OECD Issues Responsible-AI Due Diligence | TLY

AI Regulation Tracker  /  Standards and guidance

OECD Extends Its Due Diligence Method to the AI Value Chain

On February 19, 2026, the OECD published its Due Diligence Guidance for Responsible AI, taking the same six-step responsible-business-conduct method that already governs supply-chain risk and applying it to enterprises that build, deploy, or use AI. It is voluntary guidance, not binding law. It matters anyway, because US multinationals and their advisers are already using the OECD process as the default global template for documenting AI risk across a supply chain.

The Leveraged Years AI Regulation News

Here is the thing to understand first, because it changes how you read the whole document. The OECD did not invent a new compliance regime for AI. It reached for a tool it has been refining for years. The Guidelines for Multinational Enterprises and the companion Due Diligence Guidance for Responsible Business Conduct already tell companies how to look through their own operations and their business relationships, find where they might be causing or contributing to harm, and do something about it. That method was built for human rights, labor, bribery, and the environment. This new document takes that exact method and points it at AI.

The six steps, unchanged, now aimed at AI

If you have ever sat through a supply-chain due-diligence exercise, the structure will look familiar, because it is identical. The OECD lays out six measures. In the guidance's own words, they are: "Step 1: Embed RBC into policies and management systems," "Step 2: Identify and assess actual and potential adverse impacts," "Step 3: Cease, prevent, and mitigate adverse impacts," "Step 4: Track implementation and results of due diligence activities," "Step 5: Communicate actions to address impact," and "Step 6: Provide for or cooperate in remediation when appropriate."

What is new is the application. Each step now comes with practical examples for AI and, more usefully, a roadmap table that cross-references how that step lines up with roughly 20 other frameworks, including the EU AI Act, the ISO 42001 family, and the UN Guiding Principles on Business and Human Rights. That is the quiet value here. Instead of maintaining a separate compliance workstream for every regime your AI touches, you run one due-diligence process and the roadmap shows you which boxes it also satisfies elsewhere.

Voluntary is not the same as optional

I want to be precise about status, because it is easy to oversell a document like this. It is not law. The framework rests on the MNE Guidelines and the OECD AI Principles, which are themselves voluntary recommendations for responsible business conduct rather than binding instruments. There is no OECD AI fine, no filing, no enforcement action attached to this guidance. Anyone telling your clients they now "have to comply with the OECD" is wrong.

But voluntary guidance from the OECD has a way of hardening into expectation. The National Contact Point system already lets stakeholders bring complaints against companies for failing to observe the MNE Guidelines, and courts and regulators in Europe increasingly treat the OECD due-diligence standard as the reference point for what reasonable conduct looks like. The EU's own corporate sustainability due-diligence rules were built on this same skeleton. So the honest way to frame it for a client is this: nothing forces you to adopt it, and everything about where the market is heading suggests you will be measured against it.

Who the OECD says this is for

The scope is deliberately broad, and it reaches well past the model developers. The guidance states that "It serves as a tool for multinational enterprises engaged in the AI system value chain," and then defines that chain as "those supplying inputs for AI development, actively participating in the AI system lifecycle, or utilizing AI systems in their operations, products, and services across all sectors." Read that last clause carefully. Utilizing AI systems in your operations, products, and services across all sectors. That is not a description of AI labs. That is a description of ordinary companies that bought an AI tool and turned it on. If your client uses AI in hiring, underwriting, clinical review, drafting, or customer service, the OECD considers them part of the value chain and expects them to run the process at a level appropriate to their involvement.

Why a US professional should care

The OECD is not a US regulator, and this guidance imposes nothing on anyone in the United States by itself. The reason it belongs on your desk is practical, not legal. It is becoming the de facto global baseline for how a sophisticated enterprise documents AI risk across a supply chain, and that has three concrete consequences for US advisers.

First, procurement. The OECD notes that enterprise customers increasingly fold AI risk management into their purchasing decisions. If your client sells software or services with AI in them, expect large buyers to ask, in a diligence questionnaire, how the client identifies and mitigates AI harms, and expect the OECD six-step language to be the frame the buyer uses. Being able to answer in that vocabulary is a commercial advantage. Not being able to is friction at exactly the wrong moment.

Second, defensibility. When something goes wrong with an AI system, the question a court, regulator, or board asks is whether the company acted reasonably. A completed, documented due-diligence file built on a recognized international standard is one of the cleaner answers you can give. For lawyers advising on liability, for accountants and auditors assessing controls, and for executives who sign off on AI deployments, the OECD process gives you a defensible, auditable trail rather than an ad hoc one.

Third, harmonization. Your multinational clients are already drowning in overlapping AI regimes. The OECD roadmap that maps one due-diligence process onto the EU AI Act, ISO 42001, and the rest is the closest thing available to a single spine you can hang everything on. That is worth real money in reduced duplicate compliance work, and it is the pitch to bring to a client who is standing up an AI governance program from scratch.

What to do now

Do not tell a client this is a new mandate, because it is not. Tell them the OECD just published the reference process for AI due diligence, that it is voluntary but fast becoming the baseline their customers and their own board will expect, and that adopting it early is cheaper than retrofitting it later. If a client already runs supply-chain due diligence for human rights or anti-bribery, the move is to extend that same six-step machinery to AI rather than build a parallel program. Map the AI systems the client develops or uses, run steps two and three honestly against them, and keep the tracking and communication records the framework calls for, because those records are the whole point when someone later asks what you knew and what you did. And use the roadmap tables to show the client where this one process also covers their EU AI Act and ISO obligations, so the effort does double duty. This is guidance, not a deadline. The professionals who treat it as the emerging standard now will be the ones with a clean file when it stops being optional in practice.

Questions professionals are asking

Is the OECD Due Diligence Guidance for Responsible AI legally binding?

No. It is voluntary guidance built on the OECD MNE Guidelines and the OECD AI Principles, both of which are voluntary recommendations rather than law. There is no OECD fine or filing tied to it.

What does the guidance actually require an enterprise to do?

It sets out a six-step due-diligence process: embed responsible business conduct into policies and management systems; identify and assess actual and potential adverse impacts; cease, prevent, and mitigate them; track implementation and results; communicate actions taken; and provide for or cooperate in remediation when appropriate. It applies the OECD's long-standing supply-chain method to AI, with practical examples for each step.

Who does it apply to?

The OECD frames it as a tool for multinational enterprises engaged in the AI system value chain, defined as those supplying inputs for AI development, actively participating in the AI system lifecycle, or utilizing AI systems in their operations, products, and services across all sectors. That reaches ordinary companies that merely use AI, not only AI developers.

Why should a US professional care about a non-binding OECD document?

Because it is becoming the common baseline. Enterprise customers increasingly build AI risk management into procurement, courts and regulators treat the OECD due-diligence standard as a reference for reasonable conduct, and the guidance maps to about 20 other frameworks including the EU AI Act and ISO 42001. A due-diligence file built on it is defensible and does double duty across regimes.

How is this different from the EU AI Act or ISO 42001?

The EU AI Act is binding law with penalties; ISO 42001 is a certifiable management-system standard. The OECD guidance is neither. It is a voluntary process that cross-references those regimes, so an enterprise can run one due-diligence workflow and use the OECD roadmap tables to see how it also lines up with the EU AI Act, ISO standards, and the UN Guiding Principles.

RELATED BRIEFINGS

Browse the full AI Regulation News tracker

Informational analysis for working professionals, not legal advice. This briefing summarizes a voluntary OECD guidance document that does not itself create legal obligations. Confirm how any development applies to your situation with qualified counsel in the relevant jurisdiction.