Ethics is, in the maturity measurement, not a separate department and not a code of conduct sitting in a drawer. It is the dimension that measures whether an organization knows which decisions it hands over to a system, who is responsible for that, and whether that can be accounted for to customers, employees and regulators. A system can work fast and correctly and still be a problem if no one can explain why it produces this outcome, or if no one has thought in advance about the cases where it goes wrong.
This dimension is connected to others, but does not stand apart from them. Someone who does not know which data a model uses also cannot judge whether an outcome is explainable or fair — that touches on what privacy and security must already have in order. And someone who has not appointed anyone with authority to reject AI outcomes is missing a step that is normally arranged under performance management: who assesses what, and on what grounds.
At the baseline level, ethics is usually not a topic. There has been no incident, so there is no reason to think about explainability or bias. Decisions about AI deployment are made without anyone asking whether that is responsible. That is not necessarily unwise — it has often simply not come up yet. You can read more about what that level means in practice at what the baseline level means.
At foundation there is usually a first document: an internal position, a few agreements about which applications are and are not acceptable. That document is rarely consulted before a new application is launched. See what the foundation level means for the broader context of that level.
At activation, ethics becomes part of the process: new AI applications are assessed beforehand, there is a fixed moment at which someone asks who can explain the outcome and who is liable if it goes wrong. At insight, that assessment is measured: the organization keeps track of which applications have been assessed, which deviations were found and how they were resolved. At intelligence, ethical assessment is no longer a separate process but woven into the way AI applications are developed and maintained, with ongoing visibility into where risk arises before it materializes.
The spread between what different people in your organization score on this dimension is often larger than for other dimensions. A lawyer sees risks that an operational manager does not see, and conversely an operational manager sees practices that do not exist on paper. That spread, made visible in the plot round, is usually more informative than the average.
What it costs to rise one level depends on where the bottleneck lies. In the transition from baseline to foundation, it is often not about money but about the time of the right people: someone must ask the question no one has asked yet, and put a first framework on paper. That framework does not need to be complete to be useful.
In the transition from foundation to activation, the nature of the task changes. It is then no longer about a document but about a habit: a fixed moment in every project when someone asks the ethical question, and a person authorized to stop an application on that basis. That requires something from people and skills, because that person must be able to judge what an AI system can and cannot handle, and that is a skill that is not present everywhere.
In the transition to insight and intelligence, more is added: a way to keep track of assessments, recognize patterns across multiple applications, and learn from what has gone wrong before. That does not require a large budget, but it does require persistence — it is easier to do an assessment moment once than to repeat it structurally as the pressure to deliver quickly increases.
What it does not cost is a separate ethics department or an external review committee. Most organizations that rise on this front do so with the people already there, by giving the question a fixed place in a process that already exists.
This dimension is one of seven, and does not stand on its own. Ethics does not rise as an organization if IT infrastructure or data management have not yet reached a level at which outcomes can be traced — explaining what a model does requires knowing which data goes into it and how the system is set up. If you want to see how this dimension relates to the other six and where the spread within your own organization is greatest, the maturity measurement gives you a picture of that.
This page is about whether your organization can carry AI — whether there is a foundation in place on which responsible decisions can be made. Another question, not answered here, is which part of the actual work AI could take over. The work scan from FTE TO AI calculates that per task, so you can see where potential lies, independent of whether the organization is already ready for it.
Vraag maar wat er moet staan voordat AI in uw organisatie kan landen.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.