Ahead of her session at the Retail Hive’s Tech Leaders meeting on 15th October 2026, I sat down with Dr Jo Michalska, founder of Ethica Group, a former senior risk executive at JPMorgan and HSBC. I wanted to ask Jo more about an area we’re seeing Hive members exploring and planning: AI accountability and governance. I asked Jo about some of the urgent challenges we hear from retailers and brands moving into agentic AI and AI-driven commerce….

Dr Joanna Michalska
Founder & CEO
Ethica Group Ltd
You’ve spent your career in financial services risk management before starting Ethica. Why turn your attention to retail now?
Because more and more organisations, retail included, want to bring in agentic AI, and with that comes a whole level of preparation they haven’t necessarily done yet; understanding the risks, and in many cases redesigning how the organisation itself is structured.
The awareness of that is growing, but it’s still early. We’re working on a first pilot cohort at the moment to test our methodology, and retail is a really interesting audience for it because the pressure is building fast.
Retail is often seen as less mature on governance than financial services. What can retailers learn from how finance has handled this?
Finance is more regulated, that’s true, and it’s had to build these muscles under real pressure. But the principles behind what we do aren’t only relevant to regulated industries, they’re built to address problems every organisation deploying AI at scale will eventually face. The message to retail is essentially: this is what hasn’t gone well elsewhere, here’s what we’ve learned, and here’s why you need to be thinking about it and preparing for it today, not once it’s already a problem. It’s not just about governance and control, either, it’s about creating the right conditions to scale safely and build a commercial advantage as the market accelerates, which it will.
When you talk about a governance ‘framework’, what does that actually cover? Is it about who takes responsibility and who has the final say, or is it about what you allow AI to access and do?
It’s all of those things. Zoom out far enough and the topic is really trust and accountability. Can you demonstrate that you have control over the systems helping you run your commercial agenda? Once a system gives you information, do you know what decision to make, and do you have the authority to make it? Human authority is a huge part of this; how you build it, what tools support it, and how you handle the risk and compliance side of putting it into practice.
Agentic commerce is already taking off in the US, while the UK feels like it’s still on the edge of it. Should retailers be building for what exists today, or for where things will be in a year?
It’s a combination of both. You can’t build agentic capability without first understanding your own processes, context and knowledge — the groundwork has to happen now. But you’re building that groundwork with a clear picture of where you want to be in a year.
And underneath all of it is one non-negotiable: you need to be able to demonstrate that you can stop the system in time if something goes wrong. That’s what real accountability looks like – not just to a regulator, but to a customer. It means being able to say: I have the authority, the tools and the process to intervene, as a human, before harm happens. That whole chain of logic – showing authority, expressing accountability, is what builds trust, and trust is something we’ve historically never been very good at measuring. With autonomous systems making decisions on our behalf, that’s changing fast.
When you say trust, do you mean customer trust, or something broader?
Both. Externally, it’s customer trust. But internally, trust also erodes as organisations get more complex, because the people building and running the technology often can’t clearly explain to the business what’s changing, what it costs, what it saves, or how it fits the broader strategy. A big part of this work is helping technical and executive layers communicate better with each other, so trust gets built both across the organisation and out to the customer.
Retailers can be quite reticent about this. I’ve had people tell me outright, “we don’t want to be technology leaders.” How do you square that with what you’re describing?
I hear that a lot too, but the reality is you’re already using technology to try to lead in something, so you can’t really opt out. And you need to understand a technology well enough to govern it before you can safely use it. Frankly, a lot of organisations avoid automating decisions simply because they don’t trust or understand the system enough to stand behind it, so they defer instead. But that’s not how you build competitive advantage. None of this is a new problem, either. Organisations have never been particularly good at change management, at restructuring roles, or at being clear about what accountability actually means. AI doesn’t create that problem, it magnifies it. And that makes fixing it urgent rather than optional.
How much of your work is a best-practice model you apply consistently, and how much is customised to each organisation?
Very much dependent on the organisation’s profile. We take in information about what a company is doing, what problems it’s facing and how it operates, and use that to assess where they actually stand. The output is effectively a verdict: here is where your structural conditions are broken, and here’s what needs fixing if you want to achieve what you say you want to achieve. We use our own tooling to produce that assessment. Think of it like a scoring or traffic-light system, applied against the areas that matter most, and where relevant, mapped directly to specific regulatory expectations. Even for a retailer with no direct regulatory obligation, the underlying framework still holds.
A lot of the retailers and brands in the room sell across multiple markets; UK, EU, and beyond. How do you help them navigate the differences between jurisdictions?
This matters more than people often assume, even outside regulated sectors. Jurisdiction generally follows where a company is based and where its customers are, so if you’re operating or selling into other markets, their expectations become relevant to you too, even if you’re not formally in scope for an external audit there, you still need awareness of what’s expected. For this audience, I’ll bring in the UK principles that matter most to them and lay that alongside what’s happening across the EU, since we’ve done a lot of work on that side as well.
Join Jo and other industry leaders at Technology Leaders:
Technology Leaders
Dr Joanna Michalska will be joining us as a speaker at our Technology Leaders meeting, and we can’t wait!
When? 15th October, 2026
Where? 18 West Smithfield, London
What can you expect? A day built around 1:1 meetings, huddles and roundtables for senior retail tech decision-makers, covering agentic AI, tech debt and integration risk, single customer view, AEO and LLM search visibility, payments and unified commerce, and the widening skills gap.

