1 August 2026
Artificial intelligence has moved from science fiction into the center of our daily lives. It decides which loan applications get approved, which resumes get shortlisted, which neighborhoods get policed more heavily, and even which patients get flagged for follow-up care. The promise is efficiency and objectivity. The reality is that AI systems are built by humans, trained on human data, and deployed in human institutions. So they inherit our biases, our blind spots, and our shortcuts. Left unchecked, they can amplify discrimination at a scale and speed that no individual human decision-maker could ever match.
That is where policy comes in. Not as a buzzword, not as a compliance checkbox, but as the actual mechanism that forces accountability, transparency, and fairness into systems that otherwise have none. Policy is the difference between hoping AI does no harm and designing it so that harm is structurally difficult to commit.

The first and most common source is biased training data. If you train a hiring model on ten years of resumes from a company that historically favored male candidates, the model learns to favor male candidates. It does not reason about why. It just sees patterns in text, in education history, in job titles, and it latches onto correlations that happen to track with gender. The model is not malicious. It is just a mirror. But mirrors do not forget what they reflect.
The second source is biased labels. Sometimes the data looks fine, but the ground truth is skewed. Consider a predictive policing system trained on arrest records. Arrest records do not reflect crime rates. They reflect which communities get policed. If a city has historically concentrated patrols in minority neighborhoods, those neighborhoods show up with more arrests, and the model dutifully predicts more crime there. The model is not learning about crime. It is learning about the police department's own past behavior.
The third source is biased feature selection. Even with clean data, the choice of which variables to include can encode discrimination. A credit scoring model that includes zip code as a feature will indirectly penalize applicants from predominantly minority areas, even if race is never explicitly mentioned. The model has found a proxy for race, and proxies are often more stubborn than direct discrimination because they are harder to spot and easier to defend.
The fourth source is deployment bias. A model can be perfectly fair in the lab and still cause discrimination in the real world because of how it is used. If a hospital uses an AI triage system that was trained on data from affluent patients, it may systematically underestimate the health risks of lower-income patients who lack access to regular checkups. The model is not biased in its training data. It is biased in its application context.
None of these sources are exotic. They are the normal, everyday ways that machine learning systems fail. And none of them will be fixed by better engineering alone. They require policy.
Consider the pressure to ship a product faster than a competitor. Consider the incentive to maximize user engagement, even when that engagement comes from recommendation algorithms that amplify extreme content. Consider the simple fact that fairness metrics often conflict with profit metrics. A model that approves fewer loans for minority applicants is not just discriminatory. It is also cheaper, because it rejects more risky applications. A model that shows different job ads to men and women is not just biased. It is also more efficient at targeting, because it optimizes for click-through rates.
When ethics and profit collide, ethics tends to lose unless there is an external force that changes the calculation. That external force is policy. It can be legislation, regulation, industry standards, or contractual requirements. But it has to be binding. It has to have teeth. And it has to be enforceable.

This sounds obvious, but most AI systems are deployed without any formal assessment at all. They are built, tested for accuracy, and shipped. Accuracy is not fairness. A model can be 99 percent accurate for the majority population and 70 percent accurate for a minority group, and nobody will notice unless someone specifically checks for it. An impact assessment makes that check mandatory.
The European Union's proposed AI Act takes this approach for high-risk systems. It requires conformity assessments, risk management systems, and post-market monitoring. It is not perfect, and it has been criticized for being too vague in places. But it represents a real shift from voluntary self-regulation to enforceable obligations.
This is not about publishing trade secrets. It is about creating a baseline of accountability. If a model is trained on data from one region, that should be known. If it was trained on historical records that predate civil rights legislation, that should be known. If the data contains proxies for protected characteristics, that should be known.
Some companies already do this voluntarily. The model cards framework, popularized by researchers at Google, provides a structured format for documenting model performance across different demographic groups. But voluntary documentation is inconsistent. Policy can make it a legal requirement, with penalties for omission or misrepresentation.
These audits should not be one-time events. Models change, data changes, and the populations they serve change. An audit at deployment time tells you very little about the system's behavior two years later. Policy should require periodic audits, with results made available to regulators and, where appropriate, to the public.
The challenge is that independent auditing is still an immature field. There are no universal standards for what constitutes a fair model, and auditors themselves may have biases. But the solution to imperfect audits is not to abandon them. It is to develop better standards, which itself is a policy task.
More importantly, there must be a mechanism for affected individuals to challenge decisions made by AI. If a loan is denied, a tenant is evicted, or a patient is denied coverage based on a model's output, the person affected should have the right to know why and to appeal.
This is not just a matter of justice. It is also a practical mechanism for detecting bias. The people who interact with AI systems are often the first to notice when something goes wrong. If there is no channel for them to report problems and get a meaningful response, the problems will simply persist.
There was no federal policy requiring impact assessments or bias audits for these systems. Individual cities made their own decisions, often based on vendor marketing rather than independent evaluation. When problems became public, the response was not to fix the systems but to quietly discontinue them in some cities. The damage, however, had already been done. Communities had been over-policed, and trust in law enforcement had been further eroded.
The lesson is that policy cannot be reactive. It has to be in place before the technology is deployed, not after the harm is documented.
These laws were written long before modern machine learning, but they have proven adaptable. Regulators have issued guidance on how they apply to algorithmic decision-making. Lenders are required to conduct disparate impact analysis, which measures whether a lending policy has a disproportionately negative effect on a protected group, even if there is no intent to discriminate.
The system is not perfect. There are gaps in coverage, and enforcement has been inconsistent. But the existence of a legal framework has forced lenders to think about fairness in ways that they would not have otherwise. It has also created a market for fairness consultants and audit tools, which is a sign that policy can drive innovation rather than stifle it.
For high-risk systems, the Act requires risk management, data governance, technical documentation, transparency, human oversight, and accuracy and robustness standards. It also requires conformity assessments before deployment and post-market monitoring afterward.
The Act is not without critics. Some argue that it is too broad and will burden small companies. Others argue that it is too narrow and does not address the full range of AI harms. But it represents a genuine attempt to create a comprehensive policy framework, and it will likely influence regulations in other countries.
Bias is a systems problem. It involves data collection practices, organizational incentives, cultural assumptions, and power dynamics. A fairness algorithm cannot fix a company that refuses to gather demographic data because it is inconvenient. It cannot fix a deployment team that ignores audit results because the model is profitable. Policy is what forces organizations to address those non-technical dimensions.
But more data can also make things worse. If the data reflects historical discrimination, more data means more of that discrimination is encoded. If the data is collected in a biased way, more data amplifies the bias. Policy should require that data collection itself be examined, not just the size of the dataset.
But the evidence from other industries suggests that well-designed regulation can coexist with innovation. The automotive industry has thrived despite safety regulations. The pharmaceutical industry has produced life-saving drugs despite clinical trial requirements. The financial industry has developed complex products despite disclosure rules.
The key is to regulate outcomes and processes, not specific techniques. Require that models be tested for bias. Require that results be documented. Require that there be a mechanism for redress. But do not dictate which algorithms should be used or which fairness metric should be adopted. That flexibility is what allows innovation to continue within a framework of accountability.
If fairness is only considered after a model has been built, the fixes are usually superficial. You end up applying a patch to a system that was fundamentally flawed from the start.
For a hiring system, you might care about whether the selection rate is similar across groups. For a medical diagnosis system, you might care about whether the false negative rate is similar across groups. The important thing is to measure multiple things and look at the trade-offs. A model can be fair on one metric and deeply unfair on another.
International coordination matters because AI systems cross borders. A model trained in one country may be deployed in another. Data collected in one jurisdiction may be processed in another. Without international standards, there is a risk of a race to the bottom, where companies locate their operations in places with the weakest regulations.
That does not mean that every country should have identical laws. Different societies have different values and different legal traditions. But there should be a baseline of agreement on fundamental principles: transparency, accountability, non-discrimination, and the right to human review of consequential decisions.
You can also be more discerning about the technology you use. When you choose products and services, consider their track record on fairness. Support companies that are transparent about their AI practices. Avoid those that are not.
That policy will not be perfect. It will be messy, contested, and sometimes slow. There will be unintended consequences, and there will be loopholes that need to be closed. But the alternative is a world where automated systems quietly institutionalize discrimination, and where the people who are harmed have no recourse and no explanation.
We have the technical knowledge to build fairer systems. We have the legal knowledge to design better regulations. What we need now is the collective will to put them into practice. The stakes are high, but the path is clear. It is time to walk it.
all images in this post were generated using AI tools
Category:
Tech PolicyAuthor:
Reese McQuillan