Imagine a company receiving hundreds of job applications and using a model to rank them. The system is fast, and its recommendations closely resemble past hiring decisions. As a prediction task, it seems to work.
One question remains: what if those earlier decisions already excluded equally capable people? The model can learn a decision very well without making it a decision we should repeat.
This example is fictional. It helps locate the problem without attributing an incident to a real employer. AI ethics is not a list of good intentions attached to a finished project. It asks what we turn into an objective, who bears the mistakes and who can challenge the outcome. A metric cannot answer on our behalf.
What does getting it right actually mean?
A responsible system needs more than accuracy. It can predict well while invading privacy, explain its decisions while discriminating, or satisfy one legal obligation while leaving ethical problems unresolved.
Fairness and non-discrimination require looking beyond an average score. For our hiring tool, I would examine which profiles it repeatedly rejects, how applications were collected and what the label “good candidate” means. Being hired does not itself prove someone was the best choice. Removing a sensitive attribute does not remove every trace of it: other features may act as proxies.
Privacy starts before training. Do we need every detail in a CV? Is indefinite retention justified? Replacing a name with a code is pseudonymization, not proof of anonymity. If the person remains identifiable, the data remains personal.
Transparency helps people know that AI is being used, for what purpose and with what limitations. Interpretability concerns understanding a model’s behavior. Explainability seeks a useful account of an outcome even when the model is not directly interpretable. Publishing source code does not automatically provide any of these to someone trying to understand a rejection.
Responsibility and accountability require identifiable roles and procedures. “The algorithm decided” does not identify who chose the data, approved its use or has authority to correct the outcome.
Social benefit and avoiding harm mean comparing usefulness with foreseeable damage. Saving time can matter; making an unfair rejection happen faster is not sufficient progress. Accessibility and resource consumption matter too. A simpler tool might solve the problem with fewer risks.
These principles can conflict. Collecting group information can help investigate unequal treatment while creating privacy risks. Choosing one word, “fairness” or “privacy,” does not settle the issue. We need to justify the data, identify a lawful processing route and protect it.
The legal framework is not one law of algorithms
Several rules can apply to the same project. The AI Act addresses AI systems and models; the GDPR addresses personal-data processing. Employment, consumer protection, copyright and product safety can introduce further requirements depending on the use.
The practical question is not which law we prefer, but which rules apply to this activity and how they fit together. Using an external model does not remove the obligations of the organization building or operating the application.
We must also distinguish legislation from technical standards and ethical recommendations.
The legal content was reviewed on 5 October 2026. This is an educational introduction, not a compliance opinion for a particular product. Scope, exceptions and deadlines must be checked against the applicable legal texts.
Under the AI Act, purpose matters
The AI Act is Regulation (EU) 2024/1689, not a proposal awaiting adoption. Its approach is risk-based: a music recommendation tool and a system influencing access to employment do not receive identical treatment.
These distinctions offer an initial map:
| Situation | What to understand |
|---|---|
| Prohibited practices | Some uses cannot be made acceptable simply by adding controls. |
| High-risk systems | Their purpose can trigger specific requirements before and during use. |
| Transparency obligations | Certain interactions or content require disclosure of their artificial nature. |
| Other uses | They do not automatically trigger all those obligations, but remain subject to applicable rules. |
This is not four boxes that classify every product. Obligations can overlap, and general-purpose models have a separate layer of rules.
Prohibitions include certain harmful manipulation and social-scoring practices. Biometric uses also face specific restrictions. “All facial recognition is prohibited” is too broad: practice, context and legal exceptions matter. A permitted high-risk system and a prohibited practice are not the same category.
Recruitment and candidate evaluation are among the uses covered by Annex III. Classifying a particular application requires considering its intended purpose and Article 6 conditions. “It only uses a small model” or “a person makes the final decision” does not settle that classification.
The AI Act text sets out these distinctions. Preparing a high-risk system includes risk management, data governance, documentation, records and effective human oversight. It does not amount to a promise that the model will never make a mistake.
A chatbot and a foundation model are different things
A customer-service chatbot needs to examine obligations to disclose interaction with AI. For synthetic content, Article 50 distinguishes provider and deployer obligations, with conditions and exceptions. It does not demand the same visible notice for every text that received any AI assistance. The Commission’s transparency guidelines explain the details.
General-purpose AI models, or GPAI, have provider obligations of their own, including documentation and copyright matters. Models with systemic risk require additional measures. This layer does not replace assessment of the application built on the model. The Commission’s overview helps separate the two.
The obligations did not all start on one day
Entry into force differs from application of obligations. The timetable has also changed: Regulation (EU) 2026/1744, the AI Omnibus, entered into force on 27 July 2026.
| Milestone | Reference date |
|---|---|
| Application of the initial prohibitions | 2 February 2025 |
| Application of the general-purpose model regime | 2 August 2025 |
| General application, including transparency obligations, subject to exceptions and transitions | 2 August 2026 |
| Application of the main high-risk requirement and obligation blocks for Annex III systems | 2 December 2027 |
| Application of those blocks to Article 6(1) systems linked to Annex I | 2 August 2028 |
This does not cover every transition or obligation. Previously marketed models and particular measures have their own conditions. Before a launch, I would check the updated official timetable, rather than an old infographic presenting the entire regulation as applicable from August 2026.
The GDPR still applies when the model comes through an API
Where personal data is processed, Regulation (EU) 2016/679, the GDPR, remains relevant. It does not require a neural network, and calling personal information a “prompt” does not make it stop being personal information.
We need a lawful basis, purpose and data limitations, information for people and appropriate protection. Consent is not the only lawful basis, nor blanket permission for any reuse. Article 6 provides several bases, while special-category data also requires examining Article 9. The GDPR text published by Spain’s official gazette contains the relevant provisions.
For the recruitment tool, I would give the privacy team a specific data-flow description: what leaves the organization, who receives it, why it is retained and whether international transfers occur. Purchasing an API does not automatically answer those questions.
Article 22 concerns solely automated decisions with legal or similarly significant effects. It has exceptions and safeguards; it does not prohibit every model recommendation. Someone clicking “accept” is not necessarily meaningful human review. The automated-decision guidelines hosted by the AEPD call for meaningful intervention by someone competent and authorized to change the outcome.
A data protection impact assessment, or DPIA, is required where processing is likely to create a high risk to people’s rights and freedoms, under Article 35. It differs from the AI Act Article 27 fundamental-rights impact assessment, which applies to specified deployers and uses rather than automatically to every AI project. They can be coordinated; they are not one assessment with two names.
Other rules can enter the discussion
In Spain, Organic Law 3/2018, the LOPDGDD, complements the GDPR framework. Organizations cannot simply choose whichever regime feels more convenient.
The Digital Services Act, or DSA, imposes obligations on intermediary services and platforms within its scope, including transparency around recommender systems. It is not a generic law applying identically to every chatbot. The Commission’s DSA questions and answers explain its reach.
Copyright matters when collecting training material and when using documents in RAG. An internet-accessible file is not automatically available for unrestricted reuse. Spain’s Royal Decree-law 24/2021 addresses text and data mining under specified conditions and possible rights reservations. “The model can read it” is not a substitute for checking licenses.
Sector rules also matter: employment, health, products and financial services. Calling a tool AI does not erase rights that already exist in those domains. A system deciding about candidates deserves more than a technology checklist.
ISO and ethical principles are useful, not a free pass
ISO/IEC 42001:2023 sets requirements for an AI management system, helping organize policies, responsibilities, risks and continual improvement. ISO/IEC 38507:2022 addresses organizational governance implications of using AI.
They are not legislation in themselves, or automatic declarations of compliance for every application. Enforceability can depend on contracts or incorporation into particular requirements. Management-system certification does not establish that every prediction is fair.
The UNESCO Recommendation on the Ethics of AI offers another layer: human rights, proportionality, oversight and accountability as guidance. An ethical recommendation does not carry the same obligations and penalties as a regulation.
Their value lies in turning them into verifiable work. Transparency needs understandable information. Accountability needs an identifiable person or team able to respond. Oversight needs someone able to stop the process rather than merely watch it.
Back to the applications
Before using the recruitment system, I would record what it does and does not do. Does it summarize CVs, score people or automatically reject them? These are different activities even if they use the same API.
Then I would examine data sources, labels and results across relevant groups, without treating a statistical difference as proof of unlawful discrimination on its own. Technical evaluation raises questions; it does not replace every other assessment.
I would design a review that can contradict the model, a way to correct information and proportionate records of what happened. Traceability does not mean keeping every CV and conversation indefinitely. Records also need to respect minimization and retention limits.
Finally, I would agree what happens when the provider changes its model, a pattern of errors emerges or the tool starts serving a different purpose. Initial approval cannot be the last time anyone examines its consequences.
For me, this is the practical part of AI ethics. Not declaring our model responsible, but showing how we check it, which limits we accept and what we do when someone tells us the system got them wrong.

Found this useful? If you would like to support this space, you can buy me a coffee.
Buy me a coffee Optional support through PayPal. You choose the amount.

