OECD AI Due Diligence Guidance

OECD Due Diligence Guidance for Responsible AI

OECD

RAI-XO-GO-DILIGEN-2026
Effective: 19 Feb 2026
In Force(In Force)As published at oecd.org · checked 9 Sep 2026

OECD AI Due Diligence Guidance is In Force in OECD as of 9 Sep 2026, according to oecd.org.

GuidelineRisk ManagementGovernance and OversightFundamental Rights
Export PDF

The OECD Due Diligence Guidance for Responsible AI guides enterprises across the AI value chain to identify, prevent, and mitigate risks from artificial intelligence. Adopted by the Organisation for Economic Co-operation and Development in 2026, the framework sets out a six-step process and came into force on 19 February 2026.

Summary

The OECD Due Diligence Guidance for Responsible AI is currently In Force, having been officially published by the Organisation for Economic Co-operation and Development (OECD) on 19 February 2026. As a non-binding voluntary guidance document, no external regulatory body enforces it or possesses formal supervisory powers to audit, fine, or penalize non-compliant entities.

The instrument operationalizes the OECD Guidelines for Multinational Enterprises on Responsible Business Conduct and the revised OECD Recommendation on Artificial Intelligence adopted in May 2024. It provides multinational enterprises across the AI value chain with a practical, risk-based due diligence framework to identify, prevent, mitigate, and account for adverse impacts associated with the development and deployment of artificial intelligence systems.

The guidance establishes a voluntary six-step due diligence process adapted for AI technologies. These steps include embedding responsible business conduct into policies and management systems, identifying and assessing actual and potential risks across the AI system lifecycle, ceasing and mitigating adverse impacts, tracking implementation results, communicating actions externally, and cooperating in remediation where appropriate.

Designed to apply across the entire AI value chain, the framework covers input suppliers, enterprise developers and deployers, and end-users of AI tools. By offering a common reference point for AI risk management, the guidance aims to promote international policy coherence, support innovation, and enhance interoperability across emerging national and regional AI governance regimes.

Full article

Read full text ↗

Overview

The OECD Due Diligence Guidance for Responsible AI, published by the Organisation for Economic Co-operation and Development in February 2026, serves as a pivotal instrument in the evolving landscape of international AI governance. This comprehensive guidance aims to provide multinational enterprises with a structured, practical approach to identify, prevent, mitigate, and account for actual and potential adverse impacts associated with the development and use of Artificial Intelligence systems. It is designed to operationalize the high-level principles established in the OECD Guidelines for Multinational Enterprises on Responsible Business Conduct (MNE Guidelines) and the revised OECD Recommendation on Artificial Intelligence (AI Principles), both of which underpin the OECD's commitment to fostering trustworthy and human-centred AI. The guidance specifically addresses the unique challenges posed by AI technologies, such as opacity, complexity, and autonomy, ensuring that responsible business conduct principles are effectively applied throughout the entire AI system lifecycle.

The significance of this guidance lies in its 'whole-of-value-chain' approach, recognizing that responsible AI practices extend beyond direct developers to encompass all actors involved, from data suppliers and infrastructure providers to financiers and end-users across diverse sectors. This holistic perspective ensures that accountability for AI impacts is distributed and managed collaboratively across the ecosystem. By offering a common reference point for AI risk management, the OECD seeks to promote coherence and, where possible, interoperability among various national and international governance frameworks. This ensures that enterprises can navigate the complex regulatory environment more effectively, fostering innovation and investment while upholding ethical considerations and societal values, and preventing regulatory fragmentation that could hinder global AI development and deployment.

Definitions

The guidance defines key terms to ensure a shared understanding of its scope and application. While the full glossary is extensive, central to the document is the definition of an “AI system” as a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. This definition aligns with the broader OECD AI Principles, emphasizing the functional aspects and potential impacts of AI technologies.

Another fundamental concept is "Responsible Business Conduct (RBC) due diligence," which refers to the ongoing, proactive, and reactive process through which enterprises identify, prevent, mitigate, and account for how they address their actual and potential adverse impacts. In the context of AI, this involves a systematic risk management approach applied throughout the AI system lifecycle, considering risks related to human rights, safety, security, privacy, labour, and intellectual property rights. The guidance explicitly links this to the framework outlined in the MNE Guidelines, providing a consistent foundation for responsible operations.

Governance and Institutional Framework

The OECD Due Diligence Guidance for Responsible AI is an international policy instrument developed by the Organisation for Economic Co-operation and Development. As a non-binding voluntary guidance document, no formal regulatory or supervisory body enforces its provisions, and no authority holds powers to audit, fine, or sanction enterprises for non-compliance. Instead, the guidance relies on voluntary adoption by multinational enterprises and integration into internal corporate governance systems.

Implementation is supported at the policy level by the OECD and its member countries through existing responsible business conduct mechanisms, including National Contact Points for Responsible Business Conduct where applicable, and the OECD.AI Policy Observatory. These institutions promote awareness, monitor broader policy developments, and facilitate dialogue among governments, businesses, and civil society to encourage consistent international application of trustworthy AI practices.

Key Provisions

The core of the guidance is a six-step due diligence framework, adapted from the OECD Guidelines for Multinational Enterprises, tailored for the unique challenges of AI systems. This framework provides a systematic and iterative process for managing AI-related risks. The first step, "Embed RBC into policies and management systems," emphasizes integrating responsible AI considerations into an enterprise's overarching governance, assigning clear roles, responsibilities, and oversight. This ensures that AI due diligence is not an isolated activity but an integral part of business operations, supported by adequate resources and senior management commitment. Enterprises are expected to develop internal policies, codes of conduct, and training programs to foster a culture of responsible AI.

Subsequent steps involve "Identify and assess actual and potential adverse impacts," which requires proactive identification of risks across the AI lifecycle, including impacts on human rights, safety, fairness, and the environment. This includes conducting impact assessments, engaging with stakeholders, and considering both direct and indirect impacts. This is followed by "Cease, prevent, and mitigate adverse impacts," where enterprises develop and implement plans to address identified risks, prioritizing the most severe and likely harms. Mitigation strategies can include redesigning AI systems, implementing human oversight mechanisms, or establishing robust feedback loops. The framework also mandates "Track implementation and results," through continuous monitoring and evaluation of the effectiveness of mitigation measures; "Communicate actions to address impacts," ensuring transparency with affected stakeholders and the public; and "Provide for or cooperate in remediation when appropriate," underscoring the iterative nature of due diligence and the importance of accountability and transparency throughout the AI value chain, including access to effective grievance mechanisms for those adversely affected.

Scope and Application

The OECD Due Diligence Guidance for Responsible AI is primarily intended for multinational enterprises. Its application is broad, covering entities involved at any stage of the AI system value chain. This includes enterprises that supply inputs for AI development, those actively participating in the AI system lifecycle (such as developers and deployers), and those that utilize AI systems in their operations, products, and services across all sectors. The guidance acknowledges that enterprises may have varying degrees of influence and responsibility depending on their role in the value chain.

Geographically, as an OECD instrument, the guidance is backed by all OECD member countries, plus 17 partner governments and the European Union, making it an internationally agreed and government-backed tool. While the guidance provides a universal framework, it also allows enterprises to tailor their due diligence actions to their specific contexts and the regulatory environments within which they operate. This flexibility is crucial given the diverse legal and ethical landscapes concerning AI globally, encouraging alignment with international standards while accommodating local nuances.

Implementation Framework

The implementation framework provided by the OECD Due Diligence Guidance for Responsible AI is structured around the aforementioned six-step due diligence process, offering practical examples and a roadmap of related provisions from existing AI risk management frameworks. Enterprises are encouraged to integrate responsible business conduct (RBC) principles directly into their policies and management systems, ensuring that AI-related risks are managed systematically from the outset. This involves establishing clear internal governance, assigning responsibilities, and fostering a culture of accountability.

For each step of the due diligence framework, the guidance offers practical tips and illustrations, demonstrating how enterprises can adapt supporting measures to their specific circumstances. It emphasizes that due diligence is an ongoing, iterative process, requiring continuous monitoring and adaptation as AI systems evolve and new risks emerge. The guidance also highlights the principle of proportionality, suggesting that due diligence efforts should be scaled based on the severity and likelihood of potential harms, with deeper assessments and stakeholder engagement required for high-risk AI systems.

Monitoring and Evaluation

The guidance integrates monitoring and evaluation as a critical component of the due diligence process, specifically in "Step 4: Track implementation and results of due diligence activities." This step requires enterprises to continuously monitor the effectiveness of their efforts to prevent and mitigate adverse impacts. It underscores that due diligence is not a one-time exercise but an ongoing cycle, necessitating regular reviews and adjustments to remain effective in a rapidly evolving technological landscape.

While the guidance itself does not prescribe a specific external monitoring body, it implicitly supports the work of the OECD.AI Policy Observatory in tracking AI-related risks and incidents. Enterprises are expected to establish internal mechanisms for tracking their implementation, measuring outcomes against their objectives, and making necessary improvements. This internal accountability is crucial for demonstrating adherence to responsible AI practices and building trust among stakeholders, including users and impacted communities, who are also encouraged to be involved in identifying and mitigating risks.

Relationship to Other Instruments

The OECD Due Diligence Guidance for Responsible AI is explicitly designed to complement and support the implementation of two foundational OECD instruments: the OECD Guidelines for Multinational Enterprises on Responsible Business Conduct (MNE Guidelines) and the OECD Recommendation on Artificial Intelligence (AI Principles). The MNE Guidelines provide a broader framework for responsible business conduct across various domains, while the AI Principles set forth high-level, values-based principles for the responsible stewardship of trustworthy AI. This guidance bridges the gap between these overarching principles and their practical application in the context of AI.

Furthermore, the guidance actively draws upon and references existing international, national, multi-stakeholder, and industry-led AI risk management frameworks and regulations. Examples cited include the ASEAN Guide on AI Governance and Ethics, the European Union AI Act, and the Korean AI Basic Act. By doing so, it aims to promote coherence and, where possible, interoperability between diverse governance approaches, providing a common reference point for enterprises navigating a complex global regulatory landscape.

International Alignment

A core objective of the OECD Due Diligence Guidance for Responsible AI is to promote global cooperation and policy coherence for trustworthy AI, contributing to interoperability where appropriate. The guidance is an internationally agreed, government-backed tool, supported by all OECD member countries, 17 partner governments, and the European Union. This broad endorsement underscores its role as a common reference point for AI risk management frameworks across jurisdictions, aiming to reduce fragmentation and facilitate cross-border responsible AI practices.

By drawing on and complementing a wide array of existing international and national AI-specific risk management frameworks, regulations, and initiatives, the OECD aims to foster a harmonized approach to AI governance. This alignment helps enterprises operating in multiple jurisdictions to streamline their compliance efforts and ensures that responsible AI principles are consistently applied globally. The emphasis on interoperability supports innovation, investment, and growth by providing clarity on how enterprises can proactively identify and address adverse impacts while navigating diverse regulatory landscapes.

Implementation Timeline

The guidance follows key milestones in OECD standard-setting: on 3 May 2024, the OECD Council revised the Recommendation on Artificial Intelligence (AI Principles). On 19 February 2026, the OECD officially published the Due Diligence Guidance for Responsible AI. Since its publication, implementation by multinational enterprises across AI value chains remains ongoing on a voluntary basis.

Adoption and Endorsement

EntityDateStatus
Organisation for Economic Co-operation and Development (OECD)2026-02-19Adopted
OECD Member Countries2026-02-19Endorsed
17 Partner Governments2026-02-19Endorsed
European Union2026-02-19Endorsed

Sources and References

Official sources for this instrument include the OECD Publication Page for the Due Diligence Guidance for Responsible AI and the OECD Recommendation on Artificial Intelligence (OECD-LEGAL-0449).

Requirements for a company

What an organisation has to do under OECD AI Due Diligence Guidance, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

0

Nothing in this category.

Must not do

0

Nothing in this category.

Should do

7
  • Integrate responsible business conduct principles and AI risk management into corporate policies and management systems.Multinational enterprises across the AI value chain
  • Identify and assess actual and potential adverse impacts across all stages of the AI system lifecycle.Multinational enterprises across the AI value chain
  • Implement risk mitigation plans to cease, prevent, or reduce identified adverse impacts from AI systems.Multinational enterprises across the AI value chain
  • Continuously monitor and evaluate the effectiveness of AI risk mitigation measures and overall due diligence.Multinational enterprises across the AI value chain
  • Communicate transparently with affected stakeholders and the public regarding measures taken to manage AI impacts.Multinational enterprises across the AI value chain
  • Provide for or cooperate in remediation when AI systems cause or contribute to actual adverse impacts.Multinational enterprises across the AI value chain
  • +1 more in the table below

Should not do

1
  • Do not deploy or operate AI systems without establishing ongoing human oversight and risk mitigation mechanisms.Multinational enterprises utilizing or deploying AI systems

Who must do what

The obligations under OECD AI Due Diligence Guidance, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Multinational enterprises across the AI value chainIntegrate responsible business conduct principles and AI risk management into corporate policies and management systems.
“Embed RBC into policies and management systems”
——Recommended
2Multinational enterprises across the AI value chainIdentify and assess actual and potential adverse impacts across all stages of the AI system lifecycle.
“Identify and assess actual and potential adverse impacts”
——Recommended
3Multinational enterprises across the AI value chainImplement risk mitigation plans to cease, prevent, or reduce identified adverse impacts from AI systems.
“Cease, prevent, and mitigate adverse impacts”
——Recommended
4Multinational enterprises across the AI value chainContinuously monitor and evaluate the effectiveness of AI risk mitigation measures and overall due diligence.
“Track implementation and results”
——Recommended
5Multinational enterprises across the AI value chainCommunicate transparently with affected stakeholders and the public regarding measures taken to manage AI impacts.
“Communicate actions to address impacts”
——Recommended
6Multinational enterprises across the AI value chainProvide for or cooperate in remediation when AI systems cause or contribute to actual adverse impacts.
“Provide for or cooperate in remediation when appropriate”
——Recommended
7Multinational enterprises across the AI value chainScale AI due diligence activities based on the severity and likelihood of potential adverse impacts.
“due diligence efforts should be scaled based on the severity and likelihood of potential harms”
——Recommended
8Multinational enterprises utilizing or deploying AI systemsDo not deploy or operate AI systems without establishing ongoing human oversight and risk mitigation mechanisms.——Recommended

© Regulations.AI — created on 10 Apr 2026 using Gemini 2.5 Flash · reviewed against official sources on 9 Sep 2026 using Gemini 3.6 Flash