Lesson 3 — Ethics and Professional Standards
Unit 4 | Lesson 3 of 3
By the end of this lesson, you will be able to:
- Describe the five ethical principles relevant to AI and what each means in practice (K2, K7)
- Explain what transparency requires of a practitioner before deployment (K2)
- Describe the chain of accountability when an AI system causes harm, and locate your own position in it (K2, K7)
- Apply safe working practice when using AI for legal or compliance research (K2)
📅 Legal position correct as of September 2026. Legislation and regulator guidance change; every claim below links to its source, so check the source before relying on the claim.
🎬 Microsoft and Google on Responsible AI
The two videos below present Microsoft's and Google's own responsible AI frameworks — real-world reference points from two major AI platform providers, useful to compare against the independent regulatory and professional standards below.
Video 1 — Microsoft: Responsible AI Principles Microsoft Learn, AI-3017 Episode 3 | 10 minutes 17 seconds
Microsoft's six principles — fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability — sit within a governance approach that distributes responsibility across the organisation.
Video 2 — Google: Introduction to Responsible AI Google Cloud | 7 minutes 55 seconds
Google's three principles — be socially beneficial, avoid creating or reinforcing unfair bias, and be built and tested for safety — are a shorter list, but cover much the same ground.
The five ethical principles
Across the UK government's AI principles, professional frameworks and the major platform providers (Microsoft, Google) above, the same commitments recur. They are practical, not abstract:
- Fairness — the system should not unjustly advantage or disadvantage individuals or groups. This goes beyond legal compliance with the Equality Act 2010: examine who benefits and who bears the cost, even where no law is broken.
- Transparency — be open about what the system does, what data it uses, and how it reaches an output. If you cannot explain a decision in plain language to the person it affects, the system is not ready.
- Accountability — someone is responsible for outcomes; "the AI did it" is never an answer.
- Reliability — the system performs as intended, consistently, across the inputs it will actually meet, with known limitations disclosed.
- Privacy — respect people's rights over their data (the UK GDPR essentials from Lesson 1).
Transparency in practice
The core obligation: a person affected by an AI-assisted decision should be able to understand, in terms meaningful to them, what the system did and why. "The algorithm assessed your application" is not an explanation. A meaningful one names what was assessed, what was found, what it means for the person, and how they can challenge it. The same four-part test applies to you as the designer before deployment — if you cannot draft a transparent explanation for the people your system affects, that is a signal it is not ready. Where the automated decision-making rules apply, this is a legal requirement and not just good practice: Article 22C gives the person a right to information about the decision and a route to contest it, neither of which works unless someone can explain what the system did. The ICO's joint guidance with the Alan Turing Institute, Explaining decisions made with AI, is the practical starting point.
Accountability: who is responsible when AI causes harm?
Accountability runs as a chain, and it does not disappear because a decision was automated. Multiple parties can be accountable for the same harm at once:
- Model providers / developers — accountable for the capabilities and limitations of the tool, and for disclosing known failure modes.
- Deploying organisations — accountable for using the tool within its intended scope, with data-protection duties met and oversight in place.
- Individual practitioners (you) — accountable for the quality of your design and for flagging risks you identify. A practitioner who builds a system they knew might discriminate, and did not raise it, is not absolved because a manager approved it.

Your professional question is always: what did I know, what did I flag, and what did I do about it?
Using AI for legal and compliance research
GenAI tools can produce legal information that sounds authoritative and is wrong — in 2023, two lawyers and their firm were sanctioned $5,000 jointly for citing AI-fabricated cases and then standing behind them when challenged (Mata v. Avianca). The subtler risk for practitioners is partial accuracy: a model may miss the current ICO interpretive position, or conflate EU and UK GDPR. Automated decision-making is the clearest live example — a tool trained before 2026 will tell you Article 22 bans solely automated significant decisions outright, which was true in the UK until 5 February 2026 and remains true in the EU, but is no longer the UK position. The rule is simple: AI-generated legal information is a starting point, never an endpoint. Any legal or regulatory claim that informs a design decision or recommendation must be verified against an authoritative primary source — the legislation, ICO guidance, or a published regulator position — before you rely on it.
📚 Extended reading — depth in Module 8. Transparency-in-practice explanation frameworks and the full accountability treatment are revisited where they are applied, in Module 8 (Monitoring Risk & Bias).
📝 Activity — Ethics & accountability self-check
Complete Section 3 and Activity 2 of your Module 1 Workbook (Unit 4 section). The questions guide you through:
- Applying the five ethical principles to your project — which is easiest to satisfy, and which is hardest
- Drafting a plain-language explanation you could give to a person affected by one of your system's decisions
- Naming who in your organisation is accountable for a harmful or unfair output — the role, not "the organisation"
- A Flag for any part of the system's operation you currently cannot explain clearly — that gap needs resolving before deployment
Activity 2 asks you to draft a brief Legal Considerations note that you will incorporate into your Unit 5 Business Case.
These notes also feed your Module 2 Responsible AI Adoption Plan, where risk assessment and ethical sign-off are developed in full.
✅ Unit 4 complete. You now have the legal, data-protection and ethical frameworks to judge whether your project is viable and responsible. In Unit 5 you fold this into your Business Case, and in Module 2 you apply these frameworks in depth — running the risk assessment and producing your Responsible AI Adoption Plan.