BRIEFING PAPER

FOR THE BCS LEADERSHIP TEAM

AI Ethics, Cultural Values, and the Architecture of Failure

Why the Current Approach Cannot Work — and What Must Change Before It Is Too Late

Prepared by David Sutton CITP MBCS  |  Southport Innovation Centre  |  May 2026

Drawing on The Weavers and the Web strategic framework and the Weavers Cultural Values and Ethics register.

Important note: the Weavers Cultural Values and Ethics system is at an early stage of development. It is presented here as an initial analytical instrument, before feedback learning and wider application have been applied. The insights it generates are directional and structural rather than definitive. They are offered as the starting point for a conversation the BCS is positioned to lead, not as completed conclusions.

For the Leadership Team — the essential argument in four sentences The most frequently quoted sentence in AI ethics reviews has been the same for eight years: organisations treat ethics as an afterthought. The fact that this sentence has not changed — after the EU AI Act, after $10 billion of annual investment, after 703 published tools — is not a mystery. It is a structural signal that the interventions being made are not addressing the mechanism that produces the pattern. This briefing identifies that mechanism and describes what addressing it would require — drawing on direct experience of what changed Data Protection from aspiration to practice, and on an emerging strategic framework that identifies structural gaps the current AI ethics discourse cannot see.

1.  The State of AI Ethics in 2026

The AI ethics landscape in 2026 is the most developed it has ever been. The EU AI Act imposes binding obligations on high-risk AI systems. Investment in ethical AI exceeds $10 billion annually. There are 703 tools in the OECD catalogue for trustworthy AI. Transparency standards are maturing. Regulators have moved from guidance to enforcement. Agentic AI systems — capable of acting autonomously in clinical, financial, and governmental contexts — are generating serious new thinking about liability and moral responsibility.

Against this investment, three findings from current research define the structural problem:

1The defining sentence has not changed in eight years Every major AI ethics review opens with approximately the same observation: organisations treat ethics as an afterthought, bolting it on late in the process or not at all. This was the defining sentence in 2018. It is the defining sentence in 2026. Eight years of frameworks, tools, regulation, and investment have not changed it. This is not a failure of effort. It is a structural signal: the mechanism that produces performative ethics rather than genuine ethics has not been identified, because it cannot be identified from within the frame of the discourse that is trying to address it. What this means for the BCS:  The BCS has members who have lived the equivalent pattern in Data Protection — and who know from direct experience what changed it. That experience is the most important evidence base available for understanding what would change the AI ethics pattern.
2Performative governance versus operational governance — named but not resolved The defining distinction in AI governance in 2026 is between performative governance — satisfying external measurement requirements — and operational governance — changing what organisations actually do. Industry conferences are drawing this distinction explicitly. Regulators are signalling that documentation gaps may constitute violations. But the architectural cause of performative governance — why it is structurally inevitable in certain organisational environments — has not been identified. Without the architectural account, every intervention produces better performance of ethics rather than better practice of it. What this means for the BCS:  The BCS is positioned to provide the architectural account that the current discourse lacks. Its members have direct experience of the conditions that produce genuine ethical practice rather than ethical performance — and of the specific structural mechanisms that make the difference.
3Power concentration is visible, growing, and structurally under-addressed AI corporate structures have crystallised. Government-industry alignment has deepened. The US federal government has actively preempted state-level AI regulation that the AI industry opposed. The AI ethics frameworks being produced exist within a political economy in which those with the most to gain from specific ethical conclusions have the most influence over the process that produces them. This is not being named directly by any major independent ethics body. What this means for the BCS:  The BCS’s independence from commercial AI development makes it one of the very few bodies with the standing to name this directly. That independence is the BCS’s most valuable asset in the current AI ethics landscape — and the asset most at risk if the BCS remains primarily engaged with the existing discourse rather than challenging its structural limitations.

2.  The Data Protection Parallel — What It Tells Us

The most instructive evidence base for understanding the current AI ethics situation is not from AI research. It is from Data Protection — specifically from the experience of those who were responsible for Data Protection compliance in major UK organisations before and after GDPR.

The structural parallel is precise. Before GDPR, Data Protection had: a legal framework (the Data Protection Act 1998); a set of principles (purpose limitation, data minimisation, accuracy); accountability requirements; and nominal responsibility in most organisations. Most organisations had a Data Protection policy. And most treated Data Protection as a compliance checkbox. The defining sentence of every Data Protection review before 2018 was approximately the same sentence that opens every AI ethics review in 2026.

What changed — and what made it change

Genuine enforcement with material consequences.  The ICO moved from issuing guidance to issuing fines that were material at board level — not uncomfortable, but affecting shareholder value and requiring chief executive sign-off on remediation. The abstract ethical principle became a concrete financial risk. This is precisely what the EU AI Act is attempting to replicate for AI, and precisely what the current discourse predicts will be 2026’s defining test: whether frameworks influence real-world behaviour or become a box-checking exercise.

The Data Protection Officer role with genuine independence.  The DPO under GDPR cannot be dismissed for performing their function, reports directly to the highest level of management, and has specific legal protections that ordinary employees do not have. This is the structural mechanism that addresses the performative ethics problem: the DPO is in the observed environment, but the observation structure has been modified so that saying what they genuinely think is legally protected rather than professionally dangerous. The AI ethics equivalent does not yet exist. Chief Ethics Officers exist in many organisations, but almost none have the legal protections, the reporting lines, or the independence that the DPO role was specifically designed to provide.

The shift from self-certification to independent audit.  Post-GDPR, organisations must demonstrate compliance to external scrutiny rather than merely assert it. The audit trail, the Data Protection Impact Assessment, the Record of Processing Activities — these create the evidentiary basis for enforcement. AI ethics currently operates almost entirely on self-certification and voluntary disclosure. The structural shift to mandatory external audit — which the EU AI Act is beginning to require for high-risk AI — is the equivalent of what moved Data Protection from aspiration to practice.

The most important parallel — building in versus retrofitting

When GDPR arrived, organisations discovered that their data architecture had been built for a world in which data was an asset with no corresponding obligation. The database designs, the processing agreements, the consent mechanisms, the data flows across organisational boundaries — none of these had been designed with the assumption that individuals would one day have enforceable rights over their data. Retrofitting those rights into live systems was expensive, partial, and in many cases structurally impossible without replacing systems that had been in production for decades.

The organisations that managed GDPR well were those that had built data architecture with privacy in mind before it was legally required. Those organisations retrofitted relatively little. The organisations that had built for maximum data exploitation retrofitted everything, at enormous cost, and still produced systems that were legally compliant but not genuinely privacy-respecting.

The broken clock — set at the transition moment The broken clock in Data Protection was set at a specific moment: when the assumption was embedded in the architecture that data had value and no corresponding cost. Every system built on that assumption needed to be reset after GDPR — and resetting a clock embedded in the foundations of live systems is orders of magnitude more expensive than setting it correctly at the beginning. The AI broken clock is being set right now, at this transition moment, in every organisation making AI adoption decisions. The decisions being made now — which models to use, how to integrate them, what data they are trained on, what governance they operate within, what human capability is retained alongside them — are the clock-setting decisions. They are being made under competitive pressure and time urgency, which means they are being made with less examination of their long-term consequences than the moment requires. The cost of resetting the AI ethics clock after it is embedded in live systems will be what the Data Protection cost was: orders of magnitude greater than setting it correctly now, producing systems that are compliant rather than genuinely ethical, and failing to protect the people most exposed to harm in the years between the broken clock and its eventual correction.

The parallel that has not yet been drawn — individual rights

Data Protection works — to the extent it works — because it gives individuals enforceable rights over how their data is used. Not aspirational rights — rights that can be exercised, that create obligations, that generate liability when they are violated. The right of access. The right to erasure. The right to object. The right to explanation of automated decision-making.

The AI ethics equivalent would be enforceable individual rights over how AI systems affect people: the right to know that an AI system is making or substantially influencing a decision about you, the right to an explanation, the right to human review, the right to object. Article 22 of GDPR already provides some of this for automated decision-making. It has been applied inconsistently and enforced rarely. The structural principle is right: ethics that produces only organisational obligations, without corresponding individual rights, remains at the level of the grand hall and never reaches the people it is supposed to protect.

The children in the lemon panel — those who will inherit the consequences of today’s AI decisions — have no rights in the current AI ethics framework. They have rhetorical protection. They do not have the equivalent of what GDPR gave data subjects: specific, enforceable obligations on the organisation, an independent function empowered to say when those obligations are not being met, and consequences material enough to change board-level behaviour.

3.  Seven Structural Gaps — What the Current Discourse Cannot See

The following seven gaps are identified by the Weavers Cultural Values and Ethics framework — an early-stage analytical instrument that has not yet been through feedback learning and wider application. The insights are directional and structural. They are presented as starting points for the BCS’s own analysis rather than as completed conclusions.

Gap 1: The discourse cannot examine itself.  The AI ethics frameworks being produced are shaped by the interests of those who produce them. No current framework applies a reflexive test to its own production process. The BCS, as an independent professional body, is positioned to apply that test — to ask of every major AI ethics framework: who was in the room? Who was absent? What does this framework structurally prevent from being asked? What interests does it serve?

Gap 2: The architectural cause of performative ethics.  In any environment where what you say about ethics is being watched and can be used against you, the ethics that emerges is the ethics that is safe to say. The gap between performative and operational ethics is not produced by insufficient commitment — it is produced by the observation structure. The Data Protection parallel is exact: the DPO role changed the observation structure by providing legal protection for genuine ethical voice. The AI equivalent does not yet exist.

Gap 3: Ethics for actors who cannot see what they produce.  Most actors within AI systems cannot see the full consequences of their actions. The engineer building a model component does not see what it produces in deployment. The organisation deploying AI cannot see what it produces in the communities it affects. Ethics designed for full visibility and full agency fails everyone operating under structural ignorance — which is virtually everyone in modern AI systems. The current frameworks do not account for this.

Gap 4: Cost extraction as the invisible ethical failure.  AI-driven efficiency frameworks consistently produce ethical harm that the efficiency metric cannot see, because the metric measures from above the level at which the harm occurs. The people absorbing the costs are in the externalities of the model. An ethical framework that does not measure from the bottom of the system is a framework that serves those above it. The lemon principle: the measure of an ethical efficiency framework is not how much has been squeezed out, but what condition those at the bottom are in after the squeezing.

Gap 5: AI training on past ethics cannot produce genuinely new ethics.  AI trained on human ethical reasoning reproduces the ethical reasoning humans have been applying — including the reasoning that has produced the outcomes the new ethics is supposed to prevent. AI’s most valuable contribution to ethics development is identifying what existing frameworks have systematically excluded, not generating new frameworks from the accumulated record of old ones. This distinction is not yet present in the current discourse.

Gap 6: Intergenerational ethics — structurally absent.  The AI systems being built now will operate for decades. No current ethics framework has specific, operational mechanisms for intergenerational representation. The BCS’s members will implement the consequences of today’s AI decisions for the next twenty to thirty years. They are the intergenerational stakeholders the current ethics framework has no mechanism for including. Making this explicit — and building it into BCS ethics development as a structural principle — would fill the most significant gap in the current landscape.

Gap 7: The invisible controllers.  Every ethics framework is produced within a set of interests that determine what it is permitted to examine. The interests most powerfully shaping AI ethics are those with the most to gain from specific conclusions and the most resources to produce them. An ethics body that cannot name the interests shaping its own framework has been captured by those interests before it has written a word. This is the most uncomfortable gap to name and the most important one for the BCS to address.

4.  Designing for the Future — Setting the Clock Correctly Now

The most important lesson from the Data Protection parallel is about timing. The organisations that managed GDPR well were those that treated the transition moment — before the regulation was in force, before the architecture was embedded — as the opportunity to set the clock correctly for the world ahead, not just to comply with the world as it was.

The AI transition is that moment, now. The decisions being made in 2025 and 2026 about AI architecture, AI governance, AI workforce design, and AI supply chain relationships are the clock-setting decisions. Their consequences will compound for decades. The cost of resetting them after they are embedded will be what the Data Protection cost was — and the harm done in the interval will fall, as it always does, on those least able to protect themselves.

The Weavers Cultural Values and Ethics framework identifies five forward design principles — principles that will remain true across multiple possible futures because they address the structural conditions of ethical AI deployment rather than specific current technology. They are presented here as design constraints, not aspirations.

ASovereignty before scale No AI system should be deployed at a scale that exceeds the organisation’s ability to understand what it is producing and to operate without it. The dependency cascade — the three-phase process by which organisations outsource first the doing, then the understanding, then the direction — should be treated as an architectural constraint, not a post-deployment risk. The sovereign capability test: does the organisation understand enough about this AI system to govern it, audit it, catch its errors, and operate effectively without it? If not, the system should not be deployed at that scale. This is a harder constraint than anything in the current ethics framework. It is the right one.
BThe independent function at the design stage, not the deployment stage The DPO lesson is precise: the independent function that cannot be dismissed for saying what needs to be said must be present at the design stage, not brought in to review systems already in production. The AI ethics equivalent — the role with legal protection, independent reporting lines, and the mandate to say when ethical obligations are not being met — should be specified before the first deployment decision is made. Any organisation that cannot answer the question ‘who has the standing and the protection to say this AI system should not be deployed?’ has not yet built the function. Building it before the first deployment is the clock-setting moment.
CSupply chain obligations before the supply chain is built The most expensive Data Protection remediation work was in the supply chain — the processors, the platforms, the analytics firms — where the organisation had limited leverage once the contracts were in place. The AI supply chain is deeper and less visible. Ethical requirements must be built into procurement specifications before vendor contracts are signed, not imposed on vendors whose systems are already embedded in production. The organisation that cannot answer ‘what are our ethical obligations to those affected by this vendor’s AI system, and how are they contractually secured?’ has not yet set its clock correctly.
DDesign from the blue flower — the least well-resourced participant as design constraint Every AI architecture decision should be tested against the condition of the participant most exposed to harm — the blue flower without leaves, alive only because the network beneath it is working. This is not a rhetorical commitment to inclusivity. It is a structural design constraint: if this system fails, who fails with it? The answer identifies who must be at the centre of the design. The organisations and communities most exposed to AI harm — those with the least power to protect themselves, the least access to redress, the least capacity to absorb the costs of failure — are the design constraint. Everything else in the architecture must be arranged around the condition that they survive.
ETransparency of uncertainty before transparency of outputs The Data Protection right to explanation is a right to understand how a decision was reached, not merely to see the decision. The AI equivalent requires transparency not just about what the system decided, but about what the system was uncertain about when it decided it — where its model diverges from reality, what it cannot tell you about the confidence of its outputs, where the model’s training data does not represent the population it is being applied to. A system that presents confident outputs from uncertain foundations without making that uncertainty visible is not a transparent system. It is a system that conceals the most important information it holds.

5.  The BCS’s Role — and Why It Is Currently Vacant

The AI ethics landscape contains many organisations producing ethical frameworks. It does not contain an organisation that is simultaneously: independent of commercial AI development; possessed of the technical depth to understand AI systems at the level ethical analysis requires; mandated to serve the public interest; capable of operating across every sector in which AI is deployed; and in possession of a professional membership that has lived the equivalent structural problem in Data Protection.

The BCS has all five of these properties. What it does not yet have is the strategic commitment to deploy them in the specific role the AI ethics landscape needs: the independent ethical catalyst that applies the reflexive test to the frameworks being produced, names the gaps the conventional discourse cannot see, and creates the conditions in which genuine ethical voice is safe.

What the current AI ethics landscape hasWhat the BCS uniquely offers
703 tools of varying quality, unvalidated against common criteriaIndependent quality test applied to the frameworks themselves
Ethics produced within commercial relationshipsEthics produced outside commercial AI development
Performative ethics that survives observationThe standing to name what performative ethics is concealing
No equivalent of the DPO — independent function with legal protectionThe professional body with the standing to argue for one
Self-certification and voluntary disclosureThe credibility to demand independent audit
Individual rights as rhetoricThe mandate to argue for individual rights as enforceable obligations
Intergenerational ethics as aspirationA membership that will implement consequences over the next thirty years
AI-generated ethics guidanceHuman professional judgment grounded in real implementation experience

6.  Five Specific Opportunities — Ordered by Impact

1Apply the reflexive test to the major AI ethics frameworks No current body is applying a systematic quality test to the AI ethics frameworks being produced. The BCS could establish a structured review process that asks of every major framework: who was in the room? Who was absent? What does this framework structurally prevent from being asked? What interests does it serve? This is not hostile — it is the honest application of the same rigour the BCS applies to technical standards. It positions the BCS as the quality assurance body for AI ethics: not producing another framework, but testing the ones that exist. What this means for the BCS:  This requires the willingness to name what is found, including when it is uncomfortable to those producing the frameworks. It is the most immediately distinguishing action available to the BCS and the one that most directly addresses the structural gap no other body is filling.
2Argue publicly for an independent AI ethics function with legal protection The single most important structural change that moved Data Protection from aspiration to practice was the DPO role — independent, legally protected, reporting directly to the highest level of management. The BCS should argue publicly and specifically for the AI equivalent: a mandatory, independent AI ethics function in organisations deploying high-risk AI, with the legal protections and reporting lines that make genuine ethical voice possible. This is a concrete policy position grounded in direct professional experience of what actually changes organisational ethics behaviour. What this means for the BCS:  This is the BCS’s strongest ground. Its members have operated Data Protection functions. They know from direct experience what the DPO role did and did not change, and why the specific structural protections made the difference. No other body has this evidence base or the professional standing to deploy it in this argument.
3Build the mechanism for intergenerational ethical representation No current ethics body has operational mechanisms for intergenerational representation in AI ethics design. The BCS could establish a standing intergenerational ethics panel — early-career members, student members, and recent graduates alongside established professionals — as a formal input to every BCS ethics position. This is the first such mechanism in the UK professional body landscape, it is practically achievable, and it directly addresses the most significant structural gap in the current ethics framework: the absence of the people who will implement the consequences. What this means for the BCS:  The BCS’s student and early-career membership is the intergenerational constituency that current ethics frameworks have no mechanism for including. Making their voice structurally present in BCS ethics development is both the right thing to do and the clearest possible demonstration that the BCS is designing for the future, not for the present.
4Develop domain-specific ethical architecture guidance grounded in implementation experience The 703 OECD tools are heterogeneous, unvalidated, and often impractical for implementation in specific operational contexts. The BCS’s cross-domain professional community has direct implementation experience across every sector where AI is being deployed: healthcare, finance, education, infrastructure, government, utilities. It could develop domain-specific ethical architecture guidance — not ethics principles, but the specific design decisions required to build ethical AI into operational systems from the beginning — grounded in the knowledge of what has actually worked and what has not in adjacent domains like Data Protection, information security, and critical infrastructure management. What this means for the BCS:  This guidance would be the first of its kind: ethics designed not for the grand hall but for the people who have to implement it in real systems under real operational conditions. It is the BCS’s most direct contribution to closing the gap between stated ethics and operational practice.
5Name the clock-setting moment publicly and occupy the forward-design role visibly The most significant opportunity available to the BCS right now is to publicly name the transition moment for what it is: the moment at which the AI ethics architecture is being set, when setting it correctly is still possible and relatively affordable, and when the cost of getting it wrong will compound for decades. The BCS is the organisation with the professional depth, the independence, and the public interest mandate to say this clearly — and to say what setting it correctly requires, drawing on direct professional experience of the equivalent moment in Data Protection. What this means for the BCS:  This is the role that is currently vacant. It requires saying things that the commercial AI development community and its government allies find uncomfortable. It requires the leadership team to treat the BCS’s independence as its primary strategic asset rather than as a constraint on engagement. And it is the action most likely to make a genuine difference at the level of structural ethics rather than compliance performance.

7.  The Two Questions the BCS Should Be Asking

The Weavers Cultural Values and Ethics framework begins with two founding questions that no current ethics body is asking directly. They are not comfortable questions. They are the questions the BCS is uniquely positioned to ask.

Question One Can organisations within a system develop comprehensive ethics covering their own role without stepping outside the system? The structural answer is no. An organisation’s ethical framework is built from inside the system that determines its existence. Examining the system honestly would require questioning the legitimacy of the organisation’s own position within it — which the system provides no incentive and no mechanism to do. The ethics that emerges from within is the ethics the system permits. The ethics the situation requires may be different. The BCS’s independence from commercial AI development is the specific property that allows it to step outside the system and ask this question on behalf of those who cannot.
Question Two Can AI support the development of its own ethics? The structural answer is: not in the way currently being attempted. AI trained on human ethical reasoning reproduces the ethical reasoning humans have been applying — including the reasoning that has produced the outcomes the new ethics is supposed to prevent. AI’s most valuable contribution to ethics is identifying what existing frameworks have systematically excluded — the silences, the absences, the questions that have never been asked — not generating frameworks from the accumulated record of old ones. The BCS should be making this distinction publicly and clearly, before AI-generated ethics guidance becomes the default and the distinction is lost.

8.  The Barely Visible Consequence — Named Directly

What is already in motion The barely visible consequence of the current trajectory is not a single dramatic failure. It is the gradual consolidation of an AI ethics architecture that looks comprehensive, is genuinely well-intentioned, and systematically protects the interests of those who shaped it — while the people most affected by AI continue to be included in consultation rather than design, while intergenerational ethical obligations remain rhetorical rather than operational, and while the gap between performative compliance and genuine ethical practice continues to widen. The organisations making AI adoption decisions in this window are setting their ethics clocks. Most are setting them for the world as it is understood now, under competitive pressure, with ethics frameworks designed by the same class of people who govern the systems being deployed. By the time the consequences of those decisions are fully visible — when the retrofitting cost becomes explicit, when the people in the lemon juice begin to be seen, when the children in the water become adults who can name what happened — the architecture will be embedded and the clock-setting moment will have passed. The moment at which this consequence becomes visible will be the moment at which it is too late to change the architecture without dismantling what has been built. The BCS’s role is to name this consequence now — before the architecture is set — and to occupy the role that prevents it from being structurally inevitable.

The recommendation, stated plainly

The BCS should not produce another AI ethics framework. There are already 703. The BCS should become the organisation that applies the quality test to the frameworks that exist, argues publicly for the structural changes that would make genuine ethics possible, and names the clock-setting moment for what it is before it passes.

This requires treating the BCS’s independence from commercial AI development as its primary strategic asset. It requires the willingness to occupy an uncomfortable position — to name what is being concealed, to challenge frameworks produced by powerful organisations, and to hold the standard higher than the standard those organisations find comfortable.

The Data Protection parallel tells us exactly what makes the difference: not more frameworks, not more tools, not more aspirational principles — but the independent function that cannot be dismissed for saying what needs to be said, the individual rights that make ethics enforceable rather than aspirational, and the decision to set the clock correctly at the transition moment rather than to retrofit it after the architecture is embedded.

A note on the framework this briefing draws on The Weavers Cultural Values and Ethics system, from which several insights in this briefing are drawn, is at an early stage of development. It has been developed rapidly using the Weavers and the Web strategic framework as a foundation — a method that has demonstrated the ability to develop domain-specific analytical instruments in days rather than months. But it has not yet been through the feedback learning and wider application that would validate and extend its insights. It is presented here as an initial analytical instrument: a starting point for the BCS’s own analysis, not a finished set of conclusions. The BCS’s engagement with it — its own experience, its members’ knowledge, its institutional understanding of what actually changes organisational behaviour — would be the feedback learning the instrument most needs.

The compass rose of AI ethics will point truly only when the independent ethical catalyst — the organisation willing to name what the grand hall cannot say — is present and visible. That organisation should be the BCS.

David Sutton CITP MBCS

Southport Innovation Centre  |  davesutton19@gmail.com  |  southportinnovationcentre.co.uk

May 2026  |  Based on the Weavers and the Web (v35), Weavers ARIA (v1.6), and Weavers Cultural Values and Ethics Register (v0.1 — early stage, pre-feedback learning)

Current AI ethics evidence: ACM SIGAI AI Ethics Column (March 2026), Darden Report (January 2026), Dataversity (April 2026), KDnuggets (December 2025), OECD AI Observatory, Opal Group Compliance in the Age of AI (May 2026).