AI and human rights due dilligence: what businesses need to know 

AI and human rights due dilligence: what businesses need to know 

GoodBlog | read time: 8 min

Published: 14 August 2026

Artificial intelligence is quickly becoming embedded in everyday business decision-making, creating new questions about how organisations understand and manage their impacts on people. Importantly, this does not only apply to businesses that develop AI, but also those that deploy it. 

In 2025, both the Office of the United Nations High Commissioner for Human Rights (OHCHR) and the UN Working Group on Business and Human Rights published reports on applying the UN Guiding Principles on Business and Human Rights (UNGPs) to the procurement and deployment of AI. The OHCHR Report evaluates the practical application of existing human rights principles to AI usage and advocates the development of AI legislation that encompasses human rights due diligence. 

The Working Group Report found that businesses are largely procuring and deploying AI systems without conducting human rights due diligence, creating the risk of adverse human rights impacts occurring. It goes on to make the case that the UNGPs must therefore apply to the deployment of AI, emphasising that organisations need to understand the actual and potential human rights impacts of AI usage whether systems are developed in-house or procured from third parties. 

This distinction is important because AI-related human rights risks often arise even when a system is functioning exactly as intended. An AI tool used in recruitment may disadvantage certain groups, while workplace monitoring software may affect employees’ privacy or autonomy. The issue is therefore not simply whether AI works accurately, but whether organisations understand the risks and how to address them. 

Why the UN reports matter 

AI regulation is developing rapidly. The EU AI Act established a risk-based framework for AI, while other jurisdictions are introducing their own legislation. Although these developments will increasingly shape how organisations develop and deploy AI, they do not replace their broader responsibilities to understand how their use of AI technologies affect people’s rights. 

The UN Working Group and the OHCHR report address this gap by focusing on corporate responsibility rather than technical compliance. They reinforce that AI should not be treated as a separate category of risk, but as another business activity to which existing human rights due diligence applies. 

This is becoming increasingly important and relevant because AI is no longer confined to specialist technology teams. AI-enabled capabilities are embedded by organisations into recruitment platforms, workplace software, customer service tools and other third-party applications that are used daily. As a result, many organisations may already be relying on AI to support decisions without fully understanding its potential impact on their employees, customers, suppliers and other stakeholders. 

For businesses, this creates both governance and commercial challenges. AI-related decisions can affect access to employment, services and opportunities, expose organisations to regulatory scrutiny or legal challenge and undermine trust if they are not properly understood or managed. Both reports address these challenges by encouraging organisations to look beyond whether AI systems function effectively and consider whether they are being used in ways that respect people’s rights. 

Ultimately, organisations that fail to understand the human rights impacts of AI technologies may face consequences that extend beyond compliance obligations. This may then affect how they are perceived and trusted by the people who rely on their services, work for them or invest in them. 

What AI means for human rights due diligence   

The Working Group’s report makes clear that businesses do not need to create separate human rights due diligence processes for understanding the impacts of AI. Instead, existing human rights due diligence should be applied wherever AI systems influence business activities and decisions. 

For organisations already applying the UNGPs, the core principles remain the same. Businesses should identify actual and potential human rights impacts, take steps to prevent or mitigate harm, monitor whether those measures are effective and communicate how impacts are being addressed. What changes under AI is the context in which these responsibilities apply. As AI technologies become embedded across business operations, organisations need to understand where these systems are being used, how they influence decisions and who may be affected by their use. 

Technical testing can identify important AI risks but cannot by itself establish whether people’s human rights are being respected. An AI system may meet its technical performance requirements and still produce discriminatory outcomes, intrude on privacy or affect people’s employment opportunities. Human rights due diligence therefore needs to examine how the system operates in practice, who may be affected and whether the resulting impacts are effectively prevented or mitigated. 

Considering these outcomes using a full-lifecycle perspective is particularly important, because human rights impacts can emerge or change over time. A system that performs as expected during development may produce different outcomes once deployed at scale, used with new datasets or applied in a different context. Organisations should therefore consider human rights impacts throughout the operational life of an AI system, including when systems are updated, repurposed or eventually retired, rather than only assessing risks before deployment. 

What adverse human rights impacts can AI create? 

The human rights impacts associated with AI will depend on how a system is designed, procured and used, who is affected and the context in which it operates. The OHCHR Taxonomy of Human Rights Risks Connected to Generative AI identifies a range of potential impacts, many of which are relevant to businesses deploying AI in their own operations. 

Equality, privacy and autonomy. AI systems can reproduce or amplify biases in the data on which they rely, resulting in less favourable outcomes for particular groups and potentially contributing to discriminatory treatment. They may also involve the collection, processing or inference of personal information, including through profiling and monitoring. AI can influence people’s choices or opinions in ways they do not fully understand, raising wider questions about individual autonomy and privacy. 

Work and livelihoods. AI can affect people’s right to work through job displacement, changes to recruitment practices and changes in working conditions. AI-enabled employee monitoring and performance assessment can also affect workers’ data privacy and employment opportunities, particularly where decisions rely on inaccurate or biased outputs. 

Information, expression and access. AI-generated content can produce inaccurate or misleading information, while AI systems may perform poorly for particular languages or groups. The use of AI in content generation, moderation or information provision can therefore affect people’s ability to access information or express themselves. 

These examples illustrate why AI-related human rights due diligence needs to focus on the people affected by an AI system and the consequences of its use, rather than assessing technical risks in isolation. 

What businesses should do in practice 

Understanding the UNGPs is only the first step. In practice, businesses need to translate human rights due diligence into the way AI systems are selected, deployed, governed and monitored. 

Identify where AI may create human rights impacts 

Businesses should begin by mapping where AI systems are used and assessing whether they could affect people’s rights. This may include systems used in recruitment or workplace management, as well as AI that influences decisions affecting customers, employees or other individuals. 

The risk assessment should consider the specific ways in which people could be adversely affected. This may include discrimination, loss of privacy or impacts on employment and working conditions. Depending on how AI is used, it could also affect people’s autonomy or access to information, or cause physical or psychological harm. 

Businesses should consider factors such as the severity of potential harm, the number of people who could be affected and whether impacts could be difficult to reverse. 

This may involve asking questions such as: 

  •      Could this system influence decisions about employment, access to services or opportunities?
  •      Could certain groups be disproportionately affected by its use?
  •      Are there appropriate safeguards, oversight and review processes in place?
  •      Can affected people understand or challenge decisions that affect them?

Identifying these issues early allows organisations to prioritise the AI systems where human rights risks may be most significant. 

Embed human rights considerations into AI governance 

Once potential impacts have been identified, businesses should ensure there is clear responsibility for managing them. This means considering who has oversight of AI use within the organisation and whether the relevant teams understand the potential human rights impacts. Human rights considerations should also form part of decisions about whether and how AI tools are selected, developed or deployed. 

Responsibility also extends to AI systems provided by third parties. Procuring AI from an external provider does not remove a business’s responsibility to understand and address potential human rights impacts. The level of influence a business has over a third-party system may vary, but the UNGPs recognise that businesses should use the leverage available to them to prevent or mitigate adverse impacts. 

In practice, this may include incorporating human rights expectations into procurement processes, seeking greater transparency from AI vendors and including appropriate requirements in contracts or working collaboratively with suppliers to strengthen safeguards. While businesses may not control every aspect of a third-party system, they are expected to take reasonable steps to influence responsible outcomes. 

For higher-risk applications, businesses may wish to undertake a human rights impact assessment before deployment of an AI system or when systems are significantly changed. Unlike a purely technical assessment, a human rights impact assessment considers how a system may affect different groups in practice, helping organisations identify potential harms and determine appropriate mitigation measures. 

Engage with affected stakeholders 

A key message from the UN is that businesses need to proactively identify and understand any potential adverse human rights impacts of their AI usage. Engagement with potentially affected people and groups can help identify concerns that may otherwise remain hidden. 

Meaningful stakeholder engagement means considering the perspectives of affected groups throughout the design, development, testing and deployment of AI systems. This can help businesses understand how systems operate in practice and ensure that safeguards address the concerns of those most likely to be affected. 

For example, employees using AI-enabled workplace tools may identify practical concerns about monitoring or decision-making that are not apparent from a system review. Similarly, customers or communities affected by automated decisions may highlight barriers or unintended consequences that may otherwise be overlooked. 

Meaningful engagement should form part of the wider human rights due diligence process, helping businesses better understand the impacts of AI and make more informed decisions about how they are managed. 

Monitor outcomes and provide remedy 

Human rights due diligence is an ongoing process. Businesses should monitor whether safeguards remain effective as AI systems and the contexts in which they are used change. This includes reviewing outcomes to identify whether particular groups are disproportionately affected and whether the system continues to operate in a way that respects the rights of those affected. 

Organisations should also ensure there are appropriate channels for concerns to be raised and decisions to be reviewed, such as accessible grievance mechanisms. Where harm has occurred, businesses should consider how affected people can access remedy and how lessons learned can inform future use of AI. 

Ultimately, applying a human rights approach to AI is not about preventing the use of technology. It is about ensuring that organisations understand where AI may affect people, take reasonable steps to address those impacts and remain accountable for the consequences of its use. 

Final thoughts 

As AI becomes embedded across business operations, organisations need to understand how its use may affect people and whether existing AI governance is equipped to address those impacts. Guided by our Artificial Intelligence Governance Framework, GoodCorporation helps organisations broaden and apply human rights due diligence to emerging technologies, supporting businesses to identify AI-related risks, undertake human rights impact assessments and embed responsible AI governance across their operations. To find out more about our services, contact a member of the team. 

 

work with us