top of page

Legal Topics | Article

法務Topics

How to Integrate "Responsible AI" and Cybersecurity into Enterprise Risk Management

  • 2 days ago
  • 6 min read

For companies, actively leveraging AI and managing its risks are not mutually exclusive. Given the multifaceted nature of technology risks, it is useful to manage AI governance and cybersecurity in an integrated manner as a single enterprise risk that cuts across people, data, technology, and value chains. This form of enterprise risk management also requires an active role not only from technology teams but from professionals responsible for internal control and governance.



Rethinking Enterprise Risk Management in the Age of AI


AI, including generative AI, is permeating a wide range of corporate activities, from document drafting, translation and summarization to contract review, customer service, recruitment and performance evaluation, and control of production equipment. While AI can improve operational efficiency and promote innovation, it can also create overlapping risks, including misinformation, discrimination, privacy violations, intellectual property infringement, information leakage, safety incidents, and criminal misuse.

AI systems also depend on large volumes of data, cloud services, external models, and software, making them both targets and vectors of cyberattacks. AI can be used to automate and refine attacks, while data poisoning, prompt injection, and tampering with models or outputs can undermine corporate decision-making and operations themselves. Responsible AI and cybersecurity therefore cannot be addressed in isolation from one another.

Against this backdrop, drawing on my experience advising companies on technology-related legal matters, I contributed an article entitled “How to Integrate ‘Responsible AI’ into Enterprise Risk Management—Internal Control and Audit Practices for Managing Multifaceted AI Risks” to Monthly Statutory Auditor No. 792. Below, I also draw on the perspective presented in my earlier article, “Strengthening Cyber Security Governance—Based on Trends in Regulations and Practices Regarding Cyber Security”, published in Monthly Statutory Auditor No. 733, to outline an approach for integrating both areas into enterprise risk management.


Five Perspectives for Understanding "Responsible AI" as a Multifaceted Issue


Responsible AI means more than simply complying with AI-related laws and regulations. It means developing, providing, and using AI in a manner consistent with the OECD AI Principles, including inclusive growth, respect for human rights and democratic values, transparency and explainability, robustness, security and safety, and accountability. Translating responsible AI into practice requires attention to the following five perspectives.

1. Multiple functions, use cases, and risks: Risks vary depending on the function and use of AI, including generation, recognition, prediction, recommendation, decision support, scoring, control, and AI agents. A useful starting point is to maintain an AI inventory that makes visible each use case, model, input and output data, relevant business functions, risks, and mitigation measures.

2. Multiple layers of rules: Companies need to navigate overlapping hard law and soft law, including the OECD AI Principles, the G7 Hiroshima AI Process, the EU AI Act, Japan’s Act on Promotion of Research and Development, and Utilization of Artificial Intelligence-related Technology (Act No. 53 of 2025, Japan’s AI Act), the NIST AI Risk Management Framework (AI RMF), Japan’s AI Guidelines for Business, rules relating to human rights due diligence (DD), and applicable laws on personal information, intellectual property, labor, and consumer protection.

3. Multiple impacts on people: AI can affect the rights of a wide range of stakeholders, including consumers, workers, business partners, citizens, children, and people in socially vulnerable situations. It is important to incorporate not only impact assessment, but also meaningful stakeholder engagement and corrective action and remedy when problems arise.

4. Multiple corporate roles: Companies have responsibilities not only as developers and providers of AI, but also as users. Even companies that merely use third-party generative AI need to manage input data, output verification, bias, privacy, security, and human oversight.

5. Multiple time horizons: In addition to short-term risks such as erroneous outputs and information leakage, companies should consider medium- and long-term effects, including reduced human judgment due to overreliance on AI, the loss of professional know-how and tacit knowledge, inadequate development of junior personnel, and an organizational culture of avoiding responsibility or suspending independent thought.


Positioning Cybersecurity as an Issue of Corporate Value


Cyber incidents are not limited to “physical risks” such as system outages or the loss of information and assets. They can be compounded by “social risks,” including damages and regulatory responses arising from personal data breaches, contractual liability and lost business caused by leakage of customer confidential information, the spread of harm to business partners and social infrastructure, and reputational damage. Together, these risks can have a serious impact on corporate value.

Companies therefore should not view themselves only as “victims” of cyberattacks. They also serve as “gatekeepers” responsible for preventing harm from arising or spreading through their own systems, products and services, and supply chains. Cybersecurity is not solely a technology issue; it is a governance issue that should be managed enterprise-wide under the oversight of the board of directors and, where applicable in Japanese corporate governance structures, statutory auditors (kansayaku).


Six Practical Steps for Integrating AI and Cyber Risks


1. Management-level policies and accountability: AI and cyber risk should be positioned as material enterprise-wide risks, with the board discussing risk appetite, priorities, staffing, and budgets. Roles and reporting lines should be clearly defined for the CISO, legal and compliance, risk management, internal audit, business functions, human resources, and procurement.

2. Connecting the AI inventory with information-asset management: Link the AI inventory with the management of information assets such as data, accounts, systems, and service providers. Companies need to understand actual AI use, including shadow AI, and apply enhanced controls to higher-risk use cases.

3. Risk reduction throughout the lifecycle: It is useful to incorporate legal-by-design, security-by-design, and human-rights considerations from the planning and design stages. Depending on the use case, controls should also address data management, access controls, output verification, logging, testing, red teaming, human oversight, and procedures for suspension or withdrawal.

4. Supply-chain and third-party management: Companies should understand dependencies involving AI models, cloud services, data, and outsourced developers and operators, and combine due diligence at the selection stage with contractual provisions on security, notification, audit, and remediation, together with ongoing monitoring.

5. Connecting normal operations with incident response: AI-specific incidents and complaints should be integrated into existing CSIRT, crisis management, business continuity planning (BCP), whistleblowing, and grievance mechanisms. Companies should simulate the full response process—from detection and analysis, containment and recovery, and notification to authorities and business partners, through disclosure, root-cause analysis, recurrence prevention, and remedy for affected persons.

6. Continuous review and stakeholder engagement: Technology, threats, and rules evolve rapidly. In addition to periodic audits, companies need continuous monitoring and agile improvement, while using engagement with workers, consumers, and other affected people to identify risks and improve controls.


Role of Internal Control and Governance Professionals


AI can enhance internal control and governance even where resources are limited, for example through anomaly detection, data analysis, document review, and monitoring. At the same time, the very use of AI to manage risk can create new risks, including erroneous outputs, bias, information leakage, and black-box decision-making.

Professionals involved in internal control and governance need to use AI appropriately without accepting its conclusions uncritically. They must be able to question assumptions, raise alternative views, engage sincerely with stakeholders, and make fair value judgments. Understanding both technology and human rights and ethics—and integrating them into practice—can support corporate resilience and integrity.


Cross-Disciplinary Perspective: Global Compliance / ESG, Governance & Sustainability / Technology & Innovation


The integration of responsible AI and cybersecurity is one of the areas where the three fields I focus on—Global Compliance / Sustainability / Technology —intersect most closely.

•    Global Compliance: Companies need to understand, across jurisdictions, applicable laws including those with extraterritorial reach, sector-specific regulation, disclosure and incident-reporting obligations, contractual and procurement standards, and international norms and guidelines, and to respond flexibly to rapidly evolving rules.

•    Sustainability: Companies need to assess and mitigate the impacts of AI and cyber risks on human rights, labor, consumers, and social infrastructure, and to maintain responsible business conduct and trust through stakeholder engagement and remedy.

•    Technology: Companies need to understand the characteristics and limitations of technology and reconcile risk management with innovation through legal-by-design, security-by-design, and human oversight.


Activities and Publications on Responsible AI and Cybersecurity


Through dialogue and collaboration with technology experts, I have supported companies and financial institutions on legal, compliance, and crisis-management matters in technology-related fields including data protection, cybersecurity, and AI. I have also had opportunities to serve as an outside statutory auditor of an AI development company and as an external committee member or expert adviser to ICT companies and data-platform operators.

I will continue to support companies in moving beyond passive compliance and building management foundations that enable them to withstand uncertainty, maintain public trust, and proactively realize the value of AI and digital technologies.



Related Pages



 
 

Latest article

最新記事

Areas

業務・研究分野

bottom of page