Course resource
AI Ethics Decision Framework
A short procedure for deciding whether to do something, when the law does not settle it.
The four tests
Run all four. If any fails, do not proceed as planned.
1. The transparency test. If everyone affected knew exactly how I used AI here, would they object?
The most useful single question. It catches undisclosed synthetic media, AI-written personal messages, and automated decisions people assumed were human.
2. The accountability test. If this goes wrong, is there a named human who owns the outcome?
If the honest answer is "the AI did it", stop. Every output needs an owner who checked it and can defend it.
3. The reversibility test. If this is wrong, can it be undone, and how fast?
Money moved, a message sent to a list, a person rejected — these are hard or impossible to reverse. The less reversible, the more human review required.
4. The substitution test. Would I be comfortable if a competitor did exactly this to me, or to my customers?
Catches things that are technically permitted and still corrosive.
The decision path
Is it illegal, or does it breach a contract?
-> STOP
Does it involve a person's data, voice, likeness or a decision about them?
-> Consent required. Written, specific, revocable.
Could someone be materially harmed if the output is wrong?
-> Human review before output. Named reviewer. Logged.
Would the audience feel misled if they knew?
-> Disclose, or do not do it.
Am I unsure?
-> Ask someone. Uncertainty is a signal, not a formality to clear.
The recurring cases
Using AI to write something personal. A condolence note, a reference, a message to a friend. Legal, and most people feel deceived when they find out. Use it to structure your own thoughts, not to substitute for having them.
AI in hiring. Screening CVs, ranking candidates, scoring interviews. High risk of systematic bias, often regulated as automated decision-making, and the affected person usually has rights to human review and explanation. Use AI to help a human read more carefully; never to filter without a human seeing the rejections.
AI-detection tools on students or staff. Detectors are unreliable in both directions and systematically flag non-native English writers. Never take an adverse action based on a detector score alone. It starts a conversation; it does not end one.
Synthetic voice or likeness. Written consent, always, covering the specific use. Never for a real person without it, whatever the purpose.
Training on customer data. Almost always a purpose-limitation problem. Data given for one reason is not available for another without a fresh basis.
Publishing AI content unlabelled. Depends entirely on whether the audience would care. Marketing copy, no. A testimonial, a case study, a review, or anything presented as first-hand experience — yes, and doing otherwise is fabrication.
Automating a job. Legal. The ethical weight sits in how you handle the people, not whether you automate. Tell them early, honestly, and with a plan.
Documenting a hard call
When a decision is genuinely contested, write it down. Six months later nobody remembers the reasoning, and the record is what protects both the decision and the person who made it.
DECISION: [WHAT]
Date: [DATE] Decided by: [WHO]
Who is affected: [WHO]
The tension: [WHAT MAKES THIS HARD]
Options considered: [WHAT ELSE WE COULD HAVE DONE]
What we chose and why: [REASONING]
Controls we put in place: [SAFEGUARDS]
What would make us revisit this: [TRIGGER]
Review on: [DATE]
For teams
- One named person can stop anything. An ethics process where nobody can say no is decoration.
- Escalation must be easy and safe. If raising a concern is career-limiting, you will not hear about problems.
- Review the decisions, not just the policy. Policies drift from practice quietly.
- Record the calls you got wrong. That list is the most valuable training material you will ever have.
The line to remember
Legality is the floor, not the standard. The four tests at the top of this page will keep you well above it, and they take about ninety seconds.