RSS Amplifier

AI regulation, standards and reality · Jun 1, 2026

You can't do AI ethics without AI ethicists

0
Sign in to vote or save

This page did not load. You can still read it on the original site — the toolbar below keeps your place in the directory.

EN 18274 approaches publication

This is a guest post by Dr. Enrico Panai. Dr. Enrico Panai is an AI ethicist and founder of BeEthical, Convenor of CEN-CENELEC JTC 21 WG 4, and Editor within ISO/IEC JTC 1 SC 42 WG 3. He is President of the Association of AI Ethicists and teaches at Università Cattolica (Milan). His research focuses on information ethics and semantic capital.

Browse the LinkedIn profiles of anyone working in AI governance today, and you will find “AI ethicist” appearing as a job title with remarkable frequency and remarkable inconsistency (Cocchiaro et al., 2025). The same label covers a philosopher hired to write internal position papers, a communications manager tasked with handling reputational risk, a compliance officer who added “ethics” to their existing portfolio, and a data scientist who attended a two-day workshop. They are all tagged AI ethicists. Yet, they do not all do the same things; they do not all know the same things.

AI regulation, standards and reality is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

This is not a minor inconvenience. It is a structural vulnerability in the way organisations are approaching AI governance. When a title carries no shared definition of competence, it becomes a signal of intent rather than a guarantee of capability. Companies can, and do, satisfy internal and external demands for “ethical oversight” by appointing someone to a role that sounds right, without anyone being able to verify whether that person is equipped to do what the role actually requires.

The result is a well-documented phenomenon: ethics washing. Not necessarily deliberate. Often well-intentioned. But structurally inevitable when the profession has no floor. Briefly, the title proliferated, the profession did not.

A European standard could be set out to change that: the Competence requirements for professional AI ethicists (EN 18274).

It just received the FV (final vote) result: 100% approval with no comments.

What EN 18274 actually does

EN 18274, developed under CEN-CENELEC JTC 21 passed its final vote and is expected to be published before the end of 2026, making it the first European standard to address this professional role directly.

Before going further, one clarification is worth making explicit. Being an AI ethicist does not mean being better at moral deliberation than other people or having superior ethical instincts. It means having a defined and verifiable set of knowledge, skills, and attitudes that enable an individual to help organisations make better-informed decisions about AI systems. The standard does not license moral authority. It defines professional capacity.

The standard covers four main domains: knowledge (what an AI ethicist must understand, from AI system life cycles to fundamental rights frameworks), skills (what they must be able to do, including stakeholder engagement, ethical impact assessment, and documentation), competences (the demonstrated ability to apply knowledge and skills in complex and unpredictable situations), and attitudes (obligations of independence, confidentiality, and conflict-of-interest management).

Crucially, the standard also defines the boundaries of the role. An AI ethicist operating under EN 18274 is not expected to be a lawyer, a data scientist, or a philosopher in residence. They are expected to operate at the intersection of those domains, with sufficient fluency in each to translate between them and to surface the ethical implications of technical and organisational decisions.

The standard, drafted by the project leaders, Alessio Tartaro and Enrico Panai and European experts, is designed to be compatible with existing certification infrastructure across member states.

The gap the EU AI Act could not fill by itself

The EU AI Act is structured around roles and responsibilities. Providers, deployers, notified bodies, market surveillance authorities: each has defined obligations. The Act presupposes that the humans filling these roles will be competent to do so. It does not define what competence looks like for the people responsible for ethical oversight.

This is not a criticism of the AI Act. It is how legislation works. The Act sets outcomes and requirements; standards provide the technical specifications that give those requirements operational meaning. This is the logic of the New Legislative Framework, and it is the logic that underpins the entire harmonised standards programme currently being developed by JTC 21.

But there is a specific problem with ethics. Other roles in the AI Act compliance ecosystem have established analogues. For example, cybersecurity professionals operate within a recognised field with established curricula and credentials (ISO/IEC 27021). The AI ethicist had none of this. Until now.

The parallel with other regulated professions is instructive. The Data Protection Officer role, introduced by the GDPR, initially suffered from the same definitional vacuum. Anyone could claim to be a DPO. The market responded with a proliferation of short certifications of variable quality, followed eventually by a consolidation around more rigorous frameworks. The process was slow and uneven. EN 18274 attempts to short-circuit that cycle by establishing the professional baseline at the point when the demand for AI ethicists is accelerating, not after the market has already fragmented.

The same logic applies to safety engineers, financial auditors, and environmental impact assessors. Professionalisation does not happen by accumulating well-meaning individuals. It happens when there is a shared, verifiable definition of what the role requires.

The certification question

Passing a standard is not the same as simply creating a functional certification ecosystem. The next question is who certifies against EN 18274, and on what basis.

This standard was inspired by what the AAIE (Association of AI Ethicists) has been developing: a certification curriculum structured around five knowledge pillars, including AI foundations, ethics theory and application, social impact, governance and regulation, and professional practice. In France, Infocert is already preparing a certification programme aligned with the standard, with the examination process designed to test both knowledge and applied competence. The expectation is that other national certification bodies across Europe will follow. And starting from this basis, we can go further.

What the standard cannot do by itself is guarantee that a certified AI ethicist will have a meaningful impact inside an organisation. Certification defines competence; organisations must provide the conditions for that competence to matter. That means a clear reporting line, access to technical documentation before deployment decisions are taken, and an organisational mandate that goes beyond producing reports that sit unread. The standard is a necessary condition to build trust between the industry and a sometimes foggy profession. However, it is not sufficient on its own.

A EN 18274-certified professional placed in a purely advisory role with no structural authority to intervene is better than nothing, but not by as much as it should be.

What this means for compliance teams and procurement

For organisations navigating the EU AI Act, EN 18274 changes the practical landscape in at least three ways.

First, it provides a contractual reference point. Organisations commissioning external AI ethics consultancy can now specify EN 18274 certification as a procurement requirement, in the same way they might require ISO/IEC 27001 certification for information security suppliers. Without a standard, “proven AI ethics expertise” is an unverifiable claim. With one, it becomes a checkable credential.

Second, it changes the risk calculus for internal hiring. An unqualified AI ethicist, regardless of their intentions, may provide false assurance. If a person without the relevant competences conducts an ethical impact assessment, signs off on a high-risk AI deployment, and the system subsequently causes harm, the organisation’s governance defence is significantly weakened. Good intentions do not substitute for verified competence, in court or before a market surveillance authority.

Third, it creates pressure on training providers. The market for AI ethics education is large but still unregulated. EN 18274 gives that market a reference framework, which means training programmes that prepare candidates for certification will need to demonstrate coverage of the standard’s domains. That is a discipline the sector currently lacks.

The risk of unqualified practitioners in this field is not hypothetical. An AI ethicist who lacks sufficient technical literacy may fail to identify the conditions under which a model produces discriminatory outputs. One who lacks regulatory knowledge may provide guidance that is legally inconsistent with the AI Act requirements. The damage in both cases is not just reputational. It is also operational.

A floor, not a ceiling

EN 18274 will not solve the deeper questions about what ethical AI deployment actually requires. It will not resolve disagreements about which ethical frameworks should take precedence in specific contexts, or how to balance competing stakeholder interests in genuinely hard cases. It does not claim to.

What it does is establish a professional floor: a minimum definition of what someone calling themselves an AI ethicist should know and be able to do. That floor changes the incentive structure. It makes ethics washing marginally harder. It gives organisations a basis for distinguishing credible oversight from performative compliance. This also gives practitioners a basis for demonstrating their competence during recruitment processes or when applying for procurement opportunities.

There is a temptation to treat ethics in AI as something that resists formalisation, as if defining competences for ethical practice somehow undermines the moral seriousness of the enterprise. That view has it backwards. What slows responsible AI adoption is not rigorous ethics. It is bad ethics, applied without sufficient knowledge, by people who were never equipped to do the job properly. That is the problem EN 18274 is designed to address.

The standard will not be sufficient. But it was necessary. And it was missing. It is a first step, but the broader European picture already suggests the direction of travel. In France, AFNOR has developed the Spec AICET (https://aicet.eu/standard-aicet/), establishing a national-level competence framework for AI professionals. At CEN-CENELEC level, a CEN Workshop Agreement (CWA) on AI professional role profiles. And in Italy, UNINFO published UNI 11621-8, the first national standard in Europe to define, systematically, 12 professional role profiles for the AI sector, in alignment with the AI Act. Taken together, these initiatives are not isolated experiments. They are the early signals of a dedicated line of competence standards for AI that Europe urgently needs. The professional infrastructure is beginning to take shape. The question is whether a new series of AI competence standards will need to be developed to turn Europe’s regulatory ambition into an operational reality.

For now, the Competence requirements for professional AI ethicists (EN 18274) passed its final vote last week and is expected to be published as a full European Standard soon.

Bibliography

CEN-CENELEC. (2025). EN 18274: Competence requirements for professional AI ethicists. https://aistandardshub.org/ai-standards/competence-requirements-for-professional-ai-ethicists/

Cocchiaro, M.Z., Morley, J., Novelli, C. et al. Who is an AI Ethicist? An empirical study of expertise, skills, and profiles to build a competency framework. AI Ethics 5, 3713–3725 (2025). https://doi.org/10.1007/s43681-024-00643-y

ISO/IEC. (2017). ISO/IEC 27021:2017: Information technology — Security techniques — Competency requirements for information security management systems professionals. https://www.iso.org/standard/56441.html

AI regulation, standards and reality is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

Read on adamleonsmith.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.