AI Governance, Compliance & Regulation

Using foundation models: Your responsibilities

March 24, 2026

Most organizations already have company-wide licenses for general-purpose AI (GPAI), tools like ChatGPT, Copilot, or Claude that function as personal assistants or agents for employees across the business. That’s exactly where governance gets complicated.

When everyone has access, oversight tends to disappear. Thousands of employees start building their own workflows, prompts, and mini-applications, often with little understanding of the risks they’re creating. How can you, as an organization, better understand and act on your responsibilities?

How are you using your foundation models?

Bought, wide use with little overview  

Neither built nor bought – both 

Building applications

Why this matters for AI Governance

Using GPAI doesn’t eliminate your governance responsibilities. You’re still responsible for:

The GPAI provider handles: 

But you handle: 

Understanding your role and obligations

There are essentially three roles in the AI value chain. Who are you?

GPAI Provider (Rare)

Train foundation models from scratch.

Examples: OpenAI, Anthropic, Google, Meta

Downstream Provider (Most common – Most likely you)

Build applications using foundation models.

Examples: Building chatbot with GPT-4 API, deploying diagnostic tool with Med-PaLM, using LLMs for credit scoring.

Deployer

Use AI tools as-provided without building.

Examples: Using ChatGPT Enterprise for productivity.

Even if you’re a deployer and not building anything, you still carry responsibility. Your role determines your obligations, but it doesn’t eliminate them. The provider handles how the model was trained, its base capabilities, and the infrastructure behind the API. Everything built on top of that is yours.

Foundation_models_responsabilities

Your obligations as a downstream provider

If you’re a downstream provider, you must implement:

Provider compliance is not your compliance

This is the mistake that catches organizations off guard: assuming that because the model is compliant, their application is too.

It isn’t. “We use GPT-4, which is compliant” is not a governance position. “We use GPT-4, and we’ve governed our specific application” is.

Think of it like cloud infrastructure or a database. The provider ensures the technology works reliably and securely. What you build with it, and how you deploy it, is entirely your responsibility, even if their governance is exemplary. Your application may create risks the provider never anticipated and couldn’t have designed for.

Responsibility flows through the value chain. The provider governs the model. You govern the application.

Download the whitepaper​

We dive into this and much more in the complete whitepaper. Co-developed with 12+ industry partners, including Deloitte & BearingPoint, it 

The question isn’t whether you’ll need robust AI governance. It’s whether you’ll build it in time.

More news

Whitepaper: AI Governance & Control Framework
August 26, 2026
Introducing the EU AI Act Hub: a reference for a moving target
July 21, 2026
AI agent governance is no longer optional: Why accountability matters
June 22, 2026

Thank you for subscribing!

You will receive a confirmation shortly.

Build audit-ready AI governance from day one