"Technology is neither good nor bad; nor is it neutral." — Melvin Kranzberg's first law (governance steers outcomes)
Opening scenario: Your team loves a new writing assistant. Then someone generates biased job descriptions. A teacher worries about cheating. A client asks if you trained on their confidential memo. Leadership wants "ethical AI" but not a 200-page policy nobody reads. This module gives frameworks, workflows, and templates for responsible deployment—without coding.
Learning Objectives
By the end of this module, you will be able to:
- Explain core ethical dimensions of AI: fairness, transparency, accountability, privacy, and safety.
- Map governance roles (owner, reviewer, approver) for assistive AI in your context.
- Apply bias mitigation practices in hiring, communications, and service delivery workflows.
- Draft a short responsible-use policy colleagues can actually follow.
- Facilitate ethics discussions using scenarios, not abstract philosophy.
- Connect governance to Module 09 security and Module 07 strategy.
Concept:
Governance turns values into who decides, what is allowed, and what to do when something goes wrong — short enough to read, concrete enough to follow.
1. Ethics in Plain Language: Harms That Show Up at Work
Fairness: Decisions should not systematically disadvantage protected or vulnerable groups—even if unintentional.
Transparency: People know AI is involved and understand limits.
Accountability: A named human owns outcomes.
Privacy: Data is collected and used proportionally with clear purposes.
Safety: Outputs do not enable harm (violence, self-harm, deception).
Real World Example
A city launches a chatbot for permits. Early answers are wrong on fees. They pause the bot, publish a correction, add human review for fee questions, and log changes. Transparency + accountability restored trust faster than silence.
Real-world examples
- Hiring: Resume screeners trained on past hires can encode historical exclusion.
- Schools: Surveillance tools may chill expression or misidentify students.
- Customer service: Chatbots may gaslight or deny rights if not governed.
| Practice | What It Does | Try It Here |
|---|---|---|
| RACI | Names who approves AI-assisted outputs | Draft for one workflow |
| Impact review | Surfaces harms before launch | Turn pre-launch bullets into a checklist |
| Appeals path | Gives humans recourse | Write three sentences for your FAQ |
Did You Know?
Many bias issues are process problems (no second reader, sloppy prompts) as much as model problems — fix the cheap controls first.
Try This Now
- Ask Claude: "List 8 workplace harms from careless AI use; map each to a mitigation." Edit for your sector.
Table: Ethical dimension → office signal
| Dimension | Signal something's wrong |
|---|---|
| Fairness | Systematic skew in outcomes |
| Transparency | Secret scoring |
| Accountability | "The AI decided" |
| Privacy | Data sprawl |
| Safety | Dangerous instructions |
Discussion prompts
- Which harm worries your community most?
2. Governance Frameworks You Can Actually Use
Layers
- Principles (1 page)
- Policies (what you must/must not do)
- Standards (approved tools, data classes)
- Procedures (how to request access, how to report incidents)
- Training (annual + onboarding)
RACI for an AI-assisted workflow
- Accountable: executive sponsor
- Responsible: team lead running pilot
- Consulted: legal, IT, DEI advisor
- Informed: affected staff
Walkthrough: policy drafting session (60 minutes)
- Brainstorm red lines (20 min)
- Cluster into 5–7 rules (15 min)
- Examples for each rule (15 min)
- Owner + review date (10 min)
Try This Now
- Draft seven bullet rules for your team; no legalese first pass.
Discussion prompts
- Who updates the policy when tools change monthly?
3. Bias Mitigation: Hiring, Comms, and Services
Hiring playbook
- Avoid automated scoring without audit
- Document criteria before posting
- Human review edge cases
- Monitor demographic outcomes where law allows
- Offer appeals
Communications playbook
- Review AI drafts for stereotypes
- Check imagery for representation
- Plain language for access
Services playbook
- Disclose when AI is first responder
- Escalation path to humans
- Accommodations for users who cannot use chat
Scenario: AI rewords a job post to sound "dynamic" and accidentally adds age-coded phrases. Fix: template library + second reader.
Try This Now
- Generate a job post; run a second prompt: "Flag potentially biased or exclusionary phrases; suggest neutral alternatives." Human decides.
Table: Mitigation levers
| Lever | Example |
|---|---|
| Data | Clean labels |
| Process | Human gate |
| Product | Confidence thresholds |
| People | Training |
Discussion prompts
- When is aggregate fairness not enough?
4. Responsible Deployment: Checklists Before Launch
Pre-launch
- Purpose limited and documented
- Data lawful and minimal
- Testing with diverse scenarios
- Incident response path
- Accessibility check
Post-launch
- Monitor outcomes
- Collect feedback
- Iterate quarterly
Real-world examples
- Bank: Human reviews all adverse notices assisted by AI.
- Museum: AI caption tool labels uncertain items "verify".
Try This Now
- Convert the pre-launch bullets into a one-page checklist with checkboxes.
Discussion prompts
- What would you discontinue if metrics showed harm?
5. Policies, Transparency, and Stakeholder Trust
Transparency spectrum
- Internal-only documentation
- Employee FAQ
- Public statement on website
- Per-interaction disclosure ("You may be chatting with AI")
Trust moves
- Publish limitations
- Invite feedback
- Report incidents candidly
- Compensate when harm occurs
Scenario: A city chatbot gives wrong permit info. Fix: rollback, corrective notice, process fix—not silent patch.
Try This Now
- Write three customer-facing sentences explaining AI assist on support emails.
Table: Transparency by audience
| Audience | Needs |
|---|---|
| Staff | Rules + tools |
| Customers | Limits + escalation |
| Regulators | Controls + logs |
Discussion prompts
- How much detail is useful vs. noise?
Activities
- Ethics speed-round: 10 scenarios; thumbs up/down on permitted use.
- Bias hunt: Review three AI outputs for stereotypes; rewrite.
- Governance map: Draw who approves what for your org.
- Policy edit-a-thon: Cut a verbose draft in half without losing red lines.
- Stakeholder letter: Explain governance to clients in 120 words.
Your Challenge
Create a Responsible AI Policy v0.9 (1–2 pages):
- Purpose & scope
- Approved use cases + prohibited uses
- Data rules (paste, PII, client secrets)
- Human review requirements
- Reporting + consequences (proportionate)
- Review cadence
Run it past legal or HR if available; note open questions.
Expanded challenge: step-by-step policy workshop
- Scope: Write who the policy covers (employees, contractors, volunteers) and which tools it applies to (named approved list vs. “any AI”).
- Purpose: One paragraph: why now, what good looks like, what fear you are addressing (surveillance, bias, leaks).
- Approved uses: 5–7 bullets with examples (“OK: draft email from bullet notes I wrote”).
- Prohibited uses: 5–7 bullets with examples (“Not OK: paste student records into consumer chat”).
- Data rules: Reference your data classification; include redaction examples; link to IT for enterprise accounts.
- Human review: Table by risk tier (public comms, hiring-adjacent, client deliverables, safety).
- Reporting: Clear path for near-misses (blameless) vs. violations (investigation); proportionate consequences.
- Cadence: Quarterly tool review + annual training; owner named.
- Open questions: List 3 for legal/DEI/IT. Version the doc (v0.9) and date it.
Industry governance patterns (practical)
| Sector | Extra lens | Example guardrail |
|---|---|---|
| Healthcare | Patient trust, clinical boundaries | No diagnostic language from general assistants without clinical workflow |
| Education | Child privacy, pedagogy | Separate staff assist from student work integrity rules |
| Finance | Fair lending, suitability | No individual advice from ungoverned tools; disclosures on client comms |
| Legal | Professional responsibility | Partner/supervisory review; citation verification |
| Marketing | Truth-in-advertising, inclusion | Stereotype checks; label synthetic imagery |
Comparison table: Transparency vs. practical security
| Stance | Benefit | Cost / risk |
|---|---|---|
| Max transparency (“we use AI on X”) | Trust, predictability | Competitors and critics parse wording |
| Minimal disclosure (internal only) | Simpler comms | External surprise if discovered |
| Contextual disclosure (per channel) | Tailored | Requires training to execute consistently |
| Over-disclosure (every sentence) | Cautious | Noise; users tune out |
Prompt: Pick contextual where customers could reasonably assume a human-only path.
Discussion Corner
- Appeals: If someone believes an AI-assisted decision harmed them, what happens next—who hears them, what timeline, what documentation?
- Workers: How do frontline staff get real voice in governance—not only town halls?
- Vendor vs. values: When a vendor’s defaults conflict with your DEI commitments, who has authority to say no?
- Kids and vulnerable users: What extra rules apply if your audience includes minors or crisis contexts?
Try This Now (added)
- Take your v0.9 draft. Ask: “Find vague phrases like ‘appropriate use’ and suggest specific replacements with examples.” You choose what survives.
- Bias rehearsal: Generate a job ad; run a second prompt: “Flag coded language by category (age, gender, disability).” Rewrite manually; note one phrase you’ll ban org-wide.
- Incident tabletop: With two colleagues, walk through: “Biased outreach email shipped.” Roles: comms, HR, legal. Output: 5-bullet runbook addendum to your policy.
Key Takeaways
Try This!
Red-team one customer email drafted with AI: ask two colleagues to find stereotypes, overpromises, and missing disclosures in five minutes.
- Ethics shows up as concrete harms and processes—not slogans.
- Governance stacks principles → policies → procedures → training.
- Bias is everyone's job in content and decisions—mitigate with gates and audits.
- Deployment checklists prevent fire drills.
- Transparency builds trust when paired with accountability.
- Policies must be short enough to read—or they won't be followed.
Resources
- NIST AI RMF
- Partnership on AI
- Ada Lovelace Institute — reports readable for non-specialists
- Your legal counsel and DEI lead
Extended Scenario: School AI Use
Tension: Teachers want assistants; parents fear privacy and cheating. Path: district policy separating staff assist from student work integrity; training; transparency site; annual review.
Extended Scenario: Law and Professional Responsibility
Pattern: Assist research and drafting; verify citations; disclose to clients per bar rules where applicable. Never substitute tool for judgment.
Comparison Table: U.S. vs. EU Orientation (Very High Level)
| Theme | Typical emphasis |
|---|---|
| EU | Rights-based AI Act themes |
| US | Sectoral + agency actions |
Always consult counsel for your facts.
Discussion Prompts (Advanced)
- Should wronged individuals receive more than an apology?
- How do you balance transparency with security?
- What role do workers have in governance bodies?
Glossary
- Impact assessment: Structured review of harms and mitigations.
- Red team: Simulated attacks or stress tests.
- Appeal: Human review of adverse outcomes.
Reflection Journal
- The ethical risk I used to underrate: ___
- The policy line I will defend: ___
- A stakeholder I should listen to more: ___
Facilitator Notes: Ethics Brown-Bag (45 Minutes)
- Case 1: Hiring assistant (15)
- Case 2: Client confidentiality (15)
- Policy co-create (15)
Quality Attributes for Policies
- Short sentences
- Examples
- Named owners
- Review date visible
When External Review Is Essential
Seek legal review for regulated sectors (health, finance, education, government) before external deployment or binding decisions.
Closing
Governance is how values become habits. Good governance is boring on purpose—checklists, owners, dates—so people can create with confidence.
Key Takeaway
- Ethics = fairness, transparency, accountability, privacy, safety — in workflows, not posters alone.
- Stack principles → policies → procedures → training with owners and review dates.
- Bias mitigation needs templates, audits, and human gates in hiring and comms.
- Transparency should match the audience — contextual beats both secrecy and noise.
- Short policies get used; invite feedback and update when tools change monthly.