SaveMyCert
Log in
5 of 5 free questions left today·for 30 a day
Identify AI concepts and capabilities

Microsoft's Responsible AI Principles for Azure AI Fundamentals (AI-901)

14 min readAI-901 · Identify AI concepts and capabilitiesUpdated

Responsible AI is the practice of designing, building and running AI systems so that they are fair, reliable and safe, private and secure, inclusive, transparent and accountable, which are the six principles Microsoft uses to guide its own AI and the first task of the AI-901 exam. This lesson explains what each principle asks of an AI solution, the practical measures that put it into effect (from rebalancing training data and confidence thresholds to content filters, de-identification, accessibility features, disclosure and governance boards), and how to tell the principles apart when a scenario could seem to fit more than one.

What you’ll learn
  • Name Microsoft's six responsible AI principles and the question each one asks of an AI solution
  • Explain how bias enters a model through historical data and proxy features, and how rebalancing data and per-group measurement address it
  • Describe reliability and safety measures, including testing beyond the demo, confidence thresholds, targeted human review and content filters on Microsoft Foundry deployments
  • Describe privacy and security considerations for both the data an AI system uses and the information it can reveal
  • Describe inclusiveness, transparency (disclosure and global or local interpretability) and accountability (governance and human final authority) in practice
  • Tell near-twin principles apart: fairness vs inclusiveness, transparency vs accountability, and reliability and safety vs accountability or privacy

What are Microsoft's six principles of responsible AI?

Microsoft's six principles of responsible AI are fairness, reliability and safety, privacy and security, inclusiveness, transparency and accountability. They are the considerations every team should work through when it designs, builds, deploys and runs an AI solution, and AI-901 asks you to describe what each one means in practice.

Each principle answers a different question about the system. Learning that question is the quickest way to place any scenario under the right principle:

PrincipleThe question it asksTypical practices
FairnessDo similar people get similar outcomes from the model?Representative training data, rebalancing or reweighting, comparing outcomes and error rates per group
Reliability and safetyDoes the system behave as designed, including on unexpected input, and avoid causing harm?Testing beyond the happy path, confidence thresholds, human review where the model is weak, content filters, adversarial testing, monitoring
Privacy and securityIs personal and organizational data protected, both in the data and in what the system reveals?Data minimization and retention limits, de-identification, access control, encryption, consent and user control, preventing the model from disclosing private details
InclusivenessCan everyone use and benefit from the system, whatever their abilities or circumstances?Accessibility features (captions, typed or alternative input), designing and testing with a diverse range of people
TransparencyDo people understand that AI is involved, how it works and where it falls short?Disclosing AI use, describing training data, stating known limitations, explaining predictions (interpretability)
AccountabilityWho answers for the system, and do people stay in control of it?Governance frameworks, review boards, named owners, humans as the final authority, appeal routes

The principles overlap in real projects, and one measure can support more than one of them. When you classify a measure, ask what problem it mainly solves: unequal outcomes, unsafe behavior, exposed data, people being shut out, people misunderstanding the system, or nobody being answerable.

What does fairness mean in an AI solution?

Fairness means an AI system should treat people equitably: people in similar circumstances should get similar outcomes, whatever their gender, age, ethnicity, neighborhood or other characteristics that should not matter. Microsoft's guidance gives the classic example of a loan-approval model that should make the same recommendation for applicants with similar financial circumstances.

Where unfairness comes from

Most unfairness comes from the training data. A model learns patterns from past examples, so if those examples reflect historical bias, the model reproduces it. A model trained on years of past admissions, hiring or lending decisions will learn whatever preferences shaped those decisions, and a group that is under-represented in the data tends to get less accurate predictions.

Simply deleting a sensitive column (such as gender) does not remove the bias. Other features often correlate with it, so they act as proxy features: a postcode can stand in for ethnicity or income, and the wording, hobbies or career gaps on a CV can stand in for gender. The model can rebuild the same pattern from the proxies, and without the sensitive column it becomes harder to measure whether it has done so.

How teams address fairness

  • Make the data representative. Collect more data for under-represented groups, or rebalance or reweight the training data so every group is adequately represented.
  • Measure outcomes per group. Compare selection or approval rates and error rates across groups of people with similar relevant characteristics, on held-out test data. This produces the evidence that similar people get similar decisions. The fairness assessment in the Azure Machine Learning Responsible AI dashboard is built for exactly this kind of comparison across sensitive groups.
  • Check quality of service, not just decisions. Microsoft's Responsible AI Standard treats a system that works noticeably worse for some groups (for example, a document-scanning model that misreads handwriting from some regions far more often) as a fairness harm, even when nobody is refused anything.
  • Keep checking after release. Data and populations change, so fairness metrics are monitored, not measured once.

A useful test: a measure supports fairness only if it changes, or produces evidence about, how outcomes and error rates compare between groups of people. Good practices that do something else, however valuable, sit under another principle.

What does reliability and safety mean in an AI solution?

Reliability and safety means an AI system should perform consistently as designed, respond safely to conditions it was not designed for, and resist being manipulated into harmful behavior. The starting point is that AI is probabilistic: a model produces the most likely output for an input, which is usually but not always correct, and it can be wrong while sounding or scoring confident.

Why a good demo is not enough

A demo exercises a handful of typical inputs. Real users send unusual, ambiguous and adversarial ones, and models are least reliable on inputs unlike their training data (for example, rare situations that barely appear in it). Reliability therefore requires testing with a wide range of normal, edge-case and unexpected inputs before release, and planning for what happens when the model is wrong.

Designing for the model's weak spots

  • Confidence thresholds. Many models return a confidence score with each prediction. A system can act automatically above a threshold and stop, ask for help or hand over to a person below it, as a medical-triage model might when it flags a case it cannot classify with enough confidence for a clinician to assess.
  • Targeted human review. Where errors are serious, send the risky cases (low confidence, or categories known to be weak) to a human reviewer, and keep automation for routine cases where the model performs well. This reduces the risk while keeping the benefit of automation. Error analysis, which breaks a model's errors down by type of input, is how teams find out which categories those are.
  • Safe failure. When the system cannot answer well, it should fail gracefully, for example by declining or escalating rather than guessing.

Reliability and safety for generative AI

Generative models add a specific risk: they can produce harmful content such as hateful, violent, sexual or self-harm material, or be steered towards it by crafted prompts. The main mitigations are:

  • Content filters (guardrails). In Microsoft Foundry, model deployments such as Azure OpenAI models apply content filtering by default, powered by Azure AI Content Safety, that detects and blocks harmful categories of content in both prompts and responses. Each category's severity threshold can be configured.
  • Adversarial testing. Teams evaluate the app with realistic and deliberately hostile prompts (often called red teaming) before launch to find where it misbehaves.
  • Monitoring. Once live, the app's outputs and any filter hits are monitored so new failure patterns are caught and fixed.

Content filters target categories of harmful content. Other risks, such as unequal outcomes or exposed personal data, are addressed by the fairness and privacy measures described in their own sections.

What does privacy and security mean in an AI solution?

Privacy and security means an AI system must protect the personal and organizational data it uses, and must not become a way to reveal that data. AI depends on large amounts of data, often personal, so the principle covers two things: the data that goes into the system, and what the system can be made to give out.

Protecting the data the system uses

  • Minimize and limit retention. Collect only what the system needs and keep it no longer than necessary.
  • De-identify. Mask, remove or replace names, addresses, card numbers and other identifiers before data is used for training, fine-tuning or analysis.
  • Restrict and encrypt. Limit who can access datasets and recordings, and encrypt data at rest and in transit.
  • Consent and control. Privacy laws, and Microsoft's principle, expect people to have appropriate control over how their data is collected and used: ask permission before using their data (for example, to improve a model), explain the use, and let them withdraw that permission.

Protecting what the model can reveal

A trained model can memorize details from its training data, and an assistant grounded on internal documents can quote from them. Microsoft's guidance is that the system itself must not be usable to reveal private personal or organizational details. A document-search assistant that can be prompted into quoting confidential contract terms or a customer's home address fails privacy and security, even though nothing it says is offensive or violent. Mitigations include keeping sensitive data out of training sets or grounding sources unless it is needed, applying the user's own access permissions to the documents an assistant can retrieve, and testing whether prompts can extract private information.

What does inclusiveness mean in an AI solution?

Inclusiveness means an AI solution should empower and engage everyone and must not exclude people from using it or benefiting from it, whatever their physical ability, gender, age, language, location, connectivity or other circumstances. Where fairness asks whether the model's outcomes are equal, inclusiveness asks whether everyone can use the system in the first place.

  • Accessibility. Offer more than one way to interact: captions or on-screen text for people who cannot hear a voice interface, typed input for people who cannot speak, screen-reader support and adjustable speech speed for people with visual or other impairments, plain language for people with limited reading skills.
  • Design for real conditions. Consider slow connections, older devices and different languages, so the benefit is not limited to users with ideal circumstances.
  • Involve diverse people from the start. The most effective practice is to include people with a range of abilities, ages and backgrounds in design and user testing, so barriers are found and removed before release rather than discovered afterwards.

What does transparency mean in an AI solution?

Transparency means people should understand that an AI system is involved, how it works and what its limitations are, so they can judge how much to trust it, especially when it informs decisions about them. Transparency calibrates trust: users who do not know they are dealing with AI, or who do not know where it can go wrong, tend to over-trust it.

Disclosure

  • Disclose AI use. Tell people when they are interacting with an AI system (for example, that a chat assistant is AI and not a human agent) or when AI contributes to a decision about them.
  • Describe the data. Explain the kinds of data the system was trained on and its intended uses, without revealing confidential details.
  • State limitations. Say where the system is known to perform poorly and that its outputs can contain mistakes. Microsoft publishes transparency notes for its AI services for this purpose, and teams can write the same kind of document for their own systems.

Interpretability

Microsoft treats interpretability, giving human-understandable explanations of a model's behavior, as a crucial part of transparency. There are two kinds of explanation:

ExplanationWhat it showsExample use
GlobalWhich features drive the model's predictions overallA report for business stakeholders on what the model relies on
LocalWhich features drove one particular predictionTelling a patient which test results most influenced the risk score a model gave them

The Azure Machine Learning Responsible AI dashboard includes model interpretability with both global and local feature importance. Note that explaining an individual decision is transparency; comparing outcomes across groups is fairness, even though both use model analysis tools.

What does accountability mean in an AI solution?

Accountability means the people and organizations that design, build and deploy an AI system are answerable for how it operates. AI should not be the final authority on decisions that affect people's lives, and humans should keep meaningful control over highly autonomous systems.

  • Governance framework. Organizations set internal policies and standards, often with a review board or committee that must approve AI systems before release, guided by industry and legal requirements.
  • Named owners. Each system in production has a person or team who answers for its behavior, signs off releases and acts on problems.
  • Humans as the final authority. For consequential decisions, people review the model's output (for example, case officers reviewing a model's recommendation before a benefits application is turned down) and affected people can appeal to a person rather than to the model.

Records such as audit trails support accountability by making it possible to trace an outcome back to the system and the people responsible for it.

How do you tell near-twin principles apart?

Near-twin principles are told apart by asking what problem a measure mainly solves. Four pairs cause most confusion:

PairFirst principle is aboutSecond principle is about
Fairness vs inclusivenessFairness: people who can use the system get equal outcomes and equal quality of service (no group gets worse decisions or more errors)Inclusiveness: nobody is shut out of using or benefiting from the system (accessibility, alternative input, diverse design)
Transparency vs accountabilityTransparency: people understand the system (disclosure, data descriptions, limitations, explanations)Accountability: people answer for the system (governance, owners, human final authority, appeals)
Reliability and safety vs accountabilityReliability and safety: a human is brought in because the model may be wrong and the error could cause harm (confidence thresholds, safe failure)Accountability: a human holds authority and responsibility for decisions regardless of the model's confidence
Reliability and safety vs privacy and securityReliability and safety: harmful or unsafe output, such as violent or hateful content, blocked by content filtersPrivacy and security: private data exposed, whether from a dataset or extracted from the model through prompts

One scenario can raise two principles at once. A face-verification check that fails more often for people with darker skin tones has a fairness problem (unequal quality of service); if the same self-service kiosk also has no screen at wheelchair height, it has an inclusiveness problem too (some people cannot use it at all). Likewise, a public chat assistant may need a disclosure that it is AI (transparency) as well as content filters (reliability and safety).

In short, transparency is aimed at the people who use or are affected by the system and is measured by whether they understand it; accountability is aimed at the organization and is measured by whether someone is answerable for it.

Tip. AI-901 tests this task mostly with short scenarios that describe a measure, a design choice or a problem with an AI system and ask which responsible AI principle it relates to, or which action best addresses a given principle. Distractors are usually the near-twin principle (fairness vs inclusiveness, transparency vs accountability, reliability and safety vs accountability or privacy) or a sound practice that belongs to a different principle. Some items ask you to select two measures for one principle, or to name both principles raised by a scenario, so know the concrete practices behind each principle, not just its definition.

Key takeaways
  • The six principles are fairness, reliability and safety, privacy and security, inclusiveness, transparency and accountability; classify a measure by the problem it mainly solves.
  • Fairness: similar people get similar outcomes. Bias usually comes from historical or unrepresentative training data, and removing a sensitive column does not fix it because proxy features carry the same pattern.
  • Fairness is evidenced by comparing selection and error rates across groups, and improved by rebalancing or reweighting data; unequal quality of service for a group is a fairness harm.
  • Reliability and safety starts from AI being probabilistic: test widely, use confidence thresholds, send weak or high-stakes cases to people, and fail safely.
  • For generative AI, content filters on Microsoft Foundry deployments block harmful content in prompts and responses; adversarial testing and monitoring complete the safety picture.
  • Privacy and security covers the data (minimize, de-identify, restrict, encrypt, get consent) and the model's outputs (it must not reveal private personal or organizational details).
  • Inclusiveness means nobody is excluded from using or benefiting: accessibility features and diverse people in design and testing from the start.
  • Transparency means people understand the system: disclose AI use, describe the data, state limitations, and explain predictions globally (overall) or locally (one decision).
  • Accountability means people answer for the system: governance boards, named owners, and humans as the final authority with an appeal route.

Frequently asked questions

What are Microsoft's six principles of responsible AI?

Microsoft's six responsible AI principles are fairness, reliability and safety, privacy and security, inclusiveness, transparency and accountability. Fairness asks that similar people get similar outcomes; reliability and safety that the system behaves as designed and avoids harm; privacy and security that data is protected; inclusiveness that nobody is excluded; transparency that people understand the system and its limits; and accountability that people answer for it.

What is the difference between fairness and inclusiveness in responsible AI?

Fairness is about the outcomes an AI system gives: people in similar circumstances should receive similar decisions and similar quality of service, so a model that is less accurate for one group is a fairness problem. Inclusiveness is about access: nobody should be shut out of using or benefiting from the system, so an app that only works with a touchscreen gesture some users cannot perform, or that needs a fast connection, is an inclusiveness problem.

What is the difference between transparency and accountability in responsible AI?

Transparency helps people understand an AI system: that AI is being used, what data it was built on, its known limitations and why it made a particular decision. Accountability makes people and organizations answerable for the system's outcomes, through governance frameworks, named owners and keeping humans as the final authority on decisions that affect people.

Does removing a sensitive attribute such as gender make a model fair?

No. Removing a sensitive column on its own does not make a model fair, because other features that correlate with it, such as postcode, job history or wording on a CV, act as proxies and let the model learn the same biased pattern. Fairness is improved by making training data representative, for example by rebalancing or reweighting it, and verified by comparing the model's outcomes and error rates across groups.

Which responsible AI principle do content filters support?

Content filters support the reliability and safety principle. In Microsoft Foundry, model deployments such as Azure OpenAI models apply content filtering by default, which detects and blocks harmful categories of content, such as hate, violence, sexual and self-harm content, in prompts and responses. Protecting private information is a separate privacy and security concern with its own controls.

What is the difference between global and local explanations in AI?

A global explanation shows which input features drive a model's predictions overall, which helps stakeholders understand how the model behaves in general. A local explanation shows which features drove one particular prediction, such as why one patient received a particular risk score. Both are forms of interpretability, which Microsoft treats as part of the transparency principle.

Why is human review part of responsible AI?

Human review serves two principles. Under reliability and safety, people review cases where the model is likely to be wrong and an error could cause harm, such as low-confidence predictions. Under accountability, people stay the final authority on decisions that affect others' lives, with a route for affected people to appeal to a person rather than the model.

Source

This lesson covers the "Identify AI concepts and capabilities" domain of the official AI-901 exam guide. Vendors revise their guides — check the source for the current version.

Test yourself on this topic
Practice now

Sign up free to mark lessons complete, bookmark topics and track your exam readiness.

Spotted a mistake in this lesson?