Trusted AI built on 175 years of Thomson Reuters knowledge. Meet The CoCo

ARTICLE

Ethics of artificial intelligence

Every professional is already using AI. Few organizations can say they're governing it

AI is no longer on the horizon for professional work — it’s already embedded in it. Seventy-four percent of professionals now use AI several times a week, and most say it’s boosting productivity and saving valuable time, according to the Future of Professionals Report 2026. The adoption question is settled. The governance question isn't.

Improper AI use carries risks well beyond bias, plagiarism, and privacy violations — the concerns that dominated the conversation a few years ago. Organizations now have to manage inaccurate or fabricated outputs, confidentiality and security failures, unclear intellectual property and content provenance, overreliance that erodes professional judgment over time, and, as AI agents take on more autonomous work, unauthorized actions taken without a human in the loop. Left unmanaged, any of these can result in lost clients, regulatory penalties, and reputational damage.

The ethics of AI require you to focus on fairness, transparency, privacy, and accountability to navigate trust, accuracy, and compliance issues in professional services. That discipline matters most in regulated sectors, and it depends on adopting clear principles and real operational controls for how your organization uses AI, not just what your policy says.

Understanding AI ethics in professional services

Whatever their field of practice, professionals are seeking technologies that conform to rigorous ethical standards. These standards include:

  • Fairness and non-discrimination. Organizations need to avoid biases and discriminatory outcomes. When it comes to AI, algorithms and machine learning protocols must be trained to deliver reliable, unprejudiced outputs.
  • Transparency and explainability. Professionals need to disclose to their clients the application of any technology in critical decisions that will directly impact their clients’ success or wellbeing. A digital tool also must be “explainable.” That is, professionals should be capable of explaining in clear, non-technical language how the technology works, what benefits it provides, and what its limitations and potential risks might be.
  • Privacy and data protection. Professional organizations must ensure that the management of sensitive data conforms to data protection regulations and, whenever possible, avoids disclosing private information to AI tools. Legal professionals, for instance, need to protect client confidentiality.
  • Accountability and responsibility. These principles include clear governance structures, internal policies, and mechanisms for identifying and rectifying errors.

Navigating the ethical and regulatory challenges of AI

Adoption is no longer an obstacle. What holds many professionals back — and what should concern the ones who have already adopted — is whether their organization’s governance of AI has kept pace with its use.

AI ethical concerns

Many professionals are concerned that AI’s productivity gains come at the cost of their own professional judgment. Nearly half (48%) worry about AI’s impact on how independent judgment develops, and legal professionals now expect the timeline to trusted judgment to stretch by nearly two years, even as tax professionals expect theirs to accelerate. The concern isn’t hypothetical — many professionals remain uncertain about how to balance technical innovation and professional ethics, and that uncertainty manifests in how experienced professionals mentor others.

The bigger and more current risk is shadow AI. Thirty-four percent of professionals now use AI tools their organization hasn’t sanctioned and can’t see — not out of carelessness, but because approved tools don’t meet the bar, or no clear strategy tells them what’s allowed. That gap doesn’t just create a compliance blind spot. It signals that governance isn’t keeping pace with how the work gets done.

Having a plan isn’t enough on its own, either. Among professionals whose organization has a named AI strategy, 35% say that strategy isn’t visible in their day-to-day work, and 17% say their organization has no AI strategy at all. Left unresolved, that gap pushes the decision down to individual professionals, each interpreting responsible AI use on their own terms. Inconsistent, unsanctioned use naturally follows.

AI regulations

Many professionals approach AI warily because of regulatory challenges — or a lack of regulation. There’s no central body that generates and enforces rules of ethical AI conduct. Still, the guidelines that do exist have shifted meaningfully over the past year, and your organization should track where each one stands:

  • Sector-specific requirements. For legal professionals, the clearest guidance is the ABA’s Formal Opinion 512, which applies the Model Rules of Professional Conduct directly to generative AI — covering competence, confidentiality, client communication, candor to tribunals, supervision of AI-assisted work, and reasonable fees. Several state bars have since issued their own guidance building on it, and California is amending its Rules of Professional Conduct directly — COPRAC-approved amendments to six rules (1.1, 1.4, 1.6, 3.3, 5.1, and 5.3) cleared their comment period in May 2026. That’s a bar-ethics development, distinct from the state AI statutes below.
  • State-level AI laws. Colorado remains the furthest along, but the law itself has changed. The original Colorado AI Act was repealed and replaced by SB 26-189, which narrows the framework to disclosure and transparency requirements around automated decision-making and takes effect January 1, 2027 — later, and lighter than the high-risk system rules it replaced. Other states continue introducing their own AI bills, so it’s worth revisiting the details closer to any compliance deadline.
  • The European Union. The EU AI Act remains the world’s first comprehensive legal framework for regulating artificial intelligence, but its timeline has moved. Under the AI Omnibus agreement, obligations for high-risk, standalone AI systems are now deferred to December 2, 2027, and obligations for AI embedded in regulated products to August 2, 2028 — both pushed back from their original 2026 dates.

Agentic AI adds a layer regulation hasn’t fully caught up to. An AI agent doesn’t just answer a question — it plans, acts, and can chain decisions across systems to complete a task. That shift, from answering to acting, changes what accountability requires. Generative AI gives you an answer you can check before you use it; agentic AI can already have acted by the time you look. Only 15% of organizations use agentic AI today, but another 53% are planning or considering it, according to the Thomson Reuters 2026 AI in Professional Services Report — which makes the controls below urgent for most organizations, not theoretical.

Treating agentic AI responsibly means building controls in before you deploy it, not after something goes wrong:

  • Bounded permissions. Give agents access to only the systems, data, and actions their task requires — nothing more.
  • Human approval for consequential actions. Anything that affects a client, a filing, a payment, or a public-facing communication should require sign-off before it happens, not review after.
  • Action logs. Every step an agent takes should be recorded and traceable, so you can reconstruct what happened and why.
  • Escalation mechanisms. Agents should be built to recognize the edge of their competence and hand a decision back to a person, rather than proceeding on a best guess.
  • Clear accountability. A named person, not a department, owns the outcome of what an agent does on your organization’s behalf.

Get this wrong, and the failure mode looks different from a bad AI-drafted email: an agent that files the wrong document, sends the wrong figure to opposing counsel, or acts on stale data before anyone notices. Any governance built for agentic AI must assume autonomy from the outset, not bolt controls on afterward. That’s why we’re building CoCounsel with agentic capabilities around the same safeguards — grounded sourcing, human sign-off, and traceability.

Organizations that build governance into their AI strategy will pull ahead. Those without an AI strategy risk falling behind — and the risk is measurable. Just 18% of professionals say their organization tracks AI’s return on investment, and another 40% don’t know if it’s tracked at all. Reinventing how work gets done, not just adopting a tool, is what turns AI investment into a return you can point to.

Implementing responsible AI governance frameworks

Despite the concerns and regulations, one of AI’s most significant benefits is greater efficiency. By taking on repetitive but necessary tasks, AI tools can allow professionals to focus their time on higher-value work that can better serve their clients and business.

However, technology must serve as an enabler of broader organizational objectives, not an end in itself. Organizations can establish AI governance frameworks that can meet the highest levels of professional conduct.

How to establish AI ethics

An operational AI governance framework goes further than good intentions. At a minimum, it should include:

  • Risk classification. Not all AI use carries the same stakes. Classify use cases by the consequence of an error — a low-risk drafting aid isn’t the same as a tool that touches a regulatory filing — and apply controls proportionate to that risk.
  • Approved tools and data. Maintain a clear list of sanctioned AI tools and the data they’re permitted to access. If professionals don’t know what’s approved, they’ll use what’s available — which is how shadow AI takes hold.
  • Vendor diligence. Before adopting any AI tool, understand how the vendor sources its training data, secures customer information, and where its outputs come from.
  • Pre-deployment testing. Test AI systems against real scenarios from your own practice before rolling them out, not just against a vendor’s benchmark.
  • Ongoing monitoring. Governance isn’t a one-time review. Re-test deployed systems as models, data, and regulations change.
  • Incident response. Define what happens when AI produces a wrong, biased, or harmful output — including who is notified and how it gets corrected.
  • Role-specific training. General AI literacy isn’t enough. Train professionals on the judgment calls specific to their role; when to trust an output, when to verify it, and when to override it.
  • Named accountability. Every governance framework needs an owner — a specific person, not a committee — responsible for keeping it current and enforcing it.

Since you often need to make decisions and take actions that can have a significant impact not only on clients but also on other stakeholders, you should be able to provide audit trails — how AI platforms generate outputs. As such, it allows you to demonstrate what AI data and results have been incorporated into the decision-making, which can provide transparency and accountability in case of errors, biases, or misuse.

To many people, AI seems mysterious, even a bit frightening. Organizations should be able to reassure clients and others that these tools provide measurable benefits, and that they are using them mindfully and responsibly. You needn’t be an AI developer, but you should be knowledgeable enough to discuss the platforms you use in layperson terms.

All this points to one overarching strategy for using AI ethically — human oversight. But human oversight is not a checkbox, and not every review is meaningful. A reviewer only catches what AI gets wrong when they have the expertise to recognize an error, the evidence to verify the output against a source, the time to actually do that work rather than rubber-stamp it, and the authority to push back and change the result. Take away any one of those four conditions, and “human in the loop” becomes a formality rather than a safeguard.

A robust human review and fact-checking system — one built around those four conditions — can prevent AI tools from compromising the reliability of your organization’s decisions and services. A human-centric approach to AI adoption enhances professional capabilities while maintaining the necessary preeminence of human oversight and judgment.

AI should be used to augment rather than replace human decision-making; a powerful assistant, not an unmanaged independent.

The Thomson Reuters view on ethics

Many AI technology developers have established their own frameworks for responsible AI use. At Thomson Reuters, that framework is Fiduciary-Grade AI™, our standard for how AI should perform in high-stakes professional work — the kind where outputs influence legal judgments, financial disclosures, regulatory filings, or client advice. It rests on four principles — AI grounded in authoritative, domain-specific content; data privacy and security built into the system’s architecture rather than added as a policy overlay; workflows shaped by continuous input from credentialed subject-matter experts; and transparent, verifiable reasoning that a qualified professional can check against its sources. Accountability, under this standard, stays with the human professional — AI is built to support that judgment, not to stand in for it. The proof point is CoCounsel, where professional work is grounded in trusted, authoritative content and is relied on by more than a million users. CoCounsel is evolving into an agentic operating system for the professions we serve — built to the same fiduciary-grade standard as it takes on more autonomous work.

Thomson Reuters approach to AI centers on delivering AI built for high-stakes professional work, not general-purpose productivity. That means grounding outputs in authoritative, domain-specific content, building privacy and security into the system by design, and keeping subject-matter experts embedded in how our models are built and refined.

The result is AI that produces outputs you can trace back to a source and defend under scrutiny — the standard the work demands, not a claim about the work itself. We build AI meant to support your judgment, and to be verified rather than simply trusted.

CoCounsel

When being wrong won't do, trust CoCounsel

Tackle your biggest legal, tax, and business challenges with CoCounsel — The only AI powered by 175 years of Thomson Reuters knowledge