Summary: A ~94,000-word consensus document from The IEEE Global Initiative on Ethics of Autonomous and Intelligent Systems. Five general principles plus thirteen committee chapters. Ethics-first rather than security-first, and the oldest source in this corpus.
Sources: raw/Laws/ead_v2.md
Last updated: 2026-07-28
What this document is
Ethically Aligned Design: A Vision for Prioritizing Human Well-being with Autonomous and Intelligent Systems (A/IS), Version 2 — For Public Discussion. Produced by committees of “several hundred participants from six continents.” Licensed CC BY-NC 3.0 US (source: ead_v2.md).
Status caveat, and it matters for how you cite this page. This is a request-for-input draft: “Input about Ethically Aligned Design should be sent by email no later than 7 May 2018,” with a final version “to be released in 2019” (source: ead_v2.md). The file in raw/ is the v2 public-discussion draft, not the final EAD1e. Treat specific recommendations as historical positions, not current IEEE guidance. Anything load-bearing should be verified against the final release.
Its stated purposes: advance public discussion on ethical implementations; “inspire the creation of Standards (IEEE P7000™ series and beyond) and associated certification programs”; and facilitate national and global policies aligned with these principles.
The P7000 series link is the practical legacy — this document is the reasoning behind a family of IEEE standards.
Five general principles
- Human Rights
- Prioritizing Well-being
- Accountability
- Transparency
- A/IS Technology Misuse and Awareness of It
Principle 5 is the security-relevant one and is unusual: no other framework in this corpus elevates misuse awareness to a top-level principle. NIST folds misuse into Secure and Resilient; OECD folds it into 1.4 robustness. IEEE treats the fact that these systems will be deliberately abused, and that the field must be aware of it, as a first-class design principle.
The thirteen chapters
| Chapter | Focus |
|---|---|
| General Principles | The five above |
| Embedding Values into A/IS | Identifying norms, implementing norms, evaluating implementation |
| Methodologies to Guide Ethical Research and Design | Interdisciplinary education, corporate practices, research ethics, lack of transparency |
| Safety and Beneficence of AGI and ASI | Technical section + general principles |
| Personal Data and Individual Access Control | Digital personas, regional jurisdiction, agency and control, transparency and access, symmetry and consent |
| Reframing Autonomous Weapons Systems | — |
| Economics and Humanitarian Issues | Economics, privacy and safety, education, equal availability |
| Law | Legal status of A/IS, governmental use, legal accountability for harm, transparency/accountability/verifiability |
| Affective Computing | Systems across cultures, when systems become intimate, system manipulation/nudging/deception, systems supporting human flourishing, systems with their own emotions |
| Policy | — |
| Classical Ethics in A/IS | Definitions, globally diverse traditions, classical ethics for a technical world |
| Mixed Reality in ICT | Social interactions, mental health, education and training, the arts, privacy access and control |
| Well-being | Well-being metrics and their value for A/IS |
Sections worth returning to for security work
Embedding Values — Section 3: Evaluating the Implementation of A/IS. The evaluation problem: having specified norms, how do you verify a system implements them? This is the same question adversarial testing asks from the attacker’s side.
Law — Section 4: Transparency, Accountability, and Verifiability in A/IS. Verifiability is the legal hook for logging and traceability. Compare AI Act Art 12 and OECD Principle 1.5.
Affective Computing — System Manipulation/Nudging/Deception. The closest thing in this corpus to a sustained treatment of manipulation by AI systems of humans, which is the “harmful manipulation” specified systemic risk and, from the offensive side, PITAX’s persuasion cluster pointed outward.
Safety and Beneficence of AGI/ASI. Predates the current loss-of-control discourse and reaches similar conclusions. Compare the loss of control specified risk.
Personal Data and Individual Access Control — Section 5: Symmetry and Consent. The longest single section in the document (~320 lines).
Assessment for this vault
Lowest security-density source in the corpus by a wide margin: ~94k words, almost none of it about adversaries, attacks or controls. Its value here is conceptual — Principle 5 and the manipulation/nudging material name problems the more operational frameworks assume away — and historical, as the origin of the P7000 series.
Practical guidance: do not cite EAD v2 for anything current. Use it to trace where an idea came from, then cite the framework that operationalised it.