Ethics Practices in AI Development: An Empirical Study Across Roles and Regions
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: AI Radio. Generated commentary on the latest Artificial Intelligence papers.
Tom: Next we'll be talking about the paper "Ethics Practices in AI Development: An Empirical Study Across Roles and Regions".
Jane: The paper was written by Wilder Baldwin, Sepideh Ghanavati and Manuel Woersdoerfer from University of Maine.
Tom: Stay tuned as we take you through the paper and discuss its implications.
Title: Tom: Welcome back to the show, everybody. Today we're digging into a paper that's been making the rounds, and it's called "Ethics Practices in AI Development: An Empirical Study Across Roles and Regions." Jane, I have to say, just the title alone tells you this isn't another opinion piece about AI ethics — this is actual data.
Jane: Exactly, Tom. And that's what got me excited when I first skimmed this. The authors, Baldwin, Ghanavati, and Woersdoerfer from the University of Maine, they didn't just ask a handful of developers what they think. They went out and surveyed four hundred fourteen people across forty-three countries. That's a big deal because most of the conversation about AI ethics happens in boardrooms or in philosophy papers, not on the ground with the people actually building these systems.
Tom: And that's the key thing, right? They talked to people in very different roles. You've got your AI managers, your developers, your quality assurance folks, even information security and privacy experts. I mean, that's the whole lifecycle of building an AI product, from the person writing the requirements to the person testing it for vulnerabilities.
Jane: Right, and that's what makes this study so valuable. Because when you only ask developers, you get one slice of the story. But when you ask the manager who sets the guidelines, the analyst who writes the requirements, the QA person who tests for bias, and the security expert who worries about data leaks, you start to see where the gaps are. And let me tell you, there are gaps.
Tom: Oh, big ones. I mean, one of the first things that jumped out at me was that people in quality assurance and information security roles were the least familiar with most AI ethics principles. These are the people whose whole job is to catch problems before they reach the user, and they're the ones who know the least about things like fairness or transparency.
Jane: It's almost backwards, isn't it? You'd think the gatekeepers would be the most informed. But the data shows that managers and researchers are the ones who are most familiar with these principles, while the people who actually need to apply them in testing and security are left in the dark.
Tom: So the paper isn't just saying "everyone should know more about ethics." It's saying different roles need different kinds of training, and right now, the training isn't reaching the people who need it most.
Jane: And that's the kind of insight you can only get from a study like this, with this many people, across this many regions. We're going to dig into the actual numbers and what they mean for how teams should be structured. Stick around.
Summary: Tom: So we're back with "Ethics Practices in AI Development: An Empirical Study Across Roles and Regions," and Jane, I want to get into the actual findings, because there's a lot here that surprised me.
Jane: Same here. Let's start with the big one. They asked people how familiar they were with nine different AI ethics principles, things like data protection, transparency, fairness, accountability. And across the board, the most familiar principle was data protection and privacy. Over ninety percent of people with AI development experience said they were at least somewhat familiar with it.
Tom: That makes sense though, right? Privacy has been a thing since before AI was cool. We've had GDPR, we've had all these data breach scandals. So people know that one. But here's what got me — the principle they were least familiar with was "democracy and rule of law." Only about seventy-six percent of experienced developers were familiar with that one.
Jane: And that's a problem, because that principle is about making sure AI doesn't undermine democratic institutions. It's about who gets to make decisions about how AI is used in society. If the people building these systems don't even know that's a consideration, then we're building systems that could have really serious societal impacts without anyone thinking about them.
Tom: Right. And the study also found that this familiarity isn't just about the individual. It's about the role. Managers were the most familiar with all nine principles. Information security people were the least familiar, except when it came to privacy, which makes sense given their job.
Jane: And here's another layer — the researchers found that gender mattered too. Female participants reported higher familiarity with all the principles and said they considered ethics in their work more often than their male counterparts. That's a finding that has implications for how we think about team diversity.
Tom: Yeah, and that's not just a nice-to-have. The paper suggests that diverse teams bring broader ethical perspectives. And they also found that people in government and academic institutions were more familiar with these principles than people in multinational corporations.
Jane: Which is interesting because you'd think big tech companies would have all the resources to train their people. But the data says otherwise. The paper also did some fancy statistical modeling — LASSO regression and mixed-effects models, for those of you who like that kind of thing — and they found that the single biggest predictor of how familiar someone is with AI ethics principles is how familiar they are with AI governance initiatives.
Tom: So knowing about the EU AI Act or the NIST framework actually makes you more likely to know about the underlying principles. It's like the regulations are teaching people what the ethics are.
Jane: Exactly. And that's a really actionable finding. If you want people to understand ethics, teach them about the regulations. We'll get into what this means for how teams should actually work in a minute.
Improvements: Tom: So we've talked about what the paper found, but now I want to get into what they're suggesting we actually do about it. And Jane, this is where I think the paper really shines, because they're not just pointing out problems — they're proposing solutions.
Jane: Absolutely. And one of the most interesting suggestions is around threat modeling. You know how in cybersecurity, you have frameworks like LINDDUN that help you identify privacy risks early in development? The authors are suggesting we need something similar for AI ethics. A structured way to identify ethical risks before you even start building.
Tom: That's a great idea. Instead of waiting until the model is trained and deployed to discover it's biased, you'd have a framework that helps you think through potential ethical issues from the very beginning. Like a checklist, but smarter.
Jane: And they're also pushing for tools that can automatically translate AI ethics regulations into software requirements. So instead of a developer having to read through the entire EU AI Act and figure out what it means for their specific product, you'd have a tool that does that translation for them.
Tom: That would be huge. Because one of the things the study found was that people struggle with vague principles. They know they should be "fair" or "transparent," but what does that actually mean in code? What does it mean in a requirements document?
Jane: Right. And the paper also suggests building nudging tools into development environments. So imagine you're writing code and the tool detects that you're about to use a dataset that might have bias issues, and it prompts you to think about that. Kind of like how your word processor flags spelling errors, but for ethics.
Tom: And they're not just talking about the technical side. They're also emphasizing education. The paper found that a lot of practitioners, especially in QA and security roles, just don't have the training they need. So they're suggesting role-specific training programs, not just a one-size-fits-all ethics course.
Jane: And that's the key insight for me. A manager needs to know different things than a developer. A QA person needs different tools than a security expert. The paper is saying we need to tailor our approach to each role, and we need to make sure the people who are least familiar with ethics principles — the QA and security folks — get the most attention.
Tom: There's also a really interesting finding about regulation. Most practitioners actually see regulations as a positive thing. About sixty-six percent of them said they think AI regulation will have a positive impact. But there's a worry, especially in smaller companies, that compliance could slow down innovation.
Jane: And the paper's data suggests that the people who consider ethics most often in their work are also the ones who view regulation most positively. So the more you practice ethics, the less scary the regulations seem. That's a powerful argument for getting ethics into the workflow early.
Tom: So the message is clear: build the tools, train the people, and make ethics a part of the process from day one, not an afterthought. We'll wrap this up in a second.
Conclusion: Tom: Alright, let's bring it home. We've been talking about "Ethics Practices in AI Development: An Empirical Study Across Roles and Regions," and honestly, this is one of those papers that should be required reading for anyone in the AI field.
Jane: Completely agree. And the core message is simple but powerful. Ethics in AI isn't just about having principles written on a website. It's about making sure the people who build these systems actually know those principles, understand what they mean in practice, and have the tools and training to apply them.
Tom: And the study showed that right now, that's not happening evenly. Managers know their stuff, but the people testing and securing AI systems are being left behind. Women are more engaged with ethics than men, which tells us something about the value of diverse teams. And people who know about regulations are more likely to know about ethics, which tells us that teaching regulations is a way to teach ethics.
Jane: The paper also gives us a roadmap. Build threat modeling frameworks for ethics, build tools that translate regulations into requirements, build nudges into development environments, and build role-specific training programs. It's ambitious, but it's concrete.
Tom: And it's not just about avoiding bad outcomes. It's about building trust. The more people understand how AI works and how it's being kept in check, the more they'll be willing to use it. That's good for everyone.
Jane: Well said. So that's our take on "Ethics Practices in AI Development: An Empirical Study Across Roles and Regions." Big thanks to the authors for doing this work, and to you for listening. We'll be back soon with another paper, so until then, keep asking the hard questions.
Tom: See you next time, folks.
Wilder Baldwin, Sepideh Ghanavati, Manuel Woersdoerfer
University of Maine
cs.CY, cs.AI, cs.HC, cs.SE
Submitted: 2026-08-12
Comments: Accepted at Empirical Software Engineering Journal (EMSE)
License: http://creativecommons.org/licenses/by-nc-nd/4.0/
Importance score: 69/100
The gist: This paper presents a large-scale mixed-methods survey study examining ethical perceptions, practices, and knowledge of individuals involved in various AI development roles.
Key concepts
- AI ethics principles
- These are guidelines for AI development covering areas like data protection, transparency, fairness, and accountability. The study found that data protection and privacy were the most familiar principles among those with AI development experience.
- role-specific training
- The paper suggests that a one-size-fits-all ethics course is insufficient. Instead, training should be tailored to different job roles—such as managers, developers, QA staff, and security experts—to ensure people receive the specific ethical knowledge they need for their tasks.
- AI governance initiatives
- Familiarity with formal AI governance initiatives, like the EU AI Act or NIST frameworks, was found to be the biggest predictor of familiarity with underlying AI ethics principles. Knowing regulations helps practitioners understand the core ethical considerations.
- threat modeling for ethics
- This is a suggestion to create a structured way to identify potential ethical risks early in development, similar to cybersecurity frameworks. The goal is to think through issues like bias before the AI model is trained and deployed.
Terminology
Summary
This paper presents a large-scale mixed-methods survey study examining ethical perceptions, practices, and knowledge of individuals involved in various AI development roles. The study comprises 414 participants from 43 countries, representing roles such as AI managers, analysts, developers, quality assurance professionals, and information security and privacy experts. The research combines statistical and qualitative analyses to address four research questions (RQs) concerning: (RQ1) general perceptions around AI and its usage, (RQ2) familiarity with AI ethics principles and how familiarity, practice, and perception differ across roles and demographics, (RQ3) familiarity with AI governance initiatives, and (RQ4) risk perceptions and mitigation practices.
Participants were recruited through Prolific and online platforms including X (formerly Twitter), Reddit AI-focused subreddits, Quora, LinkedIn, Hugging Face, and Kaggle. Of the 411 participants who reported their location, 201 were from North America, 118 from Europe, 43 from Africa, 25 from Central and South America, 16 from Asia, four from Australia, three from the Middle East, and one from another region. The survey comprised three sections: demographics and experience with AI development; perceptions and practices related to AI; and knowledge, experiences, and risk mitigation strategies regarding AI ethics principles, regulatory initiatives, and best practices. The analysis employed LASSO regression, linear mixed-effects models, Kruskal-Wallis tests, Chi-square tests, and thematic qualitative coding across nine ethics principles, eight governance initiatives, and role-specific risk mitigation strategies.
The results reveal that participants tend to associate AI with process automation and performance enhancement.
Both groups primarily define AI in terms of process automation, performance improvement, content creation, and content synthesis. Even those not involved in AI development use AI in their daily routines, often viewing it as beneficial for enhancing productivity and accuracy.
Most participants (82.24% of Group A and 96.67% of Group B) use AI at least 1-3 times per week, with more than 50% of Group B using AI tools daily. All participants consider increased efficiency
(71.0% and 77.5% of Groups A and B) and improved accuracy
(41.1% and 55.3%) as the main effects of AI on their work. Data protection and security concerns remain prominent, particularly among those who have not yet adopted AI in their development practices,
with privacy and security concerns cited as the most significant factor limiting AI adoption (45.2%).
The findings reveal disparities in familiarity with AI ethics principles across roles and other demographics.
Both groups are most familiar with data protection and the right to privacy
(81.2% and 92.3%) and least familiar with democracy and rule of law
(58.0% and 75.7%). Group B reports significantly higher mean principle familiarity than Group A (U = 9684.5, p < 0.001, r = 0.31). "Participants in oversight roles (e.g., product managers or requirements analysts), researchers, those in government or mid-sized companies, and female participants generally reported higher familiarity with most AI ethics principles. Those in AM roles are the most familiar with all AI ethics principles, followed closely by AI researchers and ethicists, while those in ISec roles are least familiar with most principles except
data protection and the right to privacy and
harm prevention and beneficiary."
The Intra-Class Correlation (ICC) revealed greater variability within roles than between them
for familiarity (ICC = 2.9%), but for ethics consideration frequency, ICC = 15.5%, indicating that role has a negligible impact on knowledge but a moderate impact on practice frequency.
Female participants are more familiar with all principles than male participants (p = 0.0003). The LASSO analysis showed that familiarity with AI governance initiatives, particularly the EU AI Act, is the factor most strongly associated with higher familiarity with AI ethics principles
(β = 0.154). The mixed-effects models confirmed that while AI development experience significantly predicts familiarity (β = 0.182, p = 0.001), it accounts for only 6.3% of the variance, whereas familiarity with AI governance initiatives is the dominant predictor of ethics consideration frequency (β = 0.348, p < 0.001), explaining 17.4% of the variance.
Familiarity with AI governance initiatives likewise varies across roles and demographics.
AI managers were the most familiar with governance initiatives, whereas those in quality assurance and information security roles were the least. North American participants generally reported greater familiarity than their European counterparts, except for the EU AI Act, which was most familiar to participants in the EU, EEA, and UK. For Group B, significant correlations were found between familiarity with AI governance initiatives and participants' roles, location, company size, and gender (p-values = 0.0008, 0.0003, 0.000, and 0.0001, respectively). "Perceptions of these initiatives are largely positive: a majority (66.5%) view the impact of AI regulation favorably, though some practitioners, particularly in smaller companies, worry that compliance could slow innovation. The LASSO analysis indicates that
a positive regulatory outlook is most strongly associated with how frequently practitioners consider ethics in their work (β = 0.333), suggesting that hands-on experience with ethical practice reduces regulatory anxiety."
Risk mitigation practices vary notably by role and demographic context.
Individuals in administrative roles such as product managers often focus on establishing clear ethical guidelines, providing AI ethics training to their employees, and communicating AI ethics principles across their organizations.
Along with requirements analysts, they frequently lead ethics-related risk and impact assessments of AI systems. Those in development roles employ complementary strategies such as evaluating model outputs or assessing model performance across diverse populations, to mitigate biases in AI systems.
Information security and privacy practitioners tend to focus mainly on traditional security measures, such as encryption and access control, rather than other aspects of AI ethics.
Researchers rely on institutional guidelines, policies, or personal judgment when developing AI tools, yet they report challenges in writing ethics statements due to the difficulty of addressing multiple ethical considerations and the lack of precise guidance.
The paper concludes that "these findings underscore the importance of structured ethics guidelines and robust cross-role communication to ensure that diverse perspectives inform ethical decision-making and support the effective integration of ethics into AI development. The authors advocate for
developing tailored, inclusive solutions to address ethical challenges in AI development and propose future research directions including: development of standardized threat modeling for ethics in AI systems, practical tools and automated frameworks to support
ethics by design," tools for automated translation of AI ethics regulations into software requirements, nudging tools embedded within development environments, tools enabling automated testing of ethics requirements, and investigation of regulatory and cultural influences. Educational takeaways emphasize that educational programs should move beyond traditional technical training to include modules on ethical risk assessment, transparency, communication, and the practical implementation of governance frameworks.
Improvements for AI systems
Based on the findings of this paper, I can implement the following specific improvements to AI systems:
Improvement: Implement a role-based ethics configuration system that adapts AI behavior and transparency levels based on the user's professional role (developer, manager, QA, security expert, researcher).
What the improved system can do:
-
For managers/administrators: Automatically generate ethics compliance reports, flag potential regulatory violations (especially EU AI Act), and provide executive summaries of ethical risks
-
For developers: Provide real-time bias detection in training data, suggest diverse dataset augmentation, and offer explainability features for model outputs
-
For QA/testers: Automatically generate test cases targeting vulnerable groups, run fairness audits across demographic subgroups, and flag potential discrimination patterns
-
For security experts: Emphasize data encryption, access control, and privacy-preserving techniques while also alerting them to broader ethical concerns beyond just security
These improvements collectively create an AI system that is role-aware, governance-compliant, ethically proactive, and capable of bridging the gaps identified in the paper between different development roles and their ethical practices.
Abstract
Recent advances in AI applications have raised growing concerns about the need for ethical guidelines and regulations to mitigate the risks posed by these technologies. In this paper, we present a mixed-methods survey study - combining statistical and qualitative analyses - to examine the ethical perceptions, practices, and knowledge of individuals involved in various AI development roles. Our survey comprises 414 participants from 43 countries, representing various roles such as AI managers, analysts, developers, quality assurance professionals, and information security and privacy experts. The results reveal varying degrees of familiarity and experience with AI ethics principles, government initiatives, and risk mitigation strategies across roles, regions, and other demographic factors. Our findings underscore the importance of a collaborative, role-sensitive approach that involves diverse stakeholders in ethical decision-making throughout the AI development lifecycle. We advocate for developing tailored, inclusive solutions to address ethical challenges in AI development, and we propose future research directions and educational strategies to promote ethics-aware AI practices.
Sources
- Current state of LLM Risks and AI Guardrails
- Ethically Aligned Design of Autonomous Systems: Industry viewpoint and an empirical study
- Understanding Practices, Challenges, and Opportunities for User-Engaged Algorithm Auditing in Industry Practice
- How Close is ChatGPT to Human Experts? Comparison Corpus, Evaluation, and Detection
Related papers
- Reasoning Enhances Robustness to Prompt Injection in LLM-Based Consensus
- Generative AI Purpose-built for Social and Mental Health: A Real-World Pilot
- PersonaMem-v3: Toward Omni-Platform Personal Intelligence for Holistic User Understanding, Recommendation, and Agentic Tasks
- What is an intelligent system?
- AI University: An LLM-Powered Learning Assistant for Engineering---A Finite Element Method Case Study
- Generative AI Use in Entrepreneurship: An Integrative Review and an Empowerment-Entrapment Framework