Real-World AI Ethics Issues: Case Studies Every Business Should Know

11 min read

Most AI ethics case studies stop at the anecdote. The five below all end in a regulator's order, a tribunal ruling or a signed consent decree, which makes them useful in a way that a cautionary tale is not: each one tells you what a decision-maker actually held, and what it cost. Every case here concerns a system that was doing ordinary business work. Clocking staff in. Screening applicants. Spotting shoplifters. Answering a customer question.

Read them for the failure mode rather than the headline. In four of the five, the technology worked roughly as designed. What went wrong was the process around it: no alternative offered, no accuracy testing, no human in the loop, no ownership of what the system said.

1. Serco Leisure: biometric clock-in ordered to stop

In February 2024 the Information Commissioner's Office ordered Serco Leisure, Serco Jersey and seven associated community leisure trusts to stop using facial recognition and fingerprint scanning to monitor employee attendance. The ICO found unlawful processing of the biometric data of more than 2,000 employees across 38 leisure facilities, used for attendance checks and subsequent payment.

The decisive finding was not that biometrics are banned. It was consent in a power imbalance. Employees had not been proactively offered an alternative to having their faces and fingers scanned, and the scan was presented as a requirement in order to get paid. The enforcement notices required the organisations to stop all such processing and to destroy biometric data they were not legally obliged to retain, within three months.

The control this implies: if a system collects biometric data from staff, a genuine, equally convenient alternative must exist and must be offered up front. Consent that costs the employee their wages is not consent.

2. Rite Aid: a five-year ban on facial recognition

In December 2023 the US Federal Trade Commission announced an order prohibiting Rite Aid from using facial recognition technology for surveillance purposes for five years. The FTC's complaint covered the period 2012 to 2020, during which the retailer deployed AI-based facial recognition in hundreds of stores to identify customers it believed might be shoplifting.

The detail worth reading is how the database was built. Rite Aid collected tens of thousands of images, many of them low quality, drawn from security cameras, employee phone cameras and even news stories. The system generated thousands of false-positive matches, in some cases matching customers against people enrolled on the basis of activity thousands of miles away. Acting on those alerts, employees followed customers, searched them, ordered them to leave and called the police. The FTC said the harms disproportionately affected people of colour, and that Rite Aid did not tell customers the technology was in use.

The control this implies: a detection system that triggers a human action needs an accuracy standard, a disparate-impact test and a documented threshold before it goes live, plus a rule that staff cannot act on a match alone. Garbage enrolment data produces confident, wrong accusations.

3. iTutorGroup: age cut-offs written into the screening code

In September 2023 iTutorGroup agreed to pay 365,000 US dollars to settle a US Equal Employment Opportunity Commission suit. The EEOC alleged the company had programmed its tutor application software to automatically reject female applicants aged 55 or older and male applicants aged 60 or older. The consent decree required continuing training for those involved in hiring, a new anti-discrimination policy, injunctions against discriminatory hiring and against requesting applicants' birth dates, and EEOC monitoring for at least five years.

This one is not really an AI case at all, and that is the point. There was no opaque model to blame. A rule was written down, automated, and applied at scale to thousands of applicants who never saw a human. Automation turned a policy someone would have challenged in a meeting into a silent, consistent outcome.

The control this implies: every automated rejection rule should be readable in plain English by someone outside the engineering team, and reviewed against protected characteristics before deployment. If you would not put the rule in the job advert, do not put it in the filter.

4. Moffatt v Air Canada: the chatbot is you

In Moffatt v Air Canada, 2024 BCCRT 149, decided in February 2024, British Columbia's Civil Resolution Tribunal considered a passenger who had asked the airline's website chatbot about bereavement fares while booking travel after a death in the family. The chatbot told him a discount could be claimed retroactively. It could not, and the airline refused the refund.

Air Canada argued that the chatbot was a separate legal entity responsible for its own actions. The tribunal rejected that squarely: a chatbot "is still just a part of Air Canada's website", and it "makes no difference whether the information comes from a static page or a chatbot". The airline was ordered to pay damages of CAD 650.88 for negligent misrepresentation, the difference between the fare paid and the bereavement fare.

The sum is trivial. The principle is not, because it applies to every generative assistant now answering policy questions on a company website. If the model states a refund policy, a delivery time or an eligibility rule, the company has stated it.

The control this implies: constrain customer-facing assistants to retrieved, approved content; log what they say; and put a named owner on the accuracy of policy answers. Treat the bot's output as published copy, because that is what a tribunal will call it.

5. Clearview AI: where the law reaches

In May 2022 the ICO fined the US company Clearview AI 7.5 million pounds and issued an enforcement notice, for scraping images of UK residents from the web and social media into a global facial recognition database sold as a commercial service. Clearview appealed, and in October 2023 the First-tier Tribunal held that the ICO lacked jurisdiction because the processing fell outside the scope of the UK GDPR.

The ICO appealed in turn. In October 2025 the Upper Tribunal upheld three of the Commissioner's four grounds, concluding that Clearview's processing relates to monitoring the behaviour of UK residents, that it does not fall outside UK data protection law merely because the services were provided to foreign law enforcement and government agencies, and that the First-tier Tribunal had applied the law incorrectly. The ICO's John Edwards said the ruling "gives greater confidence to people in the UK that we can and will act on their behalf, regardless of where the company handling their personal information is based". On 19 December 2025 the Upper Tribunal granted Clearview permission to appeal to the Court of Appeal, so the case is still live.

The control this implies: the provenance of a vendor's training data is your problem too. Ask where the data came from, on what lawful basis, and whether the vendor has ever been the subject of a regulatory notice. "It is a US company" has stopped being an answer.

What the five have in common

Line them up and the same three gaps recur. First, no genuine alternative or opt-out where the system touched people who could not say no: staff, applicants, shoppers. Second, no accuracy or fairness testing proportionate to the consequence, so a false positive that cost someone a job, a purchase or their dignity was treated as a technical error rather than a harm. Third, no clear owner of what the system said or decided, which is how "the chatbot said it" and "the software rejected them" get used as defences that regulators and tribunals do not accept.

None of those gaps is closed by better models. They are closed by governance: a written policy, a review step before deployment, a record of the decision, and a person accountable for the outcome.

Turning the cases into your own controls

A workable minimum, drawn directly from the five: publish an internal AI use policy that covers customer-facing assistants as well as internal tools; require a documented impact assessment before any system that screens, scores or identifies a person goes live; guarantee a human review route for any automated adverse decision; offer a real alternative to any biometric process; and keep a register of AI systems in use with a named owner for each.

Our guide on how to write an AI use policy for employees covers the first of those, and the EU AI Act compliance checklist covers the regulatory layer sitting above it. For the underlying reasoning, see ethical principles in business, or start from the E-Business Ethics homepage.

Primary sources for the cases above: the ICO's statements on Serco Leisure and on the Clearview Upper Tribunal judgment, the FTC's Rite Aid press release, and the EEOC's iTutorGroup settlement.

Frequently Asked Questions

What are the most useful AI ethics case studies for a business?

The ones with a regulator or a tribunal attached, because they tell you what a decision-maker actually held rather than what a commentator thought. The Serco Leisure biometric enforcement notices, the FTC's order against Rite Aid, the EEOC's iTutorGroup settlement, Moffatt v Air Canada and the ICO's Clearview litigation between them cover employment, customer-facing tools, biometrics and jurisdiction.

Can a company be held to what its AI chatbot says?

Yes. In Moffatt v Air Canada the tribunal rejected the argument that the chatbot was a separate entity, holding that a chatbot "is still just a part of Air Canada's website" and that it "makes no difference whether the information comes from a static page or a chatbot". If your bot states a policy, you have stated a policy.

Is it lawful to use facial recognition to clock staff in and out?

Not by default. In February 2024 the ICO ordered Serco Leisure, Serco Jersey and seven associated leisure trusts to stop using facial recognition and fingerprint scanning for attendance monitoring, having found unlawful processing of the biometric data of more than 2,000 employees across 38 sites. A central failing was that employees were not proactively offered an alternative, and the scan was presented as a requirement in order to get paid.

What is the legal risk in AI recruitment screening?

Discrimination liability sits with the employer, not the vendor. The EEOC's iTutorGroup case is the clearest example: the software was programmed to reject female applicants aged 55 or over and male applicants aged 60 or over, and the company paid 365,000 US dollars in September 2023 to settle, with EEOC monitoring for at least five years.

Does UK data protection law apply to an AI company based abroad?

The Upper Tribunal's Clearview judgment says it can. It concluded that Clearview's processing relates to monitoring the behaviour of UK residents and does not fall outside UK data protection law merely because the service was supplied to foreign agencies. Clearview has been granted permission to appeal to the Court of Appeal, so the point is not finally settled.

How should we turn these cases into internal policy?

Take the failure mode from each and write it as a control: an opt-out for any biometric process, a documented accuracy and disparate-impact test before a customer-facing detection system goes live, a human review of any automated rejection, an ownership rule that whatever the bot says is company policy, and a data-provenance check for any vendor model. Then name someone accountable for each.

Need Help Governing AI in Your Organisation?

We provide ethics training and consulting to help organisations put practical controls around the AI systems already in use across their business.

Get in Touch