsourcing responsibility, but adds another layer of supervision

Many companies’ AI systems are actually provided by third-party vendors or used via cloud services. The guidelines explicitly require that when organizations outsource AI, they must carefully evaluate the vendor’s expertise and experience, include clauses on security, data protection, liability, and penalties in contracts, and require vendors to retain execution records for traceability and verification.

The key point is: outsourcing the AI system does not mean outsourcing AI governance responsibility. When customers, the board, or regulators ask, "Why did this AI make this decision?" the company cannot respond with "It’s the vendor’s black box." Outsourcing should be seen as adding a layer of "supply chain governance responsibility," not as an excuse to avoid accountability.

Lesson Four – Fairness: Human-centered values must be visible in algorithms

The guidelines emphasize the principle of "fairness," requiring organizations to adopt human-centered, human-controllable measures in algorithm design, data collection, and model development. They should use diverse and representative data as much as possible and avoid relying solely on data from a single group to reduce bias against specific populations. If sensitive parameters such as name, residence, ethnicity, religion, or physical characteristics are involved, necessity assessments must be conducted from security, compliance, and risk management perspectives.

This is highly relevant for AI recruitment, AI credit scoring, and AI customer service. If an AI recruitment tool systematically excludes female or specific group resumes due to biased training data, or if certain credit scoring models unconsciously exacerbate financial exclusion of vulnerable populations, it serves as a reminder: while pursuing efficiency, algorithms must not silently replicate or amplify historical biases. The governance issue is not just technical—it also concerns who is accountable for "fairness."

Lesson Five – Data Privacy: More data does not mean better; governance starts with "less"

In the intuition of most companies, "more data leads to more accurate models" is almost a belief. Yet the guidelines reiterate the long-standing principle of data minimization. Organizations should implement appropriate safeguards when processing AI-related data to prevent unauthorized access or leaks, and limit data collection to the minimum necessary to achieve the purpose, avoiding excessive collection of sensitive information.

From a governance perspective, each additional data point increases potential risk. Good AI governance is not about blindly pursuing "collecting all data," but about asking a simple question before collection: "Is this data truly necessary?" When companies begin to routinely ask this question before collecting data, half the risk to data privacy is already mitigated.

Lesson Six – Security and Robustness: Protect AI as a critical system

The guidelines require organizations to ensure the security of selected models or algorithms during model development and validation, implement data quality processing, model validation, and monitoring to improve training quality and prevent inappropriate content generation. They must also follow security standards, establish protection mechanisms, and continuously monitor AI system outputs.

This means AI should not be treated merely as a "conversational or analytical tool," but as an integral part of the enterprise’s core information systems. Once it begins to affect customer rights, financial decisions, or internal processes, it must be incorporated into information security, internal control, and risk management frameworks, with regular testing and updates. Using insecure and unstable AI puts the enterprise in a dangerous position.

Lesson Seven – Transparency and Explainability: Let users know who they are interacting with

The guidelines require that when organizations use AI to interact directly with consumers, they must clearly inform users that the interaction is automatically conducted by AI, allowing consumers to understand the context and retain choice. For significant decisions such as financial transactions, organizations must understand how the AI reached its judgment and enhance model explainability.

For general enterprises, the core of this principle is simple: do not let users mistakenly believe they are interacting with a human, and do not allow internal decision-makers to be unable to explain the AI’s logic. When management routinely uses "the system’s output" as a免责 shield, corporate governance is already on the edge of danger. Explainability is not the exclusive domain of technical departments—it is a shared governance responsibility across the organization to build trust.

Lesson Eight – Do Not Blindly Trust and Prevent Leaks: Generative AI must not be fully trusted and must not become a data leak channel

The guidelines specifically warn that the use of generative AI must be strictly controlled: organizations must not fully trust its outputs, nor use unverified content as the sole basis for decisions. Without proper controls, personnel must not provide confidential, business-sensitive, or personal data to generative AI systems.

Yet in reality, many companies have already fully adopted generative AI, with employees pasting large amounts of internal company data—such as unreleased product ideas, customer contract terms, and internal meeting minutes—into various large language models daily. However, boards and senior executives often do not understand where this data goes, nor have clear usage policies. Companies must clearly inform employees: generative AI is an auxiliary tool, not a免责 guarantee, and certainly not a storage bin into which confidential data can be freely dumped.

AI governance capability will be the next watershed in corporate governance

The greatest future risk for companies is not falling behind in the AI technology race, but "having AI without governance." As AI increasingly moves into the core of decision-making, these guidelines—originally designed for securities and futures firms—actually present common challenges that all AI-adopting organizations must face: who governs, how risks are classified, how third parties are supervised, how fairness and data privacy are ensured, how system security and robustness are maintained, and how decisions are made transparent and explainable.

The true competition in the AI era is no longer just the speed of algorithms, but the maturity of governance systems. Whether a company can earn the trust of the market, investors, and regulators will no longer depend on "how much AI it uses," but on "whether it has established a trustworthy, supervisable, and accountable AI governance system." What is truly dangerous is not

FACT BOX

  • Source: PR Times
  • Category: News