Welcome to the latest installment in CFM’s exploration of all things museums and artificial intelligence. This week the estimable Nik Honeysett proposes some simple laws to govern museums’ use of AI. To catch up with our coverage so far, read three scenarios of potential AI futures—bright, dark, and muddling through—Nik’s essay on how AI is changing how people encounter information; a tour of the National Archives Museum’s new AI-powered exhibition, and my framework for critical decisions about AI. Stay tuned for more examples of great museum applications of AI, and commentary exploring how this technology is impacting our sector and the communities we serve.
–Elizabeth Merritt, Vice President, Strategic Foresight and Founding Director, Center for the Future of Museums, American Alliance of Museums
Science fiction fans will know Isaac Asimov’s Three Laws of Robotics: a robot must not harm a human; it must obey humans unless doing so causes harm; and it must protect itself unless that conflicts with the first two laws. Asimov fans will also know that the Three Laws rarely made things simple. That was the point.
The best stories weren’t about rules, but about what happened when simple rules encountered messy reality. What constitutes harm? Whose interests take precedence? What happens when two perfectly reasonable rules conflict?
Museum AI policies will encounter exactly the same problem. A policy cannot anticipate every possible use of AI, particularly when the technology itself is changing so quickly. We need rules, certainly, but we also need principles, judgment, accountability, and a process for dealing with situations nobody imagined when the rules were written. We need governance to provide those rules and the framework to apply them, and then stewardship to provide judgment when the rules aren’t enough. We need AI governance, and by that I mean the policies, principles, responsibilities, and decision-making processes that guide how an institution uses AI. We need our own version of Asimov’s Three Laws:
Do No Harm. Preserve Trust. Create Value.
Like Asimov’s laws, the order matters. An AI application that saves twenty hours has no value if it compromises confidential information. An application can be perfectly legal and secure but still inappropriate if it undermines curatorial accountability or public trust. Only after addressing AI governance should we ask the more exciting question: what can AI help us accomplish that advances our mission?
First Law: Do No Harm
“AI must not compromise privacy, security, intellectual property, legal obligations, or the people and communities whose information museums steward.”
The first responsibility is protection. Before asking whether AI can make us faster, more productive, or more innovative, museums need to establish what it must never be allowed to compromise.
What information may enter an AI system? What happens to constituent, employee, lender, visitor, student, or strategic information? Do we have the right to upload an artist’s work, collection image, scholarly text, or community-contributed material? What permissions does an AI application receive when it connects to institutional systems?
These are questions of privacy, security, copyright, intellectual property, and legal responsibility. They aren’t particularly glamorous, but they form the foundation of responsible experimentation.
But for museums, harm cannot be defined solely by what is legally permissible. Museums should distinguish possession from permission. An institution may possess information without having unlimited moral or cultural authority to place it into an AI system. Public accessibility does not necessarily mean appropriateness for unrestricted computational reuse. Indigenous knowledge, culturally sensitive collections, oral histories, community-contributed knowledge, sacred material, and traumatic histories may require us to ask not simply whether the museum can use something, but whether the people represented would reasonably expect it to do so.
Do No Harm should also apply internally. If an institution expects staff to adopt AI, it assumes a responsibility to provide equitable access, appropriate training, and time to develop those capabilities. AI adoption should not create a new divide between employees who happened to have the opportunity to experiment and those who do not.
That gives us our first question: Are we allowed to do this? Compliance provides an essential starting point. But compliance is the floor, not the ceiling.
Second Law: Preserve Trust
“Subject to the First Law, AI should preserve transparency, authenticity, professional accountability, human judgment, and public confidence in the institution.”
With basic legal and security protections in place, the next responsibility is trust. Museums hold a rarefied position in society and in the information ecosystem. Audiences expect authenticity, accuracy, transparency, scholarship, and professional accountability. These should not change simply because an “intelligent” machine helped produce something: AI can assist a curator, but it must not become the curator; AI can support prospect research, but it should not determine donor strategy; AI can assist HR, but it should not independently decide whom to hire; and AI can generate interpretation, but someone still has to take responsibility for whether that interpretation is accurate, appropriate, contextualized, and worthy of the museum’s name.
The principle is straightforward, and perhaps this should be the line in the sand:
AI can assist professional judgment, but it cannot be assigned professional responsibility.
Trust also requires us to think about provenance differently. Museums have spent generations establishing the provenance of objects. In an AI-mediated information environment, we also need to consider the provenance of information. Where did this interpretation come from? Which sources informed it? Was AI involved? Who reviewed it? Who is accountable for it? Can we distinguish institutional scholarship from machine-generated synthesis?
Disclosure is central to a museum’s preservation of trust. Transparency, however, does not necessarily mean labelling everything that AI has touched. If AI corrected the grammar in a press release, suggested a headline, or helped reorganize an internal document, disclosure discloses little. A more useful principle is that disclosure should be proportional to the degree to which AI materially affects authorship, authenticity, interpretation, or institutional authority. The greater AI’s role in creating something the public might reasonably assume was produced by a museum professional, scholar, artist, or other human source, the stronger the case for making that role visible. The threshold should be particularly low for scholarship, collections interpretation, historical claims, generated or manipulated imagery (as we saw in the case of the British Museum’s social media posts), culturally sensitive material, and other contexts where provenance itself contributes to meaning and trust.
The goal is not to persuade audiences to trust AI. Museums don’t need to transfer their institutional credibility to AI; they need to avoid transferring AI’s trust deficit to themselves. Transparency tells audiences that AI was involved; accountability tells them who stands behind the result. I used to think the “human in the loop” requirement solved the problem, but that doesn’t guarantee accountability; it should be “human judgment in the loop.” But again, simply requiring human judgment in the loop is not enough; governance creates an obligation to train. Giving staff access to AI without appropriate training is like handing everyone the keys to a car because the organization has decided driving will now be part of their jobs. Some already know how to drive. Some think they do. Some will be reluctant to get behind the wheel, while others will immediately want to see how fast it can go. But if the institution expects people to drive, it either assumes responsibility for teaching them the rules of the road, how to operate safely, and when not to drive at all, or proof that they are capable of doing it successfully. Your AI software license provides access, but training creates capability.
Not every use requires the same level of scrutiny, however. A useful test is to consider visibility, consequence, and reversibility: an internal meeting summary is less risky than a collection interpretation published under the museum’s name; a first draft of an internal document is much less consequential than a donor communication; a mistranslated public label may be harder to correct than an inaccurate brainstorming note; and an AI-influenced personnel decision could have consequences that are difficult or impossible to reverse. We might express this as an equation:
Visibility + Consequence + Reversibility = Level of Human Oversight
Resulting in a risk model that looks something like:
- Low-risk/incidental use: AI may lead; human remains accountable
- Spelling, grammar, formatting, brainstorming, routine editing.
- Probably no disclosure
- Moderate-risk/substantive use: AI assists; human reviews and approves.
- Significant drafting, synthesis, translation, image manipulation, research assistance.
- Disclosure depends upon context and consequence
- High-risk/material use: Human leads; AI may assist.
- AI substantially creates something the public might reasonably assume was created by museum professionals, artists, scholars, or another identifiable human source.
- Disclosure should generally be expected.
The higher the stakes, the greater the human responsibility. There is also a practical test that shouldn’t be forgotten amid all this governance: Is AI actually making the work better? Does it save time? Improve quality? Expand access? Or does the checking, correcting, reprompting, and reworking consume whatever benefit AI was supposed to provide? Responsible AI doesn’t mean finding a way to use AI everywhere. It means using it where the benefit is real and matching human oversight to institutional risk.
This gives us our second question: Under what conditions should we do this? AI governance provides a framework for answering that question consistently, helping establish who decides, what criteria they use, what level of review is required, and when a decision needs to be revisited.
Third Law: Create Value
“Subject to the first two laws, museums should use AI where it creates genuine value: increasing capacity, improving quality, expanding access, supporting staff, or advancing the mission.”
Once we have established what we shouldn’t do and what requires additional oversight, we can stop talking only about risk and start talking about possibility. The strategic question isn’t: What can we do with AI? Because there will always be another product demonstration answering that question. The better question is: Why would our museum use AI at all? Every museum and perhaps every department within it should be able to articulate an AI value proposition. A simple formula that works for me is:
Use AI to [solve a problem] so that [staff/audiences] can [achieve an outcome] while maintaining [museum values].
Marketing might use AI to cut time spent producing routine drafts so staff can focus on strategy and creativity. Curatorial might use it to accelerate research while preserving scholarly rigor. Education might use it to expand multilingual access while retaining human responsibility for interpretation.
The important part isn’t the AI, but the outcome. AI should be a means rather than an objective, and this should change how we think about productivity in an AI world. Saving ten hours isn’t necessarily valuable if those ten hours simply produce more material nobody needs. Efficiency should create capacity for something that matters.
The question isn’t whether AI can do something, or even whether it will save us time; it is: Does using AI make us better at fulfilling our mission? A value proposition helps bridge the gap from AI capability to institutional purpose.
This leads to the hardest of our three questions: Should we do this? That’s where stewardship comes in.
When the Laws Aren’t Enough
But as Asimov’s stories illustrated, no set of rules can anticipate every situation, and neither can an AI policy. Technologies will change. Vendors will disappear. Capabilities will evolve. Social expectations will shift. Uses that seem innocuous today may become consequential tomorrow, and questions we haven’t imagined will emerge. That’s why museums need more than a document called an “AI Policy.”
Policy can provide the rules; governance can provide the framework for applying them; and stewardship can provide the judgment when the rules aren’t enough.
The concept of stewardship is something museums are deeply familiar with. Museums don’t just possess collections; they accept responsibility for them. They make decisions in the present while considering people in the past, communities in the present, and generations in the future. We would be wise to apply that same long-term view to AI.
The Three Laws aren’t supposed to answer every question; they are a place to start:
Do no harm. Preserve trust. Create value