Back to Insights
AI GovernanceLegal OperationsMarch 18, 202612 min read

AI Governance Is Not a Future Compliance Project

Boards are setting AI adoption targets. CEOs are celebrating deployment milestones. And somewhere downstream, a compliance officer is waiting for an AI-specific law to arrive before building a governance framework. That wait is producing liability right now. A review of major AI enforcement actions across multiple jurisdictions reveals a consistent pattern: not one required an AI-specific statute. Air Canada was held liable for chatbot misinformation under basic tort law. UnitedHealth and Cigna face class action claims under insurance contract and Medicare law for AI-driven claim denials. Workday faces a national class action under 1967 employment discrimination law for its AI hiring tools. A Berlin bank was fined €300,000 under GDPR's 2018 automated decision-making provisions. The legal infrastructure to hold organisations accountable for what their AI does was already in place. It is being actively used. This article examines why AI governance is not a future compliance obligation but a present-day legal risk — and why the decisions that close the governance gap can only be made at the board and CEO level.

The Adoption Trap
採用的陷阱

Across industries and geographies, the pressure on businesses to adopt AI is now nearly uniform. Boards are setting targets. CEOs are celebrating milestones. Digital transformation offices are running pilots. Investment in AI tools — whether off-the-shelf applications, API integrations, or custom deployments built on general purpose models — is being actively encouraged at the highest levels of most major organisations.

The governance conversation, meanwhile, has been quietly delegated downward. To the IT department. To the data science team. To a compliance officer who is waiting for the AI legislation to arrive and clarify what the requirements actually are. The implicit operating assumption across much of the corporate world is that AI governance is a future obligation: something to be built once the law comes into force, once regulators issue guidance, once the standards solidify.

That assumption is not just wrong. It is actively producing liability right now.

AI浪潮席捲全球,沒有產業、沒有地區能夠置身事外。董事會要求盡快追上,執行長在財報電話會議上宣示進展,數位轉型辦公室在各業務線密集推進試點。這股壓力只有一個方向:快。

但與此同時,另一件事正在靜靜發生:治理的責任被往下移交了。移交給IT,移交給資料科學,移交給某位法遵長——而那位法遵長,正在等一部AI法規問世,等主管機關說清楚「我們到底要做什麼」。這種等待,在許多機構已成為不言而喻的共識:AI治理是未來的事,等法令到了再說。

這個共識,不只是錯的。它正在替機構製造此時此刻、真實存在的法律責任。

The implicit assumption is that AI governance is a future compliance obligation. Almost every enforcement action brought against AI use so far has been under laws that existed before AI did.
等一部AI專法來告訴你該怎麼做,是錯誤的姿態。因為目前幾乎所有AI相關執法行動,援引的都是AI問世以前就已存在的法律。
The Evidence: No AI Law Required
證據:不需要任何AI專法

The enforcement record across multiple jurisdictions tells a consistent story. When AI deployments have gone wrong and regulators or courts have intervened, they have almost never needed an AI-specific statute to do so. Consumer protection law, employment discrimination law, insurance contract law, data protection law, tort law, securities law — all pre-existing, all fully applicable, all being actively used.

The following cases span industries and geographies. The column that matters is the last one.

翻開各國監管機關與法院的執法紀錄,有一個規律令人難以迴避:AI部署出了問題、公權力介入時,幾乎每一次,翻出來的都不是什麼AI新法,而是一部早就存在的舊法——消費者保護、就業歧視、保險契約、資料保護、侵權責任、證券揭露。架構都在,只是換了一個被告。

以下十個案例,橫跨不同產業與地區。看最後一欄。

Case案例 What Happened發生什麼 Law Applied援引法律
Air Canada加拿大航空
Canada, 2024加拿大,2024
AI chatbot gave a passenger incorrect information about bereavement fares. The airline argued the chatbot was "a separate legal entity" responsible for its own actions. The tribunal called this "a remarkable submission" and held Air Canada fully liable.AI聊天機器人向乘客提供了錯誤的喪假機票政策說明。航空公司辯稱聊天機器人是「獨立法律實體」,應自行負責。裁判所斥之為「驚人的主張」,裁定加拿大航空全額負責。 Tort / Negligent Misrepresentation侵權法 / 過失不實陳述
DoNotPay
US, 2024美國,2024
Marketed as "the world's first robot lawyer" with claimed expertise across 200 areas of law. FTC found the AI was undertrained and could not deliver. Fined $193,000 and subject to ongoing advertising restrictions.以「全球首位AI律師」自居,聲稱精通200個法律領域。FTC認定其AI訓練不足、無法兌現承諾。罰款19.3萬美元,並受持續廣告限制。 FTC Act 1914FTC法(1914年)
Evolv TechnologiesEvolv科技
US, 2024美國,2024
Sold AI weapons detection scanners to schools claiming proven accuracy. Schools reported the system missed weapons and triggered false alarms. Settled December 2024: banned from unsubstantiated accuracy claims; K-12 customers given right to cancel.向學校銷售AI武器偵測掃描系統,宣稱準確率有目共睹。學校反映系統漏判武器、誤報頻繁。2024年12月和解:禁止不實準確率聲明,K-12客戶獲解約權。 FTC Act — Consumer ProtectionFTC法——消費者保護
Pieces TechnologiesPieces科技
US, 2024美國,2024
Healthcare AI deployed in Texas hospitals to summarise patient charts. Texas AG found the company made false and misleading statements about the accuracy and safety of its products. Settled with a five-year disclosure and non-misrepresentation order.醫療AI部署於德州醫院,用於摘要病患病歷。德州AG認定該公司就產品準確性與安全性作出不實與誤導性聲明。和解結果:五年揭露義務及禁止不實陳述令。 Texas DTPA 1973德州欺騙性商業行為法(1973年)
EEOC Tutoring Co.EEOC補教業和解案
US, 2024美國,2024
AI hiring tool automatically rejected women over 55 and men over 60, having learned discriminatory patterns from historical hiring data and applied them at scale. First-ever EEOC AI hiring discrimination settlement: $365,000.AI招募工具自動拒絕55歲以上女性及60歲以上男性應聘者,從歷史招募數據中習得歧視性模式並大規模套用。史上首件EEOC AI招募歧視和解案:36.5萬美元。 ADEA 1967 / Title VII 1964就業年齡歧視法(1967)/ 民權法第七章(1964)
Mobley v. WorkdayMobley訴Workday案
US, 2023–ongoing美國,2023年至今
AI applicant screening tools alleged to discriminate by race, age, and disability. Certified as a national class action in May 2025, potentially covering millions of applicants. Court found the vendor — not just the employer — carries liability as an "agent."AI應聘篩選工具被指涉及種族、年齡與身心障礙歧視。2025年5月獲認證為全國集體訴訟,潛在涉及數百萬求職者。法院認定系統供應商與雇主同樣負有「代理人」責任。 ADEA 1967 / ADA 1990就業年齡歧視法 / 身心障礙者法案
UnitedHealth / Cigna / Humana聯合健保 / Cigna / Humana
US, 2023–ongoing美國,2023年至今
AI tools used to deny medical insurance claims at scale. Cigna reviewed over 300,000 claims in two months — averaging 1.2 seconds per claim. UnitedHealth's nH Predict denied post-acute care for elderly patients. Breach of contract and good faith claims proceeding in federal court.保險公司以AI工具大規模拒絕理賠。Cigna的演算法在兩個月內審核逾30萬件理賠案——平均每件1.2秒。聯合健保的nH Predict拒絕為高齡患者提供急性後期照護給付。違約及誠信義務違反索賠案正在聯邦法院進行中。 Insurance Contract / Medicare Act保險契約法 / 醫療保險法
Berlin Bank柏林某銀行
Germany, 2023德國,2023
Automated credit card rejection with no explanation provided to the applicant and no meaningful way to challenge the decision. Fine: €300,000.自動化拒絕信用卡申請,未向申請人說明原因,亦未提供有效申訴途徑。罰款:30萬歐元。 GDPR Article 22 — 2018GDPR第22條(2018年)
SEC Investment AdvisersSEC投資顧問案
US, 2024美國,2024
Two investment advisory firms fined $400,000 for claiming to use AI in their services when they did not. First SEC enforcement actions for AI washing.兩家投資顧問公司謊稱使用AI,合計被罰款40萬美元。SEC首批AI洗白執法行動。 Securities Exchange Act證券交易法
Taishin Bank台新銀行
Taiwan, 2025台灣,2025
AI anti-fraud system froze hundreds of legitimate customer accounts without warning. Self-reported accuracy rate characterised publicly as no better than a coin toss. Regulator intervened with binding proportionality principles.AI防詐系統在未事先通知的情況下凍結數百名正常客戶帳戶,自稱準確率被輿論評為與擲硬幣無異。監管機關介入,提出具約束力的比例原則要求。 Banking Act / Consumer Protection銀行法 / 消費者保護

None of these cases required an AI-specific statute. Consumer protection legislation dating to 1914. Employment discrimination law from 1964 and 1967. GDPR from 2018. Basic tort. Insurance contract. The legal infrastructure to hold organisations accountable for what their AI does to people was already in place. It is being used.

And the volume is growing. Securities class actions targeting AI misrepresentations doubled between 2023 and 2024. The FTC has signalled that its AI enforcement focus is bipartisan and durable. State attorneys general are developing AI enforcement capabilities. Courts are extending existing doctrine — the Workday ruling, in particular, establishing that AI vendors and the businesses deploying their tools share liability — in ways that expand the field of exposure significantly.

上表沒有一個案例需要AI專法。FTC法是1914年的立法,就業年齡歧視法是1967年的,GDPR是2018年的,基本侵權原則更是一百多年的普通法積累。讓機構對AI行為付出代價的法律工具,早就齊備,只待援引。

而且趨勢很清楚。針對AI不實聲明的美國證券集體訴訟,從2023到2024年翻了一倍。FTC明確表態,AI執法優先順序不因政治換屆而改變。各州司法部長持續擴大AI執法版圖。法院則透過Workday等裁決,將既有反歧視原則延伸適用至AI場景,明確指出供應商與部署方可能同時承擔責任——使潛在曝險範圍進一步擴大。

The legal infrastructure to hold organisations accountable for what their AI does was already in place. Courts and regulators are not waiting for an AI law. Neither should you.
追究機構AI行為責任所需的法律工具,早已齊備。監管機關和法院不在等待AI專法。你的機構也不應該。
Deploying Is Not Passive — Three Layers of Risk
部署不是被動行為——三層風險

A common response to the enforcement record above is: "But we didn't build the AI. We're using a general purpose model — OpenAI, Gemini, Claude. The copyright issues, the training data questions, the bias in the model architecture — those are the provider's problem, not ours."

This is partly right. For organisations deploying rather than building, the technology risk profile does shift. Training data provenance, model hallucination rates, foundational algorithmic bias — these sit primarily with the model provider, governed by their own policies and terms of service.

But deploying a general purpose model is not a passive act. Between the model and your customers, your employees, and your counterparties, there are two layers of decisions that are entirely your organisation's — and both carry significant governance weight.

看完前面的案例,不少人的第一反應是:「但這跟我們不一樣。我們又沒有自己訓練模型,我們只是在用OpenAI、Gemini、Claude這些通用模型,著作權、訓練資料、演算法偏見,那些是供應商的事。」

這話有一半是對的。對於「使用」而非「自建」模型的機構,技術層面的風險確實大部分留在供應商那一側,受其服務條款與治理政策規範。訓練資料來源、幻覺率、底層偏見——這些不是你的直接問題。

但「只是在用通用模型」,並不是被動行為。在模型與你的客戶、員工、業務對手方之間,你的機構做了兩層決定——每一層都有真實的治理重量,每一層都完全屬於你。

Layer 1 — The Model
第一層——模型本身

Training data, foundational architecture, baseline bias, hallucination rates. Risk sits primarily with the provider. Not your direct governance problem — but still your due diligence obligation when selecting and contracting with vendors.

訓練資料、底層架構、基線偏見、幻覺率。風險主要在供應商那側。不是你的直接治理問題——但仍是你在選擇和簽約時的盡職調查義務。

Layer 2 — Prompting & Application Design ← Yours
第二層——提示詞設計與應用程式架構 ← 屬於你

The system prompt, the application architecture, the guardrails, the output validation, the disclosure design. These are policy decisions written in code. They determine what the AI is authorised to say, what it is prevented from doing, how outputs are framed, and when a human gets involved. Entirely your organisation's governance responsibility.

系統提示詞、應用程式架構、防護機制、輸出驗證、揭露設計。工程師寫這些,但這些是政策決定,不是技術決定。AI被授權說什麼、被禁止做什麼、輸出以什麼面貌觸達使用者、何時需要轉給人工——這些是你的機構決定的,完全屬於你的治理責任。

Layer 3 — Organisational Decisions ← Yours
第三層——組織決策 ← 屬於你

Which decisions have you delegated to AI outputs? Who reviews outputs before they affect customers or employees? What happens when the AI is wrong? Who is accountable — not for the technology, but for the consequences? These are governance questions that no model provider can answer for you.

哪些業務決策你已經交給AI輸出來決定?輸出影響到客戶或員工之前,有人在看嗎?AI判斷錯了,怎麼處理、誰來擔責?不是技術責任,而是後果責任。這些問題,模型供應商沒有辦法替你回答。

The prompting and application design layer deserves particular attention, because it is almost universally treated as a technical matter when it is in fact a policy matter. When your engineers write a system prompt, they are making decisions about what the AI is authorised to represent on your organisation's behalf, what constraints it operates under, and how it presents its outputs to the people interacting with it. Those are not engineering decisions. They are governance decisions — and they carry the same legal weight as a policy document or a customer-facing disclosure, regardless of the format they are written in.

Consider two organisations that both use the same general purpose model for customer-facing support. The first designs its application with a carefully scoped system prompt that defines the AI's role explicitly, prohibits it from making representations outside its scope, triggers human escalation when it encounters unfamiliar queries, and discloses to users that they are interacting with an AI. The second deploys the same model with a generic system prompt and no escalation logic. Same model. Entirely different governance posture. Entirely different liability exposure.

The Air Canada case is almost certainly not a story about a bad model. It is a story about a deployment where the application design did not anticipate a scenario the model would encounter, did not constrain the model's outputs appropriately, and did not build in verification logic before responses reached customers. That is a Layer 2 failure — one that sits entirely with the deploying organisation, regardless of who built the underlying technology.

第二層尤其值得單獨說清楚,因為它長期處於一個尷尬的灰色地帶:被當作技術問題處理,實際上是政策問題。工程師寫系統提示詞,但那份提示詞決定的是:AI在這個應用場景裡被授權代表機構說什麼,它的邊界在哪裡,輸出如何包裝給使用者,什麼情況必須轉給真人處理。這套決定寫在程式碼裡,但它的法律含義,與一份正式政策文件或客戶揭露聲明沒有本質差別。

一個具體的對比:兩家公司,同樣使用Claude或GPT做客服。甲公司的系統提示詞明確界定AI的角色與權限,禁止它就授權範圍以外的事項給出答覆,碰到不確定的問題自動升級至人工,並在介面上清楚告知使用者「您正在與AI互動」。乙公司套用一個通用提示詞,沒有邊界設定,沒有升級機制。相同的底層模型,完全不同的治理狀態,完全不同的法律曝險。

加拿大航空案,幾乎可以確定不是「模型出了問題」的故事。那個模型可能完全正常。問題出在應用程式設計:沒有預見到機器人會遇到客戶問喪假機票的情境,沒有設定讓它在沒把握時停下來,沒有在答案觸達客戶之前加一層人工核查。這是第二層的失靈,完全屬於部署方,跟底層技術是誰開發的毫無關係。

Scope Creep
範圍失控

A poorly scoped system prompt allows the AI to make representations beyond its intended domain — creating misrepresentation exposure the organisation never intended to assume.

提示詞授權範圍模糊,AI就可能在你沒預料到的場景給出答覆——製造機構原本無意承擔的不實陳述責任。加拿大航空的機器人就是這樣誤入了喪假機票的話題。

Disclosure Failure
揭露失靈

Application design that presents AI outputs as authoritative institutional responses — without disclosure — can create misleading impression liability and, in some jurisdictions, statutory violations.

AI輸出以機構名義呈現、沒有任何「這是AI」的提示,使用者很容易視之為官方立場。這在部分司法管轄區已有明確揭露義務,在更多地方則至少構成誤導性印象的侵權風險。

Absent Escalation
缺乏升級機制

No human-in-the-loop trigger means consequential decisions — credit, coverage, employment — are made entirely by AI output, without any human review of the specific circumstances of the affected individual.

沒有設計人工審核節點,信貸核准、保險理賠、求職篩選這類牽涉個人重大利益的決定,就完全由AI輸出決定——既無法審視具體情況,也無從問責。這是聯合健保和Cigna案的核心問題。

No Remedy Path
無救濟途徑

Application design that provides no accessible path to challenge an AI-driven decision may violate existing regulatory requirements around automated decision-making — before any AI-specific law comes into force.

應用程式設計裡如果沒有「申訴」這個選項,受影響的人就只能接受AI的判定。GDPR第22條早在2018年便要求自動化決策具備可申訴性,在台灣,金管會2025年9月的三原則也明確要求提供恢復使用的管道。這不是未來的要求,已是現行要求。

The Questions Only Leadership Can Answer
只有領導層能回答的問題

AI governance is not a technology problem that IT can solve, a compliance project that can be deferred until legislation arrives, or a risk management exercise that can be delegated to the digital transformation office. The decisions that determine whether an organisation's AI deployments are governable are made — or defaulted — at the top. And the liability that follows lands on the organisation, not on the team that wrote the system prompt.

There are four questions that boards and CEOs should be able to answer about their organisation's AI deployments. They are not technical questions. They are accountability questions.

AI治理不是IT能解決的技術問題,不是等法規落地才開始的合規項目,也不是可以放進數位轉型辦公室待辦清單的風險管理作業。決定機構的AI部署是否處於可治理狀態的那些決定,是在最高層做出的——或者因為沒人做,以沉默的形式做出的。後續產生的責任,落在機構身上,不是落在寫提示詞的工程師身上。

以下四個問題,是董事會和執行長應當能夠回答的。不是技術問題。是問責問題。

1
Which decisions have we delegated to AI — and did we make that decision deliberately? 我們已將哪些決策委託給AI——這是我們審慎做出的決定嗎?

The UnitedHealth case involves an insurer whose policy documents promised that coverage decisions would be made by clinical staff — while the company appears to have allowed AI to serve as a near-automatic gatekeeper. The gap between what was promised and what was delivered was not a technology failure. It was a governance failure that no one at leadership level appears to have caught. Every organisation deploying AI in consequential decisions should be able to name the decisions involved, the rationale for delegating them, and the human oversight mechanism that remains in place.

聯合健保的保單白紙黑字承諾:給付決定由臨床人員作出。但實際運作中,AI在數秒內批量拒絕了本應由醫師審核的申請。承諾與現實之間的落差,不是工程師的失誤,而是在最高層從來沒有人問過「我們到底在把什麼決定交給AI?」。每個在業務決策中使用AI的機構,都應當能夠清楚回答:涉及哪些決策、基於什麼理由交給AI處理、以及保留了什麼有效的人工監督機制。

2
Do we know which existing legal frameworks our AI deployments are operating under? 我們知道自己的AI部署正在哪些現行法律框架下運作嗎?

Employment decisions, consumer-facing communications, credit determinations, healthcare coverage, insurance claims, financial recommendations — each domain already has a legal framework governing how decisions must be made, what transparency is owed to affected parties, and what recourse is available. AI does not change the framework. It changes the speed and scale at which you can fall foul of it. The question is not "what will the AI law require?" It is "which of our existing legal obligations is our AI deployment currently touching — and do the people responsible for those obligations know that?"

招募、客戶溝通、信貸審核、醫療給付、保險理賠、財務建議——每一個業務領域都已有一套法律框架,規範決策如何作成、應向受影響方提供什麼說明、以及留了什麼申訴管道。AI不改變這個框架,它改變的是你違反這個框架的速度和規模。真正要問的問題不是「AI法規將要求我們做什麼」,而是「我們的AI部署正在觸碰哪些現有法律義務,而負責這些義務的人,知道嗎?」

3
Who reviewed our prompting and application design from a legal and governance perspective — not just a technical one? 我們的提示詞設計與應用程式架構,有沒有從法律與治理角度——而不僅僅是技術角度——被審查過?

In most organisations, system prompts are written by developers and reviewed by developers. Legal and compliance see the vendor contract and the privacy policy. Nobody reviews the system prompt itself — the document that most directly governs what the AI is authorised to do — through a legal or regulatory lens. This is the governance gap that the prompting and application design layer represents. It is not a technology problem. It is an organisational blind spot that requires cross-functional ownership to close.

現實情況是:在多數機構中,系統提示詞由工程師寫、工程師審。法務和法遵部門看的是供應商合約和隱私政策聲明。沒有人從法律或監管角度審閱系統提示詞本身——但那份文件,恰恰是最直接決定AI被允許做什麼的文件。這個缺口不是技術問題,是組織設計問題,需要工程、法務、法遵三方共同持有,才有辦法填補。

4
What is our answer when something goes wrong — and have we prepared it in advance? 當出了問題,我們的回應方案是什麼——我們有事先準備嗎?

Air Canada's answer was to argue that the chatbot was a separate legal entity responsible for its own actions. The tribunal called this "a remarkable submission." Taishin Bank's answer was that its model accuracy was "50%-plus" — which critics correctly noted was statistically indistinguishable from a coin toss. Neither answer was prepared in advance. Both were improvised under public pressure. The organisations that navigate AI incidents most effectively are those that have defined — before the incident — what their remedy process looks like, who is accountable, and what their communication posture will be.

加拿大航空的危機回應是宣稱機器人是「獨立法律實體」,自行負責——裁判所稱之為「驚人的主張」。台新銀行的回應是模型「五成以上準確率」——被輿論直接類比為擲硬幣。兩個機構都沒有事先準備好任何答案,都是在公眾壓力爆發後即興應對。這是最糟糕的危機管理方式。處理AI事件最從容的機構,都是在事件發生之前就想清楚了:補救流程怎麼走、誰來出面負責、對外溝通的立場是什麼。

The Law Is Not Coming to Save You
法規不會來拯救你

The EU AI Act, and the wave of AI-specific legislation that will follow it globally, will add to the compliance burden. New categories. New procedural obligations. New disclosure requirements. New penalties. That is worth preparing for — and the organisations that build their AI governance infrastructure now will be better positioned when those frameworks fully land.

But AI-specific legislation will not create the baseline. The baseline already exists. It is the law of contract, consumer protection, employment discrimination, data protection, and insurance — the legal frameworks that have governed how organisations treat people for decades. AI governance, at its core, is the organisational discipline of ensuring that deploying AI does not put the organisation in breach of the obligations it already has.

The exposure in every case in this article was not created by AI. It was created by an organisational decision — to delegate a consequential judgement to an automated system without adequate governance of what that system was authorised to do, how its outputs would be used, and who would be accountable when things went wrong. In most of these cases, neither the board nor the CEO appears to have been involved in that decision. Which is itself part of the problem.

AI governance is not a future compliance project to be delegated to the digital transformation office while leadership focuses on adoption targets. It is a present-day organisational accountability question — because the legal exposure is present-day, the enforcement is present-day, and the decisions that close the governance gap can only be made at the top.

The question is not when the AI governance obligation arrives. It already has.

歐盟AI法案,以及各地陸續跟進的AI專法,確實將帶來新的合規要求:更細的風險分類、更多的程序義務、更嚴的揭露標準、更重的罰則。這值得提前準備,而且現在就動手建立AI治理架構的機構,等這些框架全面生效時,會比那些等待觀望的機構從容得多。

但有一件事要說清楚:AI專法不會創造責任的基準線。那條線,早就在了。它叫做契約法、消費者保護法、就業歧視法、資料保護法、保險法。這些法律存在了幾十年,規範的是機構如何對待人。AI沒有改變它們,只是讓違反它們變得更快、更大規模、更難解釋。

本文每一個案例裡的法律曝險,都不是AI製造的。是一個組織決定製造的——在沒有人認真想過的情況下,把重大判斷交給了自動化系統:沒人管它被授權做什麼,沒人管輸出怎麼被使用,沒人管出了事誰來承擔。在這些案例中,最高層大多沒有參與那個決定——這本身,就是問題所在的一部分。

AI治理不是日後再說的事,不是等監管落地才需要的合規項目,更不是可以丟給數位轉型辦公室的技術作業。它是此刻、現在、這個季度就必須面對的組織問責問題——因為法律曝險是此刻的,執法是此刻的,而填補這個缺口的決定,只能由最高層來做。

AI治理義務什麼時候到來?它早就到了。

AI governance is not a future compliance project. The exposure is present-day, the enforcement is present-day, and the decisions that close the governance gap can only be made at the top.
AI治理不是下一個財年的議程。法律曝險是今天的,執法是今天的,而填補治理缺口的決定,只有最高層有權做出。

A note on vendor contracts: The Workday case established that deploying an AI tool does not transfer liability to the vendor — both the vendor and the deploying organisation may be held accountable. Yet research published by Stanford CodeX found that 92% of AI vendors claim broad data usage rights, while only 17% explicitly commit to regulatory compliance — a significant departure from standard SaaS contract norms. This means that when something goes wrong, the loss lands on the deploying organisation. Treat AI vendor negotiations as risk management exercises, not standard procurement — and audit your existing AI vendor contracts for indemnification gaps before an incident forces the issue.

關於供應商合約:Workday案確立了一個重要原則:部署AI工具,不等於把責任轉給了供應商——供應商與部署方可能同時承擔責任。然而,史丹佛大學CodeX法律科技中心的研究發現,92%的AI供應商在合約中主張廣泛的數據使用權,只有17%明確承諾遵守監理法規——遠低於一般SaaS合約的標準。這意味著:一旦出事,損失大概率由你的機構全額承擔,而不是由供應商分擔。AI供應商談判應被視為風險管理作業,而非標準採購流程——現有AI供應商合約的賠償與免責條款,值得在事件發生之前主動審查一遍。

This article is published for informational and thought leadership purposes only. It does not constitute legal, regulatory, or compliance advice. The cases referenced are summarised for illustrative purposes; readers should consult primary sources and qualified professional advisers for complete and accurate information. CloudVista Consulting LLC makes no representation as to the completeness or currency of the information presented.

本文僅供資訊參考及思想領導之用,不構成法律、監理或合規建議。文中援引案例僅供說明之用;讀者應查閱原始資料並諮詢合格專業顧問,以獲取完整及準確的資訊。雲蔚管理顧問有限公司對本文所呈現資訊之完整性或時效性不作任何陳述。