AI governance and human rights
International Law
Programme Resetting the relationship
January 2023
Kate Jones
Chatham House
Affairs, is a world-leading policy institute based in London.
Our mission is to help governments and societies build
a sustainably secure, prosperous and just world.
— Artificial intelligence (AI) is redefining what it means to be human. Human rights
have so far been largely overlooked in the governance of AI – particularly in the
UK and the US. This is an error and requires urgent correction.
— While human rights do not hold all the answers, they ought to be the baseline for
AI governance. International human rights law is a crystallization of ethical principles
into norms, their meanings and implications well-developed over the last 70 years.
These norms command high international consensus, are relatively clear, and can
be developed to account for new situations. They offer a well-calibrated method of
balancing the rights of the individual against competing rights and interests using tests
of necessity and proportionality. Human rights provide processes of governance for
business and governments, and an ecosystem for provision of remedy for breaches.
— The omission of human rights has arisen in part because those with human
rights expertise are often not included in AI governance, both in companies
and in governments. Various myths about human rights have also contributed
to their being overlooked: human rights are wrongly perceived as adding little to
ethics; as preventing innovation; as being overly complex, vague, old-fashioned
or radical; or as only concerning governments.
— Companies, governments and civil society are retreading the territory of human
rights with a new proliferation of AI ethics principles and compliance assessment
methods. As a result, businesses developing or purchasing AI do not know what
standards they should meet, and may find it difficult to justify the costs of ethical
processes when competitors have no obligation to do the same. Meanwhile,
individuals do not know what standards they can expect from AI affecting them
and often have no means of complaint. Consequently, many people do not trust
AI: they suspect that it may be biased or unfair, that it could be spying on them
or manipulating their choices.
— The human rights to privacy and data protection, equality and non-discrimination
are key to the governance of AI, as are human rights’ protection of autonomy
and of economic, social and cultural rights in ensuring that AI will benefit
everyone. Human rights law imposes not only duties on governments to uphold,
but also responsibilities on companies and organizations to comply, as well as
requirements for legal remedies and reparation of harms.
Human rights are central to what it means to be human. They were drafted
and agreed internationally, with worldwide popular support, to define freedoms
and entitlements that would allow every human being to live a life of liberty and
dignity. Those fundamental human rights have been interpreted and developed
over decades to delineate the parameters of fairness, equality and liberty for
every individual.
AI offers tremendous benefits for all societies but also presents risks. These risks
potentially include further division between the privileged and the unprivileged;
the erosion of individual freedoms through ubiquitous surveillance; and the
replacement of independent thought and judgement with automated control.
This paper aims to explain why human rights ought to be the foundation for
AI governance, to explore the reasons why they are not – except in the EU and
some international organizations – and to demonstrate how human rights can
be embedded from the beginning in future AI governance initiatives.
AI governance and human rights
Resetting the relationship
The following chapter explains AI and the risks and benefits it presents
for human rights. Chapter 3 aims to dispel myths and fears about human
rights, before discussing why human rights should provide the baseline for AI
governance. Chapters 4, 5 and 6 outline the principal import of human rights
for AI governance principles, processes and remedies respectively. Finally,
Chapter 7 offers recommendations on actions that governments, organizations,
companies and individuals can take to ensure that human rights are embedded
in AI governance in future.
What is AI?
AI has capacity to transform human life –
both for better and for worse.
AI is increasingly present in our lives, and its impact will expand significantly
in the coming years. From predictive text, to social media news feeds, to virtual
homes and mobile phone voice assistants, AI is already a part of everyday life.
AI offers automated translation, assists shoppers buying online and recommends
the fastest route on the drive home. It is also a key component of much-debated,
rapidly developing technologies such as facial recognition and self-driving vehicles.
AI governance and human rights
Resetting the relationship
In short, when properly managed, AI can enable delivery of the UN’s Sustainable
Development Goals (SDGs) by the 2030 deadline,11 boost the implementation
of economic, social and cultural rights worldwide, and support improvements
in many areas of life.
To achieve these aims, AI must be harnessed for the good of all societies. Doing
so involves not only goodwill, but also ensuring that commercial considerations
do not dictate the development of AI entirely. Provision of funding for AI research
and development outside the commercial sector will be invaluable, as will access
to data for AI developers such that they may generate applications of AI that benefit
people in all communities.
AI governance and human rights
Resetting the relationship
Further, some AI tools may have outputs detrimental to humanity through their
potential to shape human experience of the world. For example, AI algorithms
in social media may, by distorting the availability of information, manipulate
audience views in violation of the rights to freedom of thought and opinion,17 or
prioritize content that incites hatred and violence between social groups.18 AI used
to detect aptitudes or to select people for jobs, while intended to broaden human
horizons and ambition, risks doing the opposite. Without safeguards, AI is likely
to entrench and exaggerate social divides and divisions, distort our impressions
of the world and thus have negative consequences on aspects of human life. These
risks are amplified by the difficulty of identifying when AI fails, for example when
it is malfunctioning, manipulative, acting illegally or making unfair decisions.
At present, companies rarely make public their identification of mistakes or errors
in their AI. Consumers cannot therefore see which standards have been met.
Finally, AI may entrench and even exacerbate social divides between rich
and poor, worsening the situation of the most vulnerable. As AI development
and implementation is largely driven by the commercial sector, it risks being
harnessed for the benefit of those who can pay rather than to resolve the world’s
most significant challenges, and risks being deployed in ways that further
dispossess vulnerable communities around the world.19
Governing AI:
why human rights?
Human rights have been wrongly overlooked in AI
governance discussions. They offer clarity and specificity,
international acceptance and legitimacy, and mechanisms
for implementation, oversight and accountability.
In the 1940s, there was fervent belief that human rights would be central to
world peace and to human flourishing, key not only to safeguarding humanity
from catastrophe but to the enjoyment of everyday life.20 Supporters of the ‘vast
movement of public opinion’21 in favour of human rights at that time would be
amazed at their relative absence from today’s debate on AI.
AI governance and human rights
Resetting the relationship
AI governance initiatives are often branded as ‘AI ethics’, ‘responsible AI’ or ‘value
sensitive design’. Some of these initiatives, such as the Asilomar AI Principles,23
are statements drawn primarily from the philosophical discipline of ethics. Many are
multidisciplinary statements of principle, and so may include human rights law as an
aspect of ‘ethics’. For example, the UNESCO Recommendation on the Ethics of Artificial
Intelligence lists ‘[r]espect, protection and promotion of human rights and fundamental
freedoms and human dignity’ as the first of its ‘values’ to be respected by all actors in the
AI system life cycle.24 And the Institute of Electrical and Electronics Engineers (IEEE)’s
Standard Model Process for Addressing Ethical Concerns during System Design lists
as its first ‘ethical principle’ that ‘[h]uman rights are to be protected’.25
First, in many arenas, human rights are simply omitted from discussions on AI
governance. Software developers and others in the AI industry generally do not
involve anyone from the human rights community in discussions on responsible
AI. There is a marked lack of human rights-focused papers or panels at the largest
Second, certain myths about human rights can too often lead to them being
disregarded by those involved in AI governance discussions. The following
are some of the most common.
30 Proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on
artificial intelligence (Artificial Intelligence Act) and amending certain Union legislative acts, COM/2021/206
The malleability of ethics means that it is difficult for civil society to hold
other actors to account. Some technology companies face criticism for so-called
‘ethics-washing’ undertaken for reputational purposes,31 and for exerting undue
influence on some ethics researchers through funding.32 Courts and tribunals do
not allocate remedies for compliance with ethics. Moreover, while ethical principles
are intended to ensure that technology reflects moral values, a focus on ethics
may minimize the appetite for legal regulation.33
Although in some environments, the branding of ‘ethics’ may be more palatable than
that of human rights for political reasons, it is of primary importance that human
rights are considered at all – whatever the branding. To avoid conceptual confusion,
human rights ought to be regarded as parallel to ethics rather than as a mere element
of it. Any principles and processes of ethics should complement, rather than compete
with, the existing human rights legal system. Conflicts between norms are damaging
as they undermine the legal certainty and predictability of regulatory behaviour
on which states, businesses and individuals rely.
While states are the primary bearer of duties under international human rights
law, all companies have responsibilities to respect human rights. The Office of
the UN High Commissioner on Human Rights (OHCHR)’s Guiding Principles
on Business and Human Rights, unanimously endorsed by the UN Human Rights
Council (HRC) and General Assembly (UNGA) in 2011, state that governments
are obliged to take reasonable steps to ensure that companies and other non-state
actors respect human rights, and that companies have a responsibility to respect
human rights in their activities worldwide, including through due diligence and
impact assessment.36 Consideration of human rights impacts ought therefore
to be a standard part of corporate practice.
For example, Article 21 of the International Covenant on Civil and Political Rights
states that the right of peaceful assembly shall be subject to no restrictions, ‘other
than those imposed in conformity with the law and… necessary in a democratic
society in the interests of national security or public safety, public order (ordre
public), the protection of public health or morals or the protection of the rights
and freedoms of others’. In considering whether this right has been violated,
the UN Human Rights Committee will consider first whether there has been an
interference, then if so, whether that interference is lawful and both ‘necessary for
and proportionate to’ one or more of the legitimate grounds for restriction listed in
the article.43 UN human rights bodies, national and regional courts have developed
extensive jurisprudence on the appropriate balancing of rights and interests,
balancing flexibility with predictability. These well-established, well-understood
systems have repeatedly proven themselves capable of adaptation in the face of new
policy tools and novel situations. For example, the European Court of Human Rights
(ECtHR) recently developed new tests by which to assess bulk interception of online
communications for intelligence purposes.44
For example, it has been suggested by some policymakers and academics that
the individual right to privacy should be replaced or augmented by a concept of
collective interest in appropriate handling of data that is sensitive to the interests
of minority groups.46 Group privacy may be a useful political concept in assessing
appropriate limits of state or corporate power resulting from mass collection
and processing of data.47 But it cannot substitute for human rights law. Such
claims underestimate the flexibility of human rights and its processes, including due
diligence and human rights impact assessment, to secure the protection of human
rights for all rather than just for those who claim infringement. The right to privacy
is capable of evolution in light of competing interests, and enables a balance to be
struck between privacy and the public interest in data-sharing and accessibility,
while safeguarding the interests of groups categorized as such by AI by insistence on
both freedom from discrimination and fairness and due process in decision-making.
There may be scope for considering greater empowerment of data subjects48 and/
or group enforcement of rights; but it would be a rash move to abandon many
years of judicial interpretation and scholarship, including concerns about the
displacement of individual rights by group rights, by adding, or replacing them
with, new legal constructs.
Considering human rights will not place a company or government at greater risk
from human rights claims. On the contrary, addressing human rights issues should
help to protect against potential claims.
Human rights are relatively clear. It is possible to list comprehensively the legally
binding international, regional and domestic human rights obligations that apply
in each country in the world. The meaning of those obligations is reasonably
The human rights approach has proved relatively successful over more than
70 years, developing incrementally with the benefit of several generations
of academic input, governmental negotiation, civil society input and court
rulings from many parts of the world. It has evolved in tandem with societal
development, its impact gradually increasing without meeting widespread
calls for abandonment or radical change.
UN processes affecting all states, such as the HRC’s Universal Periodic Review
and the UN treaty bodies’ periodic examinations of states’ compliance, entail that
every UN member state engages with the international human rights architecture.
Regional treaties that have strong local support reinforce these UN instruments
in some parts of the world.60 International human rights law has constitutional
or quasi-constitutional status in many countries, notably in Europe, embedding
it deep into systems of governance.61 Civil society uses the human rights law
framework as a basis for monitoring state and corporate activities worldwide.
This international legitimacy has given human rights a significant role in the
production of internationally negotiated sets of AI governance principles. For
example, the OECD AI Principles call on all actors to respect the rule of law, human
rights and democratic values throughout the AI system life cycle.62 As discussed
previously, UNESCO’s Recommendation on the Ethics of Artificial Intelligence
names human rights and fundamental freedoms as the first of the ‘values’ around
which it is crafted.63 The Council of Europe’s Committee on Artificial Intelligence
(CAI) is working on a potential legal framework for the development, design and
application of AI, based on the Council’s standards on human rights, democracy
and the rule of law.64 Although the universality of human rights is increasingly
contested, there is still, to a large degree, a global consensus on the continued
relevance of long-agreed human rights commitments.
Human rights law may develop through new attention to existing rights. For
example, the rights to freedom of thought and opinion are absolute. However,
their parameters remain relatively unclear because they were largely taken for
granted until challenged by the emergence of a technologically enabled industry
of influence.70 Further, new contexts may lead to new understandings and
formulations of rights. For example, explainability and human involvement –
commonly discussed elements of AI ethics – are not usually considered as elements
of human rights, but might be found in existing requirements that individuals be
provided with reasons for decisions made concerning them, and of the possibility
of contesting those decisions and securing adequate remedies. The Council of
Europe’s work on a potential convention is likely to clarify the application of
human rights to AI,71 as human rights litigation is already beginning to do.72
The development of human rights law and its subsequent interpretation take time,
yet technology moves quickly. Human rights in their current form, while essential,
are not sufficient to act as an entire system for the ethical management of AI.
Human rights should rather be the starting point for normative constraints on AI,
the baseline to which new rights or further ethical guardrails might appropriately
be added, including any ethical principles that businesses or other entities may
choose to adopt.
The second half of this paper explores the contributions of human rights in detail
and concludes by recommending practical actions to place human rights at the
heart of AI governance.
Some assert that, without unanimity as to what it entails, ethics offers a lexicon
that can be used to give a veneer of respectability to any corporate activity. In the
words of Philip Alston, ‘as long as you are focused on ethics, it’s mine against yours.
I will define fairness, what is transparency, what is accountability. There are no
universal standards.’78
While all rights are relevant, this section provides an overview of key rights that
should form the basis of any safeguards for AI development.
83 Ibid., para. 24.
4.2.1 Privacy
The challenges presented by AI
AI is having a huge impact on privacy and data protection. Far more information
about individuals is collated now than ever before, increasing the potential
for exploitation. A new equilibrium is needed between the value of personal
data for AI on the one hand and personal privacy on the other. There are two
parallel challenges to overcome: (i) AI is causing, and contributing to, significant
breaches of privacy and data protection; and (ii) use of extensive personal data
in AI decision-making and influencing is contributing to an accretion of state
and corporate power.
— AI’s requirement for data sets may create an incentive for companies and
public institutions to share personal data in breach of privacy requirements.
For example, in 2017, a UK health trust was found to have shared the data of
1.6 million patients with Google’s DeepMind, without adequate consent from
the patients concerned.84
— ‘Smart’ devices, such as fridges and vehicles, may not only collate data on users
to improve performance, but also to sell to third parties. If not properly secured,
such devices may also expose users to surveillance by hackers. In 2017, for
example, the German authorities withdrew the ‘My Friend Cayla’ doll from sale
over fears that children’s conversations could be listened to via Bluetooth.90
AI impacts privacy in several ways. First, its thirst for data creates compelling
reasons for increased collection and sharing of data, including personal data,
with the aim of improving the technology’s operation. Second, AI may be used
to collate data, including that of a sensitive, personal nature, for purposes of
surveillance. Third, AI may be used to develop profiles of individuals that are then
the basis of decisions on matters fundamental to their lives – from healthcare to
social benefits, to employment to insurance provision. As part of this profiling,
AI may infer further, potentially sensitive information about individuals without
their knowledge or consent, such as conclusions on their sexual orientation,
relationship status or health conditions. Finally, AI may make use of personal data
to micro-target advertising and political messaging, to manipulate and exploit
individual vulnerabilities, or even to facilitate crimes such as identity theft.
Human rights law is already the widely accepted basis for most legislation
protecting privacy. The EU’s General Data Protection Regulation (GDPR) is founded
on the right to protection of personal data in Article 8(1) of the EU Charter of
Fundamental Rights – this is an aspect of the right to privacy in earlier human rights
treaties. Privacy and data protection is one of the European Commission’s Seven
Principles for Trustworthy AI, while most statements of AI principles include
a commitment to privacy.92
Privacy should not be viewed as static: it is flexible enough to adapt and develop,
through new legislation or through judicial interpretation, in light of rapidly
changing technological and social conditions. Individual privacy remains
vital to ensuring that individuals do not live in a surveillance state, and that
individuals retain control over their own data and by whom and how it is seen
and used. This is critical at a time when the value of privacy is being steadily
and unconsciously diluted.
— In 2015, researchers found that female job seekers were much less likely than
males to be shown adverts for highly paid jobs on Google.93
to devise systems that promote equality as much, or more, than human decision-
making.101 Nonetheless, several features of AI systems may cause them to make
biased decisions. First, AI systems rely on training data to train the decision-making
algorithm. Any imbalance or bias in that training data is likely then to be replicated
and become exaggerated in the AI system. If the training data is taken from the real
world, rather than artificially generated, AI is likely to replicate and exaggerate any
bias already present in society. Second, AI systems rely on the instructions given
to them, as well as their own self-learning. Any discrimination or bias deployed
by the designer risks being replicated and exaggerated in the AI system. Third,
AI systems operate within a context: an AI system will lead to bias if it is deployed
within the context of social conditions that undermine enjoyment of rights by
certain groups.102 Without human involvement, AI is currently unable to replicate
contextual notions of fairness.
This ban on discrimination has formed the basis for well-developed understandings
of, and jurisprudence on, non-discrimination in both the public and private sectors.
Human rights law obliges governments both to ensure there is no discrimination
in public sector decision-making and to protect individuals against discrimination
in the private sector. Human rights law does not forbid differential treatment that
stems from factors other than protected characteristics, but such treatment must
meet standards of fairness and due process in decision-making (see below).
International human rights law does not simply require governments to ban
discrimination in AI. As the UN special rapporteur on contemporary forms
of racism has observed, human rights law also requires governments to deploy
a structural understanding of discrimination risks from AI. To combat the potential
for bias, the tech sector would benefit from more diversity among AI developers,
more guidance on bias detection and mitigation and the collection and use of data
to monitor for bias, and more leadership by example from the public sector.105
AI developers and implementers must consider holistically the impact of all
algorithms on individuals and groups, rather than merely the impact of each
algorithm on each right separately.106 Algorithms should be reviewed regularly
to ensure that their results are not discriminatory, even though obtaining data
for comparison purposes may be challenging.107 Vigilance is needed to ensure
that other factors are not used as proxies for protected characteristics – for
example, that postcode is not used as a proxy for ethnic origin.
The challenges presented by AI
AI poses two principal risks to autonomy. First, empathic AI109 is developing
the capacity to recognize and measure human emotion as expressed through
behaviour, expressions, body language, voice and so on.110 Second, it is increasingly
able to react to and simulate human emotion, with the aim of generating empathy
from its human users. Empathic AI is beginning to appear in a multitude of devices
and settings, from games and mobile phones, to cars, homes and toys, and across
industries including education, insurance and retail. Research is ongoing as to how
AI can monitor the mental111 and physical health of employees.112
Some empathic AI has clear benefits. From 2022, EU law requires that new vehicles
incorporate telemetrics for the detection of drowsiness and distraction in drivers.113
Besides the obvious safety benefits for drivers and operators of machinery, empathic
AI offers assistive potential (particularly for disabled people) and prospects for
improving mental health. Other possible enhancements to daily lives range from
recommendations for cures to ailments to curated music-streaming.114
However, empathic AI also carries major risks. The science of emotion detection
and recognition is still in development, meaning that, at present, any chosen
labelling or scoring of emotion is neither definitive nor necessarily accurate. Aside
from these concerns, empathic AI also raises significant risks of both surveillance
and manipulation. The use of emotion recognition technology for surveillance
is likely to breach the right to privacy and other rights – for example, when used
to monitor employee or student engagement or to identify criminal suspects.115
More broadly, monitoring of emotion, as of all behaviour, is likely to influence how
people behave – potentially having a chilling effect on the freedoms of expression,
association and assembly, and even of thought.116 This is particularly the case
where access to rights and benefits is made contingent on an individual meeting
standards of behaviour, as for instance in China’s ‘social credit’ system.117
and the decisions they make, without them being aware.118 The distinction between
acceptable influence and unacceptable manipulation has long been blurred. At one
end of the spectrum, nudge tactics such as tailored advertising and promotional
subscriptions are commonly accepted as marketing tools. At the other,
misrepresentation and the use of fake reviews are considered unacceptable and
attract legal consequences. Between those extremes, the boundaries are unclear.
In social media, too, AI offers potential for emotional manipulation, not least
when it comes to politics. In particular, the harnessing of empathic AI exacerbates
the threat posed by campaigns of political disinformation and manipulation.
AI use to harness emotion for political ends has already been widely reported.
This includes the deployment of fake or distorted material, often micro-targeted,
to simulate empathy and inflame emotions.119 Regulation and other policies are
now being targeted at extreme forms of online influence,120 but the parameters
of acceptable behaviour by political actors remain unclear.
Empathic AI could have major impacts on all aspects of life. Imagine, for example,
technology that alters children’s emotional development, or that tailors career
advice to young people in an emotionally empathic manner that appears to expand
but actually has the effect of limiting choice. Vulnerable groups, including minors
and adults with disabilities, are particularly at risk. Researchers of very large
language models have argued for greater consideration of the risks of human
mimicry and abuse of empathy they create.121
The draft EU Artificial Intelligence Act would ban the clearest potential
for manipulation inherent in AI by prohibiting AI that deploys subliminal
techniques to distort people’s behaviour in a manner that may cause them
‘physical or psychological harm’.122 The Act would also limit the uses of individual
‘trustworthiness’ profiling. As most empathic AI involves the use of biometric
Meanwhile, some are reaching their own conclusions on empathic AI. For
example, a coalition of prominent civil society organizations has argued that the
EU’s Artificial Intelligence Act should prohibit all emotion recognition AI, subject
to limited exceptions for health, research and assistive technologies.127 In June
2022, Microsoft announced that it would phase out emotion recognition from
its Azure Face API facial recognition services. In that announcement, Microsoft
noted the lack of scientific consensus on the definition of ‘emotions’, challenges
of generalizations across diverse populations, and privacy concerns as well as
awareness of potential misuse of the technology for stereotyping, discrimination
or unfair denial of services.128
Ideally, such provision would begin with research into AI technologies that
would help to implement the SDGs, and funding for the development and rollout
of those technologies. The challenges are to incentivize developments that benefit
all communities, as well as those that are most profitable; and to ensure that no
AI systems operate to the detriment of vulnerable communities.
but decisions that treat some people unfairly in comparison to others may still result.
For example, if a travel insurance provider were to double the premiums offered
to people who had opted out of receiving unsolicited marketing material, it would
not be discriminating on the basis of a protected characteristic. Its decision-making
process would however be biased against those who have opted out.
For example, the use of AI for content curation and moderation in social media
may affect the rights to freedom of expression and access to information. The use
of analytics to contribute to decisions on child safeguarding, meanwhile, may affect
the right to family life.132 The use of facial recognition technology risks serious
impact on the rights to freedom of assembly and association, and even on the right
to vote freely. In extreme cases – for example, in weapons for military use – AI risks
undermining the right to life and the right to integrity of the person if not closely
circumscribed. In each of these areas, existing human rights can form the basis
for safeguards delimiting the appropriate scope of AI activity.
Governments are increasingly considering cross-sectoral regulation of AI on
the basis that statutory obligations would help create a level playing field for safe
and ethical AI and bolster consumer trust, while mitigating the risk that pre-AI
regulation applies to AI in haphazard fashion.133 The EU is furthest along in this
process, with its draft Artificial Intelligence Act that would ban the highest-risk
133 In the UK, regulators have established the Digital Regulation Cooperation Forum to facilitate a joined-up approach
to technology regulation. In the US, the Federal Trade Commission has explained how it stands ready to enforce
existing legislation – including the Federal Trade Commission Act, the Fair Credit Reporting Act, and the Equal
Credit Opportunity Act – against bias or other unfair outcomes in automated decision-making. See Jillson, E. (2021),
‘Aiming for truth, fairness, and equity in your company’s use of AI’, Federal Trade Commission Business Blog, 19 April
2021, https://www.ftc.gov/business-guidance/blog/2021/04/aiming-truth-fairness-equity-your-companys-use-ai.
AI governance and human rights
Resetting the relationship
forms of AI and subject other ‘high risk’ AI to conformity assessments. In the US,
Congress is considering a draft Algorithmic Accountability Act.134 The British
government, having considered the case for cross-cutting AI regulation, has
recently announced plans for a non-statutory, context-specific approach that
aims to be pro-innovation and to focus primarily on high-risk concerns.135
While the British government, among others, has expressed concern that general
regulation of AI may stifle innovation, many researchers and specialists make
the opposite argument.136 Sector-specific regulation may not tackle AI risks that
straddle sectors, such as the impact of AI in workplaces. Well-crafted regulation
should only constrain undesirable activity, and should provide scope for
experimentation without liability within its parameters, including for small
companies. Moreover, it is argued that responsible businesspeople would rather
operate in a marketplace regulated by high standards of conduct, with clear rules,
a level playing field and consequent consumer trust, than in an unregulated
environment in which they have to decide for themselves the limits of ethical
behaviour. Most decision-makers in industry want to do things the right way
and need the tools by which to do so.
In addition to regulating AI itself, there are also calls for regulation to ensure that
related products are appropriately harnessed for the public good. For example, the
UK-based Ada Lovelace Institute has called for new legislation to govern biometric
technologies.137 Similarly, there is discussion of regulation of ‘digital twins’ –
i.e. computer-generated digital facsimiles of physical objects or systems – to ensure
that the vast amounts of valuable data they generate is used for public good rather
than for commercial exploitation or even public control.138
Some sector-specific laws are already being updated in light of AI’s expansion.
For example, the European Commission’s proposal to replace the current
Consumer Credit Directive aims to prohibit discrimination and ensure accuracy,
transparency and use of appropriate data in creditworthiness assessments, with
a right to human review of automated decisions.139 An analysis of legislation
in 25 countries found that the pieces of primary legislation containing the phrase
‘artificial intelligence’ grew from one in 2016 to 18 in 2021, many of these specific
to a sector or issue.140 Governments are also considering amendments to existing
cross-sectoral regulation such as GDPR, which does not fully anticipate the
challenges or the potential of AI.
A number of bodies are currently developing template risk assessments for use
by creators or deployers of AI systems. For example, the US National Institute
of Standards and Technology (NIST) has released a draft AI Risk Management
Framework.142 The Singapore government is piloting a governance framework
and toolkit known as AIVerify.143 The EU’s Artificial Intelligence Act will
encourage conformity assessment with technical standards for high-risk AI.144
The British government is keen to see a new market in AI assurance services
established in the UK, by which assurers would certify that AI systems meet their
standards and so are trustworthy.145 The UK’s Alan Turing Institute has proposed
an assurance framework called HUDERIA.146 Technical standards bodies are
developing frameworks, such as the IEEE’s Standard Model Process.147 There are
academic versions, such as capAI,148 a conformity assessment process designed
by a consortium of Oxford-based ethicists, and the European Law Institute’s
Model Rules on Impact Assessment.149 There are also fledgling external review
processes such as Z-Inspection.150
140 Stanford University (2022), Artificial Intelligence Index Report 2022, https://aiindex.stanford.edu/
Typically, AIA processes invite AI developers, providers and users to elicit the
ethical values engaged by their systems, refine those values and then assess their
proposed or actual AI products and systems (both data and models) against those
values, identifying and mitigating risks. Some models take a restrictive view of
ethics, focusing primarily on data governance, fairness and procedural aspects
rather than all rights.154 A further tool proposed for data governance is data sheets
or ‘nutrition labels’ that summarize the characteristics and intended uses of data
sets, to reduce the risk of inappropriate transfer and use of datasets.155
While the identification and addressing of ethical risks is a positive step, these
processes come with challenges. Risk assessment of AI can mean identifying and
mitigating a broad range of impacts on individuals and communities – a task that
is potentially difficult, time-consuming and resource-intensive.159 The identification
and mitigation of ethical risks is not straightforward, particularly for teams whose
prior expertise may be technical rather than sociological. Extensive engagement
with stakeholders may be necessary to obtain a balanced picture of risks.
Resourcing challenges are magnified for smaller companies.
Identification of risks may not even be fully possible before an AI system enters
into use, as some risks may only become apparent in the context of its deployment.
Hence the importance of ongoing review, as well as review at the design stage.
Yet, once a decision has been made to proceed with a technology, many companies
have no vocabulary or structure for ongoing discussion of risks. In cases where
an AI system is developed by one organization and implemented by another,
there may be no system for transferring the initial risk assessment to the recipient
organization and for the latter to implement ongoing risk management.
Once risks have been identified, the models offer limited guidance on how to
balance competing priorities, including on how to weigh ethical considerations
against commercial advantage. Subtle calculations cannot easily be rendered into
the simple ‘stop’ or ‘go’ recommendation typically required by corporate boards.
Similarly, the audit process presents challenges: auditors may require access
to extensive information, including on the operation of algorithms and their
impact in context. There is a lack of benchmarks by which to identify or measure
factors being audited (such as bias), while audits may not take account of
contextual challenges.160
British regulators have identified various problems in the current AIA and
audit landscape, including a lack of agreed rules and standards; inconsistency
of audit focus; lack of access to systems being audited; and insufficient action
following audits.161 There is often inadequate inclusion of stakeholder groups;
a lack of external verification; and little connection between these emerging
processes and any regulatory regimes or legislation.162 Recent UK research
concluded that public sector policymakers should integrate practices that enable
regular policy monitoring and evaluation, including through institutional
incentives and binding legal frameworks; clear algorithmic accountability policies
and clear scope of algorithmic application; proper public participation and
institutional coordination across sectors and levels of governance.163
Governments and companies are beginning to prohibit forms of AI that raise
the most serious ethical concerns. However, there is no consistency in such
prohibitions and the rationale behind them is often not openly acknowledged.
For example, some US states have banned certain uses of facial recognition
technology, which remain in widespread use in other states. The EU’s Artificial
Intelligence Act would prohibit certain manipulative AI practices and most use of
biometric identification systems in public spaces for law enforcement purposes.166
Twitter decided to ban political advertising in 2019.167
5.1.4 Transparency
A further approach is public transparency measures through registries,
release of source code or algorithmic logic (required in France under the Digital
Republic Law).168 In November 2021, the UK government launched the pilot of an
algorithmic transparency standard, whereby public sector organizations provide
information on their use of algorithmic tools in a standardized format for publication
online. Several government algorithms have since been made public as a result.169
166 Proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on
artificial intelligence (Artificial Intelligence Act) and amending certain Union legislative acts, COM/2021/206
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52021PC0206, Article 5.
167 Twitter (2019), ‘Political Content’, https://business.twitter.com/en/help/ads-policies/ads-content-policies/
168 Loi No. 2016-1321 du 7 octobre 2016 pour une République Numerique.
169 Central Digital and Data Office (2021), ‘Algorithmic Transparency Standard’, https://www.gov.uk/
170 Gemeente Amsterdam (2022), ‘Contractual terms for algorithms’, https://www.amsterdam.nl/innovatie/
Governments are expected to find the appropriate mix of laws, policies and
incentives to protect against human rights harms. A ‘smart mix’ of national and
international, mandatory and voluntary measures would help to foster business
respect for human rights.172 This includes requiring companies to have suitable
corporate structures to identify and address human rights risk on an ongoing basis,
and to engage appropriately with external stakeholders as part of their human
rights assessments. Where businesses are state-owned, or work closely with the
public sector, the government should take additional steps to protect against
human rights abuses through management or contractual control.173
Governments’ human rights obligations mean that they cannot simply wait and
see how AI develops before engaging in governance activities. They are obliged to
take action, including via regulation and/or the imposition of impact assessments
and audits, to ensure that AI does not infringe human rights. Governments should
ensure that they understand the implications of human rights for AI governance,
deploying a dedicated capacity-building effort or technology and human rights
office where a gap exists.174
employing rigorous standards and due process, and that such processes pay due
regard to potential human rights impacts of AI: for example by making assessment
of human rights risks an explicit feature of such processes.176 To incentivize corporate
good practice, demonstrate respect for human rights and facilitate remedy, states
should also consider requiring companies to report publicly on any due diligence
undertaken and on human rights impacts identified and addressed.
Governments have legal obligations not to breach human rights in their provision
of AI-assisted systems. Anyone involved in government procurement of AI should
have enough knowledge and information to understand the capacity and potential
implications of the technology they are buying, and to satisfy themselves that
it meets required standards on equality, privacy and other rights (such as the
Public Sector Equality Duty in the UK). Governments should negotiate the terms
of public–private contracts and deploy procurement conditions to ensure that
AI from private providers is implemented consistently with human rights. They
should also take steps to satisfy themselves that this requirement is met. Public
procurement is a means of encouraging improvements to human rights standards
in the AI industry as a whole.179 It is important also to ensure that AI systems already
adopted comply with human rights standards: the experience of the Netherlands
demonstrates that systems adopted to date can be problematic.180
Some companies’ AIAs are labelled as human rights assessment, like Verizon’s
ongoing human rights due diligence.189 Other AI ethics assessments, such as that
adopted by the IEEE and the proposed AIA for the National Medical Imaging
Platform, look similar to human rights due diligence, but are not labelled as such.
Google reviews proposals for new AI deployment by reference to its AI Principles,
a process that can include consultation with human rights experts.190
commonly omitted from corporate processes:
— Scope. Some corporate processes only cover specific issues, such as bias and
privacy, rather than the full range of human rights, or make only brief mention
of other rights.191
— Effect. It is often not clear what effect impact assessments have on the
company’s activities.192 Human rights due diligence requires that human rights
risks be mitigated, whereas some business processes seem to entail balancing
risks against perceived benefits.193
cease its use of SyRI, an automated programme that reviewed the personal data
of social security claimants to predict how likely people were to commit benefit
or tax fraud. The Dutch government refused to reveal how SyRI used personal
data, such that it was extremely difficult for individuals to challenge the
government’s decisions to investigate them for fraud or the risk scores stored
on file about them. The Court found that the legislation regulating SyRI did not
comply with the right to respect for private life in Article 8 ECHR, as it failed
to balance adequately the benefits SyRI brought to society with the necessary
violation of private life caused to those whose personal data it assessed. The
Court also found that the system was discriminatory, as SyRI was only used
in so-called ‘problem neighbourhoods’, a proxy for discrimination on the basis
of socio-economic background and immigration status.204
Consequently, its use breached the Data Protection Act. The court declined
to find that the police’s use of AFR struck the wrong balance between the rights
of the individual and the interests of the community. But it did find that South
Wales Police had failed to discharge the statutory Public Sector Equality Duty,206
because in buying the AFR software from a private company and deploying
it, they had failed to take all reasonable steps to satisfy themselves that the
software did not have a racial or gender bias (notwithstanding that there was
no evidence to support the contention that the software was biased). The case
therefore temporarily halted South Wales Police’s use of facial recognition
technology, but allowed the possibility of its reintroduction in future with
proper legal footing and due regard to the Public Sector Equality Duty. Indeed,
South Wales Police has since reintroduced facial recognition technology for
use in certain circumstances.207
— The Italian courts, having held in 2019 that administrative decisions based
on algorithms are illegitimate, reversed that view in 2021. The courts welcomed
the speed and efficiency of algorithmic decision-making but clarified that it is
subject to general principles of administrative review in Italian law, including
transparency, effectiveness, proportionality, rationality and non-discrimination.
Complainants about public decision-making are entitled to call for disclosure of
algorithms and related source code in order to challenge decisions effectively.208
— In July 2022, the UK NGO Big Brother Watch issued a legal complaint to the
British information commissioner in respect of alleged use of facial recognition
technology by Facewatch and the supermarket chain Southern Co-op to scan,
maintain and assess profiles of all supermarket visitors in breach of data
protection and privacy rights.209
who bears responsibility for its operation. In particular, clarity is required on where
the division of responsibilities lies between the developer of an AI system and
the purchaser and deployer of the system, including if the purchaser adapts the
AI or uses it in a way for which it was not intended. Consequently, purchasers of AI
systems will need adequate understanding or assurance as to how those systems
work, as was demonstrated for the public sector in the Bridges case, discussed
above. In that case, the court also held that commercial confidentiality around
any AI technology does not defeat or reduce the requirement for compliance
with the Public Sector Equality Duty.211
211 R (Bridges) v Chief Constable of South Wales Police [2020] EWCA Civ 1058, para. 199.
principle should remain provision of an effective right to remedy, including
for breach of human rights responsibilities.
As AI begins to reshape the human experience, human rights must be central to its
governance. There is nothing to fear, and much to gain, from taking human rights
as the baseline for AI governance.
For companies:
— Continue to promote AI ethics and responsible business agendas, while
acknowledging the important complementary role of existing human
rights frameworks;
— Champion a holistic commitment to all human rights standards from the top of
the organization. Enable a change of corporate mindset, such that human rights
are seen as a useful tool in the box rather than as a constraint on innovation;
For governments:
— Ensure adequate understanding of human rights among government officials
and place human rights at the heart of AI regulation and policies, either via
the establishment of a dedicated office or other existing mechanisms;
— Put in place human rights-compatible standards and oversight for AIAs and
audits, as well as adequate provision of remedy for alleged breaches;
— Educate the public on the vital role of human rights in protecting individual
freedoms as AI technology develops. Offer guidance to schools and teachers so
that children have an understanding of human rights before they encounter AI;
— Ensure that all uses of AI are explainable and transparent, such that people
affected can find out how an AI or AI-informed decision was, or will be, made;
— Provide adequate resources for national human rights bodies and regulators,
such as the UK Equalities and Human Rights Commission, to champion the
role of human rights in AI governance. Ensure these bodies are included
in discussions on emerging tech issues;
— Establish a new multi-stakeholder forum that brings together the tech and
human rights communities, as well as technical standards bodies, to discuss
challenges around the interaction of human rights and technology, including
AI.215 A regular, institutionalized dialogue would raise levels of understanding
and cooperation on all sides of the debate, and would help prevent business
exploitation of legal grey areas;216
— Ensure, via the UN secretary-general’s envoy on technology, that all parts of the
UN (including technical standards bodies and procurement offices) align with
the OHCHR in placing human rights at the centre of their work on technology;
For investors:
— Include assessment of the implications of AI for human rights in ESG
or equivalent investment metrics.217
