AI Academy · Book
Executives & Directors · Module 07 · Chapter 002

Why Responsible AI Matters

AI that people do not trust does not get used well, and AI that is not used well does not pay off. Responsible AI is the practice that earns informed trust: it creates value while protecting people, managing risk and keeping someone accountable. The law sets the floor; responsible AI is what lets valuable systems scale.

≈ 16 min read

After this chapter you can

  • Explain responsible AI as creating value while protecting people, managing risk and keeping someone accountable.
  • Distinguish responsible AI from legal compliance, and both from governance.
  • Describe informed trust and why both blind trust and blanket distrust destroy value.
  • Recognize, from real enforcement cases, what irresponsible use costs and why responsibility is cheapest when designed in.
  • Judge when a valuable AI system is still irresponsible, and in the EU possibly unlawful.

In 2025 the University of Melbourne and KPMG published one of the largest studies of public attitudes to AI to date: more than 48,000 people in 47 countries. Two thirds of them used AI regularly. Fewer than half, 46 percent, said they were willing to trust AI systems. At work, the picture was stranger still. Among employees who use AI at work, 66 percent said they had relied on its output without evaluating it, and 56 percent said they had made mistakes in their work because of AI1. The first two figures describe everyone surveyed; the last two describe only employees who use AI at work.

Sixty-six percent use AI regularly but only 46 percent are willing to trust it, while among employees who use AI at work 66 percent use its output without checking it and 56 percent have made mistakes because of it.66%Use AI regularlyOf 48,000+ people46%Willing to trust AILess than half66%Use AI outputuncheckedEmployees who use AIat work56%Made mistakesdue to AIEmployees who use AIat workSource: University of Melbourne and KPMG, 47 countries · 2025
Figure 7.2.1 Use is high and trust is low, yet much of the trust that exists is unexamined. Both are problems.

Read the numbers together and they describe two failures at once. More than half of people are not willing to trust AI, and many of those who do rely on it trust it more than they should. The researchers drew the conclusion that matters for leaders: in their statistical model, trust was a key driver of whether people accepted AI1. That makes trust a business variable, not a public-relations one. It is the subject of this chapter, and the reason responsible AI belongs on an executive agenda.

The core idea

Responsible AI is the practice of designing and operating AI so that it creates value while protecting people, managing risk and keeping someone clearly accountable. It is not a promise of perfect systems. It is a commitment to systems whose risks are understood, controlled and owned.

Responsible AI earns informed trust, informed trust drives adoption, and adoption creates sustainable value.Responsible AIDesigned and runwith careInformed trustCustomers andemployeesAdoptionPeople rely onit appropriatelyValueSustainable atscaleBreak any link and the value never arrives
Figure 7.2.2 Trust is the path from AI to value, not a constraint beside it.

The chain runs in both directions. Responsible design and operation earn trust from the people a system touches. Trust leads to adoption, meaning people use the system and rely on it to the right degree. Adoption is where the value comes from. Run the chain backward and you get the familiar failure: careless practice damages trust, low trust stalls adoption, and the business case never arrives, however good the model is.

The frameworks executives are most likely to meet say the same thing in their own language. The NIST AI Risk Management Framework describes trustworthy AI as valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed, and it stresses that these qualities involve trade-offs that people must decide on, not just engineer2. The OECD AI Principles, updated in 2024, add that organizations that develop, deploy or operate AI should be held accountable for its proper functioning3. Neither framework treats trustworthiness as a feature of the model alone. It is a property of how the organization builds, uses and answers for it.

As What Is AI Governance? showed, governance is the system of decision rights, controls and oversight that makes AI decisions at scale. Responsible AI is the standard that system is trying to meet. The first defines how the organization decides; the second defines what a good decision looks like.

The law is the floor, not the question

Many leaders first hear “responsible AI” as a legal checklist. The law matters, and in Europe much of it is not optional: the GDPR already governs most AI that touches personal data, and the EU AI Act adds duties by risk. But compliance and responsibility ask different questions.

Compliance asks whether a use is permitted and sets the floor; responsible AI also asks whether it should be done and whether people will accept it.COMPLIANCE ASKSMay we do this?The floorRESPONSIBLE AI ALSO ASKSShould we, and will peopleaccept it?Trust and adoptionvs
Figure 7.2.3 Compliance tells you what is permitted. It cannot tell you whether the people affected will trust what you built.

Compliance asks whether the organization meets its obligations. Responsible AI also asks whether a use is right for the people it affects, whether its outcomes are fair, whether it can be explained and whether someone can step in when it goes wrong. A system can pass every legal review and still lose the trust of the customers or employees it was built for. And law moves more slowly than practice. Many uses of AI fall into areas where the rules are general, untested or still arriving, and an organization that waits for the law to tell it what is acceptable will usually find out from its users first.

The gap also closes over time. Assessing the impact of risky processing before it starts was once voluntary good practice; since 2018 the GDPR has made it a legal duty for high-risk processing (Article 35)4. The AI Act is doing the same for AI, turning practices such as human oversight and logging into obligations for high-risk systems. An organization that treats responsibility as more than compliance is better placed when the floor rises, because it has already built to the higher standard.

This is why responsible AI cannot sit with the legal team alone. Legal owns the obligations. The questions of purpose, data use, fairness, ownership and oversight belong to the business that uses the system, with technology, data, security and risk as partners.

Informed trust, not maximum trust

Trust does not mean believing that AI is always right. Researchers in human factors worked this out long before generative AI. In a widely cited review, John Lee and Katrina See argued that what matters is not how much people trust an automated system but whether their trust is calibrated: matched to what the system can actually do. Overtrust leads to misuse, and distrust leads to disuse5.

Between blind trust and blanket distrust sits informed trust, where people know what the system can do, who owns it and how to challenge it.Blind trustAccept whatever it saysBlanket distrustAvoid it or work around itInformed trustKnow its limits, owner and how to challenge it
Figure 7.2.4 The target is not maximum trust. It is trust that matches what the system can really do.

Both ends are expensive. At the blind end, a confident error travels straight to a customer or into a decision. The KPMG finding that two thirds of employees who use AI at work rely on its output without checking it describes exactly this1. How that over-reliance arises, and how to design oversight against it, was the subject of Operational and Workforce Risk and Human Oversight and AI Incidents.

At the other end, people refuse a system or quietly work around it, and the investment produces nothing. This is not only a matter of attitude. In a well-known series of experiments, people who watched a forecasting algorithm make a mistake lost confidence in it faster than in a human who made the same mistake, and chose the human, even though the algorithm was more accurate6. A follow-up study found a simple remedy: when people could adjust the algorithm’s forecasts, even slightly, they became far more willing to use it7.

That result is the practical heart of informed trust. People trust a system more when they understand what it does, know its limits, know who is accountable for it and can challenge or correct it. None of those depends on a better model. All of them depend on how the organization designs and runs the system around the model.

What irresponsible use costs

The cost of irresponsible use is rarely the cost of fixing one system. A European enforcement case about data on people at work shows how the bill grows.

Deliveroo was fined 2.5 million euros in Italy for not telling riders how its algorithm managed their shifts.CaseWhat happenedWhat it costDeliveroo Italy (2021)Riders not told how the algorithm managedtheir shifts2.5 million euros and an order to reworkthe algorithms
Figure 7.2.5 The case did not involve advanced AI. It shows regulators enforcing the rules that already govern AI at work.

In August 2021 Italy’s data protection authority fined Deliveroo’s Italian business 2.5 million euros over the system that managed the shifts of about 8,000 riders. The riders had not been given transparent information about how the algorithm worked, and the app collected far more data than it needed, including their location every 12 seconds. The regulator also ordered the company to fix the violations and to complete changes to its algorithms within months, and to check the algorithm’s results regularly for accuracy8.

The same logic has applied to data on workers more broadly: in 2020 the Hamburg data protection authority fined H&M about 35 million euros after team leaders recorded employees’ illnesses and family problems in notes that an IT error exposed9.

The visible cost of irresponsible use is the fine and the fix; the hidden cost is forced rework, lost trust, reputation damage, management time and a restricted program.WHAT THE INCIDENT REPORT SHOWSThe fine · The fixWHAT THE ORGANIZATION PAYSRework under a deadlineLost employee trustReputation damageManagement timeA restricted program
Figure 7.2.6 The fine is the visible part. The larger cost is rework on someone else’s timetable and trust that has to be rebuilt.

The fines are the part that makes the news. The larger costs sit underneath: rework done on a regulator’s timetable rather than the company’s, managers’ time, employees who now assume the worst about any new system, and, often, leadership restricting the wider program rather than the one system that failed. As The AI Risk Landscape showed with the Dutch childcare benefits case, the consequences can reach well beyond the organization itself. Trust is a business asset, and it is far cheaper to protect than to rebuild.

The logic works in the other direction too. An organization that has shown its people and customers how it uses AI, and has kept its word, has a lower cost of introducing the next system. That is a capability, and it compounds.

One good question per dimension

Responsible AI is usually described through a set of dimensions. An executive does not need the catalog. One good question for each of six is enough. Fairness: could outcomes differ unfairly between groups? Privacy: can we justify this data to the people it describes? Security: how could the system be attacked or misused? Transparency: do the people affected know AI is involved? Ownership: who answers for the outcome? Oversight: who can review, override or stop it?

Six questions for any AI use - fairness, privacy, security, transparency, ownership and oversight - answered in proportion to impact.AIOne questioneachFairnessPrivacySecurityTransparencyOwnershipOversight
Figure 7.2.7 The depth of each answer should match the impact of the use.

Module 06 taught the risks behind four of them, in Bias and Fairness, Privacy and Confidential Data, Security and AI Attacks and Human Oversight and AI Incidents. Two deserve emphasis here. Transparency asks whether the people affected know that AI is involved and what role it plays; the Deliveroo case above began with a failure to tell people. Ownership asks who answers for the outcome, because “the system decided” is not an accountability model. The depth of the answers should match the stakes: a tool that drafts internal meeting notes needs lighter answers than one that affects someone’s job, pay or credit. Turning these questions into a principle set the organization can hold people to is the work of the next chapter.

Designed in, not bolted on

Responsible AI is cheapest at the start. Choices made in design, such as which data to use, what the output is for, who sees it and who can override it, are hard to reverse once a system is live, has users and is shaping decisions.

Designed-in responsible AI justifies data and purpose, assesses impact and names an owner before launch; bolted-on responsibility cuts data after complaints and reworks on a regulator's deadline.Designed inPurpose and data justified before buildImpact assessed before launchPeople told from day oneOwner and override namedBolted onData cut after complaintsAssessment written to fit the systemDisclosure after discoveryRework on a regulator's deadline
Figure 7.2.8 The same controls cost far less before launch than after it.

The GDPR already makes this expectation explicit for personal data. It requires data protection by design and by default (Article 25), and an impact assessment before processing that is likely to create a high risk to people (Article 35), not after4. Deliveroo’s case shows the alternative: the transparency and data limits that could have been designed in were instead imposed, with deadlines, by a regulator8.

Designing responsibility in does not end at launch. AI behavior changes as data, models, users and providers change, so monitoring has to continue, and buying a system from a vendor moves none of the responsibility. How each stage is governed is the subject of AI Lifecycle Governance. Nor does designing in mean slowing down. Safe experiments with approved tools and non-sensitive data can move quickly; the questions get harder as a use moves toward customers, employees and consequential decisions.

Story: the interview scores that read faces

This is a documented case. The company in it sells AI to employers, so the lesson applies as much to an organization that buys such a system as to one that builds it.

By 2019 HireVue, a US hiring-technology company, ran video interviews for more than 700 employers10. Candidates recorded answers to set questions on camera, and the company’s algorithms scored the recordings. Employers got what they paid for: a fast, consistent first screen of large applicant pools. By early 2021 the company reported that its platform had hosted more than 19 million video interviews11.

Part of the score came from the candidate’s face. In November 2019 the Electronic Privacy Information Center (EPIC), a US privacy group, asked the Federal Trade Commission to investigate. Its complaint said that HireVue collected facial expressions and movements, along with voice and words, to assess traits such as cognitive ability and emotional intelligence, that it used secret algorithms, and that these were unfair and deceptive practices10. Whatever the merits of each allegation, the shape of the problem was plain. People applying for jobs were being scored on signals they had no reason to think counted, by a method they could not examine. The product created measurable value for its customers. It was also exactly the kind of system that loses the trust of the people it judges.

The company changed the product rather than defend it. HireVue stopped using facial analysis in its assessments in March 2020 and announced the change in January 2021, together with the results of an outside audit of its assessments for early-career hiring [@shrm-hirevue-2021; @fortune-hirevue-2021].

Until 2020 HireVue scored candidates' faces, voices and words under public challenge; from 2021 it scored the words only, released an outside audit and kept its value to employers.ElementUntil 2020From 2021Data scoredFace, voice and wordsWords of the answers; facial analysis droppedScrutinyA privacy group's complaint to the FTCAn outside audit, results releasedOpen questionsNot examined in publicAudit advised checking for accent effectsValue toemployersA fast first screenKept; the face data had added about 0.25 percent
Figure 7.2.9 The data that drew the criticism added almost nothing. Dropping it cost little; keeping it was costing trust.

The reason the company gave is the most useful part of the case. Its own research had found that the visual data contributed little, about 0.25 percent of a model’s predictive power in most cases, as language analysis improved12. Its chief executive said that, set against the concern it caused, the face analysis “wasn’t worth the incremental value”12. The audit did not close every question: it recommended looking further at whether candidates’ accents affected results12. The company kept scoring what candidates said, and kept selling the product11.

Notice what changed and what did not. The service still screened candidates at scale. What changed was the data, the openness to outside review and, with them, the case the company could make to the people it scored. The data that was hardest to justify turned out to be the data the system least needed. That is one case, not a law of nature, but it is why the question “can we justify this data to the people it describes?” is worth asking early. And an employer that used the tool was the one making the hiring decisions. Under the AI Act it would be a deployer, with duties of its own; as the previous section said, buying a system moves none of the responsibility. Sometimes the responsible answer is to redesign, reduce scope, add controls or not deploy at all. Here it was to reduce scope and open the system to review, and the value survived.

What this means for leaders

The first lesson is that value is not a defense. A system can deliver measurable results and still be irresponsible, and the results do not protect it once the people affected find out how it works. The second is that trust should be managed as deliberately as cost: watched through signals such as adoption, overrides, complaints and requests for a human, and protected before launch rather than repaired after. The third is that the law is the floor, not the standard, and building to a higher one is what lets a valuable system keep its license to scale. And the fourth is the distinction this module rests on: responsible AI defines what good looks like, and governance is how the organization makes sure it happens.

Check yourself

  1. Responsible AI means AI that makes no mistakes.
  2. If an AI system is legal, it is responsible.
  3. The goal is to make people trust AI as much as possible.
  4. People are more willing to use an imperfect algorithm when they can adjust its output.
  5. If no one complains, the system must be responsible.
  6. An AI system can create measurable business value and still be irresponsible.

What comes next

Responsible AI gives an organization its reason and a shared sense of what good looks like. A shared sense is not enough for thousands of people making AI decisions every week; they need a short, explicit set of principles they can apply and be held to. The next chapter, AI Governance Principles, sets out those principles and how they become expectations teams can act on.

Laws referenced

General Data Protection Regulation · EU

Regulation (EU) 2016/679

Personal data is any information relating to an identified or identifiable person, directly or indirectly, including by an identifier such as an online ID (Art. 4(1)). Lawful basis and purpose limitation (Arts. 5-6); processing special-category data, including biometric data used to identify a person, health data and data revealing ethnicity, is prohibited unless a specific exception applies (Art. 9); data protection by design and by default (Art. 25); processors such as AI vendors may act only under a written contract with required terms and sufficient guarantees (Art. 28); transparency to data subjects (Arts. 13-14); right not to be subject to a decision based solely on automated processing with legal or similarly significant effects (Art. 22); breach notification to the supervisory authority within 72 hours (Art. 33) and to individuals without undue delay when the risk is high (Art. 34); data protection impact assessment for high-risk processing (Art. 35). Fines up to EUR 20 million or 4% of global turnover.

  • 2018-05-25 — Applies

Last verified 2026-10-08 · official text

EU AI Act · EU

Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744

Risk-based rules. Prohibited practices include social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). High-risk systems (Annex III: biometrics, safety components of critical infrastructure such as energy, water and traffic, employment and worker management, credit, education, essential services, law enforcement, migration, justice) need risk management, data governance, documentation, logging, human oversight, human oversight that keeps people able to understand the system, notice automation bias (over-reliance on its output), override it or stop it (Art. 14(4)), appropriate accuracy, robustness and cybersecurity (Art. 15), automatic logging of events (Art. 12), a provider quality-management system (Art. 17) and conformity assessment. An Annex III system is not high-risk if it poses no significant risk of harm, for example a narrow procedural or preparatory task that does not replace human assessment; systems that profile people are always high-risk, and a provider relying on this exception must document it and register (Art. 6(3)). Deployers of high-risk AI must use it as instructed, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents (Art. 26); employers must inform workers' representatives (Art. 26(7)). Public bodies, private providers of public services, and deployers of credit-scoring or life and health insurance pricing systems must carry out a fundamental-rights impact assessment before first use (Art. 27). Providers must run post-market monitoring (Art. 72). A deployer that puts its name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk takes on the provider's obligations (Art. 25(1)). A substantial modification (Art. 3(23)) of a high-risk system needs a new conformity assessment, unless the change was pre-determined and documented at the first assessment, as with planned continuous learning (Art. 43(4)). Providers of general-purpose AI models (from 2 Aug 2025) must keep technical documentation, have a policy to comply with EU copyright law including text-and-data-mining opt-outs, and publish a sufficiently detailed summary of training content (Art. 53). Research, testing and development before a system is placed on the market or put into service is outside the Act, except testing in real-world conditions (Art. 2(8)). Since the 2026 Omnibus, the Art. 4 AI-literacy duty is an obligation of effort (take measures to support literacy), not of result. Fines reach EUR 35 million or 7% of global turnover for prohibited practices.

  • 2024-08-01 — Entered into force
  • 2025-02-02 — Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply
  • 2026-07-27 — Omnibus softens Art. 4: providers and deployers must take measures to support AI literacy; no specific level must be guaranteed
  • 2025-08-02 — General-purpose AI model obligations apply; governance and penalties regime in place
  • 2026-08-02 — Transparency duties (Art. 50) apply: disclose AI interaction, label synthetic and deepfake content (marking for generative systems already on the market: 2 Dec 2026)
  • 2027-12-02 — High-risk obligations for Annex III systems (e.g. hiring, credit, education, essential services) - moved from 2 Aug 2026 by the 2026 Omnibus
  • 2028-08-02 — High-risk obligations for AI in products regulated under Annex I

Last verified 2026-10-06 · official text

NYC Local Law 144 (automated employment decision tools) · US - New York City

NYC Local Law 144 of 2021; DCWP rules

An automated tool that substantially assists hiring or promotion decisions needs an independent bias audit within the past year, a published summary of results, and notice to candidates at least ten business days before use. Penalties USD 500 to 1,500 per violation.

  • 2023-07-05 — Enforcement began

Last verified 2026-10-06 · official text

References

  1. Nicole Gillespie, Steve Lockey, Tabi Ward, Alexandria Macdade and Gerard Hassed. Trust, attitudes and use of artificial intelligence: A global study 2025. The University of Melbourne and KPMG International. 2025.
  2. National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. NIST. 2023.
  3. OECD. Recommendation of the Council on Artificial Intelligence (OECD AI Principles), updated 2024. OECD. 2024.
  4. European Parliament and Council of the European Union. Regulation (EU) 2016/679 (General Data Protection Regulation). Official Journal of the European Union. 2016.
  5. John D. Lee and Katrina A. See. Trust in automation: Designing for appropriate reliance. Human Factors, 46(1), 50-80. 2004.
  6. Berkeley J. Dietvorst, Joseph P. Simmons and Cade Massey. Algorithm aversion: People erroneously avoid algorithms after seeing them err. Journal of Experimental Psychology: General, 144(1), 114-126. 2015.
  7. Berkeley J. Dietvorst, Joseph P. Simmons and Cade Massey. Overcoming algorithm aversion: People will use imperfect algorithms if they can (even slightly) modify them. Management Science, 64(3), 1155-1170. 2018.
  8. Hunton Andrews Kurth. Italian Garante Fines Deliveroo 2.5M Euros for Unlawful Processing of Personal Data. Hunton Andrews Kurth Privacy and Cybersecurity Law Blog. 2021.
  9. The Local Germany (AFP). Germany fines H&M 35 mn euros for worker 'surveillance'. The Local. 2020.
  10. Electronic Privacy Information Center (EPIC). In re HireVue: Complaint and request for investigation, injunction and other relief. EPIC, filed with the U.S. Federal Trade Commission. 2019.
  11. Roy Maurer. HireVue Discontinues Facial Analysis Screening. Society for Human Resource Management. 2021.
  12. Jeremy Kahn. HireVue drops facial monitoring amid A.I. algorithm audit. Fortune. 2021.

Further reading

Sources last verified 2026-10-10.