Ai, Ethics and Law
A.Y. 2026/2027
Learning objectives
Across both parts of the programme, students engage with artificial intelligence as an object that is simultaneously subject to legal regulation and open to moral assessment, and they learn to move deliberately between these two registers rather than collapsing one into the other.
Knowledge and understanding
Students acquire the conceptual vocabulary needed to analyse what a norm is — legal or moral — how it conditions and constrains action, and how validity, legitimacy, and moral permissibility differ from one another and from mere technical feasibility.
Applying knowledge and understanding
Students learn to map a given AI system, or a decision involving one, onto both registers at once: identifying the legal obligations that apply to it (data protection, the AI Act, liability, fundamental rights) and the ethical questions it raises (agency, responsibility, value alignment, political effects), and locating where the two converge or pull apart.
Knowledge and understanding
Students acquire the conceptual vocabulary needed to analyse what a norm is — legal or moral — how it conditions and constrains action, and how validity, legitimacy, and moral permissibility differ from one another and from mere technical feasibility.
Applying knowledge and understanding
Students learn to map a given AI system, or a decision involving one, onto both registers at once: identifying the legal obligations that apply to it (data protection, the AI Act, liability, fundamental rights) and the ethical questions it raises (agency, responsibility, value alignment, political effects), and locating where the two converge or pull apart.
Expected learning outcomes
Making judgements
Students hold the legal "double question" — is it lawful? is it legitimate? — together with its ethical counterpart — is it permissible? who is responsible, and to whom? — and recognise that legal compliance does not exhaust moral justification, just as technical or legal proxies (fairness metrics, risk classes) never fully coincide with the normative concepts (equality, responsibility, autonomy) they stand in for.
Communication skills
Students articulate legal and ethical reasoning to interlocutors with different backgrounds — legal, technical, philosophical — translating abstract requirements into concrete design, policy, and governance implications.
Learning skills
Students read primary sources independently, whether statutory texts or philosophical arguments, and keep pace with two fields that evolve continuously alongside the technology they address.
Students hold the legal "double question" — is it lawful? is it legitimate? — together with its ethical counterpart — is it permissible? who is responsible, and to whom? — and recognise that legal compliance does not exhaust moral justification, just as technical or legal proxies (fairness metrics, risk classes) never fully coincide with the normative concepts (equality, responsibility, autonomy) they stand in for.
Communication skills
Students articulate legal and ethical reasoning to interlocutors with different backgrounds — legal, technical, philosophical — translating abstract requirements into concrete design, policy, and governance implications.
Learning skills
Students read primary sources independently, whether statutory texts or philosophical arguments, and keep pace with two fields that evolve continuously alongside the technology they address.
Lesson period: First semester
Assessment methods: Esame
Assessment result: voto verbalizzato in trentesimi
Single course
This course can be attended as a single course.
Course syllabus and organization
Single session
Lesson period
First semester
Course syllabus
MORAL AGENCY
Week 1
Floridi & Sanders, 'On the morality of artificial agents', 2004
Week 2
Wallach & Allen, 'Can (ro)bots really be moral?', 2008
Week 3
Wynsberghe & Robbins, 'Critiquing the reasons for making artificial moral agents', 2019
MODULE 2: MORAL RESPONSIBILITY
Week 4
Elish, 'Moral crumple zones: cautionary tales in human-robot interaction', 2019
Week 5
Hakli & Mäkelä, 'Moral responsibility of robots and hybrid agents', 2019
Week 6
Thoma, 'Risk imposition by artificial agents: the moral proxy problem', 2022
MODULE 3: VALUE ALIGNMENT
Week 7
Wallach & Allen, 'Top-down morality', 'Bottom-up and developmental approaches', 2008
Week 8
Bostrom, 'The superintelligent will: motivation and instrumental rationality in advanced
artificial agents', 2012
Week 9
Gabriel, 'Artificial intelligence, values, and alignment', 2020
MODULE 4: POLITICAL DIMENSIONS
Week 10
Danaher, 'The threat of algocracy: reality, resistance, and accommodation', 2016
Week 11
Benn & Lazar, 'What's wrong with automated influence?', 2022
Week 12
Christiano, 'Algorithms, manipulation, and democracy', 2022
LAW
Module 0 — Foundations: law, norms, and technology (2 h)
Lecture 1. Why AI designers must engage with the law. What
a legal norm is: conditional structure (operative facts →
legal effect), the gap between rule and case, the problem
of interpretation. Normative systems compared: law and
code ("code is law," Lessig); architecture as regulation.
Essential analytic concepts: validity, efficacy,
legitimacy. Introduction to the double question and to the
idea of subjecting computational power to the rule of law
(digital constitutionalism).
Module 1 — Personal data protection (6 h)
Lecture 2. The architecture of the GDPR: material and territorial scope;
key definitions (personal data, processing,
pseudonymisation/anonymisation — relevant to ML); the principles of Art.
5; the principle of accountability.
Lecture 3. Lawful bases for processing (Art. 6); special categories of data
(Art. 9 — relevant to bias); data subject rights; transparency and
information duties; the roles (controller, processor, joint controllership).
Lecture 4. Data protection by design and by default (Art. 25) as an
engineering requirement; data protection impact assessment (DPIA, Art.
35); automated decision-making and profiling (Art. 22) as a bridge to the
AI Act. Brief coverage: ePrivacy, the data ecosystem (Data Act, Data
Governance Act), international transfers.
Module 2 — The EU AI Act (8 h)
Lecture 5. Genesis, rationale, and structure of Regulation (EU) 2024/1689.
The risk pyramid. The definition of an "AI system" (OECD alignment; the
ELI three-factor reading). Scope and exclusions. The actors in the value
chain: provider, deployer, importer, distributor.
Lecture 6. Prohibited AI practices (Art. 5). Classification of high-risk
systems: Annex III and the product-safety route (Annex I).
Lecture 7. Requirements for high-risk systems — risk management
system, data governance, technical documentation, logging/record-
keeping, transparency towards the deployer, human oversight, accuracy,
robustness, and cybersecurity. Mapping the requirements onto the ML
lifecycle (the course's principal STEM bridge).
Lecture 8. Obligations of the provider vs. the deployer; conformity
assessment and CE marking; harmonised standards and the role of
ISO/IEC 42001; GPAI models and systemic-risk obligations; governance
(AI Office, national competent authorities); the phased application
timeline. The evolving picture: the Digital Omnibus.
Module 3 — Liability and attribution (2 h)
Lecture 9. Civil liability for AI-related harm. The revised Product Liability
Directive (software and AI as a "product," burden of proof, disclosure
duties). The debate on the AI Liability Directive (a proposal of uncertain
outcome). Causation and system opacity. The responsibility gap and the
"problem of many hands" (a philosophical reading). Allocating
responsibility along the value chain; notes on insurance and
administrative dimensions.
Module 4 — Fundamental rights, non-discrimination, and human-centered
governance (4 h)
Lecture 10. The Charter of Fundamental Rights: dignity, private life,
equality. Algorithmic discrimination as a legal problem (not merely
technical): direct and indirect discrimination, proxies, the burden of proof
in anti-discrimination law. The gap between technical fairness metrics
and the legal notion of equality.
Lecture 11. Transparency, explainability, and contestability as legal
requirements (across the GDPR, the AI Act, and sectoral rules).
Meaningful human oversight and control. The Council of Europe
Framework Convention on AI, human rights, democracy, and the rule of
law. Digital constitutionalism: disciplining public and private algorithmic
power. (Optional note: DSA/DMA and platform power.)
Module 5 — Synthesis: compliance-by-design, ethics and law, cases (2 h)
Lecture 12. From rules to design: governance management systems
(ISO/IEC 42001), the compliance lifecycle, documentation as a form of
accountability. The double question revisited: where ethics exceeds the
law. Concluding case study (e.g. a high-risk AI system in healthcare,
recruitment, or public administration): end-to-end analysis of obligations
across data protection, the AI Act, liability, and fundamental rights. Future
trajectories and the professional responsibility of those who design.
Week 1
Floridi & Sanders, 'On the morality of artificial agents', 2004
Week 2
Wallach & Allen, 'Can (ro)bots really be moral?', 2008
Week 3
Wynsberghe & Robbins, 'Critiquing the reasons for making artificial moral agents', 2019
MODULE 2: MORAL RESPONSIBILITY
Week 4
Elish, 'Moral crumple zones: cautionary tales in human-robot interaction', 2019
Week 5
Hakli & Mäkelä, 'Moral responsibility of robots and hybrid agents', 2019
Week 6
Thoma, 'Risk imposition by artificial agents: the moral proxy problem', 2022
MODULE 3: VALUE ALIGNMENT
Week 7
Wallach & Allen, 'Top-down morality', 'Bottom-up and developmental approaches', 2008
Week 8
Bostrom, 'The superintelligent will: motivation and instrumental rationality in advanced
artificial agents', 2012
Week 9
Gabriel, 'Artificial intelligence, values, and alignment', 2020
MODULE 4: POLITICAL DIMENSIONS
Week 10
Danaher, 'The threat of algocracy: reality, resistance, and accommodation', 2016
Week 11
Benn & Lazar, 'What's wrong with automated influence?', 2022
Week 12
Christiano, 'Algorithms, manipulation, and democracy', 2022
LAW
Module 0 — Foundations: law, norms, and technology (2 h)
Lecture 1. Why AI designers must engage with the law. What
a legal norm is: conditional structure (operative facts →
legal effect), the gap between rule and case, the problem
of interpretation. Normative systems compared: law and
code ("code is law," Lessig); architecture as regulation.
Essential analytic concepts: validity, efficacy,
legitimacy. Introduction to the double question and to the
idea of subjecting computational power to the rule of law
(digital constitutionalism).
Module 1 — Personal data protection (6 h)
Lecture 2. The architecture of the GDPR: material and territorial scope;
key definitions (personal data, processing,
pseudonymisation/anonymisation — relevant to ML); the principles of Art.
5; the principle of accountability.
Lecture 3. Lawful bases for processing (Art. 6); special categories of data
(Art. 9 — relevant to bias); data subject rights; transparency and
information duties; the roles (controller, processor, joint controllership).
Lecture 4. Data protection by design and by default (Art. 25) as an
engineering requirement; data protection impact assessment (DPIA, Art.
35); automated decision-making and profiling (Art. 22) as a bridge to the
AI Act. Brief coverage: ePrivacy, the data ecosystem (Data Act, Data
Governance Act), international transfers.
Module 2 — The EU AI Act (8 h)
Lecture 5. Genesis, rationale, and structure of Regulation (EU) 2024/1689.
The risk pyramid. The definition of an "AI system" (OECD alignment; the
ELI three-factor reading). Scope and exclusions. The actors in the value
chain: provider, deployer, importer, distributor.
Lecture 6. Prohibited AI practices (Art. 5). Classification of high-risk
systems: Annex III and the product-safety route (Annex I).
Lecture 7. Requirements for high-risk systems — risk management
system, data governance, technical documentation, logging/record-
keeping, transparency towards the deployer, human oversight, accuracy,
robustness, and cybersecurity. Mapping the requirements onto the ML
lifecycle (the course's principal STEM bridge).
Lecture 8. Obligations of the provider vs. the deployer; conformity
assessment and CE marking; harmonised standards and the role of
ISO/IEC 42001; GPAI models and systemic-risk obligations; governance
(AI Office, national competent authorities); the phased application
timeline. The evolving picture: the Digital Omnibus.
Module 3 — Liability and attribution (2 h)
Lecture 9. Civil liability for AI-related harm. The revised Product Liability
Directive (software and AI as a "product," burden of proof, disclosure
duties). The debate on the AI Liability Directive (a proposal of uncertain
outcome). Causation and system opacity. The responsibility gap and the
"problem of many hands" (a philosophical reading). Allocating
responsibility along the value chain; notes on insurance and
administrative dimensions.
Module 4 — Fundamental rights, non-discrimination, and human-centered
governance (4 h)
Lecture 10. The Charter of Fundamental Rights: dignity, private life,
equality. Algorithmic discrimination as a legal problem (not merely
technical): direct and indirect discrimination, proxies, the burden of proof
in anti-discrimination law. The gap between technical fairness metrics
and the legal notion of equality.
Lecture 11. Transparency, explainability, and contestability as legal
requirements (across the GDPR, the AI Act, and sectoral rules).
Meaningful human oversight and control. The Council of Europe
Framework Convention on AI, human rights, democracy, and the rule of
law. Digital constitutionalism: disciplining public and private algorithmic
power. (Optional note: DSA/DMA and platform power.)
Module 5 — Synthesis: compliance-by-design, ethics and law, cases (2 h)
Lecture 12. From rules to design: governance management systems
(ISO/IEC 42001), the compliance lifecycle, documentation as a form of
accountability. The double question revisited: where ethics exceeds the
law. Concluding case study (e.g. a high-risk AI system in healthcare,
recruitment, or public administration): end-to-end analysis of obligations
across data protection, the AI Act, liability, and fundamental rights. Future
trajectories and the professional responsibility of those who design.
Prerequisites for admission
There are no prerequisites other than those required for enrollment in the master's degree program
Teaching methods
Classes will be conducted primarily in a face-to-face format. Any other formats will be agreed upon with the students.
Teaching Resources
ETHICS
MODULE 1: MORAL AGENCY
Week 1
Floridi & Sanders, 'On the morality of artificial agents', 2004
Week 2
Wallach & Allen, 'Can (ro)bots really be moral?', 2008
Week 3
Wynsberghe & Robbins, 'Critiquing the reasons for making artificial moral agents', 2019
MODULE 2: MORAL RESPONSIBILITY
Week 4
Elish, 'Moral crumple zones: cautionary tales in human-robot interaction', 2019
Week 5
Hakli & Mäkelä, 'Moral responsibility of robots and hybrid agents', 2019
Week 6
Thoma, 'Risk imposition by artificial agents: the moral proxy problem', 2022
MODULE 3: VALUE ALIGNMENT
Week 7
Wallach & Allen, 'Top-down morality', 'Bottom-up and developmental approaches', 2008
Week 8
Bostrom, 'The superintelligent will: motivation and instrumental rationality in advanced
artificial agents', 2012
Week 9
Gabriel, 'Artificial intelligence, values, and alignment', 2020
MODULE 4: POLITICAL DIMENSIONS
Week 10
Danaher, 'The threat of algocracy: reality, resistance, and accommodation', 2016
Week 11
Benn & Lazar, 'What's wrong with automated influence?', 2022
Week 12
Christiano, 'Algorithms, manipulation, and democracy', 2022
LAW
The Artificial Intelligence Act (AI Act)
Regulation (EU) 2024/1689 (AI Act) is the world's first and most comprehensive law dedicated specifically to AI. It adopts a risk-based approach: it does not regulate the technology itself, but the use made of it, imposing rules proportionate to the potential harm to citizens.
GDPR (General Data Protection Regulation): Strictly regulates the use of personal data for model training. Article 22 grants citizens the right not to be subject to decisions based solely on automated processing (including profiling) if this produces significant legal effects.
Data Act and Data Governance Act: Aim to unlock industrial and public data in Europe, facilitating secure sharing among businesses to fuel AI training, while preventing the formation of data monopolies.
Product Liability Directive (PLD): Has been updated to explicitly include software and AI systems in the definition of a "product." It allows consumers to claim damages for physical injuries, psychological harm, or the destruction/loss of data caused by a defective AI.
Updated excerpts, articles, and supplementary materials will be
provided during the course, given the rapidly evolving regulatory
framework.
MODULE 1: MORAL AGENCY
Week 1
Floridi & Sanders, 'On the morality of artificial agents', 2004
Week 2
Wallach & Allen, 'Can (ro)bots really be moral?', 2008
Week 3
Wynsberghe & Robbins, 'Critiquing the reasons for making artificial moral agents', 2019
MODULE 2: MORAL RESPONSIBILITY
Week 4
Elish, 'Moral crumple zones: cautionary tales in human-robot interaction', 2019
Week 5
Hakli & Mäkelä, 'Moral responsibility of robots and hybrid agents', 2019
Week 6
Thoma, 'Risk imposition by artificial agents: the moral proxy problem', 2022
MODULE 3: VALUE ALIGNMENT
Week 7
Wallach & Allen, 'Top-down morality', 'Bottom-up and developmental approaches', 2008
Week 8
Bostrom, 'The superintelligent will: motivation and instrumental rationality in advanced
artificial agents', 2012
Week 9
Gabriel, 'Artificial intelligence, values, and alignment', 2020
MODULE 4: POLITICAL DIMENSIONS
Week 10
Danaher, 'The threat of algocracy: reality, resistance, and accommodation', 2016
Week 11
Benn & Lazar, 'What's wrong with automated influence?', 2022
Week 12
Christiano, 'Algorithms, manipulation, and democracy', 2022
LAW
The Artificial Intelligence Act (AI Act)
Regulation (EU) 2024/1689 (AI Act) is the world's first and most comprehensive law dedicated specifically to AI. It adopts a risk-based approach: it does not regulate the technology itself, but the use made of it, imposing rules proportionate to the potential harm to citizens.
GDPR (General Data Protection Regulation): Strictly regulates the use of personal data for model training. Article 22 grants citizens the right not to be subject to decisions based solely on automated processing (including profiling) if this produces significant legal effects.
Data Act and Data Governance Act: Aim to unlock industrial and public data in Europe, facilitating secure sharing among businesses to fuel AI training, while preventing the formation of data monopolies.
Product Liability Directive (PLD): Has been updated to explicitly include software and AI systems in the definition of a "product." It allows consumers to claim damages for physical injuries, psychological harm, or the destruction/loss of data caused by a defective AI.
Updated excerpts, articles, and supplementary materials will be
provided during the course, given the rapidly evolving regulatory
framework.
Assessment methods and Criteria
The procedures for administering and grading the final exam will be communicated to students during the first few classes. It is understood that the exams for both course modules (Ethics and Law) must be taken at the same time. The final grade will be the arithmetic mean (rounded up) of the grades obtained in the two modules, provided that a minimum grade of 18/30 is achieved in each of the two parts (that is, if you receive a 17 in the Law section and a 30 in the Ethics section, even though the average is 23.5, you will not pass the exam). If you reject the final grade, both parts must be retaken.
GIUR-17/A - Philosophy of Law - University credits: 3
PHIL-03/A - Moral Philosophy - University credits: 3
PHIL-03/A - Moral Philosophy - University credits: 3
Lessons: 48 hours
Professors:
Rossetti Andrea, Tanyi Attila Geza
Professor(s)