Regulators across jurisdictions have required that AI systems be fair and unbiased. None has specified how either should be measured. The compliance burden falls on organizations to define the standard they are meeting — and to defend that choice.
- Governments requiring AI fairness and bias assessment share three convergent goals: preventing discriminatory outcomes in consequential decisions, protecting fundamental rights, and creating accountability for automated decisions. The problem is not the goals — it is the gap between what regulators want to achieve and what they have told organizations to measure.
- "Bias" is not one thing. It encompasses at least five distinct concepts — statistical bias, data bias, design and framing bias, outcome bias, and automation bias — each requiring different interventions and carrying different legal implications. Most technical audits measure one or two of these. Most regulatory requirements are aimed at a different one entirely.
- "Fairness" has over twenty formal definitions in the academic literature, several of which are mathematically incompatible. Demographic parity, equal opportunity, and calibration cannot all be satisfied simultaneously when base rates differ across groups. Choosing among them is a policy decision with legal implications — not a technical one.
- The EU, US, and China each ground their fairness requirements in different legal theories — fundamental rights, disparate impact doctrine, and substantive anti-discrimination respectively — pointing toward different implied measurement standards. A multinational organization must navigate all three simultaneously, and satisfying one does not guarantee satisfying the others.
- No jurisdiction has specified which statistical test or fairness metric constitutes compliance. The choice of metric is itself a governance decision that must be made, documented, and defensible — and most organizations have not made it deliberately.
The regulatory requirement without a measurement standard
Governments requiring AI fairness and bias assessment share three convergent goals: preventing discriminatory outcomes in consequential decisions, protecting fundamental rights from AI-mediated erosion, and creating accountability for automated decisions that affect individuals. These objectives are legitimate and important.
The problem is not the goals. It is the gap between what regulators want to achieve and what they have told organizations to measure.
The EU AI Act — the most comprehensive AI regulatory framework to date — requires that training, validation, and testing datasets be examined for possible biases likely to affect fundamental rights or lead to discrimination prohibited under Union law. Nowhere in the Act is the term "bias" defined. No specific statistical test or metric is prescribed. US civil rights law applies disparate impact doctrine to AI-mediated decisions across employment, credit, and housing — without specifying how that doctrine translates into a technical measurement standard for algorithmic systems. China's Generative AI Measures require effective measures to prevent discrimination across specified protected attributes, without specifying what "effective" means in technical or statistical terms.
The result is that organizations deploying AI in consequential domains — employment, credit, healthcare, education, legal services — are required to demonstrate compliance against standards that have not been defined with precision. That burden requires choices that are themselves governance decisions: which definition of bias applies, which protected attributes are in scope, which outcomes are being measured, which metric is used, and by whose standard the system is fair.
Most organizations have not made these choices deliberately. Many have outsourced them implicitly to the technical vendor that conducted their last audit — without realizing that the vendor's default choices are normative positions, not neutral technical measurements.
"Bias" is not one thing
Before any measurement can take place, GCs and compliance officers need to understand what is actually being measured — because "bias" as used in regulatory contexts conflates at least five distinct concepts, each requiring different interventions and carrying different legal implications.
Most technical audits measure statistical bias or data bias — the first and second on the list above. Most regulatory requirements are aimed at outcome bias — the fourth. The gap between what is measured and what is required is where compliance risk lives. An organization whose audit report addresses only dataset representativeness has not answered the question most regulators are actually asking.
"Fairness" has multiple incompatible definitions
Even accepting that outcome fairness is the goal, there is no single agreed measure. The academic literature has identified over twenty formal definitions of algorithmic fairness. Several of the most commonly used are mathematically incompatible with each other — they cannot all be satisfied simultaneously except in trivial cases.
Three definitions appear most frequently in regulatory and compliance contexts:
The incompatibility problem — established formally by Chouldechova (2017) and Kleinberg et al. (2016) — demonstrates that demographic parity, equal opportunity, and calibration cannot all be satisfied simultaneously when base rates differ across groups. This is almost always the case in real-world applications. Optimizing for one definition of fairness necessarily means accepting that the system will fail the others.
This is not a technical problem awaiting a better algorithm. It is a policy problem requiring a normative choice about which kind of unfairness is more acceptable. That choice has legal and ethical implications that go beyond what a data science team should be deciding alone — and yet in most organizations, it is the data science team that decides it by default, through whichever metric their tooling happens to optimize for.
An audit report that says "the model achieves demographic parity across protected groups" has made a normative choice — that demographic parity is the right definition of fairness for this system and use case. That choice may simultaneously mean that the model fails equal opportunity and calibration. The report is not wrong, but it is incomplete unless it discloses what definition was used, why, and what the model's performance looks like under alternative definitions.
An organization that receives such a report and presents it as evidence of compliance without understanding the underlying definitional choice is making a compliance claim it cannot fully defend.
Different jurisdictions, different legal theories
The three major regulatory approaches to AI fairness are grounded in different legal theories pointing toward different implied measurement standards. A multinational organization must navigate all three simultaneously — and satisfying one does not guarantee satisfying the others.
The EU approach — fundamental rights and data governance
The EU AI Act addresses bias through two distinct mechanisms that serve different purposes and are often conflated in compliance discussions.
Article 10(2)(f) requires that datasets be examined for biases likely to affect health and safety, have a negative impact on fundamental rights, or lead to discrimination prohibited under Union law — particularly where data outputs influence future inputs. This is an input-side obligation targeting bias in training data. Article 10(5) adds a limited debiasing exception permitting processing of sensitive data categories for bias detection and correction under strict conditions.
Article 14(4)(b) addresses a different problem: automation bias. High-risk AI systems must be designed to enable human oversight sufficient to avoid over-reliance on system outputs. This is a behavioral requirement targeted at the human decision-making layer — not the model. Most compliance programs focused on data auditing are not addressing this obligation at all.
The Act's fairness requirements are anchored to discrimination "prohibited under Union law" — existing EU non-discrimination directives and the Charter of Fundamental Rights — without specifying how those legal standards translate into technical measurement obligations. The Act defines neither "bias" nor a measurement methodology. Organizations subject to it must determine, with legal counsel, which technical measurement approach is consistent with the legal non-discrimination standard applicable to their use case.
The US approach — civil rights doctrine across multiple domains
The United States has not enacted comprehensive federal AI legislation. Instead, existing civil rights frameworks apply to AI-mediated decisions across multiple domains, with a consistent underlying principle: existing anti-discrimination law applies fully to algorithmic systems, the fact that a decision was made by an AI is not a defense, and organizations using third-party AI tools remain liable for discriminatory outcomes those tools produce.
In employment, disparate impact doctrine under Title VII applies to algorithmic decision-making tools used in hiring, promotion, and termination. The EEOC has confirmed that such tools are subject to the same analysis as any other selection procedure. The four-fifths rule — under which adverse impact is generally indicated when a selection rate for a protected group is less than 80% of the rate for the highest-scoring group — is a rule of thumb in enforcement guidance, not the legal standard itself. The EEOC has explicitly stated it does not provide a safe harbor, and that smaller differences may indicate adverse impact depending on context and sample size.
In credit and consumer finance, the Equal Credit Opportunity Act and Consumer Financial Protection Act apply. The CFPB has confirmed that courts have held that using an algorithmic tool can itself constitute a policy producing bias under disparate impact theory. Critically, the CFPB has rejected the black box argument: the complexity or opacity of a model cannot be used as a defense against violations of the ECOA. Fair lending testing must include both disparate treatment and disparate impact analysis, and must include searches for less discriminatory alternatives.
In housing and property appraisal, a 2024 joint rule from the CFPB and five federal banking agencies requires companies using algorithmic appraisal tools to implement safeguards ensuring accuracy, data integrity, and compliance with non-discrimination law.
The China approach — anti-discrimination and values alignment as distinct obligations
China's AI governance framework combines two types of fairness requirements that serve different regulatory purposes and should not be conflated.
The Interim Measures for the Management of Generative Artificial Intelligence Services (effective August 2023) contain substantive anti-discrimination obligations: providers must take effective measures to prevent discrimination on the grounds of nationality, religion, country or region, gender, age, occupation, and health — across algorithm design, training data selection, model generation and optimization, and service provision. This is a lifecycle-spanning obligation, not limited to output monitoring.
The Algorithm Recommendation Management Provisions (effective March 2022) impose obligations on algorithm transparency, fairness, content moderation, and algorithm filing — and separately require that providers promote "mainstream values" and avoid content endangering national security or disrupting social order. This values-alignment requirement is distinct from the anti-discrimination obligation and serves a different regulatory purpose. Treating them as the same requirement mischaracterizes both.
Neither set of requirements specifies a measurement methodology. The anti-discrimination obligation is process-oriented — take effective measures — without specifying what "effective" means in technical or statistical terms. Organizations operating in China must determine, with counsel familiar with Chinese law, what process and measurement approach is sufficient to demonstrate compliance.
What meaningful measurement actually requires
A meaningful bias assessment is not a single test. It is a sequence of governance decisions, each of which must be made before technical measurement begins. Most audit reports GCs and compliance officers receive do not reflect this — they present a metric without specifying why that metric was chosen, what alternatives were considered, or what the result means relative to the applicable legal standard.
A defensible bias assessment requires specifying six things explicitly:
What GCs and compliance officers should require
Before commissioning an audit
Has the organization made a deliberate choice about which definition of fairness it is measuring — and documented the rationale? Has legal counsel confirmed which legal standard applies in each relevant jurisdiction for this specific use case and domain? Has the scope of protected attributes been defined in consultation with legal counsel, not delegated entirely to the technical team? Is the audit designed to address the full decision pipeline — model output, human decision incorporating that output, and final outcome — or only the model?
In reviewing an audit report
Does the report specify which fairness metric was used and why — and why not the alternatives? Does it disclose how the model performs under alternative fairness definitions? Does it specify which protected attributes were tested, at which point in the pipeline, and against which baseline? Does it address automation bias in the human decision-making layer, not only model-level bias? If a disparity was identified, does the report include a remediation plan with identified owners and timelines?
Most importantly: does the report explain how its findings relate to the applicable legal standard in each relevant jurisdiction — not just the technical metric used? An audit result that speaks only to the technical metric, without bridging to the legal standard, is not a compliance document. It is evidence that a measurement was taken.
On vendor claims
"Bias-free AI" is not a meaningful claim. It implies a single agreed standard of fairness that does not exist. A product described as bias-free has been found to satisfy one definition of fairness — and that definition, by the incompatibility theorem, means it fails others.
A claim that a model has been tested for bias is only meaningful if the methodology, the metric used, the attributes tested, the point in the pipeline assessed, and the relationship to the applicable legal standard are all specified. An audit report that does not specify these is a technical exercise without a normative anchor. It is not evidence of compliance — and presenting it as such creates, rather than reduces, legal exposure.
Working through these questions?
The analysis this article describes sits at the intersection of AI governance, data science methodology, legal non-discrimination standards, and organizational risk management — disciplines that most organizations do not have integrated under one function. If you are assessing your AI bias compliance posture or evaluating an audit you have received, we are happy to talk.
- ›Contact: cloudvistaconsulting.com/contact
- ›Email: contact@cloudvistaconsulting.com
- ›LINE and WhatsApp details are in the site footer
This article is for informational purposes only and does not constitute legal advice. It examines general questions about how regulatory frameworks approach AI fairness and bias assessment. The observations are general in nature and do not account for the specific circumstances, jurisdiction, or regulatory environment of any particular organization. Professional advice should be sought where specific action is contemplated.
歐盟、美國、中國等主要司法管轄區均已明確要求AI系統具備公平性並不得存在偏差,然而均未指明應以何種方式加以測量。合規舉證的責任,因此落在機構身上——機構須自行界定所達到的標準,並在必要時為這項選擇進行辯護。
- 各司法管轄區要求AI公平性與偏差評估的政府,共同指向三個目標:防止重大決策中的歧視性結果、保護基本權利免受AI媒介的侵蝕,以及建立對自動化決策的問責機制。問題不在於目標本身,而在於監管機構的訴求與機構被告知應測量之事物之間的落差。
- 「偏差」不是一個概念,而是至少五種截然不同的概念——統計偏差、資料偏差、設計與框架偏差、結果偏差,以及自動化偏差——各自需要不同的干預措施,在法律上的含意亦各有差異。多數技術稽核所測量的,是其中一兩種;多數監管要求所針對的,卻是另一種。
- 「公平性」在學術文獻中有逾二十種正式定義,其中數種在數學上相互不相容。人口均等性、機會均等性與校準性,在各群體基礎比率不同的情況下,無法同時得到滿足。在三者之間作出選擇,是一項具有法律含意的政策決定,而非技術決定。
- 歐盟、美國與中國各以不同的法律理論——基本權利、差異影響原則,以及實質性反歧視義務——為其公平性要求奠基,並隱含指向不同的測量標準。跨國機構必須同時應對三者,滿足其中一項並不必然意味著滿足其他。
- 目前沒有任何司法管轄區明確規定,以何種統計測試或公平性指標構成合規。指標的選擇本身,是一項必須作出、記錄在案且具備可辯護性的治理決策——而多數機構從未刻意作出這項選擇。
沒有測量標準的法規要求
各司法管轄區要求AI公平性與偏差評估的政府,均指向三個共同目標:防止重大決策中的歧視性結果、保護基本權利免受AI媒介決策的侵蝕,以及建立對自動化決策影響個人的問責機制。這些目標具有正當性,也確有其重要性。
問題不在於目標本身,而在於監管機構的訴求與機構被告知應測量之事物之間的落差。
《歐盟AI法案》——迄今最為全面的AI法規框架——要求對訓練、驗證及測試資料集進行審查,以識別可能影響基本權利或導致歧視的偏差。然而,「偏差」一詞在法案全文中從未得到定義,亦未規定任何具體的統計測試或指標。美國民權法律框架將差異影響原則適用於AI媒介的就業、信貸與住房決策,卻未說明該原則如何轉化為演算法系統的技術測量標準。中國《生成式人工智能服務管理暫行辦法》要求業者採取有效措施防止歧視,卻未說明「有效」在技術或統計層面意指何物。
結果是:在就業、信貸、醫療、教育、法律服務等重大領域部署AI的機構,須就尚未精確界定的標準承擔合規舉證責任。這項責任要求機構在技術測量之前,先行作出一系列本身即屬治理決策的選擇:適用哪種偏差定義、哪些受保護屬性納入範疇、測量哪些結果、採用哪種指標、依據誰的標準判定系統是否公平。
多數機構從未有意識地作出這些選擇。許多機構在不自覺的情況下,將這些選擇轉包給負責執行稽核的技術供應商——卻未意識到,供應商的工具預設值是規範性立場,而非中立的技術測量結果。
「偏差」不是一個概念
「偏差」在監管文件中頻繁出現,但監管機構與技術實務所指涉的,往往是截然不同的概念。在委託任何測量工作之前,法務長與法遵長須先釐清:技術團隊實際測量的是哪一種偏差,這與監管要求所針對的,是否為同一回事。這不是細節問題。至少五種截然不同的概念被「偏差」這個詞所涵蓋,各自需要不同的干預手段,在法律層面的含意亦各有差異。
多數技術稽核所測量的,是統計偏差或資料偏差——上述五類中的第一或第二類。監管機構所關切、亟需防範的,卻是結果偏差——第四類。稽核所觸及的範疇,與監管要求所指向的範疇,並不重合。一份僅就資料集代表性進行審查的稽核報告,尚未觸及多數監管機構所實際要求回答的問題。
「公平性」有多種互不相容的定義
即便承認結果公平性是目標,也不存在單一公認的測量方式。學術文獻已識別出逾二十種演算法公平性的正式定義,其中數種在數學上相互不相容——在非平凡情況下,無法同時得到滿足。
以下三種定義在監管與合規脈絡中最為常見:
Chouldechova(2017年)與Kleinberg等人(2016年)已從數學上嚴格證明:在各群體基礎比率不同的情況下,人口均等性、機會均等性與校準性三者無法同時成立。而在實際應用場景中,各群體的基礎比率幾乎必然存在差異。換言之,優化任何一種公平性定義,必然在其他定義下製造新的失敗。沒有例外。
這不是演算法優化能夠解決的工程問題,而是「哪一種不公平在當前使用情境中較為可被接受」的政策判斷。這項判斷牽涉法律義務與倫理責任,遠非資料科學團隊所能獨自承擔——但在多數機構中,恰恰是資料科學團隊,透過其工具所預設的優化目標,在不自覺間代替整個機構作出了這項選擇。
一份聲稱「模型在受保護群體間實現了人口均等性」的稽核報告,在作出這項陳述的同時,已作出了一項規範性選擇:以人口均等性作為衡量此系統與此使用情境是否公平的準繩。這項選擇的代價,是模型在機會均等性與校準性定義下可能存在的缺陷。報告本身並無錯誤,但若未揭示所採用的定義、選擇該定義的理由,以及模型在替代定義下的表現,便只呈現了部分事實。
機構若在未充分理解這項定義性選擇的情況下,接受並提交此份報告作為合規證據,其合規主張的可辯護性,便已出現無法以事後補救填補的缺口。
不同司法管轄區,不同法律理論
三大主要監管框架的法律理論基礎各異,所隱含的測量標準亦不相同。對跨國機構而言,三者須同時應對;滿足其中一項監管框架的要求,不等於在其他框架下亦已合規。
歐盟——基本權利與資料治理
《歐盟AI法案》透過兩項在合規討論中常被混淆的不同機制處理偏差問題。
第10條第2款第(f)項要求對資料集進行審查,以識別可能影響基本權利或導致歐盟法律禁止的歧視的偏差,特別是在資料輸出影響未來輸入的情況下。這是一項輸入端義務,針對的是訓練資料中的偏差。第10條第5款增設了有限的「去偏差例外」,在嚴格條件下允許為偵測和糾正偏差的目的處理敏感資料類別。
第14條第4款第(b)項針對不同的問題:自動化偏差。高風險AI系統的設計須能使人類監督者充分履行監督職能,避免過度依賴系統輸出。這是針對人類決策層的行為要求,而非模型屬性。多數聚焦於資料稽核的合規方案,並未就此項義務採取任何回應措施。
法案將公平性要求連結至「歐盟法律所禁止的歧視」——即現行歐盟反歧視指令及《歐盟基本權利憲章》——卻未說明這些法律標準如何在技術層面落地。「偏差」一詞在法案全文中從未獲得定義,測量方法亦未有規定。法律標準已然錨定,技術實施的橋樑卻付之闕如。受法案適用的機構,須與法律顧問共同釐清,就其具體使用情境而言,何種技術測量方式能夠回應法律反歧視標準的要求。
美國——橫跨多個領域的民權法律原則
美國迄今未制定全面的聯邦AI法規,現行民權法律框架承擔了反歧視義務的主要載體功能,並橫跨多個領域適用於AI媒介的決策。貫穿各領域的共同立場是:現行反歧視法律完整適用於演算法系統;以「由AI決策」為由提出抗辯,在現行法律框架下不能成立;使用第三方AI工具的機構,仍須對該工具所產出的歧視性結果承擔責任。
在就業領域,《第七章》下的差異影響原則適用於招募、晉升與解僱中使用的演算法決策工具。美國就業機會均等委員會(EEOC)已確認此類工具與其他任何甄選程序適用相同分析。五分之四原則——即受保護群體的錄取率低於最高得分群體80%時,通常被認為存在不利影響——是執法準則中的參考標準,並非法律本身,EEOC亦明確表示其不構成安全港。
在信貸與消費金融領域,《機會平等信貸法》及《消費者金融保護法》適用。美國消費者金融保護局(CFPB)已確認,法院已認定機構選擇使用演算法決策工具,本身即可構成差異影響理論下產生偏差的政策。尤其值得關注的是,CFPB明確拒絕黑箱抗辯:模型的複雜性或不透明性,不能用作違反《機會平等信貸法》的抗辯理由。公平貸款測試須同時涵蓋差異對待與差異影響分析,並須尋找歧視性較低的替代方案。
在住房與不動產評估領域,2024年CFPB聯合五家聯邦銀行監管機構頒布的規則,要求使用演算法評估工具的機構建立保障措施,確保估值準確性、資料完整性,並符合反歧視法律。
中國——實質性反歧視義務與價值觀對齊義務
中國的AI治理框架同時包含兩類公平性要求,二者各有其監管目的,性質上截然不同,不宜混為一談。
《生成式人工智能服務管理暫行辦法》(2023年8月施行)包含實質性反歧視義務:業者須在演算法設計、訓練資料選擇、模型生成與優化及服務提供等各環節,採取有效措施防止基於民族、宗教、國別或地區、性別、年齡、職業、健康等原因的歧視。這是一項涵蓋AI全生命週期的過程性義務,並非僅限於輸出端的監控。
《互聯網信息服務演算法推薦管理規定》(2022年3月施行)就演算法透明度、公平性、內容審核及演算法備案設定義務,並另行要求業者積極傳播「主流價值觀」、避免危害國家安全或擾亂社會秩序的內容。這項價值觀對齊義務在性質上與反歧視義務截然不同,服務於不同的監管目的。將兩者混同,既歪曲了中國的公平性要求,亦遮蔽了其所包含的實質性反歧視義務。
上述兩套規定,均未指明合規所需採用的測量方法論。反歧視義務要求業者採取「有效措施」,卻未賦予「有效」任何技術或統計層面的具體含義。在中國市場運營的機構,須與熟悉中國法律的顧問共同評估,何種過程設計與測量方法,足以在實務上支撐合規立場。
有意義的測量究竟需要什麼
有意義的偏差評估,不是一次性的技術測試,而是一系列必須在測量展開之前完成的治理決策。法務長與法遵長所收到的多數稽核報告,往往缺乏這一層認識——報告呈現一個指標結果,卻未說明選擇該指標的理由、考量過哪些替代方案,也未說明這一結果相對於適用法律標準究竟意味著什麼。
一份具備可辯護性的偏差評估,至少須就以下六項作出明確說明:
法務長與法遵長應當要求什麼
委託稽核前的核心問題
在委託任何偏差稽核之前,機構至少須先釐清以下事項:機構是否已刻意選擇了所要測量的公平性定義,並留有選擇理由的書面記錄?法律顧問是否已就此具體使用情境,確認了各相關司法管轄區所適用的法律標準?受保護屬性的範疇,是否已與法律顧問共同劃定,而非全數委由技術團隊決定?稽核範圍是否涵蓋決策管線的完整節點——模型輸出、人類決策與最終結果——抑或僅止於模型本身?
審閱稽核報告的關鍵提問
報告是否說明了採用何種公平性指標、選擇該指標的理由,以及捨棄其他指標的依據?是否揭示了模型在替代定義下的表現狀況?哪些受保護屬性被納入測試、在管線哪個節點進行、以何種基準線為參照,報告是否均有所說明?對於人類決策層的自動化偏差,報告是否有所觸及,或僅限於模型本身的測量?若已識別出差異,報告是否附有責任歸屬清晰、時程明確的糾正方案?
尤其關鍵的一點:報告是否說明了其發現與各相關司法管轄區法律標準之間的對應關係——而非只呈現技術指標本身?一份只陳述技術指標、未就法律標準進行銜接的稽核報告,不是合規文件,而是「某項測量已完成」的技術紀錄,兩者不可混同。
如何看待供應商的聲明
「無偏差AI」並非實質性聲明。這四個字背後所隱含的,是一個根本不存在的單一公認公平性標準。所謂「無偏差」,不過意味著產品在某種特定定義下通過了測試——而根據不相容性定理,這同時意味著在其他定義下必然存在缺陷。
「模型已完成偏差測試」這項聲明,唯有在明確說明測試方法論、採用的指標、涵蓋的受保護屬性、評估的管線節點,以及與適用法律標準之間的關係後,方具有實質意義。一份未就公平性定義的選擇及其理由作出說明的稽核報告,是缺乏規範性基礎的技術練習,並非合規文件。以此作為合規證據向監管機構或法院提交,其所製造的法律暴露,很可能大於其所緩解的風險。
正在面對這些問題?
本文所描述的分析,橫跨AI治理、資料科學方法論、法律反歧視標準與組織風險管理——多數機構並不具備在同一架構下整合上述能力的條件。若貴機構正在評估AI偏差合規立場,或對所接收的稽核報告存有疑問,歡迎與雲蔚聯繫。
- ›聯絡頁面:cloudvistaconsulting.com/contact
- ›電郵:contact@cloudvistaconsulting.com
- ›LINE及WhatsApp聯絡方式詳見網站頁尾
本文僅供資訊參考,不構成法律意見。本文就監管框架應對AI公平性與偏差評估的一般性問題進行概括性探討。所提出之觀察係就一般情形而言,未能涵蓋各機構之具體情況、所在司法管轄區或適用之監管環境。如擬就具體事項採取行動,應尋求專業建議。