Why Responsible AI Matters
AI that people do not trust does not get used well, and AI that is not used well does not pay off. Responsible AI is the practice that earns informed trust: it creates value while protecting people, managing risk and keeping someone accountable. The law sets the floor; responsible AI is what lets valuable systems scale.
After this chapter you can
- Explain responsible AI as creating value while protecting people, managing risk and keeping someone accountable.
- Distinguish responsible AI from legal compliance, and both from governance.
- Describe informed trust and why both blind trust and blanket distrust destroy value.
- Recognize, from real enforcement cases, what irresponsible use costs and why responsibility is cheapest when designed in.
- Judge when a valuable AI system is still irresponsible, and in the EU possibly unlawful.
In 2025 the University of Melbourne and KPMG published one of the largest studies of public attitudes to AI to date: more than 48,000 people in 47 countries. Two thirds of them used AI regularly. Fewer than half, 46 percent, said they were willing to trust AI systems. At work, the picture was stranger still. Among employees who use AI at work, 66 percent said they had relied on its output without evaluating it, and 56 percent said they had made mistakes in their work because of AI1. The first two figures describe everyone surveyed; the last two describe only employees who use AI at work.
Read the numbers together and they describe two failures at once. More than half of people are not willing to trust AI, and many of those who do rely on it trust it more than they should. The researchers drew the conclusion that matters for leaders: in their statistical model, trust was a key driver of whether people accepted AI1. That makes trust a business variable, not a public-relations one. It is the subject of this chapter, and the reason responsible AI belongs on an executive agenda.
The core idea
Responsible AI is the practice of designing and operating AI so that it creates value while protecting people, managing risk and keeping someone clearly accountable. It is not a promise of perfect systems. It is a commitment to systems whose risks are understood, controlled and owned.
The chain runs in both directions. Responsible design and operation earn trust from the people a system touches. Trust leads to adoption, meaning people use the system and rely on it to the right degree. Adoption is where the value comes from. Run the chain backward and you get the familiar failure: careless practice damages trust, low trust stalls adoption, and the business case never arrives, however good the model is.
The frameworks executives are most likely to meet say the same thing in their own language. The NIST AI Risk Management Framework describes trustworthy AI as valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed, and it stresses that these qualities involve trade-offs that people must decide on, not just engineer2. The OECD AI Principles, updated in 2024, add that organizations that develop, deploy or operate AI should be held accountable for its proper functioning3. Neither framework treats trustworthiness as a feature of the model alone. It is a property of how the organization builds, uses and answers for it.
As What Is AI Governance? showed, governance is the system of decision rights, controls and oversight that makes AI decisions at scale. Responsible AI is the standard that system is trying to meet. The first defines how the organization decides; the second defines what a good decision looks like.
The law is the floor, not the question
Many leaders first hear “responsible AI” as a legal checklist. The law matters, and in Europe much of it is not optional: the GDPR already governs most AI that touches personal data, and the EU AI Act adds duties by risk. But compliance and responsibility ask different questions.
Compliance asks whether the organization meets its obligations. Responsible AI also asks whether a use is right for the people it affects, whether its outcomes are fair, whether it can be explained and whether someone can step in when it goes wrong. A system can pass every legal review and still lose the trust of the customers or employees it was built for. And law moves more slowly than practice. Many uses of AI fall into areas where the rules are general, untested or still arriving, and an organization that waits for the law to tell it what is acceptable will usually find out from its users first.
The gap also closes over time. Assessing the impact of risky processing before it starts was once voluntary good practice; since 2018 the GDPR has made it a legal duty for high-risk processing (Article 35)4. The AI Act is doing the same for AI, turning practices such as human oversight and logging into obligations for high-risk systems. An organization that treats responsibility as more than compliance is better placed when the floor rises, because it has already built to the higher standard.
This is why responsible AI cannot sit with the legal team alone. Legal owns the obligations. The questions of purpose, data use, fairness, ownership and oversight belong to the business that uses the system, with technology, data, security and risk as partners.
Informed trust, not maximum trust
Trust does not mean believing that AI is always right. Researchers in human factors worked this out long before generative AI. In a widely cited review, John Lee and Katrina See argued that what matters is not how much people trust an automated system but whether their trust is calibrated: matched to what the system can actually do. Overtrust leads to misuse, and distrust leads to disuse5.
Both ends are expensive. At the blind end, a confident error travels straight to a customer or into a decision. The KPMG finding that two thirds of employees who use AI at work rely on its output without checking it describes exactly this1. How that over-reliance arises, and how to design oversight against it, was the subject of Operational and Workforce Risk and Human Oversight and AI Incidents.
At the other end, people refuse a system or quietly work around it, and the investment produces nothing. This is not only a matter of attitude. In a well-known series of experiments, people who watched a forecasting algorithm make a mistake lost confidence in it faster than in a human who made the same mistake, and chose the human, even though the algorithm was more accurate6. A follow-up study found a simple remedy: when people could adjust the algorithm’s forecasts, even slightly, they became far more willing to use it7.
That result is the practical heart of informed trust. People trust a system more when they understand what it does, know its limits, know who is accountable for it and can challenge or correct it. None of those depends on a better model. All of them depend on how the organization designs and runs the system around the model.
What irresponsible use costs
The cost of irresponsible use is rarely the cost of fixing one system. A European enforcement case about data on people at work shows how the bill grows.
In August 2021 Italy’s data protection authority fined Deliveroo’s Italian business 2.5 million euros over the system that managed the shifts of about 8,000 riders. The riders had not been given transparent information about how the algorithm worked, and the app collected far more data than it needed, including their location every 12 seconds. The regulator also ordered the company to fix the violations and to complete changes to its algorithms within months, and to check the algorithm’s results regularly for accuracy8.
The same logic has applied to data on workers more broadly: in 2020 the Hamburg data protection authority fined H&M about 35 million euros after team leaders recorded employees’ illnesses and family problems in notes that an IT error exposed9.
The fines are the part that makes the news. The larger costs sit underneath: rework done on a regulator’s timetable rather than the company’s, managers’ time, employees who now assume the worst about any new system, and, often, leadership restricting the wider program rather than the one system that failed. As The AI Risk Landscape showed with the Dutch childcare benefits case, the consequences can reach well beyond the organization itself. Trust is a business asset, and it is far cheaper to protect than to rebuild.
The logic works in the other direction too. An organization that has shown its people and customers how it uses AI, and has kept its word, has a lower cost of introducing the next system. That is a capability, and it compounds.
One good question per dimension
Responsible AI is usually described through a set of dimensions. An executive does not need the catalog. One good question for each of six is enough. Fairness: could outcomes differ unfairly between groups? Privacy: can we justify this data to the people it describes? Security: how could the system be attacked or misused? Transparency: do the people affected know AI is involved? Ownership: who answers for the outcome? Oversight: who can review, override or stop it?
Module 06 taught the risks behind four of them, in Bias and Fairness, Privacy and Confidential Data, Security and AI Attacks and Human Oversight and AI Incidents. Two deserve emphasis here. Transparency asks whether the people affected know that AI is involved and what role it plays; the Deliveroo case above began with a failure to tell people. Ownership asks who answers for the outcome, because “the system decided” is not an accountability model. The depth of the answers should match the stakes: a tool that drafts internal meeting notes needs lighter answers than one that affects someone’s job, pay or credit. Turning these questions into a principle set the organization can hold people to is the work of the next chapter.
Designed in, not bolted on
Responsible AI is cheapest at the start. Choices made in design, such as which data to use, what the output is for, who sees it and who can override it, are hard to reverse once a system is live, has users and is shaping decisions.
The GDPR already makes this expectation explicit for personal data. It requires data protection by design and by default (Article 25), and an impact assessment before processing that is likely to create a high risk to people (Article 35), not after4. Deliveroo’s case shows the alternative: the transparency and data limits that could have been designed in were instead imposed, with deadlines, by a regulator8.
Designing responsibility in does not end at launch. AI behavior changes as data, models, users and providers change, so monitoring has to continue, and buying a system from a vendor moves none of the responsibility. How each stage is governed is the subject of AI Lifecycle Governance. Nor does designing in mean slowing down. Safe experiments with approved tools and non-sensitive data can move quickly; the questions get harder as a use moves toward customers, employees and consequential decisions.
Story: the interview scores that read faces
This is a documented case. The company in it sells AI to employers, so the lesson applies as much to an organization that buys such a system as to one that builds it.
By 2019 HireVue, a US hiring-technology company, ran video interviews for more than 700 employers10. Candidates recorded answers to set questions on camera, and the company’s algorithms scored the recordings. Employers got what they paid for: a fast, consistent first screen of large applicant pools. By early 2021 the company reported that its platform had hosted more than 19 million video interviews11.
Part of the score came from the candidate’s face. In November 2019 the Electronic Privacy Information Center (EPIC), a US privacy group, asked the Federal Trade Commission to investigate. Its complaint said that HireVue collected facial expressions and movements, along with voice and words, to assess traits such as cognitive ability and emotional intelligence, that it used secret algorithms, and that these were unfair and deceptive practices10. Whatever the merits of each allegation, the shape of the problem was plain. People applying for jobs were being scored on signals they had no reason to think counted, by a method they could not examine. The product created measurable value for its customers. It was also exactly the kind of system that loses the trust of the people it judges.
The company changed the product rather than defend it. HireVue stopped using facial analysis in its assessments in March 2020 and announced the change in January 2021, together with the results of an outside audit of its assessments for early-career hiring [@shrm-hirevue-2021; @fortune-hirevue-2021].
The reason the company gave is the most useful part of the case. Its own research had found that the visual data contributed little, about 0.25 percent of a model’s predictive power in most cases, as language analysis improved12. Its chief executive said that, set against the concern it caused, the face analysis “wasn’t worth the incremental value”12. The audit did not close every question: it recommended looking further at whether candidates’ accents affected results12. The company kept scoring what candidates said, and kept selling the product11.
Notice what changed and what did not. The service still screened candidates at scale. What changed was the data, the openness to outside review and, with them, the case the company could make to the people it scored. The data that was hardest to justify turned out to be the data the system least needed. That is one case, not a law of nature, but it is why the question “can we justify this data to the people it describes?” is worth asking early. And an employer that used the tool was the one making the hiring decisions. Under the AI Act it would be a deployer, with duties of its own; as the previous section said, buying a system moves none of the responsibility. Sometimes the responsible answer is to redesign, reduce scope, add controls or not deploy at all. Here it was to reduce scope and open the system to review, and the value survived.
What this means for leaders
The first lesson is that value is not a defense. A system can deliver measurable results and still be irresponsible, and the results do not protect it once the people affected find out how it works. The second is that trust should be managed as deliberately as cost: watched through signals such as adoption, overrides, complaints and requests for a human, and protected before launch rather than repaired after. The third is that the law is the floor, not the standard, and building to a higher one is what lets a valuable system keep its license to scale. And the fourth is the distinction this module rests on: responsible AI defines what good looks like, and governance is how the organization makes sure it happens.
Check yourself
- Responsible AI means AI that makes no mistakes.
- If an AI system is legal, it is responsible.
- The goal is to make people trust AI as much as possible.
- People are more willing to use an imperfect algorithm when they can adjust its output.
- If no one complains, the system must be responsible.
- An AI system can create measurable business value and still be irresponsible.
What comes next
Responsible AI gives an organization its reason and a shared sense of what good looks like. A shared sense is not enough for thousands of people making AI decisions every week; they need a short, explicit set of principles they can apply and be held to. The next chapter, AI Governance Principles, sets out those principles and how they become expectations teams can act on.
Laws referenced
Not legal advice. Laws change; verify before relying on this, and consult counsel for decisions.
General Data Protection Regulation · EU
Regulation (EU) 2016/679
Personal data is any information relating to an identified or identifiable person, directly or indirectly, including by an identifier such as an online ID (Art. 4(1)). Lawful basis and purpose limitation (Arts. 5-6); processing special-category data, including biometric data used to identify a person, health data and data revealing ethnicity, is prohibited unless a specific exception applies (Art. 9); data protection by design and by default (Art. 25); processors such as AI vendors may act only under a written contract with required terms and sufficient guarantees (Art. 28); transparency to data subjects (Arts. 13-14); right not to be subject to a decision based solely on automated processing with legal or similarly significant effects (Art. 22); breach notification to the supervisory authority within 72 hours (Art. 33) and to individuals without undue delay when the risk is high (Art. 34); data protection impact assessment for high-risk processing (Art. 35). Fines up to EUR 20 million or 4% of global turnover.
- 2018-05-25 — Applies
Last verified 2026-10-08 · official text
EU AI Act · EU
Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744
Risk-based rules. Prohibited practices include social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). High-risk systems (Annex III: biometrics, safety components of critical infrastructure such as energy, water and traffic, employment and worker management, credit, education, essential services, law enforcement, migration, justice) need risk management, data governance, documentation, logging, human oversight, human oversight that keeps people able to understand the system, notice automation bias (over-reliance on its output), override it or stop it (Art. 14(4)), appropriate accuracy, robustness and cybersecurity (Art. 15), automatic logging of events (Art. 12), a provider quality-management system (Art. 17) and conformity assessment. An Annex III system is not high-risk if it poses no significant risk of harm, for example a narrow procedural or preparatory task that does not replace human assessment; systems that profile people are always high-risk, and a provider relying on this exception must document it and register (Art. 6(3)). Deployers of high-risk AI must use it as instructed, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents (Art. 26); employers must inform workers' representatives (Art. 26(7)). Public bodies, private providers of public services, and deployers of credit-scoring or life and health insurance pricing systems must carry out a fundamental-rights impact assessment before first use (Art. 27). Providers must run post-market monitoring (Art. 72). A deployer that puts its name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk takes on the provider's obligations (Art. 25(1)). A substantial modification (Art. 3(23)) of a high-risk system needs a new conformity assessment, unless the change was pre-determined and documented at the first assessment, as with planned continuous learning (Art. 43(4)). Providers of general-purpose AI models (from 2 Aug 2025) must keep technical documentation, have a policy to comply with EU copyright law including text-and-data-mining opt-outs, and publish a sufficiently detailed summary of training content (Art. 53). Research, testing and development before a system is placed on the market or put into service is outside the Act, except testing in real-world conditions (Art. 2(8)). Since the 2026 Omnibus, the Art. 4 AI-literacy duty is an obligation of effort (take measures to support literacy), not of result. Fines reach EUR 35 million or 7% of global turnover for prohibited practices.
- 2024-08-01 — Entered into force
- 2025-02-02 — Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply
- 2026-07-27 — Omnibus softens Art. 4: providers and deployers must take measures to support AI literacy; no specific level must be guaranteed
- 2025-08-02 — General-purpose AI model obligations apply; governance and penalties regime in place
- 2026-08-02 — Transparency duties (Art. 50) apply: disclose AI interaction, label synthetic and deepfake content (marking for generative systems already on the market: 2 Dec 2026)
- 2027-12-02 — High-risk obligations for Annex III systems (e.g. hiring, credit, education, essential services) - moved from 2 Aug 2026 by the 2026 Omnibus
- 2028-08-02 — High-risk obligations for AI in products regulated under Annex I
Last verified 2026-10-06 · official text
NYC Local Law 144 (automated employment decision tools) · US - New York City
NYC Local Law 144 of 2021; DCWP rules
An automated tool that substantially assists hiring or promotion decisions needs an independent bias audit within the past year, a published summary of results, and notice to candidates at least ten business days before use. Penalties USD 500 to 1,500 per violation.
- 2023-07-05 — Enforcement began
Last verified 2026-10-06 · official text
References
- Nicole Gillespie, Steve Lockey, Tabi Ward, Alexandria Macdade and Gerard Hassed. Trust, attitudes and use of artificial intelligence: A global study 2025. The University of Melbourne and KPMG International. 2025.
- National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. NIST. 2023.
- OECD. Recommendation of the Council on Artificial Intelligence (OECD AI Principles), updated 2024. OECD. 2024.
- European Parliament and Council of the European Union. Regulation (EU) 2016/679 (General Data Protection Regulation). Official Journal of the European Union. 2016.
- John D. Lee and Katrina A. See. Trust in automation: Designing for appropriate reliance. Human Factors, 46(1), 50-80. 2004.
- Berkeley J. Dietvorst, Joseph P. Simmons and Cade Massey. Algorithm aversion: People erroneously avoid algorithms after seeing them err. Journal of Experimental Psychology: General, 144(1), 114-126. 2015.
- Berkeley J. Dietvorst, Joseph P. Simmons and Cade Massey. Overcoming algorithm aversion: People will use imperfect algorithms if they can (even slightly) modify them. Management Science, 64(3), 1155-1170. 2018.
- Hunton Andrews Kurth. Italian Garante Fines Deliveroo 2.5M Euros for Unlawful Processing of Personal Data. Hunton Andrews Kurth Privacy and Cybersecurity Law Blog. 2021.
- The Local Germany (AFP). Germany fines H&M 35 mn euros for worker 'surveillance'. The Local. 2020.
- Electronic Privacy Information Center (EPIC). In re HireVue: Complaint and request for investigation, injunction and other relief. EPIC, filed with the U.S. Federal Trade Commission. 2019.
- Roy Maurer. HireVue Discontinues Facial Analysis Screening. Society for Human Resource Management. 2021.
- Jeremy Kahn. HireVue drops facial monitoring amid A.I. algorithm audit. Fortune. 2021.
Further reading
- Nicole Gillespie, Steve Lockey, Tabi Ward, Alexandria Macdade and Gerard Hassed. Trust, attitudes and use of artificial intelligence: A global study 2025. The University of Melbourne and KPMG International. 2025.
- John D. Lee and Katrina A. See. Trust in automation: Designing for appropriate reliance. Human Factors, 46(1), 50-80. 2004.
- National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. NIST. 2023.
- OECD. Recommendation of the Council on Artificial Intelligence (OECD AI Principles), updated 2024. OECD. 2024.
Sources last verified 2026-10-10.