Sirius International Holding’s Magdalena König on why trust, not speed, is the real test of enterprise AI
König explains governance can enable rather than constrain AI adoption, where accountability should sit when systems fail, the growing role of boards and general counsels, and how the UAE’s approach to responsible AI could support its ambitions as a global technology hub
27 August, 2026
TT
16
As artificial intelligence moves from experimentation into core business operations, questions around trust, accountability and governance are becoming harder for companies to sidestep. The challenge is no longer how quickly organisations can deploy AI, but how they can do so without creating new legal, reputational and operational risks.
Magdalena König, general counsel at Sirius International Holding, a subsidiary of IHC, discusses why governance can enable rather than constrain AI adoption, where accountability should sit when systems fail, the growing role of boards and general counsels, and how the UAE’s approach to responsible AI could support its ambitions as a global technology hub.
You say that trust is the real infrastructure behind AI. What does digital trust mean in practical terms for companies deploying AI at scale?
Digital trust is ultimately about confidence: that AI systems are reliable, data is handled responsibly, decisions can be understood and challenged where necessary, and accountability is clear when something goes wrong.
For companies, that means knowing what AI systems are being used, what data they rely on, what decisions they influence, who owns them and where human oversight is required.
If customers, employees, regulators or boards do not trust how AI is being used, its ability to create sustainable value will be limited. Trust must therefore be built into AI deployment from the outset.
Many businesses still view governance as something that slows innovation. How can responsible AI frameworks help companies move faster while managing legal and reputational risks?
Good governance can actually accelerate innovation by removing uncertainty. When organisations have clear principles, risk thresholds, approval processes and accountability, teams know the parameters within which they can innovate. The key is proportionality; using AI to summarise an internal document is very different from using it to influence employment or financial decisions.
Governance should reflect that difference. Done well, it gives businesses the confidence to move from experimentation to deployment while managing legal and reputational risk from the outset.
Who should ultimately be accountable when an AI system produces a harmful, biased or commercially damaging outcome?
Accountability should follow control. Developers, technology providers, integrators and deploying organisations each have responsibility for the decisions and risks they can influence.
However, companies cannot simply outsource accountability for how AI is used within their own business. Before deployment, they should establish who owns the use case, who validates the system, where human intervention is required and how problems will be escalated. The worst time to determine accountability is after something has gone wrong.
What role should general counsels and corporate boards play in AI strategy, beyond ensuring regulatory compliance?
AI is no longer simply a technology or compliance issue. It touches enterprise risk, reputation, intellectual property, data, workforce strategy and long-term value creation.
General counsels therefore have an important role in helping shape the conditions in which the organisation can innovate responsibly, rather than simply interpreting regulation after decisions have been made.
Boards do not necessarily need to become AI experts, but they should understand where AI materially affects the business, the organisation’s risk appetite, and whether appropriate accountability and oversight are in place.
How is the UAE turning responsible AI governance into a competitive advantage, and where does its approach differ from those of other major markets?
One of the UAE’s strengths is that it has approached AI as part of a broader economic and digital transformation agenda, combining investment in infrastructure, talent and adoption with increasing attention to responsible governance.
While some jurisdictions have pursued more prescriptive regulatory models, the UAE has maintained an adaptive, innovation-oriented approach suited to its highly international economy. For companies deciding where to invest and deploy emerging technologies, regulatory clarity, institutional agility and trust can increasingly become competitive advantages.
As AI systems increasingly operate across borders, how can multinational companies navigate conflicting regulations, data requirements and cultural expectations without fragmenting their technology strategies?
Complete regulatory uniformity is unlikely, so multinational companies need a strong global governance baseline with enough flexibility to accommodate local requirements.
Enterprise-wide principles around accountability, data governance, transparency, human oversight and risk assessment can provide that foundation, with jurisdiction-specific obligations layered on top. Companies should also recognise that expectations around privacy, fairness and automated decision-making can differ between markets. A consistent global framework combined with informed local implementation is therefore essential.
What practical steps should companies take before introducing generative AI into sensitive areas such as hiring, customer service, financial decisions or legal work?
Start with the use case, not the technology. Companies should ask what decision the AI will support, what happens if it is wrong, who could be affected, what data it will access and whether its output can be meaningfully reviewed. They should then assess risks including privacy, confidentiality, bias, accuracy, intellectual property and cybersecurity, while defining ownership, testing and escalation procedures. For higher-risk applications, meaningful human oversight is particularly important. The more consequential the decision, the stronger the controls should be.
How can organisations measure whether their AI governance systems are genuinely effective, rather than simply meeting compliance requirements on paper?
The real test is not whether an organisation has an AI policy, but whether that policy changes how decisions are made. Companies should look at whether AI use cases are properly identified, higher-risk applications receive appropriate scrutiny, employees understand the rules, incidents are reported and resolved, and systems continue to perform as expected after deployment.
Effective governance should ultimately result in better decisions, clearer accountability and greater confidence, not simply more process.





















