OECD Due Diligence Guidance / AI Value Chain and Corporate Responsibility: Random Thoughts
I. Structuring Responsibility in the AI Value Chain
The Organisation for Economic Co-operation and Development (OECD) has published the "OECD Due Diligence Guidance for Responsible AI" [Note 1]. Against the backdrop of the current expansion of AI utilization into various industrial sectors, this document redefines risk management across the entire AI value chain as a corporate obligation. It should be noted that this document was approved by the Committee on Digital Economy Policy and the Investment Committee.
One can raise the question of how non-binding international guidelines will regulate the practical aspects of maintaining corporate legality and intersect with the legal systems of individual countries.
1. Expansion of Scope and Classification of Roles
A distinctive feature of this guidance is that it does not limit its scope to specific AI development companies but extends it to a wide range of entities that make up the value chain. The document includes not only upstream input suppliers that provide data collection, computing resources, and funding, but also companies directly involved in the design, development, deployment, and operation of AI systems. Downstream companies that incorporate and use AI systems in their own business operations or products are also included in the scope [Note 2]. As the document states, these classifications are not mutually exclusive, and a single company may fulfill multiple roles.
Responsibility for adverse impacts caused by products has traditionally been attributed primarily to manufacturers or providers. In contrast, the risks associated with AI systems are not fixed at the development stage; they emerge through a chain of diverse factors, ranging from the quality of training data to the downstream operating environment. Issues such as poor working conditions in data enrichment tasks and the environmental burden associated with massive consumption of computing resources are not confined to a single company. It can be read as requiring all involved entities to build management systems according to their position in the business domain.
2. Tiering of Obligations Based on Degree of Involvement
The level of obligation a company must bear varies depending on how it is involved in an adverse impact. Obligations are envisioned according to the degree of involvement, such as when a company directly causes an adverse impact through its own activities, when it contributes to the occurrence of an impact, or when it is merely directly linked to an impact through business relationships [Note 3].
Companies cannot address all identified risks simultaneously. Operations that determine priorities in light of the severity and probability of occurrence of adverse impacts are permitted. On the other hand, even companies that are merely directly linked to an impact are expected to exercise their influence to encourage business partners to improve the situation. This is understood as a fairly strict requirement that does not exempt management responsibility as long as there is a business connection.
II. Implementation in Practice and External Participation
1. The Process of Practice and AI-Specific Risks
The prescribed due diligence framework consists of a practical process that begins with incorporating responsible business conduct into the company's own policies, and includes identifying and assessing adverse impacts, prevention and mitigation, tracking, external communication, and providing appropriate remediation [Note 4]. This process is not intended to be a one-time event, but is premised on being repeated as risks change.
AI-specific elements, such as risks associated with dual-use, deployment in applications with significant human impact, and the environmental burden of computing resources, are explicitly incorporated into this framework. Dialogue with affected workers and local communities is encouraged throughout, suggesting an intention to control impacts on human rights and the environment that goes beyond mere improvements in computational accuracy.
2. Intersection of Domestic Legislation and International Standards
This guidance itself is a voluntary guideline, and it is explicitly stated that it is intended to complement domestic laws and regulatory requirements of each country, and in some cases, to encourage companies to respond at a level that exceeds legal requirements [Note 5]. It is also envisioned that National Contact Points for the Guidelines for Multinational Enterprises will use it as a reference standard for responding to AI-related infringement complaints [Note 6], which shows the multi-layered implementation path of governance.
The goal of promoting policy consistency across jurisdictions is understandable. The situation where non-binding guidelines function as substantive behavioral requirements places a considerable burden on a company's system for maintaining legality. Companies are forced to build systems that not only comply with the domestic laws of the countries where they operate, but also meet the expectations set forth in the document. In relation to mandatory regulations such as the European Union's AI Act, the extent to which compliance with guidelines can be reinterpreted as the fulfillment of legal obligations varies by country and regulatory framework, and this sorting out is still in progress.
For small and medium-sized enterprises, securing resources to devote to dialogue with stakeholders and exercising influence over business partners is a practical barrier. The fact that it encourages the use of technical support through regional AI promotion networks, etc. [Note 7], can be understood as consideration for the current situation where the effectiveness of management requirements is spreading throughout the entire supply chain.
III. In Conclusion
The presentation of this guidance by the OECD is an attempt to translate ethical principles regarding AI into concrete procedures that companies should incorporate into their daily operations. Although it is a document without legal binding force, I believe it will function as a de facto norm in the market by being referenced as an international transaction requirement and a criterion for investment decisions.
Companies involved in AI systems will not be allowed to remain in the limited position of mere technology providers or users, and will be required to build a system to predict and proactively manage the impact that their business activities have on society. How the intersection with the full-scale enforcement of legal regulations in Europe will define the scope of corporate responsibility will be an important point of discussion.
[Note 1] OECD, "OECD Due Diligence Guidance for Responsible AI", OECD Publishing (2026)https://doi.org/10.1787/41671712-en, p.3, last visited February 25, 2026.
[Note 2] OECD, "OECD Due Diligence Guidance for Responsible AI", OECD Publishing (2026)https://doi.org/10.1787/41671712-en, pp.9-11, last visited February 25, 2026.
[Note 3] OECD, "OECD Due Diligence Guidance for Responsible AI", OECD Publishing (2026)https://doi.org/10.1787/41671712-en, pp.29-31, last visited February 25, 2026.
[Note 4] OECD, "OECD Due Diligence Guidance for Responsible AI", OECD Publishing (2026)https://doi.org/10.1787/41671712-en, pp.13-14, last visited February 25, 2026.
[Note 5] OECD, "OECD Due Diligence Guidance for Responsible AI", OECD Publishing (2026)https://doi.org/10.1787/41671712-en, pp.14-15, last visited February 25, 2026.
[Note 6] OECD, "OECD Due Diligence Guidance for Responsible AI", OECD Publishing (2026)https://doi.org/10.1787/41671712-en, p.12, last visited February 25, 2026.
[Note 7] OECD, "OECD Due Diligence Guidance for Responsible AI", OECD Publishing (2026)https://doi.org/10.1787/41671712-en, pp.11-12, last visited February 25, 2026.
(Magazine) "Random Thoughts on AI and Law"
*Please refer to the following for the table of contents
note General Terms of Service Article 3, Paragraph 2, First Sentence
3.2 Copyright for digital content created by the creator belongs to the creator.
