Responsible AI governance
In June 2025, the OECD described how to extend responsible business conduct due9 diligence (hereinafter RBC) to the regulation of AI. The OECD's RBC principles address human rights, labor, environment, anti-corruption, consumer interests and taxes. They apply to any area of business.
Из выпуска мониторинга No. 6 (18), June 2025 · выпуск целиком, PDF · на сайте Института Гайдара

The OECD experience
In June 2025, the OECD described how to extend responsible business conduct due1 diligence (hereinafter RBC) to the regulation of AI. The OECD's RBC principles address human rights, labor, environment, anti-corruption, consumer interests and taxes. They apply to any area of business.
The OECD recommends that companies building and implementing AI systems apply the Six-Step procedure:
− Integrate risk management into corporate policies. For example, in 2025, Microsoft revealed in reporting that each of the company's AI projects undergoes more than 30 mandatory internal reviews before launching.
− Identify and rank potential and actual negative impacts of algorithms on human rights, security and the environment. In June2 2025, Google described how its “red team” preemptively attacks the Gemini 2.5 model with malicious requests to teach the system how to respond correctly.
− Take measures to prevent and minimize risks at all stages of the model's lifecycle. For example, YouTube, starting from May 2025, obliges authors to label videos3 created with the help of AI.
− Provide independent auditing and public reporting on the plan's progress. For example, in December 2024, OpenAI invited the AI Security Institutes to test the new ChatGPT model prior to release and published4 their findings.
− Engage in meaningful dialog with stakeholders and provide a grievance mechanism with effective redress. For example, in March 2025, OpenAI promised to pay up to $100,000 to anyone who finds a serious vulnerability in its AI systems, thereby5 encouraging users to report glitches.
− Track the effectiveness of measures and disclose findings in public reports. For example, in April 2025, Google disclosed that its AI had blocked 5.1 bn malicious ads and6 disabled 39.2 mn fraudulent accounts.
Due diligence is based on risk assessment: the depth of scrutiny should be commensurate with the likelihood and severity of possible harm. For “high-risk” systems, such as those identified in the EU AI Act 2024, due diligence should be ongoing and include internal and external controls. For AI developers and suppliers, due diligence is a system for identifying and mitigating threats to human rights, consumer safety and the environment. Its implementation will reduce a company's legal and reputational risks in the event of failures and make it easier to comply with AI laws.
This is especially true for generative AI.7 In the new report, the OECD notes that generative AI research expanded beyond the IT sector, with more than 71,000 generative AI patents published worldwide in 21 sectors between 2000 and 2023, including more than 32,000 in software. In addition to software, the key sectors in terms of number of patents are life sciences, medical sciences, business solutions, document management, and8 industrial manufacturing. In 2024, the adoption of generative AI in companies remains low, with only 5.4% in the EU using chatbots and 9.3% in Canada. In the US, 22% of workers use AI on a weekly basis. At the same time, over 50% of global usage is in middle-income countries. According to the OECD, this indicates a deeper integration of AI9 into economies with growing digital maturity.
Russia’s experience
In Russia, there are initiatives that promote the implementation of RBC principles in the development and use of AI. For example, a10 voluntary Code of Ethics in the field of AI. In June 2025, the Bank of Russia also published an AI Code of Ethics for financial institutions.
There are currently no real regulatory measures to ensure responsible conduct in the use of AI, including generative AI, beyond strategies and instructions in Russia.
- https://www.oecd.org/en/publications/responsible-business-conduct-and-anticipatory-governance-of-emerging-technology_1308a723-en.html ↑
- Responsible business conduct means measures that enable a company to recognize which of its decisions and operations may harm people, the environment or fair competition, and to take timely action to prevent or compensate for such harm. This includes treating employees and suppliers fairly, respecting human rights, caring for the environment, paying taxes transparently, combating corruption, and so on. ↑
- https://security.googleblog.com/2025/06/mitigating-prompt-injection-attacks.html? ↑
- https://ppc.land/youtube-introduces-mandatory-disclosure-for-ai-content ↑
- https://www.aisi.gov.uk/work/pre-deployment-evaluation-of-openais-o1-model ↑
- https://www.forbes.com/sites/daveywinder/2025/03/29/hack-openai-win-100000-what-you-need-to-know ↑
- https://services.google.com/fh/files/misc/ads_safety_report_2024.p df ↑
- https://www.oecd.org/en/publications/is-generative-ai-a-general-purpose-technology_704e2d12-en.html ↑
- In particular, in the EU, US states, UK, Canada, Australia and others. ↑
From the monitoring issue No. 6 (18), June 2025. Download the full issue (PDF) · issue page at the Gaidar Institute