From principles to practice — and why principles alone failed
Lesson 5 of 5 in Core Ethics Principles and Trustworthy AI.
By 2019 nearly every major AI company had published principles. Then researchers started checking behaviour against them, and a new term entered the vocabulary: ethics washing — the performance of ethics as a substitute for its practice.
The case studies wrote themselves. Google announced an external AI ethics council (ATEAC) in March 2019 and dissolved it nine days later amid controversy over its composition; the year after next, it fired Timnit Gebru and Margaret Mitchell, the co-leads of the ethical-AI team whose job was internal challenge. Across the industry, principles with no assessment behind them, ethics boards with no authority, and "responsible AI" teams discovered organizational gravity: a principle that cannot block a launch is a press release.
The lesson the field drew was not that principles are worthless — it is that principles are the first stage of a pipeline, and unaccompanied first stages accomplish nothing. That pipeline is, in one picture, the story of AI governance from 2016 to today.
The operationalization pipeline
- Principles
Shared values in prose: OECD, UNESCO, HLEG, corporate charters. Necessary consensus — enforceable by no one.
- Frameworks & standards
Principles become checkable properties and processes: NIST AI RMF characteristics, ISO/IEC 42001 management requirements, testing standards.
- Assessments & audits
Someone verifies: impact assessments, bias audits, conformity assessments, certification. Evidence replaces assertion.
- Law & enforcement
Legislatures make the properties mandatory and attach penalties: EU AI Act, state statutes. Regulators and courts close the loop.
- Changed behaviour
The test of the whole pipeline: do launch decisions, designs, and incident responses actually differ? If not, everything upstream was theatre.
The pipeline’s constructive form is ethics by design: build the principles into the artifact while it is being made, rather than auditing them in afterwards — fairness criteria chosen at problem-framing, privacy budgets set at data collection, oversight interfaces designed with the model, documentation generated alongside training. Every lifecycle stage you learned earlier has a principle attached to it; ethics by design just means attaching them on time.
But operationalizing principles surfaces something the charters glossed over: the principles conflict with each other, and pretending otherwise is its own form of ethics washing. Real governance is the discipline of making these trade-offs explicitly, documenting who decided, and revisiting them — instead of letting the loudest team win silently.
Transparency vs privacy, security, and IP
Publish the training data and you may expose personal information inside it. Reveal decision logic in detail and you hand fraudsters a gaming manual and competitors a blueprint — the trade-secrets defence regulators meet daily. Resolution pattern: tiered disclosure — full access for auditors and regulators under confidentiality, meaningful explanation for affected individuals, aggregate documentation for the public. The EU AI Act is built on exactly this tiering.
Fairness vs accuracy — and vs fairness
Imposing a fairness constraint usually costs some raw predictive accuracy — though the cost is often smaller than vendors claim, and "accuracy" measured on biased labels is a rigged baseline anyway. The deeper conflict is fairness vs fairness: the impossibility theorem means even a maximally well-intentioned team must sacrifice one fairness notion for another. The governance response is not to deny the trade but to force it into the open: which metric, chosen by whom, justified how.
Oversight vs efficiency (and vs safety itself)
Human review costs speed and money — the entire business case for automation pushes against it. Sometimes oversight even fights safety: an autonomous braking system that waits for human approval defeats its purpose. The resolution is calibrated oversight — match the human role to stakes and tempo (the autonomy spectrum), and where in-the-moment review is impossible, compensate with design-time testing and post-hoc audit.
Innovation vs precaution
Move fast and someone gets hurt; wait for certainty and the benefits (and the market) go elsewhere — the pacing problem in values form. Regimes answer differently: the EU leads with precaution (ex ante obligations), the post-2025 US leads with innovation (ex post enforcement), and instruments like regulatory sandboxes try to buy both. There is no neutral answer; there are only explicit ones.
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.