Data Protection Matters
← All insights AI & Governance

Why Ethical AI Is an Engineering Problem, Not Just a Policy One

When we talk about making AI ethical, the conversation usually drifts toward regulation, compliance frameworks, and governance boards. And those things matter. But here is the thing most people miss: the decisions that determine whether an AI system is fair, transparent, or safe are made long before any policy document gets written. They are made by engineers, during design and development.

This idea got a sharp articulation at QCon London 2026, where Clara Higuera, the Responsible AI Program Lead at BBVA, argued that ethical AI is fundamentally an engineering problem. Not a legal one. Not a PR one. An engineering one. And if you are building AI systems today, that distinction changes everything about how you should be working.

The Governance Gap

Most organizations treat AI ethics as a governance exercise. They publish principles, form review boards, and write policy documents. These are valuable, but they share a common flaw: they operate after the fact. By the time a governance board reviews a model, the engineering team has already chosen the training data, selected the features, defined the optimization targets, and decided how the system handles edge cases. Those choices bake in the ethical character of the system. A policy review can flag problems, but it cannot easily undo them.

Think of it this way: if your AI model produces biased loan decisions because the training data underrepresented certain demographics, no amount of after-the-fact governance fixes that. You need to catch it during data preparation. That is an engineering task.

What Engineering Ethics Actually Looks Like

If we accept that ethical AI is an engineering discipline, what does the day-to-day work look like? Higuera outlined several dimensions that engineering teams should treat with the same seriousness as uptime or latency.

Fairness is the one that gets the most attention, and for good reason. There are now over 70 established metrics for evaluating bias in AI systems, from statistical parity to disparate impact ratios. Tools like IBM's AIF360 let teams measure fairness during model training, not just after deployment. The point is not to pick one metric and declare victory. It is to decide which fairness properties matter for your specific use case and then test for them the same way you would test for accuracy or response time.

Transparency is next. If your system makes a decision that affects someone, can you explain why? This is not just a nice-to-have anymore. The EU AI Act requires it for high-risk systems, and regulators in finance and healthcare are increasingly demanding it. From an engineering perspective, this means choosing model architectures that support explainability, building logging and audit trails into your pipeline, and creating interfaces that surface decision factors to the people who need to understand them.

Then there is security. AI systems face a class of threats that traditional software does not, including adversarial attacks that manipulate inputs to trick models, data poisoning during training, and model extraction through repeated querying. Responsible engineering means red-teaming your models the same way you would pen-test a web application.

Treating Fairness Like Performance

Here is the mental shift that makes all of this practical: treat ethical properties the same way you treat performance metrics. You would never ship a system without load testing it. You would never deploy a database without monitoring query latency. So why would you deploy an AI model without measuring its fairness across demographic groups?

In practice, this means adding fairness evaluations to your CI/CD pipeline. It means setting thresholds for bias metrics the same way you set thresholds for error rates. It means running explainability checks before every release, not as an afterthought during an annual audit. And it means building monitoring dashboards that track model behavior in production across different user groups, so you catch drift before it causes harm.

Projections from recent industry surveys suggest a 45 percent rise in ethics dashboard adoption by 2026, which signals that the industry is starting to take this seriously. Real-time monitoring of ethical properties is becoming as standard as real-time monitoring of system health.

Why This Matters Now

The regulatory landscape is accelerating. The EU AI Act is rolling out enforcement timelines. Multiple US states are introducing AI-specific legislation. A recent Malwarebytes survey found that 90 percent of people do not trust AI with their personal data. Public trust is low, and the window to build it is narrowing.

Organizations that treat ethical AI as someone else's problem, whether legal, compliance, or PR, will find themselves scrambling when regulations tighten or when a biased system makes headlines. Organizations that embed ethical thinking into their engineering culture will be ahead of the curve, not because they followed the rules, but because they built better systems from the start.

The Bottom Line

Ethical AI is not a destination you reach by signing a set of principles. It is a practice you build into every sprint, every code review, and every deployment. The engineers who design these systems hold more power over their ethical outcomes than any policy board ever will. It is time we started acting like it.

If your organization is building or deploying AI, start asking your engineering teams a simple question: what are we measuring, and what are we missing? The answer might surprise you, and it will almost certainly make your systems better.

This article is general information from Data Protection Matters, not legal advice. We aim to be accurate, but it may contain errors or omissions and we give no warranty as to its accuracy or completeness. It reflects the position at the time of writing; privacy laws change and vary by jurisdiction. Verify against official sources, seek advice for your own situation, and rely on it at your own risk.

Facing this in your own organization? We run privacy, practically, with experts, a methodology, and Privacy Nexus.

Talk to us