Every AI system a business ships now carries a question it cannot answer on its own: should the people it affects trust it? A pricing model, a fraud check, a chatbot handling benefit queries. Trust is not a setting you switch on at the end. It comes out of decisions made much earlier, about data, oversight and who picks up the phone when the thing gets it wrong.
The OECD AI Principles are one of the few serious attempts to write those decisions down in a form that governments actually signed up to. Adopted in 2019 and refreshed in 2024, they were the first intergovernmental standard for AI, and they still sit under a lot of the regulation and corporate policy being written today. If you have ever been handed an AI governance framework and wondered where half of it came from, a good chunk traces back here.
We build data and AI systems at Shipshape Data, and the OECD framework comes up more often than you might expect. Not because clients quote it at us, but because the questions it asks are the same ones that decide whether an AI project survives contact with a real audit. This is a plain guide to what the principles say, who they are aimed at, what the 2024 update changed, and how to turn them from a slide in a policy deck into something your teams can act on.
What the OECD AI Principles are
The principles are a shared reference point for what "trustworthy AI" is supposed to mean. The Organisation for Economic Co-operation and Development agreed them in May 2019, which made them the first standard on artificial intelligence that a group of national governments had all put their names to. Before that, plenty of companies and research bodies had published ethics charters. What they lacked was any common ground between countries.
The framework has two halves, and people often talk about one while meaning the other. The first half is five value-based principles that describe what a trustworthy AI system looks like. The second is five recommendations aimed at governments, telling them how to build the conditions for responsible AI. The values are for anyone building or running these systems. The recommendations are for the people writing national policy. You need to know which half someone means, because the practical work sits almost entirely in the first.
Where they came from and how far they reach
The principles were negotiated across the OECD membership and then adopted more widely, so the countries formally aligned with them cover a large share of global trade and investment. The G20 drew on them for its own AI guidance the same year. That reach is the reason they matter to a London consultancy and its clients as much as to a regulator in Paris. If your business sells into Europe, North America or much of Asia, the rulebooks you will eventually answer to were shaped, at least in part, by this document.
None of this is legally binding on its own. The OECD does not fine anyone. What the principles do is set a common vocabulary that harder law then borrows. The EU AI Act, national AI strategies and a good deal of corporate policy all echo the same five values, which is why getting comfortable with them early saves you re-learning the same ideas under five different names later.
How the two halves fit together
The split is deliberate. Responsible AI is not something a technical team can deliver alone, and it is not something a government can mandate into existence either. The values give builders a target. The recommendations give governments a way to make hitting that target easier, through funding, infrastructure and sensible rules. Most organisations only ever action the first half directly, but it helps to know the second exists, because it explains why the regulatory ground under your feet keeps shifting.
The five values that define trustworthy AI
These five values are the part worth committing to memory. They apply whether you are training a large model or wiring up a modest classifier that decides which emails get flagged. Each one names a different way an AI system can let people down, and between them they cover most of what goes wrong in practice.
- Inclusive growth, sustainable development and well-being. The system should benefit people and the planet, not just the balance sheet of whoever built it. In practice this pulls in questions you might otherwise ignore, such as the energy cost of training and whether the benefits land with the people carrying the risk.
- Human-centred values and fairness. AI should respect basic rights and steer clear of discrimination. It should support human judgement rather than quietly replace it. A model that denies someone a loan should leave a human able to understand and challenge that call, not hide behind it.
- Transparency and explainability. People affected by an AI decision should be able to find out that AI was involved and get a meaningful account of how the decision was reached. "The algorithm said so" is exactly what this value exists to rule out.
- Robustness, security and safety. The system should behave reliably across the range of conditions it will actually meet, and hold up against people trying to break or trick it. This is where model drift, adversarial inputs and plain old edge cases live.
- Accountability. Someone has to be answerable when an AI system causes harm. Not the model, a person or a team. This value is the one most often skipped, and the one auditors reach for first.
Read together, they describe a system that helps rather than extracts, that a person can question, that does not fall over the first time reality gets messy, and that has a named owner. You will notice none of these is really a technical requirement. They are governance requirements that happen to have technical consequences, which is the whole reason they are hard to retrofit. For the deeper background on the ideas underneath them, our glossary entries on what AI ethics means and responsible AI are a decent place to start.
Transparency and accountability are not features you add at the end. They are decisions about data and ownership that you either made early or now have to unpick.
The five policy recommendations, and who they are for
The second half of the framework points at governments, not at your engineering team. You will not implement these directly unless you work in public policy. They still matter to you, because they shape the environment your systems have to operate in, and because clients in the public sector are increasingly expected to show their work against them.
There are five, and they read as a to-do list for a state that wants responsible AI without strangling the innovation that produces it:
- Invest in AI research and development. Public money should back not only capability but the safety and trustworthiness research that stops that capability causing harm.
- Foster a digital ecosystem for AI. Governments are asked to build the data infrastructure, the compute access and the open standards that let more than a handful of giant firms take part.
- Shape an enabling policy environment. Rules should encourage experimentation and adoption while still protecting the public, which is a harder balance than it sounds and the reason regulation keeps getting rewritten.
- Build human capacity and prepare for labour market change. AI reshapes work, so this recommendation is about education, retraining and helping people move rather than pretending the disruption will not happen.
- Cooperate internationally. If every country writes incompatible AI rules, both safety and trade suffer, so governments are asked to keep talking to each other.
The through-line is that governments are meant to hold two things at once: pushing AI forward and protecting citizens from the harm it can do. When a government actually follows this guidance, the payoff for businesses is quieter and more useful than it looks. You get clearer rules, more predictable enforcement and less chance of building something that a regulator later decides was never allowed. If you want the wider picture of how these bodies fit together, our note on what AI governance is sets out the landscape.
What the 2024 update changed
The 2019 principles were written before most people had heard the phrase "large language model". By 2024 that gap had become a problem, so the OECD revised the text. The headline is reassuring for anyone who built governance on the original: the five values did not change. What changed is the reading of them, stretched to cover systems that barely existed five years earlier.
The revised framework brings generative AI, foundation models and reinforcement learning explicitly into scope. Those systems break several of the old comfortable assumptions at once. A model trained on a large slice of the public internet has murky provenance. A system that can produce convincing text, images or audio on demand can also produce convincing lies at scale. And an architecture whose reasoning is genuinely hard to inspect puts real strain on the transparency and explainability value.
The parts worth flagging
A few of the updates are worth calling out because they change what a governance review actually has to check:
- Misinformation and synthetic content. The update takes seriously the risk of AI generating false content, and the need to track where content came from. Provenance and watermarking move from nice-to-have to expected.
- Data governance under scrutiny. When a model trains on vast, loosely sourced datasets, questions about consent, copyright and bias in the training data stop being academic. The revision leans harder on getting the data foundation right, which is the part we spend most of our time on.
- Environmental cost. Training and running large models burns real energy, and the update acknowledges it rather than treating compute as free.
- Safety across the whole lifecycle. The emphasis widens from the moment of deployment to the entire life of a system, including what happens as it is retrained and repurposed.
Here is the practical read. If you already built governance on the 2019 principles, you do not need to tear it up. You do need to sit down and ask how each value applies to any generative system you are running, because that is exactly where the original wording was thinnest. Governance frameworks have, in general, fallen behind the capabilities they are meant to cover, and the 2024 revision is the OECD admitting as much and trying to catch up.
How to apply the principles in your organisation
A framework that stays on a slide protects nobody. The work is turning five values into things your teams do without being asked. This is the part clients most often get stuck on, usually because they treat it as one enormous compliance project instead of a series of smaller, boring, achievable moves. Do not try to fix everything at once. Map first, then close the gaps that matter.
Start with a map, not a policy
Before you write a single new rule, list every AI system you actually run. You will almost certainly find a few nobody mentioned, tucked inside a marketing tool or a spreadsheet macro that quietly grew a model. Then hold each system up against the five values and mark where it falls short. A customer-facing model with no explanation path fails transparency. A pipeline with no named owner fails accountability. The point of the map is to tell you where to spend effort, so you are fixing real gaps rather than the ones that happen to be top of mind.
Give every principle an owner
The single most common failure we see is diffusion of responsibility. Everyone assumes transparency is handled by someone else, and so nobody handles it. Assign each value to a specific person or team and write it down. Data governance might own transparency. Security owns robustness. Someone senior owns accountability, because that one cannot be delegated to a committee that meets quarterly. Without named ownership, the principles stay aspirations, and aspirations do not survive an audit.
Build the checks into how you ship, not after
Principle alignment works when it lives inside the development lifecycle rather than sitting outside it as a final gate nobody has time for. That means fairness testing while a model is being trained, not after it has gone live. It means documenting a system's limits before release, so the people using it know what it cannot do. It means wiring in human oversight wherever the AI touches a decision that materially affects someone. When engineers can point to a specific value behind an architectural choice, the abstract turns concrete, and the governance stops feeling like paperwork bolted onto real work. Our glossary entry on ethical AI goes further on what fairness testing looks like in practice.
One honest caveat from doing this work. Most of what makes these principles achievable is not clever AI at all. It is unglamorous data foundations: knowing where your data came from, who owns it, how it flows, and whether you can trace a given output back to its source. Teams that skipped that groundwork find the OECD values almost impossible to satisfy, not because the values are unreasonable but because you cannot explain a decision when you cannot explain the data underneath it. Get the foundation right and most of the framework becomes a matter of writing down what you already know.
Where the principles fit alongside real regulation
It is worth being clear-eyed about what the OECD framework is and is not. It is not a law you can be fined under. It is a shared foundation that harder rules are built on top of. The EU AI Act, with its risk tiers and genuine penalties, is where the enforcement lives. National strategies from the UK, the US and others each add their own flavour. Read the OECD principles first and those later rulebooks become far easier to parse, because you keep meeting the same five ideas wearing different clothes.
For most organisations the sensible sequence is this. Learn the five values well enough to spot them anywhere. Use them to audit what you already run. Then, when a binding regulation lands in your market, you are extending a governance posture you already have rather than starting from a blank page under a deadline. That head start is the real return on taking a non-binding framework seriously before anyone forces you to.
Where to go next
The OECD AI Principles give you a workable definition of trustworthy AI: five values covering benefit, fairness, transparency, robustness and accountability, plus a set of policy recommendations that explain the ground rules governments are meant to set. The 2024 update stretched all of that to cover generative systems without throwing away the original. None of it is binding on its own, and all of it shows up in the regulation that is.
If you want a concrete first move, audit your existing AI systems against the five values, starting with anything that touches customers or high-stakes decisions. Write down who owns each principle. Build the checks into how you ship rather than treating them as a final inspection. And be honest about whether your data foundation can actually support the claims the framework asks you to make.
That last part is where we spend our days. Moving AI from a promising pilot to something you can defend in front of an auditor takes more than good models; it takes data you can trust and trace. If that is the gap you are staring at, talk to us and start with a straight read on where your foundation stands against the standards you will be measured by.