Viewpoint
AI ethics without the sermon
Lists of principles settle nothing. Seven places where the harm actually happens, and the questions that turn them into decisions.

Contents (10)
AI ethics is usually discussed in one of two ways, neither of which helps anyone. The first is a list of principles: transparency, fairness, human-centricity, accountability. The second is the spectre of a machine taking over. Neither tells you what to do differently next Monday.
A usable question is narrower: what harm can this particular use cause, who does it land on, and who would notice. Everything else has been written on a boardroom wall.
The law does not settle this. The AI Act says what is forbidden and what requires documentation. It does not say whether something is worth doing. Most of the damage arises in entirely lawful use.
1. Bias
A model learns what is in the material. If the material contains people's earlier decisions, the model learns their biases too, and repeats them faster, more cheaply and more consistently than a person would.
The most common misconception is that bias goes away when you remove the sensitive field. It does not. Sex, age and background leak through proxies: postcode, hobbies, school, gaps in an employment history, writing style. The model finds these connections whether anyone asked for them or not.
The only approach that works is to measure outcomes rather than intentions. If a system scores people, look at the results by group and compare them. If a difference appears, it is not to be explained away but investigated.
2. The explanation that does not exist
A neural network cannot tell you why it arrived at a result. An explanation produced afterwards is a plausible story, not a description of the computation. This is worth separating out, because such explanations are often sold as a solution to transparency.
What can be promised instead are three things that are checkable: what information was used in the decision, who made the decision, and how it can be appealed. Those are usually enough for what a person actually wants, which is the chance to contest the matter.
3. Responsibility going missing
In practice this is the most serious and the least discussed. When a machine produces a suggestion and a person approves it, responsibility appears to rest with the person. In reality the person approves most suggestions without looking, because that is what happens whenever there is a lot to check and the suggestions are usually right. The phenomenon is called automation bias.
Nominal human oversight is then a facade. Oversight is real only when the overseer has the time, the competence, the authority to say no, and some reason to do so. If the rejection rate is zero, there is no oversight, whatever the signature on the form says.
4. Privacy
Everything typed into a prompt goes somewhere. Data protection law does not step aside because the tool is new. Three questions settle most cases: does personal data leave, how long does it survive in the supplier's logs, and is it used to train the model.
The contract terms answer these, and they are worth reading before the tool is in use across the organisation. A prohibition issued afterwards does not unsend what has already been sent.
5. Where the material came from, and copyright
Models are trained on material whose origin is usually not described precisely. Two different questions follow, and they are easily confused.
The first concerns the training: was using that material permitted. That is a matter between the supplier and the legislator, and it is still being argued over.
The second concerns the output, and it is the one that concerns you: who holds the rights to what the machine produced, and what happens if the output resembles something existing a little too closely. The practical guidance is dull but effective. Material going out for publication is checked, and recognisable styles or works are not requested by name.
6. The environment
One query consumes little. A million queries a day does not consume little, and the load is a real cost item rather than only an environmental question.
The honest line is to put a number on it rather than moralise about it. If a workflow runs a model on every row, ask how many calls that is per month. Usually the same result comes out of a smaller model, or out of running the model only when it is needed. That is cheaper at the same time, so the decision requires no ideology.
7. The shape of work changing
AI does not usually replace an occupation but part of its tasks. The ethical question is not whether work may be automated but who carries the transition: is the change announced in advance, are people trained for a new task, and whose workload actually changes.
Related to this is quiet use. If employees use the tools without saying so, because they fear for their jobs, the organisation loses both visibility and any chance of steering the use. A ban produces shadow use, not safety.
Three questions instead of a list of principles
The trouble with a list of principles is that it cannot be broken. Nobody ever notices themselves being against "human-centricity". These three questions, by contrast, produce answers that can be recorded and checked:
- Who carries the error? If the system is wrong, who does it land on and how badly. The applicant, the patient, the customer, or the organisation itself.
- How is an error appealed? Is there a path that leads to a person with the authority to change the decision.
- How would we notice it had been wrong all along? This is the hardest. If the answer is "the customer would tell us", there is no measurement.
The third question is what separates responsible use from a speech. A quiet, systematic error is far more likely than a dramatic one, and it is found only by measuring.
What this means in practice
Ethics becomes decisions only once it is written down. The lightest form that works is a short policy on what AI may be used for, what may be put into it, who answers for the result, and how an incident is handled. It is the same document the regulation expects, and there is a separate article about the playbook.
In one sentence
AI ethics is not settled by principles but by a named person carrying the error, somebody being able to appeal it, and somebody measuring regularly whether the outcomes are what everyone assumed.
Harri Salomaa · Forty years in software, twenty of them in the United States and Germany: from collecting process data and analysing network data to immersive computing, and most recently AI.