The Great AI Debate: Ethical Nightmare or Competitive Advantage?
Staged as a genuine disagreement rather than a panel of nodding heads, the second Ethicsverse Day 2026 session pit moderator Reid Blackman against Andrew McBride, Kay Firth-Butterfield, and Wendell Wallach on how compliance should govern artificial intelligence. This recap traces every major thread — the standards patchwork, the limits of policy, shadow AI, the speed-versus-governance tension, accountability when AI goes sideways, and pragmatic advice for turning gray into color.
Joah Park
Lead Producer for The Ethicsverse

The second session of Ethicsverse Day 2026, The Great AI Debate, was deliberately staged as a disagreement rather than a panel of nodding heads. Moderated by AI-ethics author and advisor Reid Blackman, it brought together Andrew McBride, a compliance and AI-governance leader; Kay Firth-Butterfield, a lawyer and long-time AI-governance pioneer who has helped shape IEEE standards; and Wendell Wallach, author of Moral Machines and a leading scholar of machine ethics, with host Nick Gallo of Ethico. The framing question was blunt: is AI an ethical nightmare, a competitive advantage, or both — and what is a compliance officer supposed to actually do about it right now?
What followed was a substantive argument about standards, policy, speed, and accountability. The panel largely agreed on the destination — responsible, risk-based AI governance embedded across the business — but disagreed productively about how much weight to place on written policy, how long organizations can wait for regulation to mature, and where accountability should ultimately land when an AI system behaves in ways no one intended. Underneath the debate ran a consistent message: the technology is moving faster than any governance cycle designed for it, and compliance has to change how it works to stay relevant.
Key Takeaways
Compliance Is Better Positioned for AI Than It Thinks
Andrew McBride argued that compliance functions have quietly done well on AI governance because they already know governance — policies, procedures, workflows, training, cross-functional collaboration, and enterprise risk management are exactly the muscles responsible AI requires.
The profession has been here before with GDPR and broader data-privacy regulation, cybersecurity, and breach-response processes, giving it real experience threading conflicting global rules into workable standards.
Having ethics and compliance at the table when an organization asks "what is our worst AI nightmare" is, in McBride's words, probably a very good idea — the function brings a risk lens few others do.
The Constraints Are Real — and Often Self-Imposed
Wrapping AI around investigations, third-party screening, and due diligence carries serious risk because those systems touch sensitive data, whistleblower protections, and interconnected ERP and CRM platforms; the DOJ has been clear that an AI use case must not create unintended consequences.
Many teams are stuck doing tactical AI work because leadership tells them to "do something" without giving them the tools to experiment, creating a natural ceiling on more ambitious, employee-facing projects.
The panel connected this to a training gap: compliance officers are among the few professionals trained to think about risk, but most employees are not, so teaching people to use AI wisely is itself a governance intervention.
The Standards Landscape Is a Patchwork
With US federal mandates largely absent, organizations are left navigating a patchwork of soft law. Kay Firth-Butterfield noted that many global companies are adopting the EU AI Act as a comprehensive baseline because it covers most jurisdictions at once.
The panel pointed to genuinely rich standards from ISO and IEEE — Firth-Butterfield noted IEEE alone has more than 50 standards groups for autonomous and intelligent systems — but warned that only some have been adopted, and that soft law can be proposed by anyone, making it hard to know which bodies represent true best practice.
Wallach described how IEEE moved beyond narrow technical standards to address the broader societal impact of AI, producing governance regimes that go well past wiring specifications — though compliance officers cannot be expected to read engineering standards directly.
Right-Size Governance to the Risk Profile
The panel converged on matching governance intensity to risk. A company using AI to build products it sells into the market should take the full "belt and braces" approach; a company optimizing internal systems or managing casual employee use of tools like ChatGPT or Claude should lean more on principles and ethics.
Firth-Butterfield's "shadow AI" example made the stakes concrete: an engineer at a safety-critical company used his own preferred AI tool to size a gauge, which then blew up on-site — and the company had no policy governing such use. A few basic guidelines and visibility into where AI is actually being used would have mitigated an easily avoidable risk.
Does Policy Actually Work? The Core Debate
Reid Blackman pressed the panel hard on whether policy is really the right interim tool, given automation bias — people's tendency to over-trust confident AI outputs — means a policy might not have stopped the engineer from deferring to the machine.
Firth-Butterfield defended policy on legal grounds: without it there is nothing to measure against, and in litigation a company must be able to point to what it sanctioned and prohibited. In her view, using unsanctioned AI should be treated as a serious, even fireable, offense in extreme cases.
Wallach and McBride argued that a robust risk-assessment culture can function as an implicit policy, and that due diligence — not a document alone — is what demonstrates reasonableness. All agreed policy is necessary but insufficient: training, communication, walking the floor, and cross-functional collaboration have to carry the rest.
Speed Versus Governance
The panel confronted the central tension head-on: the technology accelerates faster than committee-driven policy cycles, so policies are often written by people looking at the organization through a pinhole, already out of date by the time they are approved.
Blackman warned that compliance risks making itself irrelevant if it insists on slow, enterprise-wide policy while management moves fast — and that the answer is more dynamic, rapidly implementable governance.
Drawing on his time supporting commodity traders at BP, McBride argued risk decisions sometimes have to be made in minutes; AI governance should be right-sized and democratized into business units — much like health and safety — using experts who understand both the AI and the specific business process. Firth-Butterfield added that a cross-functional AI advisory board at or just below C-suite level keeps any one team, such as HR, from taking hidden risks.
Accountability When AI Goes Sideways
Wallach framed accountability as a top-down structure that flows from mandates through regulations, standards, and corporate policy down to a compliance officer's delegated authority — and noted the current problem is that many managements do not know what to delegate, or fail to provide the resources and authority to train employees properly.
Liability is increasingly being tested not against foundational model makers but against the companies deploying AI one level down — banks, insurers, and others. The panel stressed that employees must understand these are probabilistic instruments that hallucinate and produce unreliable long-tail judgments, which requires a genuine culture of education about when not to rely on the output.
McBride translated the problem into the familiar fraud triangle: deadline pressure, the opportunity of a powerful tool on every desk, and easy rationalization ("I am doing the company a favor") combine to produce sloppy, damaging output — as in the widely reported consulting report riddled with AI hallucinations. He argued for anchoring accountability in values rather than playing whack-a-mole with endless technical scenarios.
The Human Factors Leaders Overlook
The panel flagged the multi-generational workforce, citing research that a significant share of AI-native employees are actively resisting their company's AI strategy out of fear for their jobs, and noting evidence that women tend to use AI more cautiously than men.
Wallach cited sobering adoption data — fewer than 30 percent of companies that deploy AI do so successfully, and fewer than 10 percent of corporate leaders are satisfied with their deployments — as a way to reframe compliance not as a brake but as a route to more successful, satisfactory implementation.
Pragmatic Advice: Turning Gray Into Color
McBride's prescription was to learn as much about AI as possible — to turn the gray into color — and to ensure everyone in the company is trained.
Wallach advised adopting one of the existing rich standards, then going to leadership to ask explicitly for the authority to implement it and the resources to train the employees expected to follow it.
Nick Gallo closed with a challenge to jump in the pool: you cannot govern or leverage AI from the sidelines, so start experimenting, and crowdsource a register of the real AI use cases across the organization — there are almost certainly far more than leadership imagines.
Closing Summary
The Great AI Debate earned its name by refusing to pretend AI governance is simple. Reid Blackman, Andrew McBride, Kay Firth-Butterfield, and Wendell Wallach disagreed on the primacy of written policy and on how long organizations can wait for standards to mature, but they converged on a practical worldview: adopt a rich existing standard, right-size and democratize governance into the business units closest to the risk, treat AI outputs as probabilistic and fallible, and anchor accountability in values and a real culture of education rather than in documents alone. Their shared warning is that the pace of the technology has broken the traditional, slow governance cycle, and that compliance must become faster, more embedded, and more fluent in AI or risk irrelevance. The most memorable prescription was also the simplest — learn the technology deeply enough to turn the gray into color, and get in the pool rather than reading about how to swim.
Enjoyed this article?
Subscribe to our newsletter for more insights on ethics and compliance.
View All Articles