Responsible AI
Children, Vulnerable Groups, and High-Dependency Contexts
Assess heightened risks where age, disability, poverty, detention, illness, migration status, or institutional dependency reduces autonomy and recourse.
By the end you can
- Explain why governance for vulnerable populations must address contextual dependency, practical voluntariness, comprehension, recovery resources, and cumulative exposure
- Distinguish Formal consent, Protective design, and Proxy decision making
- Identify evidence that connects capacity and comprehension to cumulative exposure
- Design a review that moves from identify dependency to monitor cumulative harm
Visual
Five questions a consent form does not answer
Capacity, freedom to refuse, dependency, recovery resources, cumulative exposure. That is five questions, and a consent form answers only the first of them. The other four are settled by what refusal costs.
A US regulator has demanded exactly that arithmetic on the record since 1978. Before an institutional review board may approve research inside a prison, it has to weigh what the study offers against what the prison already offers — general living conditions, medical care, quality of food, amenities, opportunity for earnings. If the advantages are so large that the prisoner can no longer weigh the risks “in the limited choice environment of the prison”, the board may not approve it. Nothing in that test looks at the signature.
- 1
Capacity and comprehension
Can the person understand the choice and likely consequences?
- 2
Freedom to refuse
Can refusal occur without losing essential service, status, or safety?
- 3
Dependency
How much power does the institution hold over daily life or future opportunity?
- 4
Recovery resources
Can the person obtain advice, evidence, correction, and compensation?
- 5
Cumulative exposure
Does the system add to surveillance or disadvantage across institutions?
Comparison
Formal consent, Protective design, or Proxy decision making?
Formal consent records an agreement. Protective design removes the need to rely on one. Proxy decision making hands the choice to somebody else entirely. The last two are not abstractions to be designed from scratch. Both already exist in enforceable text, and the text is where to read what they require.
Protective design has a worked instrument. The UK's Age Appropriate Design Code came into force on 2 September 2020, with a 12-month transition. It is a statutory code: the Data Protection Act 2018 obliged the Information Commissioner to write it, and to have regard to the UK's obligations under the UN Convention on the Rights of the Child. It sets 15 standards. High-privacy settings by default. Data minimisation. Geolocation off by default. No nudge techniques that weaken privacy settings. Not one of them asks a child to agree to anything. The Commissioner's foreword states the ambition plainly: “This statutory code of practice looks to change that, not by seeking to protect children from the digital world, but by protecting them within it.”
Proxy decision making has a working legal model too, and it is not a transfer of the decision but a split of it. The US rules for research with children, in force since 1983, keep two agreements apart. The guardian's agreement is called permission. The child's own agreement is called assent, and the definition guards it: “Assent means a child's affirmative agreement to participate in research. Mere failure to object should not, absent affirmative agreement, be construed as assent.” Silence is explicitly not counted. The review board judges capacity to assent from the ages, maturity and psychological state of the children involved. Assent may be dispensed with in two cases only: where capability is so limited that the children cannot reasonably be consulted, or where the research holds out a direct benefit important to their health and available only in that research.
Formal consent
Records an expressed agreement.
- May satisfy one procedural condition
- Can be invalid under coercion or opacity
- Does not justify every downstream use
- Needs withdrawal and data governance
Protective design
Reduces dependency on consent for essential safeguards.
- Minimizes collection and automation
- Provides independent review and advocacy
- Uses age-appropriate or accessible communication
- Limits secondary use and retention
Proxy decision making
Allows guardians or institutions to decide.
- Sometimes legally or practically necessary
- May not reflect the person’s interests
- Requires conflict and abuse safeguards
- Should preserve participation where possible
Example
USD 19,910, taken before anyone was heard
The Michigan Unemployment Insurance Agency ran an automated fraud-detection system called MiDAS. Claimants alleged that it disqualified them, assessed penalties, and garnished wages and tax refunds without meaningful notice or an opportunity to be heard. Grant Bauserman, the named plaintiff, was told he owed USD 19,910 on benefits collected between September 2013 and March 2014.
The case reached the Michigan Supreme Court as Bauserman v Unemployment Insurance Agency. On 26 July 2022 it held for the first time that monetary damages are available to remedy a violation of the Michigan Constitution: “Although we have never specifically held that monetary damages are available to remedy constitutional torts, we now hold that they are.” The class action then settled for USD 20 million, covering roughly 3,000 wrongly accused claimants. The Michigan Court of Claims approved the settlement in late January 2024.
Read the dates in order. Benefits collected from September 2013. A Supreme Court decision on 26 July 2022. Settlement approval in late January 2024. The recovery-resources question stops being abstract. Money was taken first, and the right to sue for it was established afterwards. That is the cost of a remedy whose only route runs back through the institution that made the decision.
The shelter now under review is the same shape one step earlier. It introduces an AI case-management assistant that recommends services. Residents depend on the shelter for housing, and fear that refusing data collection could affect their place, even though the consent form says participation is optional.
- Formal choice: The interface offers an accept or a decline button. MiDAS is the reminder that a system can reach a life-altering conclusion with no button offered at all.
- Material dependency: Residents rely on the shelter for essential housing and support, as claimants relied on the Unemployment Insurance Agency for the benefits it later clawed back by garnishment.
- Information asymmetry: People cannot evaluate future data uses or model errors. Grant Bauserman met the agency's conclusion as a demand for USD 19,910 on benefits collected September 2013 to March 2014.
- Retaliation fear: A nominally optional choice may feel unsafe to exercise.
- Remedy weakness: Residents lack independent advocacy and stable contact after leaving. Bauserman prices that gap: a Michigan Supreme Court ruling on 26 July 2022, then a USD 20 million settlement for roughly 3,000 wrongly accused claimants, approved in late January 2024.
Dependency is what survives a signature
Vulnerability is contextual rather than an inherent label. It can arise from age, dependency, coercion, unequal information, limited resources, legal status, disability, crisis, or simply being unable to leave and seek remedy. Dependency is the one that survives a consent form. Shelter residents sign willingly and still cannot refuse.
That is not a novel ethical claim. It has been binding US regulation since 16 November 1978, when the prisoner safeguards were added to the federal human-subjects rules. The purpose section gives the reasoning in one sentence: “Inasmuch as prisoners may be under constraints because of their incarceration which could affect their ability to make a truly voluntary and uncoerced decision whether or not to participate as subjects in research, it is the purpose of this subpart to provide additional safeguards for the protection of prisoners involved in activities to which this subpart is applicable.” Notice what the safeguards that follow are not: a better consent form. They alter the conditions around the choice. The review board must have assurance that parole boards will not take participation into account, and that each prisoner is told so in advance. The cost of refusing is removed, not merely disclosed.
Higher dependency calls for stronger necessity tests, narrower data use, independent advocacy, and communication that is age-appropriate or otherwise accessible. It calls for conservative automation, monitoring for coercion, and remedies that do not depend on institutional goodwill.
Independent advocacy is the item an institution cannot provide to itself. That is why it is usually the one missing when a decline button is the only protection on offer.
Set the level of protection from the dependency itself: the less able someone is to walk away, the narrower the data use and the more conservative the automation should be.
Analogy
A contract offered during an emergency
Ask someone to accept complex terms while they are waiting to be rescued and you will get a signature. The emergency changes how freely that signature was given. Nothing on the form records the difference. The prisoner rules are written for precisely that difference. They ask what the alternatives are — general living conditions, medical care, quality of food, amenities, opportunity for earnings — rather than what the person agreed to.
An emergency ends. Dependency on a housing office, a school or a benefits system persists, and it accumulates across every institution a person deals with. That is why the safeguards below are built to hold without leaning on consent.
Protection must address dependency and coercion, not merely collect formal agreement.
Steps
What refusal costs, before what refusal means
Dependency gets identified before voluntariness is tested. What refusal costs a person is what decides whether their agreement means anything.
Step three is where the review either bites or drifts. It is worth seeing what an enforcer actually orders there. On 19 December 2022 the FTC announced two record settlements with Epic Games totalling USD 520 million. USD 275 million of that was a civil penalty for COPPA Rule violations — the largest penalty ever obtained for violating an FTC rule — under a federal court order filed by the Department of Justice. A separate USD 245 million administrative order covered dark patterns.
The conduct at issue was a default. The FTC alleged that Epic enabled live voice and text communications for children and teens by default, and that its own employees had urged an opt-in default as early as 2017. The FTC's chair, Lina M. Khan, put the case this way: “As our complaints note, Epic used privacy-invasive default settings and deceptive interfaces that tricked Fortnite users, including teenagers and children.”
So was the remedy. The orders require heightened privacy defaults: voice and text communications stay off unless parents, for users under 13, or teen users affirmatively opt in through a privacy setting. The remedy changed what the system does on its own. It did not ask for a clearer consent screen.
1. Identify dependency
Describe the service, authority, or resource the person cannot easily replace.
2. Test voluntariness
Examine practical consequences of refusal, withdrawal, and error.
3. Increase safeguards
Minimize data, narrow use, add advocacy, reduce automation, and strengthen review.
4. Communicate appropriately
Use accessible, age-appropriate, trauma-aware, and language-appropriate materials.
5. Monitor cumulative harm
Track exclusion, coercion, repeated surveillance, complaints, and remedy.
Key idea
Calling a group vulnerable can remove its agency
Calling a group vulnerable can itself remove agency or justify surveillance. Whoever runs the assessment should identify the specific dependency and build protections around it, without treating people as incapable by default.
What a risk label does at population scale is documented. The Dutch tax administration, the Belastingdienst, kept a fraud risk list called the Fraude Signalering Voorziening, or FSV. Between 4 November 2013 and 27 February 2020 it carried signals on at least 244,273 individuals and 30,000 entrepreneurs. The data protection authority's announcement puts some 270,000 people on the list over more than six years. Staff were instructed to base fraud risk partly on nationality and appearance. Signals were registered, amended, consulted, used, combined and distributed outside FSV. Access security was inadequate, and the data protection officer was brought into the impact assessment late.
On 7 April 2022 the Autoriteit Persoonsgegevens fined the Minister of Finance EUR 3 700 000 for unlawful processing, and announced it on 12 April. The breaches were of the GDPR principles of lawfulness, purpose specification, accuracy and storage limitation. Its chairman, Aleid Wolfsen, named the aggravating factor: “Terwijl juist de Belastingdienst een zeer grote verantwoordelijkheid heeft tegenover de mensen in Nederland. Die zijn immers van de Belastingdienst afhankelijk. Je kunt niet besluiten om je toeslagen maar ergens anders aan te vragen of je belastingaangifte ergens anders te doen.” You cannot take your benefits or your tax return somewhere else.
The error runs in both directions. Protective restrictions can reduce access to beneficial tools. That is why the Age Appropriate Design Code is framed as protection within a service rather than protection from it. A reviewer should compare exclusion risk with exploitation, surveillance and dependency risk, rather than assume that either shipping the thing or banning it is automatically protective. The shelter's consent form said participation was optional. Everyone signing it depended on the shelter for housing, and the form recorded nothing about that.
A vulnerability label is itself an intervention—it can license surveillance and strip choice from the people it names, so it earns its place only by pointing at a specific dependency.
Case
Article 5(1)(b) draws the line at exploitation, not at age
The EU AI Act draws its line at exploitation rather than at age, and the words are worth reading rather than paraphrasing. Article 5(1)(b) of Regulation (EU) 2024/1689 prohibits “the placing on the market, the putting into service or the use of an AI system that exploits any of the vulnerabilities of a natural person or a specific group of persons due to their age, disability or a specific social or economic situation, with the objective, or the effect, of materially distorting the behaviour of that person or a person belonging to that group in a manner that causes or is reasonably likely to cause that person or another person significant harm;”. The regulation was published in the Official Journal on 12 July 2024.
Three elements, not one. The system exploits a vulnerability due to age, disability or a specific social or economic situation. Its objective or its effect is materially to distort behaviour. And the distortion causes or is reasonably likely to cause significant harm. Membership of a vulnerable group is not the trigger. Exploitation plus distortion plus significant harm is. The phrase “the effect” is in the text, so a tool that was never designed to distort anyone's behaviour does not escape the article on its designers' intentions.
Infringements of Article 5 carry the regulation's top penalty tier. Article 99(3) reads: “Non-compliance with the prohibition of the AI practices referred to in Article 5 shall be subject to administrative fines of up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.” Article 99(4) sets EUR 15 000 000 or 3 % for other operator infringements. Because the rule is whichever is higher, the flat EUR 35 000 000 binds any undertaking whose worldwide turnover is below EUR 500 million — the turnover at which 7 % equals EUR 35 million. Above that point, the percentage binds.
Figure
The operational conclusion — governance for vulnerable and dependent populations
Vulnerability here is a relationship with an institution rather than a property of a person. The same system can create it in one setting and not in another. Wolfsen's sentence is the test in its plainest form: people depend on the Belastingdienst, and cannot take their benefits or their tax return somewhere else. Where a person can go elsewhere, a signature may carry some weight. Where they cannot, the protection has to hold without one.
That is how the prisoner rules were written in 1978. It is why the Age Appropriate Design Code sets 15 standards instead of asking a child to agree, and why the FTC's orders of 19 December 2022 changed a default rather than a disclosure.
Define when governance for vulnerable and dependent populations requires the team to redesign, restrict, remedy, or retire the system.
Key takeaways
- Vulnerability is contextual: US rules have protected prisoners since 1978 not for who they are, but because incarceration may affect the ability to make a truly voluntary and uncoerced decision.
- Formal consent is weak wherever refusal is costly. Aleid Wolfsen said it of the Belastingdienst's FSV list: people depend on the agency and cannot take their benefits or their tax return somewhere else.
- Protective design minimises data and automation instead of leaning on agreement. The Age Appropriate Design Code's 15 standards put settings at high privacy by default and geolocation off by default. The FTC's orders of 19 December 2022 against Epic Games require voice and text communications off unless parents, for users under 13, or teen users affirmatively opt in.
- Communication must fit age, disability, language, trauma and decision complexity. The US rules make the review board judge capacity to assent from the ages, maturity and psychological state of the children involved.
- Safeguards should preserve participation rather than infantilise. Only a child's affirmative agreement counts as assent, mere failure to object is not assent, and a guardian's agreement is a separate thing called permission.
- Governance weighs exclusion from benefits against exploitation and surveillance. Article 5(1)(b) of Regulation (EU) 2024/1689 bites on exploitation plus distortion plus significant harm, and Article 99(3) prices a breach at up to EUR 35 000 000 or 7 % of total worldwide annual turnover, whichever is higher.