Most organizations already have company-wide licenses for general-purpose AI (GPAI), tools like ChatGPT, Copilot, or Claude that function as personal assistants or agents for employees across the business. That’s exactly where governance gets complicated.
When everyone has access, oversight tends to disappear. Thousands of employees start building their own workflows, prompts, and mini-applications, often with little understanding of the risks they’re creating. How can you, as an organization, better understand and act on your responsibilities?
How are you using your foundation models?
Bought, wide use with little overview
- Most platforms offer little to no overview, monitoring or guardrails on the use of GPAI.
- At the same time, every employee is granted access, with often little training or understanding.
- Some organizations choose to build an interface in order to capture traffic, and guardrail the use, with tools like Deeploy.
Neither built nor bought – both
- You don’t train the foundation model (that’s the provider’s job).
- You build your application on top of it (that’s your job).
- You’re responsible for how you use it, even if you didn’t build it.
Building applications
- Access via API for specific use cases.
- Fine-tune models for your industry/needs.
- Deploy locally (if using open weights).
- Integrate into your products or workflows.
Why this matters for AI Governance
Using GPAI doesn’t eliminate your governance responsibilities. You’re still responsible for:
- What you use the model for (your use case)
- How you integrate it (your application design)
- Who you deploy it to (your users)
- What decisions it makes (your risk assessment)
- How you monitor it (your oversight)
The GPAI provider handles:
- How the model was trained.
- The model’s base capabilities and limitations.
- Technical infrastructure (for API access).
But you handle:
- Your specific application’s risks.
- Your deployment’s governance.
- Your users’ safety and rights.
Understanding your role and obligations
There are essentially three roles in the AI value chain. Who are you?
GPAI Provider (Rare)
Train foundation models from scratch.
Examples: OpenAI, Anthropic, Google, Meta
Downstream Provider (Most common – Most likely you)
Build applications using foundation models.
Examples: Building chatbot with GPT-4 API, deploying diagnostic tool with Med-PaLM, using LLMs for credit scoring.
Deployer
Use AI tools as-provided without building.
Examples: Using ChatGPT Enterprise for productivity.
Even if you’re a deployer and not building anything, you still carry responsibility. Your role determines your obligations, but it doesn’t eliminate them. The provider handles how the model was trained, its base capabilities, and the infrastructure behind the API. Everything built on top of that is yours.

Your obligations as a downstream provider
If you’re a downstream provider, you must implement:
- Risk assessment — a general-purpose model is not automatically a low-risk application. GPT-4 is general-purpose; GPT-4 making loan decisions is high-risk. Assess your use case on its own terms.
- Controls — implement controls appropriate to your application's actual risk level, not the model's default classification.
- Documentation — document your model choice, your risk assessment, and the controls you've put in place.
- Human oversight — implement oversight proportionate to the stakes of your specific deployment.
- Transparency — disclose AI use to affected parties and label AI-generated content where required.
Provider compliance is not your compliance
This is the mistake that catches organizations off guard: assuming that because the model is compliant, their application is too.
It isn’t. “We use GPT-4, which is compliant” is not a governance position. “We use GPT-4, and we’ve governed our specific application” is.
Think of it like cloud infrastructure or a database. The provider ensures the technology works reliably and securely. What you build with it, and how you deploy it, is entirely your responsibility, even if their governance is exemplary. Your application may create risks the provider never anticipated and couldn’t have designed for.
Responsibility flows through the value chain. The provider governs the model. You govern the application.

Download the whitepaper
We dive into this and much more in the complete whitepaper. Co-developed with 12+ industry partners, including Deloitte & BearingPoint, it
The question isn’t whether you’ll need robust AI governance. It’s whether you’ll build it in time.


