Ethics at the Edge: Trust, AI, and the Future of Digital Safety


Introduction: When Safety Becomes Intelligent
We are entering a new era of safety.
For decades, security largely depended on human eyes, physical guards, alarms, locks and conventional cameras. Today, those systems are being connected to Artificial Intelligence, cloud platforms, sensors, facial recognition, Internet of Things devices and automated decision-support systems.
A camera can now do more than record an event. An intelligent system can identify unusual movement, detect a possible intrusion, recognize a developing fire, monitor a restricted area or alert security personnel before a situation becomes a major incident.
But this progress creates an important question:
If technology becomes powerful enough to watch, predict and respond, who watches the technology?
That is where the real conversation about digital safety begins.
The central challenge of 2026 is no longer simply how to make technology smarter. It is how to make technology trustworthy.
NIST’s current AI-risk work increasingly emphasizes trustworthy AI, and in April 2026 it released a concept note specifically addressing trustworthy AI in critical infrastructure. Its framework focuses on characteristics such as reliability, safety, security, accountability, transparency, privacy and fairness.
Therefore, the future of safety should not be defined by one question—“Can AI do it?”
The better question is:
“Should AI do it, under what conditions, and who remains responsible when it gets it wrong?”
- Smart Surveillance: Where Should We Draw the Privacy Line?
Surveillance is not automatically unethical.
A camera at the entrance of a bank, airport, factory or sensitive facility may protect people. A system that detects an unauthorized person entering a restricted area can prevent a crime. Video analytics may help identify dangerous situations faster than a human operator watching dozens of screens.
The problem begins when surveillance changes from protecting a specific place for a specific purpose into continuously analyzing everyone for purposes they were never told about.
That distinction is fundamental.
A responsible surveillance system should answer five simple questions:
- Why are we collecting this information?
- What exactly are we collecting?
- How long will we keep it?
- Who can access it?
- What happens if the system makes a mistake?
If nobody can answer those questions clearly, the technology may be advanced—but the governance is weak.
The new danger is not only the camera
The traditional CCTV camera records.
AI surveillance can interpret.
That is a major difference.
A conventional camera may show that a person entered a building. An AI system may attempt to infer who the person is, where they have been, what they are doing, whether their behavior appears unusual and possibly whether they represent a threat.
That creates a much deeper privacy issue.
AI can also increase the ability to re-identify individuals and amplify behavioral tracking, concerns explicitly recognized by NIST in its current work on AI, cybersecurity and privacy.
Therefore, the principle should be:
Collect the minimum information necessary to achieve a legitimate safety objective—not the maximum information technology makes possible.
That is a very important distinction for the future.
- Facial Recognition: Identification Is Not the Same as Suspicion
Facial recognition can be useful, but it should never be treated as an infallible truth machine.
There is a difference between:
“The system has identified a possible match.”
and
“This person is guilty.”
Those statements are not equivalent.
An AI model produces an output. A human institution makes a decision.
That distinction becomes especially important in law enforcement, airports, public spaces, workplaces and other sensitive environments.
The European Union’s AI Act provides a useful illustration of where modern regulation is heading. Certain biometric applications—including remote biometric identification—are classified as high-risk, while particular uses of real-time remote biometric identification in publicly accessible spaces are subject to strict conditions and safeguards.
The more powerful the technology, the stronger the accountability must become.
A sensible system should therefore include:
- human review of consequential decisions;
- documented reasons for using biometric technology;
- strict access controls;
- audit logs;
- defined retention periods;
- testing for accuracy and bias;
- independent evaluation;
- mechanisms for correcting false identification.
The goal should not be to eliminate technology.
The goal should be to prevent technology from becoming an unquestionable authority.
- Bias: The Algorithm Can Inherit Our Mistakes
One of the most misunderstood issues in AI is bias.
People sometimes imagine that computers are automatically objective because they use mathematics.
They are not.
An AI system learns from data, and data reflects the world from which it came.
If the training data is incomplete, unbalanced or poorly designed, the system can reproduce those weaknesses at enormous scale.
This is particularly sensitive in facial recognition and behavioral analysis.
A human mistake may affect one decision.
An automated mistake can potentially affect thousands of people before anyone notices.
That is why responsible AI requires testing—not just demonstration.
A vendor should not simply say:
“Our system is AI-powered.”
The more important questions are:
How accurate is it? Under what conditions? Against which populations? How often does it produce false positives? How was it independently tested?
The modern security industry needs to move from technology marketing to evidence-based assurance.
NIST’s AI Risk Management Framework emphasizes evaluation across the AI lifecycle and characteristics such as validity, reliability, safety, security, transparency, explainability, privacy and fairness.
- The Human in the Loop: AI Should Assist, Not Become the Judge
One of the most important principles for AI-enabled safety is the human in the loop.
Imagine an intelligent fire detection system.
The AI sees something unusual.
It detects smoke-like patterns.
It analyses heat.
It compares the situation with previous incidents.
It sends an alert.
This is valuable.
But imagine a system that automatically makes a high-consequence decision based on an uncertain interpretation without human verification.
That is where risk increases.
The same principle applies to access control, security alerts, emergency response and law enforcement.
AI is exceptionally good at processing enormous amounts of information quickly.
Humans remain essential for:
- context;
- judgment;
- accountability;
- ethical reasoning;
- understanding unusual situations;
- deciding proportional responses.
The best model is therefore not:
Human versus AI.
It is:
Human + AI + clear responsibility.
AI should reduce human overload—not remove human responsibility.
- AI in Fire and Life Safety: Speed Matters, But Reliability Matters More
Fire safety is one of the most promising areas for intelligent technology.
A conventional detection system waits for specific physical conditions to reach a detection threshold.
Modern video-based systems can potentially identify visible indicators of fire at an earlier stage, particularly in environments where traditional detection may have limitations.
International standards already recognize video fire detection as a serious safety technology. ISO 7240-29:2024 specifies requirements, testing methods and performance criteria for video fire detectors used in and around buildings.
This is important because AI-based fire detection should not be viewed merely as a futuristic concept.
It is becoming part of a broader evolution in fire protection.
NFPA was discussing the growing role of AI in fire protection engineering at its 2026 conference, reflecting how quickly this subject is moving from theory into professional practice.
But there is a critical warning:
An AI fire system must not confuse intelligence with certainty.
Smoke, steam, dust, sunlight, reflections, industrial processes and other environmental conditions can create complex visual patterns.
A false alarm can cause disruption.
A missed alarm can cost lives.
Therefore, AI should ideally work as part of a layered safety architecture rather than becoming the only line of defence.
For example:
Camera + AI analytics + conventional detection + alarm system + trained personnel + emergency procedures
is generally a more resilient philosophy than:
Camera + AI = complete fire safety.
Technology should add another layer of protection—not remove the layers that already exist.
- The Most Dangerous Myth: “AI Is Always More Reliable Than Humans”
AI is fast.
AI can process huge quantities of information.
AI does not get tired in the same way a human monitoring operator does.
But AI can also fail in ways humans do not expect.
A model can be confused by unusual conditions.
A sensor can malfunction.
A network can go down.
A software update can introduce a problem.
A cyberattack can manipulate data.
And an operator can misunderstand the AI’s recommendation.
Therefore, safety systems must be designed around failure, not only success.
The right engineering question is not:
“What happens when everything works?”
It is:
“What happens when the AI is wrong, the network is unavailable, the sensor fails, the power goes out, or the system is attacked?”
That is the difference between an impressive demonstration and a genuinely resilient safety system.
- Cyber-Physical Security: When a Cyberattack Becomes a Physical Threat
This is perhaps the most important emerging issue.
In the past, cybersecurity and physical security were often treated as separate disciplines.
That separation is becoming increasingly artificial.
Today, a digital command can operate a physical door.
A network can control a building management system.
An IoT device can communicate with access-control equipment.
A smart alarm can be connected to a cloud platform.
A connected fire system may exchange information with other digital infrastructure.
This means a cyberattack may no longer simply steal information.
It may change the physical environment.
CISA and international partners have warned that increasing connectivity in operational technology and cyber-physical systems can create pathways for attackers, with consequences that can include operational disruption and risks to health and safety.
This gives us a new definition of cybersecurity:
Cybersecurity is no longer only about protecting data. In a connected physical world, it is also about protecting people and physical processes.
- The Smart Door Problem
Consider a smart door.
It may have:
- an electronic lock;
- a camera;
- facial recognition;
- mobile access;
- cloud connectivity;
- remote administration;
- event logging.
It looks highly secure.
But every additional connection can create another potential attack surface.
If an attacker compromises the cloud account, the problem may become physical.
If an attacker compromises the network, the problem may become physical.
If credentials are stolen, the problem may become physical.
So the question is not:
“Is this door smart?”
The question is:
“Is this entire chain secure?”
That chain includes hardware, software, network infrastructure, authentication, cloud services, administrators, suppliers and human users.
Security is only as strong as the weakest important link.
- The New Security Architecture: IT + OT + Physical Security
The old model separated security into three boxes:
IT Security
Physical Security
Operational Technology
The future requires these disciplines to work together.
A modern security team should understand that a cyber incident can become a physical incident—and a physical compromise can become a cyber incident.
CISA’s guidance on cybersecurity and physical-security convergence describes this growing overlap and the expanding attack surface created by interconnected cyber-physical systems.
This means organizations need:
- network segmentation;
- strong identity and access management;
- secure device configuration;
- continuous monitoring;
- secure software updates;
- asset inventories;
- incident-response plans;
- offline or manual fallback procedures;
- regular testing;
- supplier and third-party risk management.
Most importantly, organizations need to know what is connected to what.
You cannot secure an unknown device.
- Bangladesh: A Particularly Important Conversation
For Bangladesh, this discussion is not theoretical.
The country is rapidly digitizing buildings, businesses, public services, transportation, financial services and industrial operations.
As connectivity increases, the potential benefits increase—but so does the responsibility to protect data, systems and citizens.
Bangladesh’s draft National AI Policy 2026–2030 discusses issues including privacy, security, data governance, interoperability, data minimization and protection against unauthorized access and AI-related security risks. It also proposes stronger mechanisms for responsible data exchange and governance.
It is important to describe this accurately: the document is a draft policy, not something that should automatically be described as settled law.
But its direction is significant.
For Bangladesh, the goal should not be to copy another country’s technology model.
The goal should be to develop a Bangladesh-appropriate model of responsible digital safety—one that considers local infrastructure, legal institutions, technical capacity, cost, climate, population density and public expectations.
- Privacy Should Not Be the Enemy of Security
There is a dangerous false choice in public debate:
Either we have privacy, or we have security.
That is not necessarily true.
Good engineering can pursue both.
For example, organizations can consider:
- data minimization;
- encryption;
- access restrictions;
- anonymization where appropriate;
- short retention periods;
- purpose limitation;
- audit trails;
- privacy-preserving analytics;
- human review;
- independent oversight.
The objective is not to collect everything and promise to protect it later.
The objective is to ask:
“Do we need to collect this information at all?”
That question is becoming increasingly important in the age of AI.
- A New Principle: Safety by Design, Privacy by Design, Security by Design
The old approach was often:
Build first. Secure later.
That approach is becoming unacceptable for connected safety systems.
We should instead think in three layers from the beginning:
Safety by Design
The system should be designed to reduce physical harm and continue functioning safely when components fail.
Privacy by Design
Personal information should be minimized, protected and used only for legitimate purposes.
Security by Design
Cybersecurity should be built into architecture, hardware, software and procurement—not added after deployment.
These three principles should work together.
A system that is safe but violates privacy is not fully trustworthy.
A system that protects privacy but can easily be hacked is not safe.
A system that is secure but produces unreliable safety decisions is also not sufficient.
Trust requires all three.
- The Question Every Technology Buyer Should Ask
Before purchasing an AI-powered surveillance, fire or access-control system, organizations should ask vendors more than:
“What features do you have?”
They should ask:
- What happens when the AI is wrong?
- How is accuracy measured?
- What independent testing has been performed?
- What data is collected?
- Where is the data stored?
- Who can access it?
- How long is it retained?
- Can the organization operate if the cloud connection fails?
- What happens during a cyberattack?
- Can the system fail safely?
- How are software updates secured?
- Can the organization change vendors without losing control of its data?
- What logs are maintained?
- Who is accountable for a wrong decision?
- What is the manual fallback procedure?
These questions are more valuable than simply asking how “smart” the product is.
- The Future Will Not Be “AI Everywhere”
The future should be:
AI where it creates measurable value,
human judgment where judgment matters,
privacy where personal information is involved,
and
strong security wherever technology can affect the physical world.
This is a more mature vision of digital transformation.
Technology should not be deployed merely because it is available.
It should be deployed because there is a clear problem to solve—and because the benefits justify the risks.
- The Most Important Ethical Rule
Perhaps the simplest rule for the future of digital safety is this:
The more power we give a technology, the more accountability we must build around it.
If AI only recommends something, the risk is one level.
If AI controls access, the risk increases.
If AI controls a fire-response mechanism, the stakes increase further.
If AI influences law-enforcement decisions or determines whether a person is treated as a security threat, the requirement for safeguards becomes even stronger.
In other words:
Risk should determine governance.
The higher the potential consequence of an error, the greater the need for testing, transparency, human oversight and accountability.
- Five Principles for the Future of Digital Safety
If I had to reduce the entire discussion to five principles, they would be:
- Protect people, not just systems.
The ultimate purpose of security is human safety and dignity.
- Use the minimum necessary data.
More data does not automatically mean better security.
- Keep humans responsible for high-impact decisions.
AI can advise; responsibility must remain clearly assigned.
- Design for failure and attack.
A safety system is tested not when everything works, but when something goes wrong.
- Measure trust, not just performance.
A system should be judged by accuracy, reliability, privacy, security, transparency and accountability—not by how impressive its technology sounds.
Conclusion: The Future We Should Build
The next generation of digital safety will be extraordinarily powerful.
Cameras will become more intelligent.
Buildings will become more connected.
Fire detection will become more analytical.
Doors and access systems will become more automated.
AI will increasingly help security teams understand enormous quantities of information in real time.
But technological capability alone does not create safety.
Trust creates safety.
And trust cannot be programmed into a machine at the last minute.
It must be designed into the entire system—from the first line of code to the final human decision.
The future should not be a world where technology watches everyone.
Nor should it be a world where humans blindly trust machines.
The better future is a world where technology helps humans see danger earlier, respond faster and protect lives more effectively—while strong ethical rules ensure that the same technology does not quietly undermine privacy, freedom or human dignity.
That is the real meaning of digital safety.
It is not simply the ability to detect more.
It is the ability to protect better, fail safely, respect people and remain accountable.
And perhaps the most important question for the coming decade is therefore not:
“How intelligent can our security systems become?”
It is:
“How intelligently can we govern the power we are giving them?”
That is where the future of trustworthy AI—and the future of digital safety—will ultimately be decided.
…
With Thanks,
Saadi Shohid
References
- National Institute of Standards and Technology (NIST). (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0).S. Department of Commerce. NIST AI 100-1. https://doi.org/10.6028/NIST.AI.100-1
- National Institute of Standards and Technology (NIST). (2026). AI RMF Profile on Trustworthy AI in Critical Infrastructure: Concept Note.S. Department of Commerce.
- Government of the People’s Republic of Bangladesh. (2026). National Artificial Intelligence Policy of Bangladesh 2026–2030: Draft V2.0. ICT Division / National AI Policy Committee, Bangladesh.
- European Union. (2024). Regulation (EU) 2024/1689: Artificial Intelligence Act. Official Journal of the European Union.
- (2021). Recommendation on the Ethics of Artificial Intelligence. United Nations Educational, Scientific and Cultural Organization, Paris.
- (2024). OECD AI Principles. Organisation for Economic Co-operation and Development.
- International Organization for Standardization (ISO). (2024). ISO 7240-29:2024 — Fire detection and alarm systems — Part 29: Video fire detectors.
- Cybersecurity and Infrastructure Security Agency (CISA) / Interagency Security Committee. (2022). Security Convergence: Achieving Integrated Security.S. Department of Homeland Security.
- (2023). Artificial Intelligence Risk Management Framework Playbook. National Institute of Standards and Technology.
- (2024). Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.AI.600-1



