Contents
- Sources and impact of bias in AI data
- Data minimisation and protection of users’ privacy
- Explainability of AI decisions and accountability
- AI model security and protection against misuse
- The impact of AI on the labour market and society
- Responsible management of AI risk and ethics
- Ethics of recommendations and counteracting polarisation
- Managing the environmental impact and carbon footprint of AI
Share
Sources and impact of bias in AI data
Bias in AI data most often results from entrenched historical inequalities or from a non-representative sample, which can cause the model to discriminate despite a “neutral” objective. For example, if the data reflects earlier differences in women’s and men’s pay, the algorithm may unconsciously reinforce them. A similar mechanism appears when part of the population is missing from the dataset (e.g. people aged 60+), and the system is later used on everyone. The minimum before training is to document the data (e.g. “datasheets for datasets”) and check coverage of key groups (age, gender, region).
The effects of bias are most visible when errors are not distributed evenly, because “average” accuracy can conceal real harm on the side of one group. Simply removing a sensitive feature (e.g. “gender”) usually does not solve the problem, because its function can be taken over by proxy features such as first name, employment gaps or a postcode correlated with origin. That is why per-group metrics and discrimination risk are analysed, while monitoring indicators such as “disparate impact” and the 0.8 rule (four-fifths rule). In practice, teams combine feature impact tests (e.g. SHAP) with a pre-deployment audit and “fairness gates” in the CI/CD pipeline, also relying on checklists from the NIST AI RMF.
- Verify the representativeness of the dataset and document the data in “datasheets for datasets” before starting training.
- Report quality and error metrics per group and observe risk signals (e.g. “disparate impact” and the 0.8 rule).
- Check proxy features and analyse feature impact on the outcome (e.g. SHAP) by group.
- Carry out a pre-deployment audit (data, metrics, edge cases) and set usage limits where potential harm may be high.
- 01Historical inequalitiesEntrenched past differences
- 02Non-representative samplePart of the population missing
- 03Uneven errorsAverage accuracy hides harm
Key point: The minimum before training is documentation and checking group coverage.
Data minimisation and protection of users’ privacy
Data minimisation strengthens users’ privacy because it reduces the risk of leaks, misuse and unauthorised “recycling” of information for other purposes. Collect only the data necessary for a clearly defined purpose and do not reuse it without a new basis and communication with the user. In practice, a simple matrix works well: purpose → data categories → retention period → access permissions, which forces key decisions before the model is trained. Where processing includes profiling, sensitive data or takes place at scale, an important tool is DPIA, which identifies threats and the plan to reduce them (controls, usage restrictions, tests).
Privacy protection in AI also requires awareness that “anonymisation” is not always enough, because datasets can be combined with other data and re-identification can take place (e.g. through a combination of postcode + age + gender). In training, approaches such as differential privacy are used; this adds controlled noise and operates with a privacy budget ε (often 1–10), which always means a privacy–utility trade-off. An alternative that reduces data centralisation is federated learning, where weight updates are sent instead of raw records, although the updates themselves can also reveal information and are sometimes combined with DP or secure aggregation. An additional risk is logs and prompts in LLM systems, which is why PII masking, short retention periods and a “no-train/no-store” mode with the provider are used, while sensitive processing is protected, among other things, by encryption at rest and in transit, as well as rigorous access control and audit logs.
Explainability of AI decisions and accountability
Explainability of AI decisions means that the user can understand “why” the system returned a particular result and what actually influenced the outcome. In practice, global and local explanations are used, for example SHAP, LIME or counterfactuals showing what change in the data could reverse the result. The explanation should be understandable and operational, rather than limited to a feature-importance chart. Where a decision carries legal or financial consequences, it is also important to clearly indicate that the result is algorithmically supported, and what the appeal path looks like.
Accountability for harm requires an unambiguous assignment of roles across the AI supply chain: the producer, integrator and operator. It is crucial to establish who monitors drift, who approves model changes and who handles complaints, so that responsibility does not “dissolve” between teams. Contracts with requirements for auditing, incident reporting and usage restrictions help with this. In high-stakes areas, the ethical minimum is the ability to appeal to a human decision-maker and a genuine complaints procedure.
Transparency of the process is also strengthened by documentation in the “Model Cards” format, which describes the model’s intended purpose, training data, metrics, limitations, risks and known failure modes. In practice, this supports the approach known as “layered transparency”: a concise description for the user and a more detailed one for the auditor (e.g. under NDA) when trade secrets are involved. To make it possible to account for decisions over time, model registries (e.g. MLflow Model Registry), data versioning (DVC) and deployment approvals based on quality and fairness metrics are implemented. In addition, production testing (shadow mode), error analysis and pilots with real users help avoid situations in which a benchmark fails to reflect “long-tail” risks.
- 01Understand “why”Learn the impact on the outcome.
- 02Explanation methodsGlobal, local, operational.
- 03Legal and financial consequencesAI attribution, appeal path.
- 04Assigning rolesManufacturer, integrator, operator.
- 05Key tasksMonitoring, approval, complaints.
Understandable decisions and a clear division of roles in the AI supply chain build trust.
AI model security and protection against misuse
AI model security comes down to limiting vulnerability to attacks and designing the system so that it cannot be easily used to cause harm. In practice, the threat catalogue includes, among others, adversarial examples (bypasses through small data perturbations), prompt injection in LLMs (forcing rules to be broken and leaks), and poisoning training data with backdoors. In critical applications, robustness tests and clear usage restrictions are required when the stakes are high (e.g. transport, medicine). Before deployment, it is worth carrying out red-teaming and AI-specific penetration tests, including those based on MITRE ATLAS and OWASP Top 10 for LLM Applications.
Protection against misuse also includes the risk of model theft and intellectual property breaches through extraction attacks on APIs. In such cases, rate limits, watermarking, traffic pattern monitoring and deliberately less detailed responses for suspicious sequences are used. A separate challenge is hallucinations and “false certainties” in generative AI, which is why in critical scenarios a requirement to cite sources is designed (RAG with citations), along with verification and blocks for selected classes of responses, plus thresholds after which the response is withheld. If a system can be wrong in a harmful way, it must have verification, escalation and response-limiting mechanisms.
- In LLMs, limit prompt injection through context separation, input/output filtering and tool sandboxing.
- Protect training against data poisoning by controlling data provenance, anomaly detection, label review and validation on “canary” sets and backdoor tests.
- Reduce the risk of deepfakes and disinformation through content watermarking, provenance standards (C2PA) and misuse reporting procedures.
- In production, implement drift monitoring (e.g. Evidently AI), quality alerts and automatic fallback to rules or manual mode.
Misuse in surveillance and profiling becomes ethically indefensible when it leads to mass surveillance, a “chilling effect” and punishment without real oversight. That is why organisations often introduce restriction policies, e.g. a ban on emotion analysis in recruitment and a move away from biometrics in public spaces without an exceptionally strong legal basis and oversight. A mature approach to security also includes incident handling: a reporting channel, repair SLAs, root-cause analysis and informing users when the risk is significant. Such practices reduce harm not only on the technical side, but also organisationally, especially when the model or data environment changes after deployment.
The impact of AI on the labour market and society
AI most often transforms the structure of work by automating routine tasks and increasing demand for quality control, analytics and “AI ops”. Ethical implementation means planning reskilling so that people whose tasks are changing can move into new roles instead of being pushed out of the system. In practice, this includes training programmes of around 40–80 hours per role and checking whether the tool shifts costs onto employees (e.g. work pace, stress). Such monitoring makes it possible to identify earlier the moment when automation increases productivity at the expense of wellbeing.
AI can also deepen social inequalities if some people are excluded from services moved to automated channels. This applies, among others, to people without digital skills, with disabilities or without access to hardware and the Internet, which is why alternatives are designed ethically (e.g. a telephone/office channel) and interfaces are made WCAG-compliant. At the same time, there is a risk of violating user autonomy through persuasive recommendations and micro-targeting that “push” people towards decisions beneficial to the company. This is reduced by transparent personalisation settings, an easy way to turn recommendations off and a ban on using sensitive categories for manipulation.
Recommendation algorithms can reinforce polarisation and disinformation when they are optimised solely for engagement and reward extreme or sensational content. Ethical practices include changing the objective function (e.g. including quality/credibility), “exposure” audits and controlling recommendations for minors. Environmental impact is also important: large training runs can consume significant amounts of energy, so organisations measure consumption (kWh) and emissions (CO2e) and choose regions with lower carbon intensity. In many cases, fine-tuning, distillation or smaller models are preferred when the benefit does not justify the cost.
- 01Transformation of job rolesAutomation of routine tasks, new specialisations.
- 02Ethical implementation of reskillingPlanned upskilling, wellbeing monitoring.
- 03Risk of social inequalitiesDigital exclusion, difficult access.
Active management of AI’s impact on work and society is key to sustainable development.
Responsible management of AI risk and ethics
Responsible management of AI ethics comes down to clearly assigning roles, launching a risk assessment process, and making stop/go decisions for high-stakes applications. In practice, a product owner (accountability) is designated and a risk/ethics committee is established to review use cases against clearly described criteria. This works best when it is linked to MLOps practices as quality gates before deployment (quality, fairness, privacy and security). This set-up reduces the risk that ethics remains only a declaration with no impact on design decisions.
Regulatory frameworks and standards bring order to activities because they translate general principles into requirements that can be checked. The EU AI Act introduces a risk-based approach, including obligations for high-risk systems, while the NIST AI RMF supports mapping risks and controls throughout the system lifecycle. Increasingly, organisations also turn to ISO/IEC 42001 (AI management system) and ISO/IEC 23894 (AI risk management) as a practical organisational framework. This makes it easier to determine what must be ready before deployment, what needs to be monitored, and how to report risk to stakeholders.
Complaint and remediation mechanisms are essential, because even well-supervised systems can cause harm to specific individuals. The user should have a simple complaints channel, a defined response time and a real route to correction, for example a human review, data correction or compensation. Ethically mature organisations keep an incident register, conduct harm analyses (who was affected and how severely) and publish at least aggregated accountability reports. This approach closes the governance loop: it not only reduces risk, but also provides a procedure for action when a problem does arise.
Ethics of recommendations and counteracting polarisation
The ethics of recommendations consists in designing recommendation algorithms so that they do not fuel polarisation and misinformation in pursuit of engagement alone. The main risk appears when the objective function is optimised solely for clicks, watch time or other interaction metrics, because this can reward extreme or sensational content. A practical step is to change the objective function so that, alongside engagement, it also takes into account the quality or credibility of the content. As a result, the system gains an “incentive” to promote less polarising material, even if it does not deliver the maximum interaction boost.
Limiting polarisation also requires controlling what the user actually sees, rather than only how the model performs on average metrics. For this purpose, “exposure” audits are carried out to help assess whether exposure to specific types of content is not excessive and whether the risk of amplifying misinformation is increasing. Additional oversight mechanisms for recommendations directed at minors are also important, because their contact with extreme content can have particularly serious consequences. This approach moves the ethics of recommendations from the level of declarations to the level of measurable content distribution management practices.
Managing the environmental impact and carbon footprint of AI
Managing AI’s environmental impact means measuring and reducing the energy consumption and emissions resulting from training and iterating models. Large training runs can consume significant amounts of energy, and this cost rises with the number of parameters and the number of iterations, so “bigger” on its own is not always ethically justified. In practice, organisations monitor consumption (kWh) and emissions (CO2e) in order to make data-driven decisions rather than rely on intuition. In addition, where the infrastructure allows it, regions with lower emissions intensity are selected.
An ethical approach to the carbon footprint comes down to training large models only when the benefit outweighs the environmental cost. When there is no strong justification for full training, fine-tuning, distillation or smaller models are often chosen, because they can deliver a sufficient result with lower resource consumption. It is worth incorporating such decisions into the design process already at the experiment-planning stage, in order to reduce the number of costly iterations. This makes environmental impact part of responsible AI management, rather than a note added at the end of the project.
FAQ
Frequently asked questions
How can bias in AI data lead to discrimination?
Most often when the data reinforces historical inequalities or does not represent the whole population. The model may then perpetuate prejudice, even if its objective seems neutral.
Is removing a sensitive feature, for example gender, enough to avoid bias?
No, because proxy features such as a name, postcode or gaps in employment can take over its role. That is why you need to analyse metrics per group and check the impact of features on the outcome.
How can you protect user privacy when collecting data for AI?
You should collect only the data necessary for a clearly defined purpose and not reuse it without a new lawful basis and communication with the user. A matrix also helps: purpose, data categories, retention and access.
When is it worth carrying out a DPIA when processing data with AI?
When processing involves profiling, sensitive data or happens at scale. A DPIA helps identify risks and plan how to reduce them.
What methods increase the explainability of AI decisions?
Global and local explanations are used, for example SHAP, LIME and counterfactuals. It is important that the explanation is understandable and shows what actually influenced the result.
Why does AI model security require testing before deployment?
Because models can be vulnerable to attacks such as adversarial examples, prompt injection, data poisoning or extraction via API. Red-teaming and penetration testing help uncover these weaknesses before practical use.




