AI Product Ethics

45 min advanced Lesson 9

Learning Outcomes

  • Identify dark patterns that use AI to manipulate, addict, or deceive users — and explain why they backfire
  • Distinguish between AI that augments human judgment and AI that quietly replaces it
  • Apply the three components of informed consent to any AI feature your team is designing
  • Evaluate a product for equitable access gaps and propose concrete mitigations
  • Complete a structured ethics review that surfaces risks before a feature ships

Lesson Plan

Segment Duration Topic
Intro 3 min Why AI ethics is a product skill, not a legal formality
Dark patterns 7 min Manipulation, addiction mechanics, and deceptive AI identity
User autonomy 7 min Augmentation versus replacement — and why the difference matters
Informed consent 7 min What users have a right to know about AI use and data
Equitable access 6 min Who your AI works for — and who it quietly leaves behind
Ethics review 9 min A structured framework you can run on any feature
Wrap-up 6 min Key takeaways and next lesson

Before You Begin

Pre-work:

Shopping List:

  • A web browser
  • A shared document or whiteboard for the ethics review exercise at the end
  • Optionally, the Google PAIR People+AI Guidebook (free at pair.withgoogle.com) — it goes deeper on several design patterns referenced here

1 Why Ethics Is a Product Skill

Product teams often treat ethics as something the legal team handles — a checklist that arrives late and gets filed. That framing is expensive. Ethics in AI product design is about product decisions your team makes every sprint: what data to collect, how to present uncertain output, whether the AI acts or just suggests, who gets access on what terms. Most happen before legal is in the room.

The stakes are higher than traditional software because AI harms at scale. A bug affects one user. A biased recommendation engine affects everyone the product touches. The blast radius of a single bad design decision is qualitatively different.

NOTE
Key Insight
The Microsoft Human-AI Interaction guidelines note that AI failures are systematic — the same flaw affects every user. A design-phase ethics review is better insurance than an incident response plan.
TIP
Start With the Harm
Ask not Is this compliant? but Could this hurt someone — and at what scale?

2 Dark Patterns: Manipulation, Addiction, Deception

AI amplifies dark patterns because they can be personalised to each individual at scale. Three types carry the highest risk.

Manipulation. An AI that learns what emotional triggers drive purchases and consistently exploits them is a persuasion machine. A travel app that surfaces pricier options when it detects time pressure — because your data shows you stop comparing when anxious — is manipulation dressed as personalisation.

Addiction mechanics. Optimising purely for engagement time structurally incentivises designing for dependency. The PAIR guidebook distinguishes engagement that advances user goals from engagement that is its own end — make that distinction explicit in your metrics (see Lesson 8: Measuring AI Product Success).

Deceptive AI identity. If a user sincerely asks whether they are talking to an AI, the answer must be honest. One discovery destroys trust in the feature and the company.

WARNING
The Engagement Trap
If your primary metric is time-in-app and your AI optimises for it, you have created an incentive to design for dependency. A goal achieved and left guardrail metric is a direct corrective.
Dark pattern Why it backfires
Emotional trigger exploitation Erodes trust when users notice; regulatory exposure
Per-user addiction mechanics User backlash; regulatory attention
Deceptive AI identity One discovery destroys trust; growing legal exposure
Consent dark patterns Regulator scrutiny; enterprise buyers block adoption

3 User Autonomy: Augmentation vs. Replacement

The most consequential design decision in many AI features is whether the AI augments human judgment or replaces it.

Augmentation means AI suggests and a human decides. A doctor whose AI diagnostic tool surfaces patterns before they choose a treatment plan is augmented — judgment is enhanced, not bypassed.

Replacement means the AI decides and the human either ratifies without real review or is not in the loop. An automated moderation system that bans users without human review is replacement. The ethical problem is accountability: when an automated system makes a consequential decision about you with no appeal path, the power relationship has shifted in a way most users find deeply uncomfortable.

WARNING
Consequential Decisions Need Human Review
The PAIR guidebook identifies decisions affecting health, finances, legal status, housing, or employment as categories where AI-as-replacement is almost always wrong. The bar for removing human review from these categories should be very high.
Pattern What it does
Show the AI's reasoning Users can evaluate and override rather than accept blindly
Make override easy and visible A buried override signals you expect passive acceptance
Preserve the non-AI path Never remove the manual option entirely
Surface confidence levels Lets users calibrate how closely to review each suggestion
TIP
Design for Override
If overriding the AI takes more than two steps — or triggers a prompt implying the AI is probably right — you have designed against autonomy. The quality of your override flow signals how seriously you take user agency.

4 Informed Consent: What Users Have a Right to Know

Informed consent means users understand what they are agreeing to before they agree — in the interface at the moment it matters, not buried in a privacy policy. Three disclosures are load-bearing for AI features.

What is AI-generated. Disclosure prominence should match consequence. An AI-generated legal summary with no label is a transparency failure. An AI writing assistant where the user knows they are getting suggestions is not.

What data is used and for what. Did the AI read my full email history? Is my usage training the model? These are reasonable questions that deserve honest, findable answers — reachable in under 30 seconds.

What the AI cannot do. A medical information AI that answers every question with the same confidence is failing users who cannot distinguish reliable from unreliable answers.

NOTE
Consent at the Moment of Use
PAIR research finds that consent shown at setup is poorly retained. A tooltip on first AI suggestion acceptance (This was suggested by AI. You can always edit or ignore it.) is worth ten onboarding screens.
Question Green Red
Can users find what data the AI uses in under 30 seconds? One click from the feature Buried in a privacy policy
Is AI-generated content labelled at consumption? Yes, at appropriate prominence No label, or label only in settings
Are the AI's limitations communicated where they matter? Yes, where output might mislead Only in documentation no one reads
WARNING
Consent Dark Patterns
Common violations: defaulting all data sharing to on and hiding the off-switch; double-negatives in consent options; making the privacy-protective choice require significantly more steps than the permissive one.

5 Equitable Access: Who Your AI Works For

A feature that works brilliantly for some users and poorly for others has an equity problem, even if the disparity was unintentional. Three structural properties of AI create this risk.

Training data gaps. A hiring tool trained on historical promotion decisions encodes whatever biases those decisions contained. The gap is invisible in aggregate if your primary user group is the one the model performs well for — segmenting by demographic proxy reveals the reality.

Access gaps. AI features are often locked to paid tiers, newer devices, or high-bandwidth connections. Users who most need certain capabilities may be systematically excluded, widening rather than narrowing existing disparities.

Literacy gaps. AI interfaces reward users who know how to prompt and interpret uncertainty. A feature that works well only for technically confident users is not equitable by design.

TIP
Segment Your Metrics
Global accuracy metrics hide equity gaps. Segment every key AI metric by device tier, connection quality, language, and new versus returning user. The pattern in the tail matters more for ethics than the average.
Practice What it addresses
Test with diverse user groups early Performance gaps invisible to majority users
Provide a functional non-AI fallback Users who cannot or prefer not to use AI
Test in target languages, not just translate Language and cultural representation in AI output quality
Audit outputs for bias before shipping Discriminatory patterns in recommendations or classifications
WARNING
Unintended Exclusion Is Still Exclusion
The most common AI inequity is systematic neglect: the team never asked whether the model performs equally for all users. Unintentional exclusion at scale still harms people at scale.

6 The Ethics Review Framework

Run this before a feature enters engineering so findings shape the design rather than being retrofitted. A team can work through it in 90 minutes.

Step 1 — Define the feature and population. One paragraph: what does it do, who uses it, at what scale? Ten internal analysts have a different risk profile from ten million consumers.

Step 2 — Dark pattern audit. For each dimension, identify the risk and how the design mitigates it.

> Describe the feature. For each item, identify the risk and mitigation:
> 1. Does it exploit emotional vulnerabilities for commercial gain?
> 2. Does it optimise for engagement that conflicts with user wellbeing?
> 3. Does it present AI as human, or obscure the AI's role?
> 4. Does it use consent flows designed to maximise data extraction?

Step 3 — Autonomy assessment. Classify each AI decision using the table from Step 3. Flag any high-consequence decision lacking human review.

Step 4 — Consent review. Apply the three-question rubric from Step 4. For any red answer, name the design change and an owner.

Step 5 — Equity audit. Who is in the training data — and who is not? Who is excluded by price, device, or language? Does the interface require AI literacy your target users uniformly have?

Step 6 — Risk register. Document: Risk, Likelihood, Severity, Mitigation, Owner, Status. Issues without a clear resolution path should block launch, not trail as backlog.

TIP
Run It Early
A 90-minute ethics review at design spec costs almost nothing and can change the design. The same review at launch may require structural changes that get deprioritised in favour of shipping.
NOTE
External Resources
The Google PAIR People+AI Guidebook includes free structured worksheets for design-phase ethics review at pair.withgoogle.com. The Microsoft Human-AI Interaction guidelines (Amershi et al.) provide 18 empirically-validated design principles that map directly onto this framework.

Questions & Answers

Q: Our legal team says we're compliant. Isn't that enough?
Compliance and ethics are not the same thing. Legal tells you what you are required to do; ethics asks what you should do. Most cautionary cases in AI product history involved products that were legally compliant at the time and still caused harm. Design for user welfare, not for the legal minimum.
Q: Ethics reviews feel like they will slow us down. How do we sell this to a team under shipping pressure?
Frame it as risk management. A dark pattern story takes days to go viral and months to recover from. A 90-minute structured review at design phase is cheap insurance. It is easier to sell when it is time-boxed and produces a concrete output — a risk register — not an open-ended discussion.
Q: How do we balance personalisation (which requires data) with privacy (which limits it)?
Collect the minimum data needed for the value you are delivering, be explicit about what is used and why, and give users control to view and delete it. On-device personalisation — where the model adapts locally and nothing leaves the device — resolves most of the tension and is worth exploring with engineering even if it adds complexity.
Q: Our AI feature is genuinely better than the manual process. Do we still need a non-AI path?
Yes. Better on average is not better for every user — some will hit edge cases the AI handles poorly and need a working alternative. Users who choose the AI because it is better are also far more forgiving of its failures than users who had no choice.
Q: How do I push back when leadership wants to ship a feature that fails the ethics review?
Make the risk concrete and attach a business consequence. "There is an equity gap" is easy to dismiss. "The model performs 15 percentage points worse for Spanish-language inputs, which are 22 percent of the target market" is not. If leadership still ships, document the risk with a named owner and a committed resolution date.

Key Takeaways

  1. Ethics is a product skill, not a legal formality — your team makes ethics-shaping design decisions every sprint, usually before legal is in the room.
  2. Dark patterns become more dangerous with AI — because AI personalises the manipulation to each individual, the intent behind how you deploy a capability matters as much as the capability itself.
  3. Augmentation preserves accountability; replacement removes it — for consequential decisions, a human review step is the mechanism by which users can challenge errors that affect them.
  4. Informed consent happens in the interface, not the privacy policy — surface the relevant disclosure at the moment of use, at a prominence proportional to the consequence.
  5. Equity gaps hide in aggregate metrics — segment every key AI metric by population; the disparity that matters for ethics is in the tail, not the average.
  6. A structured ethics review is cheap at design, expensive after launch — a time-boxed framework with a risk register output turns an abstract concern into a tractable product task.

Next Steps: Lesson 10: Case Studies