PUBlished on
April 21, 2025
updated on
November 5, 2025

How to Build an Ethical AI Framework

Cynthia Valencia and Farah Iyer

Our teams are using AI everywhere these days—collaborating, supporting customers, analyzing data, managing projects. At Obsidian, we see it firsthand, both in our own work and in how our customers are adopting AI across their organizations.

Being a security company, we take protecting data and using AI responsibly really seriously. It's not just about the AI tools we build—it's about our approach to AI in everything we do. We're always thinking about how to use AI effectively while keeping data secure and systems trustworthy. That's why we wrote this blog—to share our framework for responsible AI adoption that puts security and ethics first.

More Than Just Checking Boxes

AI ethics goes way beyond just checking compliance boxes. Sure, aligning with standards like ISO 42001:2023 (the first AI management system standard) gives you a good foundation, but real ethical AI requires a deeper commitment. It's not just about meeting regulations—it's about building trust and making sure your innovation stands the test of time.

Before you dive in, ask yourself:

Integrating with your existing compliance frameworks should feel natural, not forced. When you align your AI ethics with standards you already know—like ISO 27001, ISO 27701, and SOC 2 Type 2—you create a comprehensive approach that strengthens both your compliance position and ethical standing.

Who's Steering the Ship?

A strong AI governance framework acts as your organization's compass for ethical AI operations. As you build your governance structure, think about:

Your policy development should build on what you already have while recognizing that AI brings unique challenges. Consider how your current policies might need to evolve to address:

Let's Talk About Your AI

Building trust means being transparent. As you develop your documentation approach, ask yourself:

Your transparency framework should cover:

Keeping Humans in the Loop

AI should enhance, not replace, human judgment. Consider these key questions:

Getting Started: Your AI Ethics Roadmap

The journey to ethical AI starts with understanding where you are right now. Key things to think about include:

Assessment:

Development:

Growing with Your AI

AI ethics isn't a set-it-and-forget-it process—it's a constantly evolving journey. Stay on top of emerging standards and best practices, regularly revisit and update your frameworks, talk with industry peers and ethics experts, and remain flexible while staying true to your core principles. Ask yourself periodically: How has our AI usage changed? Do our ethical principles still make sense for where we are now? What new challenges have popped up that we didn't anticipate? And how well are our current controls actually working? This ongoing reflection ensures your ethical approach grows alongside your AI implementation.

About Obsidian Security

Obsidian Security is the premier security solution designed to drastically reduce the attack surface area of SaaS applications by 85% on average. With contextual user activity data, configuration posture, and a rich understanding of 3rd party integrations in SaaS, the Obsidian platform reduces incident response times by 10x and streamlines compliance with internal policies and industry regulations. Notable Fortune 500 companies trust Obsidian Security to secure SaaS applications, such as Salesforce, GitHub, ServiceNow, Workday, and Atlassian. Headquartered in Southern California, Obsidian Security is a privately held company backed by Menlo Ventures, Norwest Venture Partners, Greylock Partners, IVP, GV, and Wing. For more information, request a demo.

Frequently Asked Questions (FAQs)

What is an ethical AI framework and why is it important for security companies?

An ethical AI framework is a structured approach to designing, deploying, and managing AI technologies in a way that prioritizes security, transparency, and responsible decision-making. For security companies like Obsidian Security, such a framework ensures that AI-driven tools protect sensitive data and maintain stakeholder trust while adhering to both regulatory and ethical standards. This approach goes beyond compliance, fostering long-term innovation and reliability.

How does Obsidian Security integrate AI ethics with existing compliance standards?

Obsidian Security aligns its AI ethics framework with recognized standards like ISO 27001, ISO 27701, SOC 2 Type 2, and the newly introduced ISO 42001:2023 for AI management systems. By integrating AI ethics with these established frameworks, Obsidian ensures both regulatory compliance and a strong ethical foundation. This holistic approach strengthens the company’s security posture and builds customer confidence in their SaaS security solutions.

What role does transparency play in Obsidian Security’s approach to AI?

Transparency is a core principle in Obsidian Security's AI approach, ensuring stakeholders can understand the decision-making processes of AI systems. The company prioritizes clear documentation of model architecture, logic, data sources, and constraints to facilitate informed conversations with customers and regulators. By explaining how AI-driven security tools operate, Obsidian builds trust and enables rational oversight.

How does Obsidian Security ensure human oversight in AI-driven processes?

Obsidian Security designs its AI systems to augment—not replace—human judgment by defining key checkpoints for human involvement in critical decisions. The company provides oversight teams with necessary training and establishes processes for documenting human decisions within AI workflows. This approach maintains accountability and ensures that human expertise remains central to sensitive security operations.

You May Also Like

Get Started

Start in minutes and secure your critical SaaS applications with continuous monitoring and data-driven insights.

get a demo