Go back

AI Governance: A conversation with Reid Blackman

35m 20s

AI Governance: A conversation with Reid Blackman

The podcast features Reed Blackman discussing AI principles and ethical AI development. While principles are foundational, they are insufficient without additional frameworks and support for developers. Companies must establish policies, procedures, and governance structures to ensure ethical AI deployment. Reed argues that explainability is not always necessary for ethical AI, emphasizing reliability and accuracy instead. He distinguishes between transparency and explainability, noting they are independent concepts. Informed consent regarding AI in healthcare poses challenges, with the need for clarity on when disclosure is necessary. Reed advises against blanket bans on AI use, highlighting the importance of context-specific considerations in AI deployment.

Transcription

7536 Words, 42790 Characters

[MUSIC] Welcome to the Voices in Bioethics podcast. I'm Anne Zimmerman and today we have Reed Blackman as our guest. Reed is CEO of Virtue Consultants and experienced in a broad range of tech ethics. He is the author of the book and now also the podcast called Ethical Machines, and his writing can also be found at his substackreadblackman.substack.com. Welcome to the Voices in Bioethics podcast. Thanks for having me again. Thanks for being here. We'll be discussing AI principles and what it means to develop AI that complies with ethical standards and generally how to deploy and use AI ethically. So Reed, to get started, do principles matter? Yes, they are necessary but not sufficient. Just think about medical ethics. You've got the three principles in the Belmont report, justice, respect for persons and beneficence and non-maloficence. But okay, that's good. It's a great start but you don't end there. Now you actually have things like requirements around informed consent and you have IRBs and you have that sort of thing. So the principles are important and they're a foundation, but they are far from the entire building if you like. You got to do a lot more with them. So one thing that we see a lot of is companies will articulate some high-level principles and they stop there and they don't know how to make progress. So yes, they're important but they are just the very beginning. So do you find that AI developers tend to meet the requirements of the principles and frameworks that are relevant to AI? Or do you find that they create their own guidelines to follow those principles? Or how are the principles incorporated in the actual behaviors? They're usually not, it depends. So the developers, if you like frontline developers, the frontline data scientists, engineers, they're going to do what their bosses tell them to do, more or less. So it's not like, oh, let's create these guardrails or let's create these guidelines or these values or these principles, whatever, and tell the developers about them and then they're going to go do it. And that's not how this works. They are usually employees of very large companies. They have a job to do. They have deadlines. They have certain requirements by their boss and their boss's boss and their boss's boss's boss. They have certain kinds of financial incentives and employee reviews that they want to do well on. And so the question is not first and foremost. I don't think, do we have the things to tell the developers? Yes, we do. But are the developers in an environment in which their boss and their bosses, boss and their bosses, bosses, bosses, etc. support them in doing it, require them to do it, create the environment in which they can plausibly pull it off? Is it part of their employee performance review? Is it part of how they think about incentives? Is it part of their role and responsibilities? Is it part of their workflows, their daily workflows? All those things are not up to the employee. They're not up to the average developer. And so they're up to the people who are in charge of those developers. So do most developers do it only on the condition that the company for which they work requires them to? I mean, of course, there are some exceptions. And most companies do not require them to do it. In your consulting and your experience, do you offer strategies to get companies to do some of these things, to make sure that the AI they create is kind of created ethically and then deployed ethically? Yeah. I mean, that's the core of my business is working with them to explain to them what's needed, develop what they need. So for instance, they're going to need policies, they're going to need procedures, they're going to need metrics, they need training, they need to figure out what the roadmap is for rolling this program out. They need to figure out who's within the scope of that program. There's lots of things to figure out. And so we work with them on all those fronts. That said, if you're talking about Fortune 500 companies, these are big, massive things and there's lots of political infighting. And so you could design it perfectly. And then the next question is, okay, we've designed it. We know what it should look like. Can we actually implement it? And that's a whole other thing. You need dozens, hundreds, ultimately you need thousands of people aligned with what that design looks like. And that's a big lift. So this is a big and very slow lift. But yeah, it's exactly the kind of work that we do for clients. And do you have any general recommendations for institutions writing their own governance policies? Do you have some things that you find you're saying to all of the clients? Some kind of general guidelines? I mean, there's lots of things. One thing that we already mentioned, actually, which is really big is a lot of our clients will already have something like a list of principles. And they're the usual suspects that are on everyone's list. So you get fairness and privacy and transparency, accountabilities and explainability. Human in the loop is sometimes oddly in there as though human in the loop were an ethical principle. That's an odd, odd thing. But one thing that we're trying to get them to do, number one, is make sure that they get all the ethics in there that needs to be in there. Because with a lot of companies, they take the word ethics and they translate it to the word fairness as though the set of ethical considerations were exhausted by the set of fairness considerations. Of course, they're not. So that's one kind of thing. And then the second really big thing that we tell everyone is, how do these values connect to the procedures? What are you going to do about it? You can say, oh, yeah, we're for fairness. We're really committed to it. But what are those procedures that you will do, that you will implement, that you'll have a policy about so that this actually gets at the end of the day gets implemented. And most of them don't have those procedures in place. They have these very high-level values. Then they have these really fine-grained risk assessments for particular AI models. And there's not much in between. And so getting a policy that actually has that kind of substance, where it's values connect to procedures is very important. And then another element that we always try to make part of the policy is something about the governance structure of how this is all going to work. So that there are certain kinds of requirements for escalating high-risk cases, that that high-risk case or those high-risk cases will be reviewed by the appropriate body, call it a risk board, call it an ethics board, call it a responsible AI board, whatever it doesn't matter. And saying a little bit about the scope and authority of that board is also a crucial element of that policy. So are those boards, are companies starting to create boards? Are they a little bit like an IRB? Yeah, I think that's fair to say. They don't deal with every case. So with an IRB, it's every case of research on human subjects. With for-profit tech companies or sorry, large companies, it's not literally every single AI that they're doing. Most of a very common strategy, it's not the only one, but a very common strategy is to have a kind of risk assessment that everyone has to perform. So those frontline developers, those data scientists, they perform some kind of risk assessment. And if it reaches a certain threshold, then it gets escalated to the ethics committee or the IRB, if you want to call it that or whatever. But that's pretty standard, but it's only going to be the high-risk cases. So then for things that maybe are designed to prevent risk, do you suggest separate little sub-polices, like policies covering data collection or data retention or even data disposal? Or do you think that different buckets in these large companies, there are different departments that handle these things? How do you envision that? Privacy, for example, seems to kind of swallow the whole thing and maybe deserves a separate attention. Yeah, the privacy people would love for it to swallow everything, but it's misguided, just as much as thinking fairness exhausts all the ethical considerations. Privacy does not exhaust all the ethical considerations. So there's not the answer to your question as to what should companies do. So first thing to say is they already have various policies as regards to the handling, collection, usage of data. But those policies already exist. So one thing that's sort of partial of our work is, all right, what are the policies that you've already gotten place? And what are the gaps? All right, so we don't want to have to recreate policies and be redundant if we can avoid it. Then the sort of question becomes, okay, do you want a self-standing AI ethics policy? Or some people call it a responsible AI policy or a trusted AI policy or an AI governance policy. It's going by different names now. Do you want a self-standing one? Where at the appropriate junctures or parts of the policy, it says to refer to other policy, let's say about data retention. Do you not have a self-standing AI policy and try to embed it in all the other existing policies? So it's like if you have taken an AI policy, an AI risk policy, AI ethics policy, and sort of chopped it up and distributed it among existing policies where you say, oh, this paragraph would fit with the privacy policy or this privacy policy as opposed to this part of the privacy policy. So you can sort of do that sort of thing. We typically recommend to our clients, you should have a self-standing AI ethics policy. And I would say 90% of them listen to us. Good, I think that's interesting. It does seem like there are a lot of ways to kind of connect different departments in these huge corporations. I want to go back to something you mentioned quickly when we were talking about principles. Some people view explainability as a principle. And I oppose that. I just don't think it's exactly a principle. And I guess I just wondered how you see explainability because we know that AI has so much to offer in these black box models. And there are big issues about how AI is coming to its output. But do you think that it's not ethical if it's a black box or what is your thought on that? Yeah, I've been saying for years that I don't think explainability is a necessary condition for being ethical. It seems to me, the first time I sort of wrote about this was in a LinkedIn post, I don't know, probably five years ago at this point or more. The example that I gave back then was, suppose you've got this magic box, it's got two buttons, button A and button B. And every time you've hit button A, a random person dies. And every time you hit button B, a random person gets cured of cancer. And the testing of this has been unethical. Okay, but let's just say we know that this is what we've seen with button A and this is what we've seen with button B. We have no problems figuring out whether it's ethically permissible to hit button A. No, it's not. A thousand people died because you hit button A. Stop hitting button A. It would be unethical if you do it. And with regards to hitting button B, that cures a random person of cancer. We don't know how it works. Again, it's by definition a magic box. It's at least ethically permissible to hit that button again. And it might even be morally required to hit that button again. So the fact that it's a black box doesn't make it unethical. That's one thing to say. Second thing relatedly is that the reason for that is because this thing has shown itself to be reliable in a particular way. So we've tested the hell out of it. It reliably performs in such, such a way. And so that puts us in a good position to know how to ethically use it. Yeah, I see accuracy as the distinction that if something is proven accurate and it's gone through a certain amount of trial use and prior to it being deployed, it would seem to me that explainability at some point wouldn't matter. Especially if you look at these situations in healthcare, which is the bioethics issues come up with healthcare. I'll say two more things, though, that sort of push in the direction of when explainability might be ethically important. One is when you think it's necessary for expressing the principle of respect. So explainability wouldn't be, if you like, its own self-standing foundational moral principle. I don't see the sense in that. But if you think that certain people deserve or owed an explanation for why they got treated in that harmful way, then you would think that, okay, well, they deserve an explanation because it's an expression of respect for persons. So if you say to a speaker, if you go up to a speaker afterwards and say, hey, I loved it and I really respect what you do, you're expressing respect in a non-required way. It's sort of going above and beyond. In other cases, the example that I use in my book is you're with this partner of yours for a decade. You seem to have a loving relationship. All of a sudden, one day your spouse says, I'm out, I'm leaving. And they just walk out the door and you say, why? Why? And they refuse to explain it to you? You might think that person's being disrespectful in a way that is ethically impermissible, that they are failing to give you an explanation, which is manifesting a lack of respect that I am owed. So I do think that there can be cases in which explainability is morally required, but it's not the foundation of moral principle. The last thing I'll say, and this is not in the bioethics space but in the criminal justice space, is there are some cases where you might think that the way in which a procedure unfolds is necessary for things being just. So a criminal justice trial, it has to proceed in a certain way for it to be considered that the outcome is fair or just. Not necessarily accurate. We get false positives and false negatives in the criminal justice system where we say someone is guilty or not guilty. But the court case is just on the condition that it follows certain kinds of procedures. And of course, you need to know where those procedures are in order to assess whether they're fair. To the extent that a black box can come into a place where what gets called procedural justice is key, now we might need explainability. So I think we're aligned on it. It's not a foundation on the moral principle, but I do think there are cases which explainability is morally necessary. Yeah, and I think that due process example comes up in criminal justice. I just think in other organizations, something similar comes up. And I really distinguish between transparency and explainability. And if you were very transparent about the degree of accuracy, which might not be perfect, but might be somewhat accurate enough to be worth trying, but you aren't truly explaining the black box algorithm. You're not really explaining how it works. How do you see transparency and explainability working together or how do you distinguish them? Yeah, I think they're completely logically distinct from each other. I think you have high transparency and low explainability and vice versa. So high transparency and low explainability would be, "Hey, everyone, guess what? We've got a black box model." And then low transparency and high explainability would be, "We've got this glass box model, but shh, don't tell anyone." That's low transparency. So transparency and explainability, for some reason, do get run together. To my great annoyance, get run together when some companies put together their ethical principles as we were talking about before. And one principle, a single principle, would be transparency and explainability. And I think that's sort of a principle of apples and oranges. So yeah, they're totally distinct things and people run them together unhelpfully. Yeah, I pulled them apart. And I think some people have trouble understanding those differences. And I think they are really key to the ethical deployment of a black box model. Sometimes, take a case where, let's take the sort of canonical AI and medicine case now, the radiologist or the AI, using AI to diagnose fractures or whatever it is in radiology. I don't know that people are owed and explainate. And that's a black box. Like, we don't know how these things get so accurate. It's not obvious to me that the person is owed an explanation. Ode the admittance that we're using a tool that's a black box. Does the patient owed that? I don't know. I mean, if we tell them, "Hey, we've got this thing that works phenomenally well." Let's just stipulate for the sake of argument. It diagnoses patients from x-rays better than doctors, better than the best doctors. I don't know that we need to disclose to them and we know how it works. And there's lots of other things, by the way, that we don't know how it works. I was just talking to someone who works at a large pharmacy company and he's got the relevant biomedical credentials. And he said, "We don't really understand how aspirin works. We don't know how it works." I mean, we know what it does fairly reliably in big swaths of the population. But in terms of the underlying mechanisms, we don't really get it. I don't think the doctor owes an explanation when they say, "Listen, you should take two Tylenol. It's been shown to help people with your kind of condition." I don't think they have to say, "But full disclosure, we don't really understand the underlying mechanisms behind why Tylenol works." Yeah, I don't think they wrote that. Yeah, I think there's a lot going on in medicine right now because people don't know what to put in informed consent documents. We don't, across the board, know whether the patient should need to sign off. Sometimes transparency looks just like an open discussion of something where informed consent is sort of a legal document. It requires a sign off. I think there are doctors who want to say, "The patient doesn't need to know X, Y, and Z." And some things don't really matter for sort of the bodily aspect. If you're signing off on AI somehow involved in your surgery, that's really different from signing off on AI that might be used in your medical record and somehow violate your privacy down the line or be subject to some security breach at the hospital. That these are really different ideas. I do have any advice for institutions kind of picking apart those ideas or figuring out when that informed consent sign off is really important and when maybe the use of AI just isn't all that relevant or a patient or customer might not need to know. Yeah, so one thing I wouldn't do is, and I've seen a number of companies who are into this, they say, "We're never going to use AI for X," whatever it is, doesn't matter. And those always turn out to be all wrong. There's always going to be a case where, "Oh, actually, it would be really useful if we did use it for X and it would be totally ethically fine. Why do we have this policy that's banning it across the board?" Incidentally, the European Union Artificial Intelligence Act, the regulation, does this with emotion-detecting software or something along those lines where it's banned. That seems crazy. You could think of cases where, say, people who are really bad at reading other people's expressions and they're socially awkward as a result and they find trouble making friends as a result, would really benefit from a kind of AI companion that says, "That person's really upset with you right now," or something along those lines. So I guess that first piece of advice is, don't create these kind of course-grained policies that ban a certain kind of usage of AI. I wouldn't do that. What I think is particularly useful is creating what I call ethical case law. Just like in the court system, in the U.S. court courses, you have the U.S. Constitution. And when juries, at least in principle, and judges in principle, deliberate about these kinds of cases, think especially about, say, the Supreme Court, they're not just thinking about the Constitution, they're also thinking about case law. And not just thinking about case law, they're also thinking about the Constitution. Again, I'm idealizing things a little bit here. The idea is that that case law is really sort of foundational to careful, appropriate, consistent, responsible deliberation. You need those kinds of cases to sort of have something to push off against, right? Oh, this new case, it's kind of like this case that we can, that these, you know, the previous five cases that we considered in this area. And in those previous five cases, we said no. And we said no for reasons X, Y, and Z. Do those same things apply in this new novel case? And if the answer is yes, that's really deliberately helpful. So the recommendation is develop, in the absence of regulations and laws that actually provide concrete guidance here, create, if you like, internal case law where you say, let's go through different kinds of cases. Ideally, you do this before it's actually on your doorstep. It's anticipatory. And these are the kind, in this kind of situation, we wouldn't do X because of, for reasons A, B, and C, and this kind of situation we would do Y, for reasons D, E, F, whatever it is. And then when a case actually comes to your doorstep and it gets escalated to your ethics committee or your IRB or whatever, it's not just, this is totally new, we've never thought about this kind of thing. It's, oh no, actually, we have an internal, we've internally established what we do with certain kinds of cases. And we can use those kinds of cases to help us deliberate about this new particular case. So developing that internal case law, I think is extremely important. It's difficult, it takes some time, but it can certainly be done. Yeah, and it's great to have it done before things go wrong to sort of anticipate how you've dealt with other issues before they've kind of caused a lot of harm and damage. And also, to some extent, lets you stay a bit objective. This is maybe more true in a corporate setting because what you don't want is, we've got to consider this ethical great case, you've ever thought about it before, and there are huge dollar signs flashing in our faces. And so that's going to bias the deliberators towards a finding that is compatible with receiving those dollars. If, on the other hand, they already have some things laid down, we don't do this sort of thing in this kind of situation, and they have a novel case with big dollar signs, at least there's the resources to say, I know there's big money involved, but we already decided this. We have a case that's just like this. Now, I'm not saying that they're always going to sort of live up to their existing ethical case law, but it's at least a tool to help guard against that sort of thing. So, turning to trust, trust has kind of become a big issue in AI, ethics, and responsible tech. But trust can feel a little like a trick. If we really focus on trustworthiness, our developers or people who are businesses deploying AI tools, are we requiring them to act in trustworthy ways? I think that we don't want to lose sight of the fact that trust really has to be earned. I think if I were to look at the documents I read about trust, so many documents are focused on how to get the consumer or the patient or the public to trust the AI, I feel like it almost centers more on that than it does on trustworthiness. And I guess I just wonder how the conversation around trust should go. The conversation on trust mostly drives me nuts, because I think it's really sloppy. One way in which it's sloppy is sort of conceptually. There's a difference between earning someone's trust and not gaining their distrust. There's just a sort of apathy or an indifference, or I don't really have a view on that. I don't know. What's a good example? Do I trust my credit card company? If I had this sort of positive attitude of trust that the sum on the bottom of my credit card statements is going to be accurate, I don't know. There's an absence of distrust. I trust my wife to look out for my welfare, something like that. Is it like I have an attitude like that towards my credit card company, just smaller in degree? No, it's not like a lower version of that. It's just I don't actively distrust them, that's it. And so one thing is, I think we just, for companies as well, it's not how do we get them to trust us. It's how do we get them to not distrust us? It's the presence of distrust that stops people from using technology or whatever it is. It's not the presence of trust. That's one thing to say. I can't tell whether that's just a sort of philosopher's sort of petty distinction, but it drives me nuts. Another thing is, I actually don't agree with diagnosis that we got to get users to trust the AI. For the most part, we have to deal with the fact that people are already too trusting. They already think, "Oh, well, chat GPT or CLAW or whatever your favorite large language model is." "Oh, it said X, so I guess X." There's well-known cases of what's called automation bias. And the most sort of famous example of that is, Google Maps has to take a left into a lake and people have actually turned and driven into lakes because Google Maps said so. This is automation bias. It's massively a much bigger problem with LLMs and their outputs. People are like, "Oh, yeah, that sounds reasonable. That sounds right. Okay, I'll follow that." But there's no distrust. There's too much trust in a machine that hallucinates or puts out false information all the time. So that's the second thing. So the third thing, though, to say about trust and why I object to it as an umbrella term is that it's not particularly guidance-oriented. All the shit's got to go right. So that means the ethics has to go right, yes. Same with cybersecurity. Cybersecurity compliance has to go right. Compliance with regulations, including privacy regulations, has to go right. It has to go right from an engineering perspective. And so you say, "Oh, we're going for trust here." It's like that's just a way of saying you want all the things and all the people in their different roles with all their different responsibilities to do those things well and for it to have the desired impact. So it feels a little bit lazy to just say, "Oh, we're for trust." Yeah, I mean, I kind of want to say, I don't know how you feel about swearing on this podcast, I want to say no shit. Yeah, no shit. You want all the things to go well and you want nothing to go poorly. Okay, now what? Now we actually have to get into what actually makes that happen. And the word trust doesn't do anything anymore. Yeah, and I think there's a difference between trying to be trustworthy. Like the EU framework is sort of designed to make the tech and the people using it behave in a trustworthy way. But actually luring people into trust you, that seems like the easy part. I agree with you, people are too trusting. And it's clearly completely different from how you trust someone in your personal relationships. I would trust a babysitter or a spouse. That's not the same as saying you trust the hospital not to share your data. Right, and I don't even do that, but I don't actually distrust them. If someone said, "Do you trust the hospital "not to share your data," I'd say, "Not really. "I don't know what they're doing. "Do you distrust them?" No, I don't really distrust them either. I also don't have a sort of strong view that they're probably going to share it. I don't have an attitude of trust or distrust. That's where I would land on, that's my genuine expression of do I trust the hospital? I don't trust them, I don't distrust them, and whatever, I need to get this operation, so let's get it done. Yeah, I agree. I think the other thing in the hospital setting is that sometimes outsiders overestimate how people care about their privacy. Lots of people, if you said a lot of patients would let anyone share their data for the sake of medical research, and I think not everybody is privacy obsessed, and I think privacy really, sometimes they say privacy swallows everything. If we were to really focus on privacy today, it might be the only thing we talked about because I think that people just view consumers and patients in hospital settings as caring more about privacy than all these other issues. And I think I'm not sure that's an accurate reflection. Yeah, I did a podcast episode, which is really just me reading a short essay that I wrote, which I actually think I should probably put on my sub-stack. And the title of which is, "Data Privacy Isn't As Important As You Think." And it's just that I think we've gotten this data privacy conversation completely wrong. I think it's completely backwards. A lot of times we're talking about data that is automatically collected by a piece of software, put into a server. It's run through an algorithm. No human being ever actually sees that data. And if they did, they probably wouldn't care at all. They don't know you. But then we get these words like surveillance that get tossed around like, "Oh, this is data surveillance." And I'm like, "Wait, because a piece of software automatically collected data about you put it, and now you're getting served an ad for towels, or now the medical community has helped out, you've been surveilled, there's not East Germany. We need to calm down." So yes, I think that the conversation on data privacy is overwrought. And it's so important to get it right for the reasons that you articulated, which is that there's legitimate, really good, morally important research to be done in healthcare that can't get done because of concerns about what I think about as misguided concerns around privacy. Yeah, and I think some of those misguided concerns are preventing large buckets of data. And then sometimes the data gets sold and shared anyway, and people aren't that aware of it, but it's really sort of not detrimental to them in any way. I do like people to be able to take part in or be reimbursed for sharing data. I view that personal data as owned, and I think that you don't see it that way. That data about oneself is their data, is kind of how I see it. Yeah, I'm dubious. I mean, can I ask you, what do you mean by it's their data? Because I think maybe you've heard that piece or something, but there's a difference between something's being data about me versus my data. So if I walk into my favorite cafe and someone in cafe Martin, let's say you're already there and you write down your notebook, read, walked into the cafe at 10 o'clock, and I go over to your notebook and say, "Hey, that's my data." You would say, "No, it's not. It's data that's about you read. It's about you coming into the cafe at 10 a.m. My notebook, it's not your data. You have no right to rip that piece of paper out of my notebook." And so it's true that it's data about me, but you can't infer from that data is about me directly to that data is mine. Certainly not in any legal ownership sense, and if there's a moral sense of ownership, I'd like to know what it is. You have to articulate what it is to morally own something, or maybe that we ought to own all the data that's about us, but that's also a very hard claim to demonstrate. So this is just me saying, yeah, I think that people confuse, they play fast and loose with this data is about me and this data is mine. It's just not the same thing and one doesn't entail the other. Yeah, and I think the degree to which I think we disagree is really, I agree with you, you can't go rip it out of someone's notebook. Someone can write down whatever they want about you and that kind of thing. And it could be your personal data that they've written down. But I do think when data is sold and resold and resold again, and you see billion-dollar industries that have to do with data sharing, they are sort of feeding off something of yours. And I think with or without the ownership discussion, there's a question of who profits from data and how and why, and how it has come impossible to kind of track your data through that system and say, it gains value as it's reshared and reshared, but you don't gain anything. I guess I still don't totally understand that. So here's just a little bit of pushback anyway. When people sell me, I don't know, I'm a rock climber, and they show me an ad for, and let's just say, I love rock climbing. It's my passion. It's a hobby, but it's my passion. And they sell me stuff. They've profited off my desires. They've profited off my passion. I've got no objection to that. When you sell them, you have a baby and someone sells me a toddler car seat. It's because I love my baby and I don't want them to get hurt. In the car, and of course, there's legal obligations as well, but it's really the love of my baby. I don't go around streaming. They profited off the love of my child. Yeah, that's how people make money because you are a certain way, and they make money from your loves, your desires, your hopes, your dreams, your fears, and then you say something like, okay, fine, you can make money from all those things. Just don't make money when it's data about me. What? The data about you is more if you're precious to you than your love of your children, such that company's making money from the love of your children, but not from the data that's about you. That just seems bizarre. I disagree. I also think, in a way, these consumer markets are making money from all of our weaknesses. They are harnessing our personal data or copies and tracking devices are really telling who would be interested in that mountain climbing equipment or this or that. People should know that they're paying with their data plus money. Data has a financial value. Additionally, we waive our privacy rights all the time and our rights to the data, which really should impact that financial value. If you put it out and you open, it would be really hard to say that you own it anymore. Hospitals and doctors are really conscientious about privacy, but a patient might go home and post about their illness, their medications, their mental and emotional health, and it's okay to do that, to waive privacy rights and to be open and honest or share with your community what you wish to share. But then people can't go back and claim that it's completely personal and private and confidential. I do think in the other setting of surveillance, and maybe the word surveillance is thrown around too much, but we do have certain issues where surveillance could become dangerous. We have states where abortion is completely illegal and then someone uses their own personal wellness apps or they post data about temperature, heart rate, and these other things that can sort of depict them as pregnant or subject them to a certain legal ramp. Oh, yeah. So to be clear, first of all, I'm against surveillance. I just don't think that all data collection counts as surveillance. So let's be more careful with how we use the term surveillance. That's one thing to say. The second thing is to say that not that there aren't ethically atrocious things being done, it's just that the alleged privacy violations are not where the ethical action is. So if, for instance, Roeview 8 gets overturned and then people collect a bunch of data so that they could target the people who are looking for abortions and harass them, prosecute them, blah, blah, blah, I think that's morally abhorrent. My objection though is not to, they violated their privacy. My objection is you're harassing them, you're immorally suing them or reporting them to the government officials or blah, blah, blah, blah. And so it's what you've done with that data to which I morally object. The collection, if you'd like, fostered that or it enabled it, but it's not the core wrongdoing. That's my general view. And of course, collecting the data enables the wrongdoing, but it's not the case that doing something that enables wrongdoing is itself wrong. I mean, you bought a kitchen knife that you could use to stab your spouse, but we don't think that, even though it's true that it enabled you to kill your spouse, it's not immoral for you to collect it to buy a knife. So, I mean, we could talk about this for hours right end, obviously, but... Yeah, and there's no need to. I think that we probably both agree that privacy just isn't the most important principle, I think, because there are so many other things that can go wrong. And I think people really need to be aware of those other risks when you deploy AI across a large institution. Yeah, I wouldn't even say that privacy is not the most important principle. I would say that privacy is one principle or one moral value among a plethora, and that it's not the one that should win in every single conflict or principle. Sometimes it should win, of course, like in cases of surveillance. In some cases, the welfare of the populace should prevail. So, if we can automatically collect and aggregate data about the general population that we then use for population-level health measures, then in some broad sense, let's just admit for the sake of argument some privacy is sacrificed because there's data about you that's being collected and you can consent to it, but I think it gets outweighed by the public benefit. In other cases, it's being done in a way that is more of an objectionable because it's a violation of privacy, and I don't care what could have happened as a result. It was nonetheless wrong of you to have done that because it's too violative, is that a word, of their privacy. So, it's not that privacy is not the most important one. It's not the only one that moral principles and values always come into conflict, and that privacy, no principle, no value, should win out in each and every single circumstance. And that thinks it's more complex and complicated than that. Yeah, and I think that the transparency and whether data is taken surreptitiously specifically, I also think we do have to protect data from those who have a sort of malicious interest in that data. But I think that's all sort of taking care of with some proper cybersecurity and really taking proper measures to protect. Totally agree. So, do you have any last words of wisdom for people, maybe especially geared towards sort of healthcare pharma and hospital settings about deploying AI in fair and equitable ways? It's all about political alignment. I've worked with some healthcare companies, some who are quite large, some that are sort of, you know, medium-ish size, worked with a number of pharma companies. And by the way, I think healthcare and pharma, healthcare especially is extremely slow in AI, in the AI world, very slow to innovate. And one reason, not the only one, but one major reason why is that they don't know how to do AI ethics. They don't know how to do governance of AI as opposed to, say, financial services. In financial services institutions, they actually, they're pretty good at it overall. And that's because they've been doing model risk management for a long time. Healthcare has not. So, it's a totally different thing for them. You know, I've seen lots of places where they don't have the right people in the room. You know, they're like clinicians, but clinicians, we want their perspective. But if we're talking about, you know, governance of a technology across the enterprise, across the company, across the whatever, the nonprofit, they're not the right, they're not going to know how to do that. So, one is get the right people in the room, get people who actually understand, call it AI ethics. And I don't just mean AI ethics from a kind of academic perspective. And, you know, I was an academic, I was a philosophy professor for 10 years. So, I know what academics are like. I was one for most of my adult career. I don't mean that good academic approach to AI ethics anymore than you would get a kind of, you know, someone who just writes a lot of biomedical ethics to be your head of ethics at a large, you know, let's say one of the biggest healthcare providers in the country. You wouldn't, they're academics. They don't have to put this stuff into practice in a systematic way. So, I think you need someone in the room in the right way who actually understands, you can call it AI ethics, you can call it responsible AI, call it AI governance, but real experts, I think that's one thing. And the second thing is political alignment. And this is true not just of healthcare, but in every organization. One person can really be into it, but we're talking about a pretty big lift here. I think, like I said this earlier, it's a big heavy lift. And if you don't have the right kinds of internal political alignment among the right sorts of people, you're not going to get anywhere. For instance, you might design it beautifully on paper, and then you want to put it into practice. And it turns out that you have to go talk to, you know, Sarah and Bob over there. And they're like, no, this is, we don't want anything to do with this. Forget this, this is going to slow us down. And now you're in trouble. So, getting the right people involved from the start, and getting an internal alignment, and getting people to appreciate the nature of the problem, the nature of the risks, the way in which having proper risk management of these things enables innovation, enables you to carry out your mission. That's the most important thing to secure. Then doing the work with the right experts, that's the second thing. I think that's really great advice. Thank you. It's been a pleasure having you. This is the Voices in Bioethics podcast with Reed Blackman. Thanks for joining us today, Reed. Yeah, thanks. My pleasure.

Podcast Summary

Key Points:

  1. Principles are important but not sufficient for ethical AI development.
  2. Frontline developers often follow instructions from higher-ups rather than ethical principles.
  3. Companies need policies, procedures, training, and governance structures for ethical AI deployment.
  4. Explainability is not a necessary condition for ethical AI, but may be important in certain cases.
  5. Transparency and explainability are distinct concepts and can vary independently.

Summary:

The podcast features Reed Blackman discussing AI principles and ethical AI development. While principles are foundational, they are insufficient without additional frameworks and support for developers. Companies must establish policies, procedures, and governance structures to ensure ethical AI deployment.

Reed argues that explainability is not always necessary for ethical AI, emphasizing reliability and accuracy instead. He distinguishes between transparency and explainability, noting they are independent concepts. Informed consent regarding AI in healthcare poses challenges, with the need for clarity on when disclosure is necessary.

Reed advises against blanket bans on AI use, highlighting the importance of context-specific considerations in AI deployment.

FAQs

Yes, principles are important as a foundation, but they are not sufficient on their own.

Developers often follow what their bosses dictate, and the incorporation of principles depends on company culture.

Companies need policies, procedures, metrics, training, and a clear roadmap for ethical AI implementation.

Institutions should ensure all ethical considerations are included, connect values to procedures, and establish a governance structure.

Transparency and explainability are distinct concepts, with high transparency and low explainability or vice versa being possible.

Explainability is not always necessary for ethical AI deployment, as reliability and accuracy can be more crucial factors.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.