The United States Department of Justice (DOJ) has recently adjusted its Evaluation of Corporate Compliance Programs (ECCP) to encompass new technological advancements, specifically addressing the application and oversight of artificial intelligence within corporations. These adjustments are poised to inform how prosecutors approach investigations into corporate use of AI that results in compliance failures or fosters criminal activity.
The revised ECCP presents a series of questions that companies should incorporate into their risk assessments regarding AI. For instance, businesses must deliberate on how they assess the impact of AI on their compliance capabilities, the integration of AI-related risk management into broader strategies, and the governance structures in place for such technologies. The guidance further emphasizes the necessity for controls that ensure AI’s operation aligns with legal standards and the company’s ethical codes. A range of other considerations, such as training mechanisms, accountability, and real-time monitoring of AI performance, is also highlighted in the revised text. More details on these aspects can be reviewed here.
The ECCP revision underscores human accountability and the requirement for robust controls, testing, and periodic assessments of AI tools, all positioned within the framework of existing compliance practices. Companies are urged to undertake comprehensive due diligence, especially in mergers and acquisitions, to preemptively identify potential compliance issues in target entities. The DOJ further insists that the use of AI technology should not solely focus on cost-saving or profit-enhancement avenues but should be leveraged for robust compliance as well, as emphasized by Deputy Assistant Attorney General Nicole Argentieri.
These developments parallel with domestic and international legislative standards pertaining to AI, including frameworks outlined in the Colorado AI Act and the European Union AI Act. They also correlate with sector-specific models such as those by the National Association of Insurance Commissioners and the New York Department of Financial Services. The common thrust across these regulations is the comprehensive risk assessment and governance framework designed to mitigate AI-associated risks throughout its lifecycle.
Legal professionals and compliance officers in various sectors will find these revised recommendations as a call to adapt existing policies to incorporate AI concerns systematically. Maintaining a proactive stance on compliance, risk management, and the integration of AI technologies proves essential, as the DOJ’s ECCP updates underscore the vital role these elements play in defending against criminal liabilities. For additional insights, visit here.