Slides — Chapter 1

Associate Professor, Risk and Actuarial Studies, UNSW Business School
feihuang@unsw.edu.au · feihuang.org
Her research and teaching focus on responsible AI, insurance, and data-driven decision-making that is accurate, interpretable, and equitable.
2-hour session, five parts, five discussion breaks
| Time | Part |
|---|---|
| 0:00 – 0:20 | Why Responsible AI? |
| 0:20 – 0:40 | Six principles of AI ethics |
| 0:40 – 1:05 | The ethical AI lifecycle |
| 1:05 – 1:15 | Break |
| 1:15 – 1:45 | Regulatory context |
| 1:45 – 2:00 | Course roadmap |
By the end of this chapter, you should be able to:
Responsible AI: designing, deploying, and governing AI so that automated decisions are fair, explainable, and privacy-respecting, not just accurate.
Note
Insurance recurs as a worked example, but the principles apply to any consequential automated decision: hiring, lending, healthcare, criminal justice.
Responsible AI is not about slowing innovation — it is about making innovation defensible.
No single field is sufficient on its own:
It also needs collaboration across stakeholders: customer advocates, regulators, and industry practitioners, and across professions within a single firm: actuaries, data scientists, lawyers, risk officers, business leaders.
Illustrative example: hidden proxy discrimination
US insurers have used credit-based insurance scores since the early 1990s. The scores are genuinely predictive of claims cost.
A 2007 FTC study found the score is far from race-neutral. It placed over 25% of Black consumers in the lowest, most expensive score band, against 3% of white consumers (Kiviat 2019).
Removing race as an input wouldn’t have fixed this. Credit history already tracks it.
Healthcare
A widely used US algorithm allocated care-management resources by predicted cost rather than predicted illness, systematically under-referring Black patients, who historically incurred lower costs for the same level of need (Obermeyer et al. 2019).
Hiring
Amazon scrapped an internal hiring tool after finding it penalised résumés containing the word “women’s,” a pattern learned from a decade of mostly male submissions (Dastin 2018).
Credit
Apple Card’s credit-limit algorithm drew a New York regulatory investigation after customers reported women receiving lower limits than their husbands despite similar finances, though the investigation found no fair-lending violation (New York State Department of Financial Services 2021).
China: e-commerce
Platforms charging loyal returning customers more than new customers for the same product, dàshùjù shāshú (“big data exploiting familiar customers”), became common enough to prompt an explicit ban in the 2022 Algorithm Recommendation Provisions (Cyberspace Administration of China 2022).
Think of an automated decision system you’ve encountered: a loan, a job application, an insurance quote, a hiring screen.
What data might it use as an unintentional proxy for a protected attribute (a characteristic like race, gender, or age that anti-discrimination law protects)?
Take a moment to think it through, then we’ll take a few answers.
Credit and lending
Postcode can proxy for race, a legacy of historical redlining. Employment gaps can proxy for gender, from career breaks tied to childcare.
Hiring
Graduation year can proxy for age. Specific résumé wording can proxy for gender, as with Amazon’s tool penalising “women’s.”
Insurance pricing
A credit-based score can proxy for race, as in this chapter’s own worked example. Vehicle engine size and mileage can proxy for gender and age, though each also carries genuine risk signal, which is what makes them harder to simply exclude.
“Proxy-ness” is a matter of degree, not a yes/no flag.
This course develops three of these six quantitatively: fairness, explainability, privacy. Reid Blackman calls this same trio AI’s “Big Three” ethical risks (Blackman 2022).
A similar cast of stakeholders recurs across all three pillars: the people affected by the decision, the regulators who oversee that domain, and the organisation deploying the system. What differs is the question each pillar asks.
| Pillar | Core question |
|---|---|
| Fairness | Does the model treat people equitably? |
| Explainability | Can decisions be understood and justified? |
| Privacy | Are personal data used appropriately? |
How do we operationalise “fairness” or “explainability” in a way that is measurable, auditable, and defensible?
| Principle | Covered in |
|---|---|
| Fairness | Ch 2–3 |
| Explainability | Ch 4–5 |
| Privacy | Ch 6–7 |
| Accountability | Ch 2, 4, 8 |
| Contestability | Ch 2, 4–5 |
| Stability & robustness | Ch 8 |
Of the six principles, which do you think is hardest to turn into something measurable and auditable, and why?
Most commonly nominated: accountability and contestability
Accountability is an organisational-structure question (is responsibility clearly assigned?), not a property of the model, so it’s audited through process evidence rather than a statistical test. Contestability has no single metric either. It’s measured through process indicators like the share of contested decisions overturned.
Also defensible: stability and robustness
Drift and adversarial-robustness tests exist, but operationalising “reliable over time” needs ongoing monitoring infrastructure, not a one-off number.
Hard to measure doesn’t mean unimportant. It’s exactly why fairness, explainability, and privacy, which already have a mature quantitative toolkit, are this course’s three pillars.
“The most frequent failure in data analysis is mistaking the type of question being considered.” — Leek and Peng (2015)
A common source of AI failure lies in problem formulation, not the model: the wrong question, the wrong outcome variable, the wrong sense of who’s affected.
Ethical risk lives at every stage of the lifecycle, not just at deployment.
The ethical AI lifecycle. Source: Huang (2025).
A practitioner’s role
Domain professionals are increasingly involved at every stage, not just development and validation, but governance, risk assessment, stakeholder communication. Responsible AI is a professional obligation.
Leek and Peng (2015): most analysis failures come from answering the wrong type of question, not answering the right one badly.
| Type | Asks |
|---|---|
| Descriptive | What happened? |
| Exploratory | What patterns exist? |
| Inferential | What can we infer about a population from a sample? |
| Predictive | What is likely to happen? |
| Causal | Does X cause Y? |
| Mechanistic | How exactly does the system work? |
Descriptive vs exploratory: how would you tell these two apart?
Inferential vs predictive vs causal: how would you tell these three apart?
Causal vs mechanistic: how would you tell these two apart?
Mistaking a descriptive or exploratory pattern for a causal one is an ethical failure, not only a technical one. A pattern that reflects historical bias or a proxy for a protected attribute (postcode, gender) can get treated as if it justifies risk, laundering that bias into the model.
A consulting firm has two teams working for two different clients, each asked a predictive question.
Team A works for a major supermarket, forecasting stock demand. No individual is priced or screened based on the output.
Team B works for an auto insurer, predicting claims for individual policyholders, to set their premiums.
For each team, what should drive model class, feature selection, and evaluation criteria? Why might the same question type lead to different choices?
Take a moment to think it through, then we’ll take a few answers.
Team A — retail demand forecasting
No individual is priced or screened, so accuracy is the dominant consideration. A complex, high-accuracy model is the right choice.
Team B — insurance pricing
Same question shape, applied to individuals, changes everything. Interpretability now matters as much as accuracy, feature selection needs scrutiny for proxies, and fairness metrics join the evaluation.
A jurisdiction-by-jurisdiction survey. Chapters 2, 4, and 6 develop the specific fairness, explainability, and privacy mechanisms in depth.
No federal AI law. States and sector regulators lead:
EU AI Act (2024) (European Parliament and Council of the European Union 2024): risk-based, applies across sectors.
High-risk (Annex III) includes life and health insurance risk assessment and pricing, employment, credit, education, law enforcement:
No standalone AI Act, existing sector laws apply, enforced in parallel by regulators such as ASIC (the Australian Securities and Investments Commission). The absence of a new AI law does not mean an absence of accountability.
Important
Obligations don’t transfer to a vendor. If a third-party model produces unfair outcomes, the regulator looks to the deploying organisation (Parra-Orlandoni and Carvão 2026).
| EU AI Act | Australia (2026) | |
|---|---|---|
| Legislation | Standalone AI-specific Act | No standalone AI Act (yet) |
| Coverage | Mandatory “high-risk” category | Existing laws apply to AI |
| Regulator | Single AI regulator | Multi-regulator (ASIC, APRA, OAIC…) |
| Enforcement | Prohibitions and fines | Standards-led, risk-based |
No new AI law ≠ no accountability. The regulators are already watching.
A governance failure
A licensee deployed an AI credit-default model, no AI strategy, no policies, no risk rating. Review ten months in found “limited understanding” of the third-party platform, “incomplete model documentation,” “poor governance.” Described as a “black box.” The licensee kept using it for months more.
Source: ASIC Report 798 (Oct 2024) (Australian Securities and Investments Commission 2024)
At what point does continuing to use a system you can’t explain stop being an operational gap and become an ethical failure?
Australia has the lowest AI trust of any country surveyed
Source: KPMG & University of Melbourne, Trust, Attitudes and Use of AI: A Global Study 2025 (KPMG and University of Melbourne 2025)
This is the public REP 798 is written for. A governance failure like the one on the previous slide is exactly what erodes the 30% further.
| Timing | Development |
|---|---|
| Oct 2025 | AI6 guidance released (Ch 8) |
| Dec 2025 | National AI Plan, mandatory guardrails shelved |
| Early 2026 | AI Safety Institute launched |
| Dec 2026 | Privacy Act ADM disclosure mandatory |
No comprehensive AI law yet, though the State Council’s 2026 Legislative Work Plan calls for “accelerating comprehensive legislation” (General Office of the State Council of the People’s Republic of China 2026). Sector rules cover most consequential use:
Note
FEAT/Veritas ask how to define, measure, justify, monitor fairness, the financial-sector counterpart to Chapter 2’s criteria, developed independently by a regulator.
If you were designing AI regulation from scratch, the EU’s single comprehensive law, or the US/Australia’s sector-by-sector approach?
What’s the trade-off?
Comprehensive law (EU)
Consistent definitions and obligations across sectors and member states, less regulatory arbitrage, one compliance standard for multinational firms. Costs: slow to negotiate, risks being too generic for sector-specific nuance, harder to amend as the technology moves.
Sector-by-sector (US/Australia)
Faster to respond to a specific, visible harm, such as NYC’s bias-audit law following hiring-tool harms directly. Rules fit existing sector regulators. Costs: gaps and inconsistency across sectors and states, and a tendency to regulate fastest where harm is most visible, leaving newer applications under-regulated until something goes wrong.
The trade-off: consistency and predictability vs speed and tailoring. Australia’s mix of existing sector law plus emerging cross-cutting guidance is itself a middle path between the two extremes.
| Ch | Title | Focus |
|---|---|---|
| 2 | Fairness Principles | Criteria, model designs |
| 3 | Fairness Practice | French motor insurance (R) |
| 4 | Explainability Principles | PFI, PDP, ALE, SHAP, LIME |
| 5 | Explainability Practice | XGBoost insurance model (Python) |
| 6 | Privacy Principles | k-Anonymity, DP, synthetic data |
| 7 | Privacy Practice | Insurance micro-data (R) |
| 8 | Trade-offs & Integration | Systemic risk, governance |
COMPAS recidivism scoring
ProPublica’s 2016 Machine Bias investigation (Angwin et al. 2016) found that among defendants who did not reoffend, Black defendants were flagged “high risk” at nearly twice the rate of white defendants. The vendor countered COMPAS was well-calibrated, same reoffense rate within each score band, across race.
Both sides had a point. A tool can be calibrated (sufficiency) and still violate error-rate parity (separation). Chapters 2–3 give you this vocabulary.
Ofqual’s 2020 grading algorithm
COVID cancelled exams. An algorithm converted teacher predictions into final grades (Centre for Multilevel Modelling, University of Bristol 2020), downgrading ~40%, leaning on each school’s history, so state-school students were downgraded more than students at small, historically high-performing private schools.
No one could get “why this grade?” answered before results day. Public backlash, including the Prime Minister calling it a “mutant algorithm,” forced a reversal within days. Chapters 4–5 cover the tools that could have quantified this beforehand.
Cambridge Analytica (2018)
Data on ~87M Facebook users, collected via a “personality quiz” under the guise of research, repurposed for political micro-targeting without consent. FTC (the U.S. Federal Trade Commission) fined Facebook $5B (Federal Trade Commission 2019).
Not a breach, but a repurposing. Data collected for one purpose, used for another. Chapters 6–7 cover this exact boundary.
By the end, you should be able to:
Illustrative example: the telematics insurer
GPS + accelerometer data → distance, time of day, speeding, acceleration, braking.
Of the three case studies today (COMPAS, UK A-levels, Cambridge Analytica), which failure would be hardest to fix with a purely technical solution, and why?
COMPAS
Has a real technical dimension, the calibration-vs-error-rate-parity impossibility result from Chapters 2–3, but is ultimately a policy choice about which fairness criterion to prioritise when base rates differ. Better modelling alone can’t resolve that.
UK A-level algorithm
Arguably the most technically fixable: the failure was a lack of transparency and no tested appeal channel before results day, both addressable with Chapters 4–5 tools.
Cambridge Analytica
The hardest to fix technically. A consent and purpose-limitation failure, not a modelling error, so no technical safeguard fixes it. It needs legal and organisational controls instead.
Most real failures need technical tools combined with governance and policy choices. That’s exactly Chapter 8’s theme.
Chapters 2–7 each have their own reading list.
Chapter 2: Fairness Principles
Bring one example (from any domain) of a decision you think might be unfair, and why.
