Legal Framework

AI & Data Ethics Statement

Last Modified: September 8, 2026


PMG’s Approach to Ethical AI

PMG defines ethical AI through four core principles:

  1. Business Integrity: AI use must align with PMG’s professional standards and commitment to client-focused, values-driven consulting.

  2. Client Trust: We use AI in ways that protect and enhance the trust clients place in us, including how we handle their data, intellectual property, and strategic challenges.

  3. Transparency & Explainability: We maintain a clear understanding internally of how AI tools function and what their limitations are. AI is used to augment—not obscure—the work of human experts.

  4. Human Oversight: AI is strictly a supplemental tool. It does not operate independently, make autonomous decisions, or replace human judgment in any engagement. Consultants remain fully responsible for all deliverables and strategic recommendations.

Explicit Algorithmic Bias and Fairness Mitigation

PMG is committed to ensuring that its use of AI is fair, equitable, and does not perpetuate or amplify harmful biases. We strive for AI systems that produce unbiased outcomes across diverse user groups.

We perform regular audits of AI-produced outputs on a system level to proactively identify and assess potential algorithmic biases within our AI tools and their outputs. This includes examining types of data, input data, input prompts, and other sources of potential bias or subjective information for biases related to protected characteristics, hallucinations, political affiliation, or unverifiable data.

Where biases are identified, PMG commits to human-produced reproduction, analyses, and other remediation steps performed without the use of the bias-producing AI system to reduce and eliminate their impact. Our goal is to ensure our AI systems promote fair and non-discriminatory results.

AI Tooling

PMG does not build proprietary AI models. We evaluate and approve tools through a structured, ongoing review process rather than a fixed toolkit. Approved platforms span categories including general-purpose foundation models and assistants, agentic and workflow tools, image/video/audio generation models, and self-hosted models for project-specific needs, sourced from providers such as Google, Microsoft, Anthropic, and others as evaluated.

The current, authoritative list of approved AI platforms, including their assigned risk tier, is maintained at PMG's internal Approved Platforms page and is updated on an ongoing basis as tools are added, removed, or re-assessed. This policy document describes PMG's evaluation criteria and governance process; consultants should always consult the live list before using any AI tool on client work, rather than relying on tools named in past versions of this document.

New tools are adopted only after assessment against PMG's risk matrix (PMG's Platform Capacity Analysis and Risk Assessment Methodology), covering safety, utility, data handling, and alignment with PMG's policies and client requirements. Beginning in 2024, PMG performs an annual review of AI platforms used globally. Clients and prospective clients may request access to these documents by contacting PMG's Data Protection Officer at dpo@askpmg.com to have a PMG Account created for them.

Use of AI in Consulting Projects

AI may be used at various stages of our consulting process, including research, drafting, analysis, and ideation, but always under human supervision.

  • AI tools are not autonomous agents; they are used strictly to support and enhance expert human work.

  • Deliverables reflect the judgment and responsibility of PMG’s consultants, regardless of whether AI tools contributed to their development.

EU AI Act Compliance

Applicability: The following provisions apply specifically to PMG's engagements involving EU clients or AI use falling within the territorial scope of the EU AI Act. Nothing in this section extends PMG's obligations to non-EU engagements unless otherwise indicated elsewhere in this policy. However, nothing in this section prevents PMG from applying EU AI Act standards as a general global practice across jurisdictions, where doing so does not conflict with the specific legal or regulatory requirements of the jurisdiction in which PMG is operating.

PMG monitors the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) and adjusts its AI governance practices to reflect obligations as they take effect.

  1. Prohibited practices & AI literacy (in force since Feb 2, 2025): PMG does not use AI systems engaging in prohibited practices under Article 5, and maintains AI literacy training for employees using AI tools (see Formalized Training section).

  2. General-purpose AI (GPAI) model obligations (in force since Aug 2, 2025): Providers of GPAI models PMG relies on (e.g., Claude, Gemini) are subject to EU transparency and documentation requirements; PMG's own risk assessments take provider compliance into account.

  3. High-risk AI system obligations: Originally set for Aug 2, 2026, these deadlines were postponed by the "Digital Omnibus on AI" amending regulation, finalized by the European Parliament and Council in June 2026. Standalone high-risk systems (Annex III) now must comply by Dec 2, 2027; AI embedded in regulated products (Annex I) by Aug 2, 2028. PMG does not use AI applications PMG deems higher-risk than "limited" absent explicit client request (see Risk Categorization and Assessment), so this delay primarily affects forward planning rather than current operations.

  4. Transparency/watermarking obligations (Article 50): Deadlines shifted to Dec 2, 2026 for systems already on the market; deployer-facing transparency obligations (e.g., disclosing AI-generated content, chatbot disclosure) remain on the original Aug 2, 2026 timeline.

  5. New prohibition: A ban on AI systems generating non-consensual intimate imagery or CSAM was added to Article 5.

Given the pace of legislative change in this area (ie.the Digital Omnibus itself went through multiple revised timelines before finalization), PMG is actively tracking EU AI Act developments on an ongoing basis and will update this section as further guidance, delegated acts, or amendments are published. This section should not be treated as legal advice; PMG consults external counsel on EU AI Act applicability to specific client engagements as needed.

Client Data & Model Training

PMG does not use client data to train or fine-tune any internal or external AI models.

  • All client data is handled in accordance with PMG’s Privacy & Cookie Policy.

  • Client data is retained securely and may be used for future analysis related to the original engagement, unless otherwise specified in a contract.

  • No client data is shared with AI platforms without explicit, documented consent from the client.

Specifics on Data Minimization and Anonymization

Data Minimization Principles: In its use of AI, PMG adheres strictly to data minimization principles. We collect and process only the personal and client data that is absolutely necessary for the specific AI application and its intended purpose, in alignment with our Privacy Policy (https://askpmg.com/privacy-cookie-policy/).

Data Anonymization and Pseudonymization: Where feasible and appropriate, PMG employs data anonymization and pseudonymization techniques to protect sensitive information. This ensures that client and personal data used for AI model training or analysis cannot be linked back to identifiable individuals without appropriate controls and consent. For situations involving AI where data can not be sufficiently anonymized or pseudonymized, PMG will disable collection and model usage within the AI tool itself.

Secure Data Handling for AI: All data used in conjunction with AI tools is handled in accordance with PMG's comprehensive data security policies, including encryption, access controls, secure storage protocols, aligned with PMG’s Privacy Policy (https://askpmg.com/privacy-cookie-policy/).

Governance & Oversight

PMG’s AI-related activities are overseen by PMG’s Data Protection Officer (DPO), who is responsible for data and AI governance, including compliance inquiries. See Section 11 of our Privacy Policy for more information.

The PMG Compliance Team monitors ethical risks, reviews emerging technologies, and advises consultants on responsible usage. PMG maintains internal policies regarding employee use of generative AI tools and continuously evaluates developments in AI law, ethics, and practice.

Detailed Risk Assessment and Management Framework

AI Risk Identification

PMG employs a structured approach to identify potential risks associated with the deployment and use of AI. This includes risks related to data privacy, security, ethical dilemmas, unintended consequences, reputational damage, and operational failures.

Risk Categorization and Assessment

All AI applications and uses are assessed for risk levels based on their potential impact and likelihood, categorized as unacceptable, high, limited, and minimal. This assessment considers data sensitivity, stability of the application provider, decision autonomy, location and jurisdiction of the application provider, and use of the application. PMG does not use any application deemed a higher-level risk than ‘limited’ unless specifically requested by a client. In such client-requested cases, a specific risk assessment and mitigation plan will be developed in collaboration with the client before deployment.

Risk Reporting and Review

Risks are regularly reported to PMG’s Data Protection Officer and reviewed as they arise to ensure the ongoing effectiveness of mitigation strategies, and reviewed annually to identify any continuing system-level risk trends.

Continuous Learning & Ethical Vigilance

PMG’s consultants are encouraged to:

  1. Review internal findings and research on AI tool usage

  2. Stay current with developments in AI regulation, bias, risk, and safety

  3. Apply AI-first or technically specialized expertise when relevant to a project

  4. AI is a rapidly evolving field. PMG continuously monitors its implications to ensure our practices remain rigorous, ethical, and aligned with the expectations of clients, partners, and regulators.

Formalized Training and a "Culture of Compliance"

Mandatory AI Ethics and Compliance Training

PMG provides regular, mandatory training programs for all employees involved in or impacted by AI use. This training covers AI capabilities and limitations, ethical AI principles, data privacy, bias detection, compliance standards, responsible use guidelines, AI literacy, bias reduction and effective prompting principles, and reporting procedures. We foster a culture that emphasizes and empowers human oversight and critical evaluation of AI outputs.

Employees are trained and encouraged to question AI suggestions, validate results, and override AI decisions when necessary, ensuring human judgment remains a priority. Beyond formal training, PMG promotes continuous learning and awareness regarding AI developments, emerging risks, and evolving best practices through knowledge sharing sessions, updated training documents, and continuous research on AI best practices, new technologies, and risks.

Stakeholder Engagement

Internal Stakeholder Engagement

PMG actively engages internal stakeholders, including project teams, systems, compliance, and our leadership, in the ongoing development, review, and refinement of its AI policies and practices.

Client and Partner Collaboration

We commit to open communication with our clients and partners regarding our AI policies and how AI is used in engagements. We seek their feedback and incorporate relevant insights to continuously improve our approach to AI governance.

External Expertise and Dialogue

PMG monitors and, where appropriate, participates in broader dialogues with external experts, industry bodies, and regulatory authorities to stay abreast of best practices and contribute to the responsible evolution of AI use in providing its consulting services. This includes engaging with AI ethics organizations, legal counsel, academic institutions, and researching the challenges and opportunities of AI use in consulting, as well as our functional areas, to most effectively support our clients.

Contact & Feedback

To inquire about PMG’s use of AI or raise a concern, please contact our DPO via the contact methods provided in our Privacy Policy.


Legal Directory
AI & Data Ethics Statement | PMG Legal | PMG Consulting