Your journey
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
0 of 34 units

You are in Degree 5 · Governance and resilienceunit 1 of 6Ahead of you: An approved use policy and a completed maturity assessment.

Degree 5 · Unit 5.1

Responsibility first

Principles usually get written in a form that nobody could possibly disagree with: "we are committed to fairness and transparency". That form has no effect whatsoever, because it does not change a single decision on a Tuesday afternoon. A principle that is actually useful gets phrased as a question you ask before you act, and it has an answer that either permits or forbids.

The two pillars of responsible AI

Technical power without awareness is a danger. The engine is finished; what remains is the steering and the brakes.

FIG. B23 — Ethical and secure
A human in the loopthe final call in money, health and lawSecurityA firewallfor promptsEthicsfairness and transparency
Ethical
Fairness: audit the training data before training — historical bias becomes an automated rule.
Transparency: no black box in a decisive call; explain the why.
Secure
Prompt injection: "ignore your previous instructions…" — test your model against it in earnest.
The assumption: every external input is an attempt until proven otherwise.
DAY TWO
Launch is a beginning, not an end: models drift and need retraining, and legal responsibility is still unsettled.

fawzooz.ai

The two pillars do not come apart: a fair model that is easy to breach becomes an instrument of harm, and a hardened model that is biased becomes injustice, well defended. And launch is a beginning, not an end: models drift and need retraining.

FIG. 24 — Four principles, four questions
Fairness
If this decision were applied to a thousand people, which group would be wronged most? And how would I know?
Transparency
Does the person affected know a system took part in their decision? And can they appeal to a human being?
Privacy
Is the least data that suffices for the task what is processed? Who can see it? And when is it deleted?
Accountability
Who is answerable by name if the system errs? And if that question has no answer now, the system is not ready.
fawzooz.ai
FIG. 25 — The decision tree: do I use it here?
1
Does the decision touch a person's rights — employment, treatment, credit, or punishment?
Yes → the system issues no decision; it prepares material only, and the decision is human, reasoned and documented.
2
Does it involve entering personal or confidential data?
Yes → no public system; an approved environment, identifying details removed, and a lawful basis for the processing.
3
Does the error show before the harm?
No → human approval before execution, a complete log, and later review by sample.
4
Can the decision-maker explain its basis to whoever objects?
No → the use is suspended until it can be explained. What cannot be explained cannot be defended.
fawzooz.ai

"A human in the loop" — on its conditions

This phrase is written into very nearly every policy, and implemented in almost none of them. Putting a human being in place to press "approve" on a hundred recommendations an hour is not oversight; it is an automatic stamp held in a human hand. Real review has four conditions. The person needs enough time to examine what is in front of them. They need enough information to decide — not the recommendation on its own, but what it was built on. They need genuine authority to refuse, at no cost to themselves. And they need a named responsibility that they know they are carrying.

And if any one of those four conditions fails, write the truth into your policy: this decision is automated — and then treat it with the controls that belong to an automated decision, rather than with a false sense of reassurance.

Do this

  1. 1 — In your field. Run an existing use in your organisation through the four-question decision tree. Where did it stop?

  2. 2 — On paper. Take an existing human review of yours and test it against the four conditions. Is it oversight or a stamp?

  3. 3 — In writing. Write the name of one person responsible for every intelligent system in your area. The blanks you cannot fill are your real risks.

Where to after this unit? You have the principles. The next unit gives you the structure that carries them out: ISO 42001 in practice.