Humanity & Society · 2026

Responsible Technology & Digital Human Rights

What does responsible technology require beyond compliance, technical controls and good intentions?
01

What this isWat dit is

A research and professional theme exploring what happens when technology begins to affect rights, opportunities, relationships and institutional power. My interest is not simply whether technology is safe, accurate or compliant. Those questions matter. But a system can be technically robust and still be deployed for the wrong purpose. It can satisfy a transparency obligation while remaining practically impossible to challenge. It can contain a human-in-the-loop who has neither the time nor authority to disagree. It can improve an organisation's risk posture while transferring risk to the person with the least power. Responsible technology therefore requires a wider question: what does this system allow one actor to do to another, and what protections exist when that power is exercised badly?

02

ContextContext

Independent research at the intersection of technology, law, business responsibility and human rights. It applies a rights-based lens to AI, data, workplace systems, digital platforms, automation, personalisation and emerging forms of technological mediation. It sits underneath the broader Technology. Humanity. Creativity. framework and alongside AI & Human Agency.

Role:Rol: Researcher / Practitioner

Format:Formaat: Research collection and practical governance framework

03

ImpactImpact

Connects legal doctrine with technology practice. Instead of treating responsible technology as an ethics checklist, it asks organisations to examine purpose, rights, power, affected people, participation, safeguards, contestability, accountability and remedy. The aim is not to make innovation less ambitious. It is to make responsibility harder to outsource.

04

Responsible technology is not a feature

Privacy. Fairness. Transparency. Safety. Human oversight.

These appear so often together that they can begin to sound like product specifications. Add enough controls and the technology becomes responsible.

I do not think responsibility works like that.

Responsibility describes a relationship between power and consequences.

A model does not take responsibility. An organisation does. A design team does. A deployer does. A manager does. An institution does. Sometimes several actors do at once.

And responsibility does not disappear simply because nobody intended the harm.

Responsible technology is not a property of a product. It is a practice of governing power across the technology lifecycle.

05

Digital rights are still human rights

The phrase digital human rights can suggest that technology has created an entirely new category of rights.

Sometimes new legal protections are needed. But many of the central questions are older: privacy, dignity, equality, expression, association, access to information, work, culture, the rights of children and an effective remedy.

What technology changes is often not the existence of the right but the scale, invisibility, speed and reach of the interference.

A manager can discriminate against one applicant. A ranking system can reproduce a pattern across thousands. A neighbour can know something intimate about you. A platform can infer it. A government can censor a speaker. A recommendation architecture can make voices effectively disappear without formally prohibiting them.

The UN Global Digital Compact consequently starts from continuity rather than replacement: human rights should be respected, protected and promoted throughout the lifecycle of digital and emerging technologies, alongside due diligence, oversight and remedy.1

The technology may be new. The human claim often is not.

06

Compliance matters more than ethics discussions sometimes admit

There is a fashionable sentence in responsible technology: compliance is only the minimum.

Sometimes it is true. It can also be careless.

Law is not merely the boring threshold that enlightened organisations transcend through ethics. Law creates obligations, enforcement, institutional oversight, rights people can invoke, sanctions, procedural protections, courts and remedies.

An organisation's ethical principles do not give an affected person the same position as an enforceable right.

So I do not want responsible technology to replace law with corporate virtue.

But compliance has another limitation. A legal system necessarily contains boundaries: definitions, thresholds, exceptions, jurisdictional limits, implementation periods and areas in which conduct can remain lawful while still deserving serious ethical challenge.

The useful distinction is therefore not law or ethics. It is: what does the law require, and what responsibility remains where the law leaves discretion?

07

The risk register usually begins with the wrong subject

Imagine an organisation evaluating a new AI system.

The risk conversation may include: could we be fined? Could data leak? Could the model hallucinate? Could this damage the brand? Could deployment fail? Could we breach the AI Act?

Those are legitimate risks.

But human-rights due diligence begins somewhere different: what could happen to the person?

Could someone lose an opportunity, be falsely classified, become more heavily monitored, lose privacy, receive worse treatment because of a proxy characteristic, be unable to challenge an automated recommendation, lose income, lose access, be silenced or be exposed to harm the organisation itself never directly experiences?

The UN Guiding Principles on Business and Human Rights make this distinction especially important: human-rights due diligence concerns actual and potential adverse impacts on people, not merely material risk to the enterprise. It is ongoing, and actual impacts may require remediation.2

Instead of asking only what this technology can do to us, we ask what we could do to people through this technology.

08

Responsibility begins before the model

One reason technological accountability becomes difficult is that we look for it too late.

By the time a system produces a harmful output, many consequential decisions have already been made.

Someone defined the business objective. Someone selected the vendor. Someone determined what data was relevant. Someone negotiated the contract. Someone decided which performance metric mattered. Someone accepted a particular error rate. Someone chose whether impacted employees would be consulted. Someone defined who could override the system. Someone decided what happened when a complaint arrived.

The OECD's 2026 Due Diligence Guidance for Responsible AI follows precisely this lifecycle logic: embed responsible business conduct in management systems; identify impacts; prevent or mitigate them; track results; communicate; and provide for or cooperate in remediation where appropriate.3

Responsibility is therefore not a review gate attached to deployment. It begins while the problem is still being defined.

09

Ask whether the problem deserves the technology

Responsible technology discussions often begin with: how do we make this system fair?

Sometimes the previous question should be: should this decision be automated at all?

A highly accurate system can still be used for an intrusive purpose. A perfectly secure database can still contain information that should never have been collected. An unbiased surveillance system is still a surveillance system. An excellent predictive model does not settle whether prediction is a legitimate basis for intervening in somebody's life.

UNESCO's AI ethics framework places proportionality and avoidance of harm before many downstream controls: an AI use should not go beyond what is necessary to achieve a legitimate aim.4

Performance cannot rescue an illegitimate purpose.

10

Human in the loop is not a governance strategy

The phrase sounds reassuring. A human remains involved. Therefore control remains human.

But imagine the human receives hundreds of recommendations each day. The interface presents one answer prominently. The person's performance is measured on speed. Rejecting the recommendation requires extra documentation. Nobody has explained the system's known limitations. Overriding it creates personal accountability. Accepting it does not.

There is technically a human in the loop. There may be very little meaningful oversight.

The EU AI Act's human-oversight provisions for high-risk systems are more demanding than mere human presence: the person assigned oversight should be able to understand relevant capabilities and limitations, recognise possible over-reliance, interpret outputs, disregard or reverse them and intervene or stop the system.5

The question I care about is whether the human has the competence, time, information and authority required to say no. If not, oversight risks becoming ceremonial.

11

Transparency is not the same as power

Technology governance loves transparency. Sometimes for good reason.

People should know when important systems affect them. Organisations should be able to explain what they are doing.

But information alone does not correct a power imbalance.

Imagine receiving a perfectly accurate twenty-page explanation of why an automated system rejected you. What can you do next? Can you correct the data? Challenge an inference? Present missing context? Reach a person? Have the decision reconsidered? Recover the opportunity?

The GDPR gives individuals protections concerning certain decisions based solely on automated processing that have legal or similarly significant effects, including safeguards around human intervention, expressing one's point of view and contesting the decision.6

The AI Act also creates, in specified circumstances involving decisions based on outputs of certain high-risk systems, a right to obtain a clear and meaningful explanation of the role of the AI system and the main elements of the decision.7

Transparency tells me something happened. Explanation helps me understand it. Contestability gives me a way to challenge it. Those are not interchangeable.

12

The missing word is often remedy

Imagine every governance process worked. There was an impact assessment. The model was tested. Policies existed. The right committee approved deployment. And somebody was still harmed.

Now what?

This is where a human-rights approach becomes much more demanding than a principles document.

Under the UN Guiding Principles, where a company has caused or contributed to an adverse human-rights impact, it should provide for or cooperate in remediation through legitimate processes.2

The OECD's 2026 AI due-diligence guidance similarly places remediation as its sixth step and describes possible remedies including restitution, compensation, rehabilitation, acknowledgement and measures designed to prevent repetition.3

If someone is wrongly denied an opportunity, can it be restored? If inaccurate information affected them, can it be corrected? If reputation was harmed, can the record be repaired? If a system repeatedly produces the same harm, can it be changed or stopped?

A mature governance system should not only be able to detect that something went wrong. It should be capable of doing something meaningful for the person to whom it went wrong.

13

A complaints inbox is not necessarily remedy

Organisations can mistake the existence of a process for the existence of protection.

A complaint form exists. Therefore people can complain.

But can they find it? Can they understand it? Is it available in their language? Does filing the complaint expose them to retaliation? Who reviews it? Can the reviewer alter the original outcome? Is there a deadline? Is the person told what happened? Can they escalate? Does anyone examine whether the same harm is happening to others?

The Digital Services Act offers an interesting example of rights becoming procedural infrastructure. Users can challenge certain content-moderation decisions through platforms' internal complaint systems and can also use certified out-of-court dispute-settlement bodies; courts remain available.8

A right becomes more real when institutions design the route through which it can be exercised.

14

Participation is not asking users what they think

Another popular answer to responsible technology is stakeholder consultation.

I support it. But consultation can become theatre remarkably easily.

The organisation has already selected the technology. The contract is signed. The objective is fixed. Deployment is three weeks away. Affected employees are invited to a workshop. Sticky notes appear. People are thanked for their valuable input. Nothing material can change.

That is not meaningful participation.

The OECD's 2026 guidance recommends engagement with workers, worker representatives, affected communities, independent experts and civil society, including before and during activities that may affect them.3

The important word is not simply consult. It is affect. Can participation change the objective, data, workflow, safeguards or decision to deploy at all? If not, we should describe it accurately: feedback, not power.

15

Privacy is no longer only about what we disclose

Traditional privacy intuitions often begin with information I provide: my name, address, health information, messages or location.

AI makes another category increasingly important: what can be inferred about me.

A person may never tell a system something explicitly. Patterns across behaviour can still produce classifications, scores or predictions.

The GDPR already recognises profiling as automated processing used to evaluate personal aspects and make predictions about people.6

This raises questions simple consent language does not resolve. If I consented to provide the data, did I consent to every inference technically possible from it? If individual data points are mundane but their combination becomes sensitive, where should the boundary sit? If an inference is wrong but influential, how do I correct something I never said?

The most consequential data about a person may increasingly be information the person never directly supplied.

16

Fairness is not simply equal model performance

Bias is another word that has become dangerously easy.

Find biased data. Debias model. Measure outcomes. Problem solved.

But discrimination can live in the surrounding institution. Historical inequality can be genuinely predictive. A proxy can recreate a protected distinction without naming it. A model can achieve similar statistical performance across groups while operating inside a process that distributes opportunities unequally. And the definition of fairness itself may require choices between competing objectives.

So the question cannot stop at: is the model fair?

We also need: what decision is being made? What right or opportunity is at stake? Which errors matter? Who bears them? What historical structure produced the data? Could this technology make an already unequal process operate at greater scale?

Technical fairness analysis is essential. It is not a substitute for legal and social judgement.

17

Responsible technology has to see people who never clicked I agree

Technology companies naturally think about users.

Human-rights analysis has to look further.

A facial-recognition system affects the person being identified. A hiring tool affects the applicant. A fraud model affects the customer who becomes suspicious. An employee-monitoring tool affects workers. A platform recommender can affect people who never joined the platform but become targets of harassment or misinformation originating there. An AI-generated representation can affect the person represented.

The rights-holder is not always the customer. Not always the user. Sometimes not even someone who knows the system exists.

The people most affected by technology may not be the people empowered to configure it.

18

Workplace consent deserves particular suspicion

Work makes the power problem especially visible.

An employee may technically agree to monitoring. But what does refusal mean if the alternative is losing access to the workplace?

An employee may have access to human review. But will challenging an automated performance assessment be interpreted as defensiveness?

A manager may be told AI is only advisory. But if the organisation expects the recommendation to be followed, where does discretion really sit?

This is why workplace AI cannot be analysed only through individual user choice. Employment contains institutional dependency and unequal bargaining power.

The EU AI Act recognises employment and worker-management uses among potentially high-risk applications, although obligations are subject to the Act's phased implementation timetable. Under the current Commission timetable, the Annex III high-risk rules are scheduled to become applicable on 2 December 2027.9

The regulatory date matters. The organisational question exists now.

19

Responsible technology is broader than AI

AI currently dominates the discussion.

Digital power did not begin with generative models.

Platforms shape visibility. Recommender systems shape attention. Interfaces shape consent. Search shapes discoverability. Moderation systems shape expression. Workplace tools shape pace. Identity systems shape access. Databases shape what institutions believe about people.

The Digital Services Act requires very large platforms and search engines to assess systemic risks including risks to fundamental rights such as freedom of expression, media pluralism, non-discrimination, consumer protection and children's rights.10

This is an important conceptual shift. Technology governance is no longer only about whether an individual piece of content or individual decision is lawful. At sufficient scale, the system itself becomes part of the rights analysis.

20

Business models belong inside the ethics conversation

Suppose a design team is instructed to minimise compulsive use, but revenue rises when users remain engaged.

Suppose privacy teams minimise unnecessary collection, but competitive advantage depends on deeper behavioural prediction.

Suppose an AI governance committee promotes careful human review, but management bonuses depend on throughput.

What happens?

Governance cannot indefinitely compensate for incentives pointing in the opposite direction.

This is why responsible technology eventually becomes a corporate-governance question.

Not simply: what did the model optimise? But: what does the company benefit from when the model succeeds?

Some harms cannot be designed away at the interface because the incentive producing them sits much higher in the organisation.

21

Responsibility is distributed, but it must not disappear

Modern technology has a long supply chain.

One company trains a model. Another provides cloud infrastructure. Another integrates it. Another resells the solution. Another purchases it. A manager configures it. An employee relies on the output. A customer experiences the decision.

Distributed technology creates a predictable sentence: that part is not ours.

Sometimes that is legally correct. It can also become the architecture through which responsibility evaporates.

Human-rights due diligence provides a more useful way of thinking because it distinguishes different relationships to harm — including causing, contributing to, and impacts directly linked through business relationships — and asks organisations to use the leverage available to them.2

Responsibility need not mean every actor controls everything. It means knowing what we control, what we influence, what we know, what we should know and what we will do when another part of the chain creates serious harm.

22

The Rights in Practice Test

I use seven questions to move digital rights from principle to practice.

It is not a certification. It is not a score. It is a way to discover where responsibility becomes vague.

  • Purpose — Why are we doing this? What legitimate objective does the system serve? Is technology necessary? Is the intervention proportionate? Could the same outcome be achieved less intrusively? An accurate system does not rescue a bad purpose.
  • People — Who lives with the consequences? Not merely: who uses the product? Ask who is classified, observed, recommended, excluded, represented, monitored and whose opportunity changes. Include people who never chose to become users.
  • Power — What power does the system redistribute? Who can see, predict, decide, remain anonymous, become legible, receive efficiency, absorb error and walk away? Power is often where an apparently technical decision becomes a rights issue.
  • Participation — Who helped define the system? Were affected people involved early enough to change the objective, workflow, safeguards or decision to proceed? Consultation after every important choice has already been made is not participation.
  • Protection — What prevents foreseeable harm? What legal safeguards apply? What organisational controls exist? What technical measures matter? Does human oversight actually work? Who monitors performance after deployment? What event stops the system?
  • Contestability — What can the affected person do? Do they know technology affected the decision? Can they understand enough to challenge it? Can they correct data, introduce context, reach a responsible human, obtain reconsideration or appeal? A transparent system can still be practically incontestable.
  • Remedy — What happens after we were wrong? Can the outcome be reversed? Can access be restored? Can damage be compensated? Can the record be corrected? Can the system itself change? Will similar harm be prevented? Who owns that process?
23

The framework needs evidence, not confidence

For every Rights in Practice question I would require five things.

Evidence: why do we believe the answer?

Owner: who is accountable for acting on it?

Rights affected: which concrete rights or interests are involved?

Uncertainty: what do we still not know?

Escalation condition: what finding would make us pause, redesign or stop?

That last question matters. A governance process without stopping conditions can become a process for documenting why deployment continued.

24

The strongest argument against my position

There is a danger in turning responsible technology into an ever-expanding procedural burden.

Impact assessment. Legal review. Ethics committee. Stakeholder consultation. Risk register. Transparency documentation. Audit. Complaint pathway. Another form. Another committee.

Eventually the organisation becomes excellent at producing evidence that governance happened while nobody knows whether outcomes improved.

Human-rights language can also become vague. What exactly does dignity require in a product decision? Different rights can conflict: freedom of expression and safety, privacy and transparency, consistency and discretion, innovation and precaution.

Strong stakeholder groups can dominate people who are harder to organise. Human reviewers can introduce prejudice that automated processes reduced. Explanations can expose security vulnerabilities or confidential information. Excessive caution can prevent technologies that genuinely improve access, safety and opportunity.

These objections are serious. So responsible technology cannot mean more governance equals more responsibility. The question is whether governance changes decisions and outcomes.

If an impact assessment could disappear without changing anything the organisation does, it was probably paperwork.

25

Trust is a result, not a governance objective

Technology companies frequently say they want to build trust.

I am increasingly uncomfortable with that formulation.

What if distrust is rational? What if the organisation has not earned confidence? What if the affected person should remain sceptical?

The objective of responsible technology should not be to make people trust systems. It should be to build systems and institutions that are worthy of scrutiny: transparent enough to examine, bounded enough to challenge, governed enough to correct and accountable enough to repair harm when safeguards fail.

Trust may follow. It should not be manufactured.

26

Regulation is becoming more rights-aware

Europe's current technology-governance architecture increasingly reflects this shift.

The GDPR gives people rights over personal-data processing and specific protections around certain forms of automated decision-making.6

The Digital Services Act combines platform duties with systemic-risk assessment, transparency and user redress.10

The AI Act includes prohibited practices, risk-management obligations, human oversight, fundamental-rights impact assessments in specified high-risk deployments and rights to explanation in certain circumstances. Its provisions are being phased in; as of September 2026, Commission guidance places Annex III high-risk requirements from 2 December 2027 and high-risk systems embedded in regulated products from 2 August 2028.9

The Council of Europe's Framework Convention on AI explicitly links the AI lifecycle to human rights, democracy and the rule of law. It opened for signature in September 2024; the Council of Europe's treaty-status page still showed no entry into force as of 12 September 2026, because the required ratification threshold had not yet been met.11

The legal landscape is becoming richer. That does not remove the need for judgement. It makes precise judgement more important.

27

Ethics should not become a hiding place from rights

There is something comfortable about ethics language.

Values. Principles. Trust. Responsible innovation.

These allow organisations to talk about difficult questions without always naming who has a claim against whom.

Human rights are less comfortable. They introduce rights-holders, duty-bearers, adverse impacts, remedy and accountability.

They shift the conversation from what kind of company do we want to be towards what people are entitled to expect from us.

I do not want to eliminate ethics. Law cannot answer every question.

But responsible technology should be suspicious whenever voluntary ethical language begins replacing an enforceable obligation.

Good intentions should add to rights, not dilute them.

28

My working position

I believe technology can expand participation, accessibility, knowledge and human capability.

That is precisely why its governance matters.

I do not want rights frameworks that make useful technology impossible. I also do not want innovation to become a word that ends an argument.

I want legal protections strong enough that dignity does not depend on corporate benevolence.

Human-rights due diligence early enough that organisations discover consequences before affected people do.

Participation meaningful enough to alter designs.

Human oversight with enough authority to be human.

Transparency connected to contestability.

Contestability connected to remedy.

And responsibility that survives the spaces between provider, platform, partner, deployer and user.

The test of responsible technology is not whether every risk disappeared. That is impossible.

The harder test is: when power moved, did responsibility move with it?

29

Method and intellectual limits

This is a practitioner-led research framework, not legal advice, a complete account of international human-rights law or a certification methodology.

It combines binding law, non-binding international frameworks, regulatory guidance, responsible-business-conduct standards and original synthesis.

Their legal status differs substantially.

The GDPR, Digital Services Act and EU AI Act are binding EU law within their respective scopes. The AI Act is subject to phased application, and its implementation timeline should be checked whenever this article is updated. UNESCO's Recommendation on the Ethics of AI is normative guidance rather than binding international law. The UN Guiding Principles on Business and Human Rights are an authoritative global framework but are not themselves a treaty. The OECD Guidelines and its Responsible AI due-diligence guidance provide responsible-business-conduct standards and implementation guidance. The Council of Europe Framework Convention is a legally binding treaty for parties once it enters into force for them; as of the September 2026 treaty-status information used for this edition, it had not yet entered into force.

Human rights can conflict and require contextual analysis. Technical accuracy is not equivalent to legality. Legality is not equivalent to ethical desirability. A human-rights impact assessment does not prove that a system is safe.

The Rights in Practice Test is an original conceptual tool by Daphne Iris van Vliet, not a validated legal compliance methodology. Its purpose is simpler: to make it harder for responsibility to disappear between principle and practice.

30

Related work

This pillar sits underneath Technology. Humanity. Creativity. and connects directly to Human Latitude: if Human Latitude asks what room remains for people, Responsible Technology & Digital Human Rights asks what duties arise when systems exercise power over that room.

It also connects to AI & Human Agency, Fear, Leadership and AI, Love, Leadership and AI, and Digital Twin. Those works test judgement, safety, care, identity, representation and memory in more specific contexts.

  • Technology. Humanity. Creativity. — What kind of systems do we want?
  • Human Latitude — What room remains for people?
  • Responsible Technology & Digital Human Rights — What duties arise when systems exercise power over people?
  • Rights in Practice Test — Can those duties actually be exercised, challenged and remedied?
  • AI & Human Agency — What happens to judgement and human action within those systems?
31

Sources and limitsBronnen en grenzen

  1. Global digital governance: United Nations — Global Digital Compact — Commits States to respect, protect and promote human rights in digital environments and calls for human-rights due diligence, oversight and remedy throughout technology lifecycles. It is a global political framework rather than directly enforceable individual legislation.
  2. Business and human rights framework: United Nations Guiding Principles on Business and Human Rights; OHCHR 2025 report on technology companies and AI — Establishes the Protect, Respect and Remedy architecture and applies human-rights due diligence to products, services and business relationships. The UNGPs are not themselves a binding treaty, although their concepts influence legislation and corporate standards internationally.
  3. Responsible business conduct guidance: OECD — Due Diligence Guidance for Responsible AI (2026) — Provides a six-step practical due-diligence framework from governance through identification, mitigation, tracking, communication and remediation. It is responsible-business-conduct guidance rather than binding legislation.
  4. AI ethics framework: UNESCO — Recommendation on the Ethics of Artificial Intelligence — A global normative framework based on human dignity and human rights, covering proportionality, privacy, fairness, accountability, oversight and impact assessment. It provides principles and policy guidance, not enforceable individual remedies by itself.
  5. Binding EU law: Regulation (EU) 2024/1689 — Artificial Intelligence Act — Binding EU regulation. Its human-oversight requirements require more than nominal human presence and address competence, interpretation, automation bias, override and intervention. Application is phased and the latest timetable must be checked when the article is updated.
  6. Binding EU law and guidance: GDPR / European Commission guidance on automated decision-making and profiling — Provides rights concerning personal data and safeguards for specified solely automated decisions with legal or similarly significant effects. It should not be paraphrased into a general right to human decision-making in every algorithmic interaction.
  7. Binding EU law: EU AI Act Article 86 — Provides a right to clear and meaningful explanation in defined circumstances involving decisions based on outputs from specified high-risk AI systems. Its scope is narrower than a universal right to explanation for all AI.
  8. Binding EU law and procedure: European Union — Digital Services Act complaint and out-of-court dispute mechanisms — Illustrates how digital rights can be translated into practical routes for challenging platform decisions. These mechanisms address defined DSA decisions and should not be generalised into a universal technology-complaints regime.
  9. Implementation timeline: European Commission — AI Act enforcement timeline — As of this September 2026 edition, the Commission states that Annex III high-risk-system requirements apply from 2 December 2027 and product-based high-risk rules from 2 August 2028. Because the AI Act implementation timetable has changed, these dates should be revalidated in future editions.
  10. Platform governance: European Commission — Digital Services Act systemic-risk framework — Requires very large platforms and search engines to assess risks including impacts on fundamental rights. It applies to defined services and cannot simply be transferred to every technology company.
  11. Treaty framework: Council of Europe — Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law — The first international legally binding treaty framework specifically addressing AI in relation to human rights, democracy and the rule of law. It opened for signature in 2024 but had not yet reached the treaty's entry-into-force threshold in the Council of Europe's status information dated 12 September 2026.
32

NextVolgende

Choose one real technology decision — a hiring tool, employee Copilot, customer chatbot, recommendation system, digital identity process, AI assistant or platform rule — and run it through the Rights in Practice Test: Purpose, People, Power, Participation, Protection, Contestability and Remedy.

Back to WritingTerug naar Writing