Giulio Faini, Master Principal Technologist, EMEA SaaS Security and Privacy, Oracle | Michel Nasrany, AI Solutions Director, Sales Consulting ERPM/HCM, WE, Oracle
June 2026 | 3 minutesIn the first article in our series on responsible AI, we explored how Oracle achieved ISO/IEC 42001:2023 certification and why a structured AI management system (AIMS) is fast becoming the baseline for the provision of responsible, trustworthy AI. In this follow-up, we move from principles to practice, showing how the core requirements of responsible AI are concretely implemented within Oracle’s AI ecosystem, both internally and for customers building AI agents.
Much like the well-established SaaS security shared responsibility model, the responsibility for implementing the core principles of ISO/IEC 42001 is distributed between the AI service provider (AISP) and the end user who builds AI agents and applications on top of the platform.
The AISP's obligations focus on the integrity and governance of the underlying AI infrastructure: verifying models are fair and robustly tested before they reach production. The end user's obligations focus on the responsible configuration, deployment, and monitoring of the AI agents they construct within that infrastructure. A thorough responsible AI approach requires both parties to play their part in bringing accountability to every layer of the stack.
Oracle has built a comprehensive AIMS that operationalizes ISO/IEC 42001 across its product development process. Two elements are particularly illustrative of how Oracle embeds governance in a corporatewide AI policy before an AI feature ever reaches a customer.
Oracle AI Review (OAR)
As required by ISO/IEC 42001 clause 6.1.4 (AI system impact assessment), the Oracle AI Review is a mandatory gate for every customer-facing or public-facing Oracle AI product and service. It focuses on the broader societal implications of AI; that is, it assesses the potential impacts of AI systems on individuals, groups, and society (for example, their impact on privacy, fundamental rights, safety, and discrimination). The process includes a formal impact assessment, and in higher-risk cases, an extended set of questions is used to apply proportionate scrutiny around core principles of fairness, explainability, privacy, and security.
Importantly, the OAR does not operate in isolation. It is one approval step within a broader set of prerelease requirements, including Oracle Supply Chain Security and Assurance for third-party/open source approvals and the Corporate Security Solution Assurance Process for security and privacy approvals. Developers are required to clear all applicable gates to confirm that responsible AI governance is integrated into, not layered on top of, Oracle's standard engineering process.
AI prohibited practices
Oracle's AI policy explicitly addresses jurisdictional restrictions on AI use cases (see 4.2 of Oracle AI Terms (PDF)). Certain practices – for example, some uses of facial recognition and biometric data – are not allowed in specific regions such as the European Union. Oracle's policy prohibits the deployment of such practices in all applicable jurisdictions.
While Oracle assumes responsibility for the integrity of the underlying AI platform, end users building AI agents with AI Agent Studio also have governance obligations.
Unlike traditional software, AI agents are inherently probabilistic: They are nondeterministic, open-ended, and might produce unexpected results, even when they appear reasonable. Moreover, AI agents’ complexity is growing and bringing new dependencies with other agents as new interoperability protocols and standards such as A2A and MCP emerge.
That’s why agents moving into production need more than conventional testing; they require a full lifecycle of evaluation, monitoring, tracing, and continuous governance. The evaluation and monitoring capabilities in AI Agent Studio are there to help demonstrate that the responsible AI and ISO/IEC 42001 principles outlined in our previous blog are consistently met. They do so in the following ways:
These and other features are part of the METRO framework, a trust-focused governance layer specifically for agentic AI that’s built into the Oracle Fusion Applications ecosystem.
Giulio specializes in AI compliance and security within the EMEA pre sales organization. He works closely with customers to align governance requirements with Oracle’s approach to safe, transparent, and responsible AI. He also supports broader compliance initiatives across Oracle Cloud, helping bridge innovation, regulatory expectations, and customer trust. Giulio has more than 20 years of experience in technology and consulting roles across multiple industries, leading complex, high impact initiatives.
Michel is an accomplished AI solutions director at Oracle, where he leads the Digital Transformation program across Continental Europe. With more than 22 years of experience at Oracle, Michel has held a variety of roles spanning the applications portfolio, consistently driving innovation and tangible business outcomes for clients.
Holding an Executive MBA in business administration and a bachelor's degree in computer science, Michel excels at delivering transformative solutions and harnessing emerging technologies on Oracle Cloud Applications across the EMEA region. Renowned for his deep expertise and commitment to customer success, Michel is based in Paris, France.
Giulio Faini, Master Principal Technologist, EMEA SaaS Security and Privacy, Oracle
Michel Nasrany, AI Solutions Director, Sales Consulting ERPM/HCM, WE, Oracle