Any company that is serious about living its values is bound to have a strong values-driven culture backed by a robust ethics and compliance program. The program would include a code of conduct for employees and contractors that is comprehensive, clear, and current, communicated through ongoing training and certification. A confidential hotline would be in place to accept concern reports in multiple languages, with an internal notification and escalation process, supported by a non-retaliation policy with teeth. Reports would be taken seriously and investigated fully, with consequences for violations up to and including termination. The full board would review the program annually, with a deeper dive by the audit committee into the process and significant concern line complaints. The company’s values would live far beyond the confines of the program, in that leaders across the organization would set high expectations for doing the right thing no matter how high the business pressures, and they would model the company’s values themselves.
But what happens when the same task formerly handled by an employee or contractor is now performed by AI?
The Scenario: Happy Consumer Brands
Imagine a mid-to-large consumer products company, let’s call it Happy Consumer Brands, that makes products sold through major retail chains and its own direct-to-consumer channels. By most standards, Happy’s values are strong and its ethics and compliance program is comprehensive and well-executed.
Over the last two years, Happy has deployed AI across several business functions. Marketing uses Claude to generate product copy, campaign briefs, and social media content. The supply chain team uses a Gemini-based platform to analyze supplier relationships and identify potential sourcing risks. HR uses a ChatGPT-based screening tool to evaluate job applications before a human recruiter sees them. Pricing analysts use an AI system to model promotional dynamic pricing for its ecommerce channels and discounts by customer for its retail channels. More recently, Happy has created agents to work hand in hand with employee teams. Agents now develop code, engage in procurement for routine purchases, and fill orders for products purchased online. The teams are encouraged to name the agents and even add them to org charts.[1]
Most boards would provide oversight by asking for a list of the company’s significant AI use cases and their expected ROI, and follow up with a generalized question about how management is identifying and managing risk. Very few boards will seek to connect the dots between the workflows and Happy’s code of conduct. They won’t comment that when humans do the same tasks, they are bound by Happy’s ethics and compliance policy, and steeped in its “do the right thing” culture. And they would not think to ask how this same standard is being upheld now that the task has been delegated to AI.
Where the Gaps Show Up
The Happy scenario may be fiction, but the concerns it raises are real, and at least one company has been very publicly damaged as a result of exactly this kind of issue.
AI was used to develop a Starbucks promotion in South Korea, and what it produced played off one of the darkest days in Korean history in a deeply offensive way. The company marketed the AI-driven campaign: a large tumbler bearing the name “The Tank”, timed to May 18, the anniversary of a 1980 crackdown in which government troops and tanks killed hundreds of pro-democracy demonstrators. The campaign compounded the initial error in judgment by including in its promotional marketing a slogan (“Hit the table”) associated with the then totalitarian government’s widely discredited explanation for the death of a pro-democracy protester in police custody. The reputational hit caused by the promotion triggered a sharp decline in sales and led to the dismissal of Starbucks Korea’s CEO along with mandatory history and cultural sensitivity training for its 24,000 employees.[2]
As AI takes on tasks, the judgment that aligns the work with the company’s values and code of conduct may get lost.
Here are a few areas where Happy’s AI usage may go wrong:
Marketing: Happy’s values require fair and respectful treatment of consumers and its code of conduct prohibits false or misleading claims about its products. Previously, Happy’s marketing group engaged an agency to generate social media posts, pursuant to a contract that required the agency to adhere to Happy’s stated values and code of conduct. Happy’s social media posts are now created by an agent tasked with posting content within defined guardrails. This has enabled Happy to vastly increase its social media presence at a deeply reduced cost. However, Happy’s process has no mechanism for determining in advance whether the posts that go out under its name consistently reflect its values, and if an agent veers from the guardrails it is not at all clear how long it will take for someone to notice or whose job it is to rein it back in.
Pricing: Happy has joined the growing number of companies using AI to assess the marketplace and recommend pricing changes dynamically. Journalist Noam Scheiber’s June 29, 2026 New York Times article, “We’re Only Starting to Grasp the Pitfalls of Using A.I. at Work,” warns that AI pricing tools do not necessarily replicate human judgment: left to their own devices, people are likely to achieve responsible and successful outcomes, but an AI model optimizing purely for short term advantage risks pushing a company toward an aggressive price war it never intended to start. On the flip side, competitors who agree to use the same software pricing tools or to allow nonpublic pricing data to be used by software also used by competitors may give rise to antitrust investigations or litigation[3].
HR: Happy’s code prohibits discrimination and supports inclusion in hiring practices and culture. Happy’s population of professional employees has historically been heavily weighted toward young white men with Ivy League MBAs who grew up in the state where the company is headquartered. Over the past five years, Happy has worked hard to identify and recruit top talent from a broader pool. The team now uses agentic AI to screen candidates and arrange for interviews with human HR screeners for candidates who meet specified job requirements and reflect what the agent determines to be consistent with Happy’s needs. The candidates presented by the agent are primarily young white men with Ivy League MBAs who grew up in the state where the company is headquartered.
Supply Chain: Happy’s code of conduct prohibits sourcing from suppliers that use forced labor or violate environmental standards. The company uses AI to flag supplier issues and once a supplier is cleared, an AI agent is used to complete routine purchases. If the AI agent misses a flag, it may complete a purchase from a supplier that violates Happy’s values. Or it may complete thousands of such purchases.
What Good Looks Like
While boards often ask general questions about compliance with respect to the company’s use of AI, framing the question in the context of the company’s code of conduct reflects a deeper question of how the company’s values will be consistently enforced across all workflows when the workforce is now part human and part AI. Board members need to know what good looks like in order to assess management’s response. Since I expect that a genAI platform should have special insight on this particular question, I asked Claude Sonnet 5 to opine on factors a member of the Happy board can use to assess management’s response. Here, with minor human editing, is Claude’s advice about how companies can protect their values while using AI, including agentic AI, to add value.
Step 1: Map the Tasks, Not Just the Tools
Happy’s first obligation is an honest inventory — not only of what AI tools it has licensed, but also of what tasks those tools are performing that was previously governed by its ethics and compliance policy. The question is not “do we use AI?” The question is “what decisions is AI influencing, and what ethics or compliance obligations attach to those decisions?”
For Happy, this means mapping each AI deployment to the specific provisions of the code of conduct that apply to the tasks it performs:
• The marketing AI maps to the fair claims and competitive conduct provisions.
• The HR AI tool maps to the anti-discrimination and fair hiring provisions.
• The pricing AI tool maps to the provisions requiring fairness.
• The AI supply chain tool maps to the supplier standards and human rights provisions.
This mapping is the foundation. Without it, management cannot govern what they cannot see.
Step 2: Classify Risk, Then Govern Accordingly
Not all of Happy’s AI work carries the same compliance risk. A Claude-assisted draft of an internal meeting summary carries far less exposure than an AI-generated product efficacy claim or an AI-influenced hiring decision. Happy needs a risk classification framework that differentiates between:
• AI uses that require a compliance review gate before output is used.
• AI uses that require periodic auditing.
• AI uses where standard monitoring is sufficient.
The HR screening tool and the pricing model, both of which influence consequential decisions about people or business relationships, belong in the highest-risk category. The social media agent belongs in an intermediate category where outputs should require human review before external use and a close eye on consumer feedback. This mirrors the same logic Happy already applies to legal review of material contracts and financial sign-off thresholds.
Step 3: Extend the Ethics and Compliance Program Explicitly to AI Outputs
Happy’s ethics and compliance policy, as currently written, almost certainly applies to employees. It may not explicitly extend to the AI systems those employees use or the outputs those systems produce. That gap needs to close, formally, in the policy itself.
This means:
• Revising the code of conduct to make explicit that the same standards that apply to human work apply to AI-assisted work, and that employees are responsible for ensuring that AI outputs they use or approve meet those standards.
• Revising the training program to address how the code’s provisions apply in an AI-assisted context. The employee who used to write a product claim understood the rules. The employee who now reviews a claim drafted by AI needs to understand that reviewing an AI draft carries the same accountability as writing it.
• Explicitly extending the hotline to cover concerns about AI behavior. If an employee notices that the HR screening tool consistently flags candidates from certain backgrounds, they need to know that this is exactly the kind of concern the hotline is designed to surface.
Vendor contracts for high-risk AI applications should also be renegotiated to include audit rights, bias testing cooperation, incident notice requirements, and data-use limitations.
Step 4: Renegotiate Vendor Relationships Around Accountability
Here is where the multi-vendor environment creates complexity that Happy’s current vendor management framework was not built to address. Anthropic, OpenAI, and Google each have their own responsible AI frameworks, and they are genuinely meaningful. But those frameworks are designed around the vendors’ values and obligations, not Happy’s.
Many AI vendors do not design products around a business’ specific compliance obligations, making it difficult to implement required transparency and consumer disclosures, explain automated decision-making outcomes, or document how outcomes are generated. As one recent legal analysis of AI vendor agreements has noted, contracts that fail to specify these terms up front leave the customer, not the vendor, exposed when something goes wrong. [4]
What Happy needs from each vendor relationship is operationally specific:
• For the HR tool: the right to conduct regular bias audits on outputs, notification of material model version changes, paired with a contractual right to re-run bias audits after any such change, and documentation adequate to respond to a state or federal agency inquiry, private lawsuit, or internal investigation.
For the pricing model: assurances about data segregation so that Happy’s proprietary pricing data does not inform competitor outputs, and evidence that Happy’s AI-recommended prices are not converging with competitors’ prices in ways that could be read as algorithmic coordination.
For the marketing tool: clarity on what content policies the model applies and whether they are consistent with Happy’s own advertising standards.
AI vendor agreements should provide rights to periodic audits or third-party assessments, require vendors to notify customers of material performance, security, or compliance issues, define human-in-the-loop expectations for consequential decisions, permit suspension or termination where continued use would be noncompliant or unsafe, and allocate responsibility for monitoring metrics such as false positives, error rates, and disparate outcomes.
Step 5: Build Monitoring and a Path for Escalation
The traditional compliance program has internal review processes and a hotline for human misconduct. Happy needs a parallel mechanism for AI behavior that violates the same standards that human conduct is measured against.
This means defining what “a compliance incident involving AI” looks like for each deployment, for example:
• For the HR tool: a pattern of disparate outcomes.
• For the marketing tool: a factually false product claim that made it through review.
• For the pricing model: a pricing decision that raises concerns about algorithmic collusion.
• For the supply chain tool: a risk flag that was overridden without prior human review and approval.
Each of these warrants the same kind of documented response that a code of conduct violation by an employee would receive.
What Values-driven Board Oversight Looks Like
As companies increasingly rely on AI, including agentic AI, to engage in tasks that were previously performed by a human, boards should be prepared to ask:
Has management mapped the tasks the company’s AI systems are performing to the company’s values and the ethics and compliance obligations that company policy has historically applied to the humans supporting those tasks, and can management describe the mechanisms by which those obligations are enforced in an AI setting?
Boards providing oversight of this issue should confirm:
• A completed mapping, for each significant AI deployment, of which ethics and compliance obligations attach to the tasks it performs, with a named enforcement mechanism.
• A code of conduct explicitly extended to AI-assisted tasks, with training that makes clear employees are accountable for AI outputs they use or approve.
• Vendor contracts for consequential AI applications that include audit rights, material model change notification, and incident response provisions beyond standard platform terms.
• A concern hotline explicitly available for AI-related issues, with a record of whether it has been used for that purpose.
• Recognition, at the board level, that a company governing human conduct carefully while leaving AI outputs ungoverned, or governed only as a check-the-box compliance exercise, has not extended its values to a significant portion of how it now operates.
Finally, in addition to ensuring that the tasks performed by AI are performed in accordance with the company’s values and ethical code, boards should take great care to ensure that employees and other stakeholders affected by the company’s use of AI will be treated thoughtfully, fairly, and humanely.
[1] Noam Scheiber, “We’re Only Starting to Grasp the Pitfalls of Using A.I. at Work,” The New York Times, June 29, 2026.
[2] NBC News, “Starbucks struggles to quell outrage over ‘Tank Day’ ad campaign that evoked massacre in South Korea,” May 2026.
[3] Algorithmic Pricing: Navigating Antitrust and Consumer Protection Risks
[4] Holon Law Partners, “The Rise of AI Vendor Agreements: 7 Clauses Every Business Needs to Get Right in 2025,” December 9, 2025