The Constitutional Prohibited Use Architecture: Why Ethical Boundaries in Enterprise AI Governance Must Be Constitutionally Entrenched, Not Policy-Governed

Enterprise AI governance frameworks impose responsible AI obligations through two distinct architectural mechanisms: policy-level constraints and constitutional constraints. The difference is not merely procedural. A policy-level constraint governs until it is overridden; a constitutional constraint governs regardless of override attempts because the override mechanism itself requires the same authority that constituted the constraint. Existing responsible AI frameworks, including ISO/IEC 42001:2023, the EU AI Act, and sector-specific regulatory guidance, impose prohibited use obligations at the policy level: they specify which AI uses are prohibited and impose legal consequences for breach. They do not specify the internal governance architecture through which those prohibitions are made resistant to organisational override under commercial pressure, competitive urgency, or regulatory absence. This paper argues that policy-level governance of AI use prohibitions is structurally insufficient for regulated enterprises operating agentic AI systems at scale. The argument rests on three claims. First, the Commercial Override Problem: the history of corporate governance demonstrates that policy-level ethical constraints are routinely overridden by commercial pressure in the absence of structural resistance. Without a governance architecture that makes overrides structurally costly rather than merely procedurally inconvenient, boundaries on prohibited use are negotiable under sufficient commercial incentive. Second, the Regulatory Absence Gap: many harmful AI uses are not yet prohibited by applicable law, and policy-level governance frameworks that derive their authority from regulatory compliance leave these uses ungoverned. A governance architecture that waits for regulatory prohibition before imposing use boundaries provides protection only after regulators anticipate harm, not before harm is caused. Third, the Accountability Diffusion Problem: policy-level governance distributes accountability across the management hierarchy, making it difficult to identify and attribute responsibility for decisions about prohibited use. Constitutional governance concentrates accountability at the Board level, where accountability is both most visible and most consequential. This paper introduces the Constitutional Prohibited Use Architecture: a governance design framework that specifies how AI use prohibitions should be constitutionally entrenched in enterprise governance to be structurally resistant to override. The architecture comprises three design elements. Constitutional Adoption requires that use prohibitions be adopted by Full Board resolution and embedded in the organisation’s constitutional governance instruments rather than its policy framework. Amendment Supermajority specifies that prohibited use boundaries may only be amended or removed by the same authority and process that constituted them — Full Board resolution — and that no management action, including CAIO determination, CRO approval, or Board committee delegation, is sufficient for amendment. Disclosure Architecture requires that the organisation’s prohibited use boundaries be disclosed to affected individuals, regulators, and the Board in a form that makes overrides visible and attributable. The paper analyses five major governance frameworks, demonstrating that none imposes constitutional entrenchment of boundaries on prohibited use.

Paper

The full text of this publication is not hosted on 44B due to licensing.

Read it at OpenAlex

Similar papers

© 2026 NYSGPT2525 LLC