Introduction to Responsible AI
Quantitative Responsible AI: Principles, Governance, and Methods
Learning objectives
By the end of this chapter, you are expected to be able to:
- Explain why responsible AI matters for consequential automated decisions (decisions that meaningfully affect a person’s life, such as who gets a loan, a job, or an insurance policy) generally, and in high-stakes domains such as insurance, lending, hiring, and healthcare specifically.
- Describe the six major principles of AI ethics and their relevance to professional practice.
- Outline a lifecycle view of ethical AI from problem definition through deployment.
- Identify key regulatory developments in AI-driven discrimination across jurisdictions and sectors.
- Map the three course pillars (fairness, explainability, and privacy) to the broader responsible AI framework.
Insurance recurs as a worked example throughout this course. It is a domain with unusually well-developed AI regulation and quantitative fairness/privacy methods. The principles themselves apply to any consequential automated decision: hiring, lending, healthcare allocation, and criminal justice risk assessment among them.
Why Responsible AI?
The promise and the problem
Responsible AI is the practice of designing, deploying, and governing AI systems so that automated decisions are fair, explainable, and privacy-respecting, not just accurate. Machine learning and AI are transforming decision-making across industries: actuaries pricing insurance risk, underwriters assessing loans, HR teams screening applicants, and clinicians triaging patients are all working alongside automated systems that shape consequential outcomes.
Responsible AI is inherently interdisciplinary. No single field supplies everything it takes to deploy AI responsibly. Domain expertise identifies what a fair or reasonable outcome looks like in context. Statistics and machine learning supply the modelling and measurement tools. Law defines the binding obligations. Economics clarifies the trade-offs and incentives at stake. Risk management embeds the effort into an organisation’s governance structure. Practising responsible AI also requires collaboration across stakeholders who do not share a single professional background, among them customer advocates and affected individuals, regulators who set and enforce standards, and the industry practitioners who build and deploy the systems. Within a single organisation, this typically means actuaries, data scientists, lawyers, risk officers, and business leaders working together rather than any one of them working in isolation.
The promise:
- More accurate risk assessment and outcome prediction
- Faster, more consistent screening and processing of loan applications, benefit claims, and job candidates
- New data sources (wearables, transaction histories, digital footprints, and telematics, meaning devices or apps that track real-time behaviour such as driving) enabling finer-grained decisions
- Automation of routine decisions, freeing professionals for higher-value work
The problem:
- Automated systems make consequential decisions affecting access, pricing, and opportunity for millions of people
- Complexity obscures how decisions are made, from the people affected, regulators, and even practitioners
- Data reflects historical patterns, including past discrimination
- Errors and biases scale automatically across large populations
Responsible AI is not about slowing innovation — it is about making innovation defensible.
A failure is not always obvious
Credit-based insurance scores are a textbook case. US insurers have used them since the early 1990s because they are genuinely predictive of claims cost. A 2007 Federal Trade Commission study found this apparently neutral, financially grounded score is far from race-neutral in practice. It placed more than 25% of Black consumers in the lowest, most expensive score band, against 3% of white consumers (Kiviat 2019).
Simply removing race as a model input would not have fixed this. Credit history reflects broader, long-standing patterns of economic inequality, so it continues to track race statistically even when race itself is never an input. Guidance from Australia’s Human Rights Commission and the Actuaries Institute makes exactly this point. Removing a protected attribute from a dataset is not sufficient, since other data may still act as a proxy for it (Australian Human Rights Commission and Actuaries Institute 2022).
The finding triggered sustained regulatory pushback, investigations in more than 17 US states and five congressional hearings. Four states have banned the practice outright. Every other state instead imposes constraints, such as mandatory disclosure and exemptions for negative credit events tied to documented hardship (divorce, job loss, a medical emergency), while still permitting the underlying score (Kiviat 2019). A statistically valid, genuinely predictive criterion can still be judged illegitimate. Chapter 8 returns to this case in depth.
The same tension shows up further upstream, in what insurers collect in the first place. Insurers increasingly draw on third-party data products, such as Resonate, that combine household composition, education, court judgments, and affluence indicators, alongside web-browsing activity and social-media footprints. Their value to the insurer lies entirely in how closely they correlate with the outcome being predicted, and several of them correlate closely with a protected attribute too, the same dynamic as the credit-score case above, now at much greater scale (Huang 2026).
The same structure recurs across sectors. A widely used US healthcare algorithm allocated extra care-management resources by predicted cost rather than predicted illness, and because Black patients historically incurred lower costs for the same level of need, it systematically under-referred them for extra care (Obermeyer et al. 2019). Amazon scrapped an internal hiring tool after finding it penalised résumés containing the word “women’s,” a pattern learned from a decade of résumés mostly submitted by men (Dastin 2018). Apple Card’s credit-limit algorithm drew a New York regulatory investigation after customers reported women receiving dramatically lower limits than their husbands despite similar or better finances, though the investigation ultimately found no fair-lending violation (New York State Department of Financial Services 2021). In China, e-commerce and travel platforms charging returning or loyal customers more than new customers for the same product, a practice known as dàshùjù shāshú (roughly, “big data exploiting familiar customers”), became common enough to prompt an explicit ban in the 2022 Algorithm Recommendation Provisions (Cyberspace Administration of China 2022).
Questions that arise:
- Is this model fair? By which definition?
- Can the organisation explain to a regulator why a given individual received a given outcome?
- What happens to the privacy of the behavioural data that informed the model?
- Who is accountable when the model produces a harmful outcome?
These are the questions this course is designed to answer. Fairness, explainability, and privacy are developed quantitatively, each with its own toolkit. Accountability is addressed too, mainly through governance practice such as documentation and named ownership, developed most fully in Chapter 8, rather than through a standalone quantitative method.
Major Principles of AI Ethics
Six principles
AI ethics frameworks converge on six core principles that apply across industries and regulatory contexts (Huang 2025).
1. Fairness and non-discrimination AI systems should not produce unjustified disparate outcomes across protected groups (groups defined by a protected attribute, a characteristic such as race, gender, or age that anti-discrimination law shields from being used in decisions). This includes both direct discrimination (using a protected attribute) and indirect discrimination (using proxies, seemingly neutral variables, that reproduce disparities).
2. Transparency and explainability Decisions must be interpretable, not only to developers, but to customers, regulators, and affected parties. Transparency operates at two levels, how the system works and why a specific decision was reached.
3. Accountability It must be clear who is responsible when an AI system causes harm: the developer, the deploying organisation, the regulator, or the professional who certified the model. Accountability requires documentation and governance.
4. Privacy and data ethics AI systems consume vast amounts of personal data. Individuals have rights over how their data is collected, used, shared, and retained. Third-party data sources, telematics, and behavioural data create new tensions between predictive utility and privacy.
5. Contestability Individuals affected by automated decisions must have meaningful channels to understand, challenge, and appeal those decisions. This principle is increasingly embedded in regulation (the EU’s GDPR, or General Data Protection Regulation, Article 22; Australian Privacy Act reforms).
6. Stability and robustness AI models must perform reliably under real-world conditions, including data drift, adversarial inputs, and distribution shift. A model that is fair and accurate at deployment may not remain so two years later.
Fairness, explainability, and privacy are three of these six, and they are the three this course develops quantitatively. Reid Blackman calls this same trio AI’s “Big Three” ethical risks in Ethical Machines (Blackman 2022). This course’s own reason for the same scope is practical. Fairness, explainability, and privacy each already have a maturing toolkit of quantitative methods (the fairness criteria, explainability techniques, and privacy methods this course covers) with precise, well-established definitions, even though choosing among them is itself a domain-specific judgment call. Accountability, contestability, and stability still matter. This course treats them as governance and monitoring practices rather than as separate quantitative modules.
Three pillars
Each pillar asks a different core question, but a similar cast of stakeholders recurs across all three: the people affected by the decision, the regulators who oversee that domain, and the organisation deploying the system.
| Pillar | Core question |
|---|---|
| Fairness | Does the model treat people equitably? |
| Explainability | Can model decisions be understood and justified? |
| Privacy | Are personal data used appropriately and protected? |
Each pillar has both a principled dimension (what should we do?) and a quantitative dimension (how do we measure, enforce, and verify it?). This course addresses both.
From principles to practice
Principles are necessary but not sufficient. Actuarial, data science, and other analytics professions all face the same translation problem:
How do we operationalise “fairness,” “explainability,” and “privacy” in a way that is measurable, auditable, and defensible?
This course focuses on the quantitative methods that bridge the gap between ethical principles and professional practice.
| Principle | Covered in this course |
|---|---|
| Fairness and non-discrimination | Chapters 2–3: fairness criteria, model designs, audit protocols |
| Transparency and explainability | Chapters 4–5: PFI, PDP, SHAP, ALE, interaction effects |
| Privacy and data ethics | Chapters 6–7: k-anonymity, differential privacy, synthetic data |
| Accountability | Chapters 2, 4, 8: governance, documentation, trade-offs |
| Contestability | Chapter 2: fairness testing and audit protocols (the statistical evidence that can support a challenge); Chapter 4: right to explanation (the ability to demand a reason for an automated decision); Chapter 5: counterfactual explanations |
| Stability and robustness | Chapter 8: integration and systemic risks |
The Ethical AI Lifecycle
AI does not fail at deployment
A common source of AI failure lies in problem formulation rather than the model itself, for example, asking the wrong question, using the wrong outcome variable, or failing to consider who is affected.
“The most frequent failure in data analysis is mistaking the type of question being considered.”
— Leek and Peng (2015)
Ethical risk is present at every stage of the AI lifecycle, not only at the point of model deployment.
A six-stage lifecycle view
Huang (2025) proposes a framework that embeds ethical checkpoints throughout the AI development and deployment process.

| Stage | Key ethical questions |
|---|---|
| 1. Problem definition | Does the objective align with fairness, transparency, and regulatory standards? Is optimisation balanced between firm profitability and customer welfare? Who owns AI use, oversight, and risk? |
| 2. Data collection | Does the data invade privacy? Do proxies (e.g. postcode or occupation) encode sensitive attributes indirectly? Is consent meaningful? Does the data reflect historical bias? |
| 3. Exploratory data analysis | Could input features have discriminatory effects, directly or through correlation with protected groups? Can each feature be justified to regulators and customers, not only internal teams? |
| 4. Modelling | Does the model balance accuracy with fairness, explainability, and transparency? Can outputs be assessed for disparities across social groups? Is it interpretable enough for audit? |
| 5. Evaluation | Does performance hold up across relevant subgroups, not only in aggregate? Do results generalise under different scenarios? Have trade-offs been communicated to decision makers? |
| 6. Deployment | Are models audited regularly after launch? Can customers appeal or contest an outcome? Is there a feedback loop back into future iterations? |
Domain professionals (actuaries in insurance, underwriters in lending who assess and price risk before approving a loan or policy, HR analysts in hiring) are increasingly involved at every stage of this lifecycle, not only model development and validation but governance, risk assessment, and stakeholder communication. Responsible AI is a professional obligation, not only a technical one.
Why problem formulation matters most
Leek and Peng (2015), quoted above, distinguish six types of question a data analysis can ask, and argue that most analysis failures come from answering the wrong type rather than answering the right type badly.
| Type | Asks | Example |
|---|---|---|
| Descriptive | What happened? | What is the average claim size by policy type? |
| Exploratory | What patterns exist in the data? | Do interview scores cluster by which recruiter conducted them? |
| Inferential | What can we infer about a population from a sample? | Is this sample’s average loan default rate representative of the full borrower population? |
| Predictive | What is likely to happen? | How many days is this patient expected to stay in hospital? |
| Causal | Does X cause Y? | Does raising the excess (the deductible a policyholder pays before cover starts) reduce claim frequency? |
| Mechanistic | How exactly does the system work? | How does a drug interact biologically to lower blood pressure? |
Mistaking one type for another is a common source of ethical failure, not only a technical one, but naming the type correctly is still not enough on its own. The same question type, asked in a different business context, can call for different choices at every downstream step.
A consulting firm has two teams working on two different client engagements, each asked a predictive question.
Team A works for a major supermarket, forecasting product demand so warehouses know how much stock to send where. Over-forecasting wastes stock. Under-forecasting loses sales. No individual customer is priced, screened, or denied anything based on this model’s output.
Team B works for an auto insurer, predicting the number and cost of claims for individual prospective policyholders, to set their premiums.
For each team, what should drive the choice of model class, feature selection, and evaluation criteria? Why might the same predictive question lead to different choices?
For Team A, no individual is priced, screened, or denied anything based on the model’s output, so prediction accuracy is the dominant consideration. A complex, high-accuracy model built from hundreds of engineered features is the right choice.
For Team B, the predictive question is the same shape, but applied to individuals rather than aggregate stock levels, and that changes everything downstream. Interpretability now matters as much as accuracy, since the model must be explainable to regulators and to the customers it prices. Feature selection now requires scrutiny for proxies, since a feature correlated with claims might also correlate with a protected attribute. Fairness metrics become part of evaluation, not only prediction error.
Regulatory Context
A rapidly changing landscape
Regulation of AI in consequential decision-making is evolving quickly across all major markets, spanning insurance, lending, employment, and other high-risk domains. This section surveys the landscape jurisdiction by jurisdiction. Chapters 2, 4, and 6 develop the specific fairness, explainability, and privacy regulatory mechanisms this landscape gives rise to, in depth.
United States: sector-by-sector leadership
In the absence of federal AI legislation, U.S. states and sector regulators have led regulatory innovation:
Colorado SB21-169 (2021) (Colorado General Assembly 2021) The first U.S. law explicitly addressing algorithmic discrimination in insurance. Prohibits insurers from using external consumer data in ways that unfairly discriminate based on race, colour, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, or gender expression.
NYC Local Law 144 (2021) (New York City Council 2021) Requires employers using automated employment decision tools (AI systems that screen or rank job candidates) to commission an independent bias audit each year, publish the results, and notify candidates that such a tool is in use.
New York DFS Circular Letter No. 7 (2024) (New York State Department of Financial Services 2024) Issued by New York’s Department of Financial Services (DFS), the state’s insurance and financial regulator. Requires insurers using AI systems and external consumer data in underwriting and pricing to conduct ongoing bias testing, maintain governance frameworks, and be able to explain model outputs to consumers and regulators.
CFPB and ECOA (2023) (Consumer Financial Protection Bureau 2023) The U.S. Consumer Financial Protection Bureau confirmed that the Equal Credit Opportunity Act’s adverse-action notice requirements (the legal duty to tell a rejected applicant why) apply to AI-driven credit decisions, regardless of model complexity.
The NAIC Model Bulletin (2023) (National Association of Insurance Commissioners 2023), from the National Association of Insurance Commissioners, gives US state insurance regulators guidance on AI governance, risk management, and third-party model oversight. Illinois’s AI Video Interview Act (Illinois General Assembly 2019) regulates AI-based hiring assessments specifically. Insurance and employment have moved fastest so far, but sector-by-sector regulation is spreading to lending, healthcare, and beyond.
European Union: horizontal AI regulation
The EU AI Act (2024) (European Parliament and Council of the European Union 2024) takes a risk-based approach that applies across sectors. Annex III designates several categories of high-risk AI systems, including risk assessment and pricing for life and health insurance, employment and worker management, creditworthiness assessment, education, law enforcement, and access to essential public services. All are subject to:
- Conformity assessment (a formal check that a system meets legal requirements) before deployment
- Mandatory risk management systems
- Data governance requirements
- Transparency and documentation obligations
- Human oversight requirements
- Post-market monitoring
Life and health insurance risk assessment and pricing is one Annex III category among several. Note that this specific category does not extend to other insurance lines, such as the motor insurance examples used throughout this course, though a motor insurer’s AI system could still fall under Annex III’s creditworthiness or other categories depending on what it does. The Act treats the categories it does cover as structurally similar to employment and credit decisions, not as a special case.
GDPR (2018) (Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation) 2016), the EU’s general data protection framework, predates the AI Act by six years and remains the more consequential instrument for most organisations in practice. Article 22 gives individuals a qualified right not to be subject to certain solely automated decisions, and Articles 13-15 separately require organisations to explain the logic behind automated processing. The AI Act applies on top of these existing GDPR obligations, not instead of them. Chapter 6 covers GDPR’s full six-principle framework and its automated-decision-making provisions in depth.
Australia: principles-based, multi-regulator approach
Australia has no standalone AI Act. Instead, existing sector laws apply to AI, enforced by several regulators in parallel. The absence of a new AI law does not mean an absence of accountability. This stands in contrast to the EU’s single, horizontal standalone Act, even though enforcement of that Act itself involves multiple national competent authorities and EU-level bodies rather than one single regulator. One such regulator, the Australian Securities and Investments Commission (ASIC), illustrates what happens when governance fails.
A licensee deployed an AI model to predict consumer credit default risk, with no AI strategy, no policies, and no risk rating of its AI use cases. An internal review, conducted ten months after deployment, found the model was built with “limited understanding” of the third-party platform it relied on, had “incomplete model documentation with missing critical elements,” and showed “poor governance and a lack of a monitoring process.” The report described it as a “black box with no ability to explain the variables in the scorecard or the impact they are having on an applicant’s score.” The licensee kept using it for several more months, and reported plans to expand its use of AI.
Source: ASIC Report 798, Beware the Gap (Oct 2024), p.7 (Australian Securities and Investments Commission 2024).
ASIC (Australian Securities and Investments Commission 2024) published 11 questions it expects licensees to be able to answer about any AI system they use. REP 798 found only 12 of 23 firms reviewed had fairness policies, and half had not updated their risk frameworks for AI.
APRA (the Australian Prudential Regulation Authority) CPS 230 (Australian Prudential Regulation Authority 2023) (in force from July 2025) requires board-approved operational risk frameworks. APRA’s 2025–26 supervisory programme makes clear it expects AI risk to be explicitly addressed within them.
OAIC (the Office of the Australian Information Commissioner) / Privacy Act automated decision-making reforms: from 10 December 2026, privacy policies must disclose how automated decisions that significantly affect an individual’s rights or interests are made (Privacy and Other Legislation Amendment Act 2024 (Cth) 2024).
FAR (Australian Prudential Regulation Authority and Australian Securities and Investments Commission 2023) (the Financial Accountability Regime) imposes a “reasonable steps” obligation. Accountable persons are responsible for the areas they oversee, including AI systems operating within them, with personal civil penalties of up to A$1.56 million for knowing involvement in a breach.
Obligations do not transfer to a vendor. If a third-party model produces unfair outcomes or breaches licence conditions, the regulator looks to the deploying organisation. The question is whether it governed the vendor adequately, not who built the model (Parra-Orlandoni and Carvão 2026).
Australia: what’s coming
| Timing | Development |
|---|---|
| Oct 2025 | AI6 guidance released (National AI Centre 2025), National AI Centre voluntary framework (see Chapter 8) |
| Dec 2025 | National AI Plan (Department of Industry, Science and Resources (Australia) 2025): mandatory guardrails shelved, but existing laws carry the load for now |
| Early 2026 | AI Safety Institute launched, A$29.9M watchdog assessing risks and advising regulators |
| Dec 2026 | Privacy Act automated-decision-making disclosure becomes mandatory |
AHRC: Human Rights and Technology (2021) (Australian Human Rights Commission 2021) and AI and Discrimination in Insurance (2022) (Australian Human Rights Commission and Actuaries Institute 2022) The Australian Human Rights Commission’s landmark 2021 report set out cross-sector principles for AI and human rights. Its 2022 insurance-specific guidance, developed jointly with the Actuaries Institute, applies those principles to underwriting and pricing, with reference to the Age Discrimination Act, Disability Discrimination Act, Racial Discrimination Act, and Sex Discrimination Act.
China: binding sector-specific rules
China does not yet have a single comprehensive AI law in force. The State Council’s 2026 Legislative Work Plan calls for “accelerating comprehensive legislation” (General Office of the State Council of the People’s Republic of China 2026). In the meantime, sector- and topic-specific rules cover most consequential AI use.
Guiding Opinions on the Safe Development and Application of AI in Banking and Insurance (2026) (National Financial Regulatory Administration (China) 2026), hereafter the “NFRA AI Guidance” China’s National Financial Regulatory Administration issued sector-specific AI guidance for banking and insurance institutions (Jin Fa [2026] No. 8, 18 June 2026). It addresses risk classification and high-risk application approval, human oversight of high-risk applications, transparency and explainability, avoiding algorithmic discrimination and other fairness issues, data and cybersecurity protection, and procedural requirements for externally introduced generative AI models. Unlike the general rules below, it applies directly to banking and insurance institutions.
Algorithm Recommendation Provisions (2022) (Cyberspace Administration of China 2022) Issued by the Cyberspace Administration of China (CAC). Filing and security-assessment obligations apply specifically to algorithmic services with public-opinion attributes or social-mobilisation capacity, not to all algorithm use. Where it applies, it also prohibits “big data price discrimination.” This means using a consumer’s own data to charge them a worse price than another consumer receives for the same product.
Personal Information Protection Law (PIPL), Article 24 (2021) (National People’s Congress (China) 2021) China’s GDPR-equivalent automated-decision-making provision requires that automated decisions be transparent and their results fair, and bans “unreasonable differential treatment… in transaction prices” arising from automated decision-making. This is a targeted rule against algorithmically charging otherwise-comparable customers different prices without justification, not a blanket ban on all price differentiation. It also grants a right to an explanation, and a right to refuse a decision made solely by automated means where it significantly affects the individual. A more directly insurance-specific fair-pricing rule, Article 27 of the Measures for the Administration of Consumer Rights Protection by Banking and Insurance Institutions, is covered in Chapter 2’s regulatory frameworks section alongside China’s Algorithm Recommendation Provisions.
Generative AI Interim Measures (2023) (Cyberspace Administration of China 2023) and content-labelling rules (2025) (Cyberspace Administration of China and Ministry of Industry and Information Technology and Ministry of Public Security and National Radio and Television Administration 2025) Require security assessment and registration before launching a generative AI service, and mandate two forms of labelling for AI-generated content. A visible label appears on the image, video, audio, or text itself, such as a watermark, tag, or icon, so a viewer can tell the content is AI-generated. An embedded label is written into the file’s metadata. It is not necessarily visible to the viewer, but it persists even if the visible label is stripped, so platforms and regulators can still trace the content back to its AI-generated origin after it is shared or reposted.
Singapore: voluntary, principles-based frameworks
Singapore has no binding AI-specific law, and has deliberately chosen a pro-innovation, “sandbox” approach (a controlled environment for testing new approaches under relaxed rules) built on voluntary frameworks and testing tools rather than mandatory obligations:
Model AI Governance Framework (IMDA/PDPC, 2019, updated 2020) (Personal Data Protection Commission Singapore and Infocomm Media Development Authority 2020) General voluntary guidance for the private sector, issued by Singapore’s IMDA (Infocomm Media Development Authority) and PDPC (Personal Data Protection Commission), since extended with a Model AI Governance Framework for Generative AI (2024) (AI Verify Foundation and Infocomm Media Development Authority 2024) and a Model AI Governance Framework for Agentic AI (2026) as new AI paradigms have emerged.
AI Verify (AI Verify Foundation 2023) An open-source AI governance testing toolkit, now stewarded by the AI Verify Foundation, which coordinates a global community building shared AI testing standards.
MAS FEAT Principles (2018) (Monetary Authority of Singapore 2018) and the Veritas Initiative (Monetary Authority of Singapore 2019) The Monetary Authority of Singapore’s FEAT principles, co-created with the financial industry, apply specifically to AI and data analytics in financial services, including insurance. FEAT stands for four dimensions of responsible AI use: Fairness (AI systems should not produce discriminatory outcomes, and fairness must be considered throughout the model’s lifecycle, not checked once at the end), Ethics (AI use should align with the institution’s ethical values and broader societal expectations, with human oversight retained over consequential decisions), Accountability (responsibility for AI outcomes must be clearly assigned, including at board and senior-management level), and Transparency (institutions must document their AI systems internally and, where appropriate, give customers meaningful explanations of AI-driven decisions that affect them).
The Veritas Initiative, developed jointly by MAS and the financial industry across several phases from 2020 to 2023, translates these four principles into concrete assessment methodologies that financial institutions can apply to their own models. Its use cases include credit risk scoring and customer marketing for banks, and predictive underwriting and fraud detection for insurers, backed by an open-source toolkit that automates fairness-metric assessment. MAS issued a consultation paper on binding AI Risk Management Guidelines for financial institutions in November 2025 (Monetary Authority of Singapore 2025).
FEAT and Veritas are the financial-sector counterpart to the fairness criteria in Chapter 2, developed independently, by a regulator, for the same underlying problem. Rather than prescribing a single fairness test, Veritas’s assessment methodology asks how a financial institution should define, measure, justify, and monitor fairness in its AI-driven pricing or underwriting system.
Common themes across jurisdictions
Despite differences in approach (the EU’s single standalone Act, the US and China’s binding-but-sectoral rules, Australia and Singapore’s voluntary frameworks layered on existing law), four themes appear consistently:
- Governance and accountability: AI systems must have clear ownership, documentation, and oversight mechanisms.
- Fairness testing and bias assessment: Deploying organisations must be able to demonstrate that AI outputs do not unfairly discriminate.
- Explainability and transparency: Affected individuals and regulators must be able to understand how AI-driven decisions are made.
- Privacy and data protection: Personal data used in these systems must be collected, used, and retained lawfully.
The last three themes map directly onto this course’s three pillars: fairness, explainability, and privacy. Governance and accountability is a cross-cutting theme this course addresses within each pillar’s quantitative methods (the audit protocol in Chapter 2, documentation practices throughout) rather than as a separate, fourth pillar. Whether a jurisdiction enforces these themes through a single law, several sector regulators, or voluntary industry frameworks is a question of regulatory strategy. The underlying obligations converge.
Course Roadmap
Structure: principles and practice
Each topic is covered in two chapters, one focused on principles and conceptual frameworks that generalise across domains, and one focused on quantitative methods worked through on a real case study.
| Chapter | Title | Key methods |
|---|---|---|
| 2 | Fairness Principles | Fairness criteria and model designs (core focus); welfare analysis and audit framework (brief overview) |
| 3 | Fairness Practice | Measuring and enforcing fairness criteria, case study: French motor insurance data (R) |
| 4 | Explainability Principles | PFI, PDP, ALE, SHAP, LIME, regulatory expectations |
| 5 | Explainability Practice | Global and local model explanations, case study: XGBoost insurance pricing model (Python) |
| 6 | Privacy Principles | k-Anonymity, differential privacy, synthetic data, regulatory frameworks |
| 7 | Privacy Practice | Re-identification risk, k-anonymity, DP, synthetic data, case study: insurance micro-data (R) |
| 8 | Trade-offs, Integration, and Governance | Fairness–accuracy–privacy trade-offs, systemic risk, governance |
Three cases to keep in mind
Three widely-documented failures anticipate the three pillars ahead. Each is a preview of a specific chapter pair. Keep them in mind as a reason the tools in this course exist.
In 2016, ProPublica’s Machine Bias investigation examined COMPAS, a recidivism-risk tool used in U.S. courts (Angwin et al. 2016). Among defendants who did not reoffend within two years, Black defendants were flagged “high risk” at nearly twice the rate of white defendants. The tool’s vendor countered that COMPAS was well-calibrated. Among defendants who received the same risk score, the reoffense rate was similar across race.
Both sides had a point, and that is exactly the problem. A tool can satisfy calibration (sufficiency) and still produce a stark disparity in error rates (violate separation). Chapters 2–3 give you the vocabulary to name this trade-off precisely, and the model designs to decide which criterion your context demands.
When COVID-19 cancelled 2020 UK school exams, the regulator Ofqual used a standardisation algorithm to convert teachers’ predicted grades into final results, aiming to prevent grade inflation (Centre for Multilevel Modelling, University of Bristol 2020). The algorithm downgraded roughly 40% of teacher predictions, leaning heavily on each school’s historical results, so students at historically lower-performing (disproportionately state) schools were downgraded more than students at small, historically high-performing (disproportionately private) schools.
Neither students, schools, nor the government could get a satisfying answer to “why did this student get this grade?” before results day. Public backlash, including the Prime Minister calling it a “mutant algorithm,” forced a reversal to teacher predictions within days. Chapters 4–5 cover the explainability tools (PDP, SHAP) that could have shown, before deployment, how strongly school-history variables influenced the model’s predictions overall and for individual students, though they would not have settled the more fundamental question of whether school history should determine an individual student’s grade at all. That question belongs to the fairness lens in Chapters 2–3.
In 2018, it emerged that the political consultancy Cambridge Analytica had obtained data on roughly 87 million Facebook users, collected via a third-party personality-quiz app under the guise of academic research, then repurposed for political ad micro-targeting without those users’ knowledge or consent. The US FTC (Federal Trade Commission) fined Facebook $5 billion (Federal Trade Commission 2019) for violating an earlier commitment to clearly notify users when their data was shared with third parties.
The core failure was not a data breach in the technical sense, but data collected for one purpose being repurposed for an unrelated one. Chapters 6–7 cover exactly this boundary (contextual integrity, purpose limitation) and the privacy-enhancing techniques that make repurposing harder to do quietly.
A quantitative course
This is not a course about AI ethics as a philosophical discipline. It is a course about the quantitative tools that make ethical commitments measurable and enforceable.
By the end of the course, you should be able to:
- Fit and compare fairness-aware models and quantify the fairness–accuracy trade-off
- Interpret complex machine learning models using state-of-the-art explanation tools
- Assess and reduce re-identification risk in a tabular dataset
- Generate and evaluate synthetic data for privacy-preserving analysis
- Communicate technical results to non-technical stakeholders, including regulators
The principles chapters draw examples from insurance, lending, hiring, healthcare, and criminal-justice applications alike. The practice chapters apply the resulting methods to real insurance datasets as a consistent worked case study, using industry-relevant tools (R, Python, XGBoost, SHAP, sdcMicro, synthpop). The same methods can be adapted to a hiring, lending, or healthcare dataset, though the relevant outcomes, fairness considerations, and legal context will differ.
Connecting the pillars
The three pillars of the course are not independent. They interact in important ways that will be explored throughout.
An insurer introduces telematics-based pricing using GPS and accelerometer data from a smartphone app. Telematics-derived rating factors may include distance driven, time of day, speeding, rapid acceleration, and harsh braking.
- Fairness: do these telematics-derived factors act as proxies for protected attributes such as age, gender, or socioeconomic status?
- Explainability: can the insurer explain to a policyholder which telematics-derived factors contributed to their premium or renewal-premium increase?
- Privacy: does the insurer have the legal basis to collect continuous location data? Does it share data with third parties? Can policyholders request deletion?
Each pillar generates distinct obligations, but a complete responsible AI framework must address all three. The same three-way tension appears in workplace productivity-monitoring software (fairness in performance scoring, explainability of automated flags, privacy of continuously logged activity) and in health wearables feeding into insurance or employer wellness programs.
Recommended reading
- Huang (2025): ethical AI lifecycle framework used throughout this chapter
- Leek and Peng (2015); Peng and Matsui (2015): the question-types framework and characteristics of a well-posed data science question
- Barocas and Selbst (2016): foundational legal and technical treatment of algorithmic disparate impact, general to any automated decision
Chapters 2–7 each provide their own recommended reading specific to fairness, explainability, and privacy.