Internet Security Auditors Blog

Impact Assessment of Artificial Intelligence Systems

Written by María Alejandra Cuervo | Jul 27, 2026 9:02:34 AM

Fairness, Human Rights, Accessibility and Social Impact under ISO/IEC 42001:2023

Information security programs have matured for more than two decades around a relatively stable perimeter: confidentiality, integrity, and availability. The accelerated adoption of artificial intelligence (hereinafter, AI) introduces a different risk surface, which cannot be addressed solely through technical controls. AI systems make or influence decisions about real people—personnel selection, credit scoring, criminal justice, clinical diagnosis, content moderation—which shifts part of organizational risk from the technical sphere to the sphere of impact on individuals, groups, and societies.

In December 2023, the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) published ISO/IEC 42001:2023, the first certifiable international standard for Artificial Intelligence Management Systems (hereinafter, AIMS). Just as ISO/IEC 27001 did for information security, it adopts the harmonized structure of management systems, making it easier to integrate into existing GRC (Governance, Risk, and Compliance) programs.

ISO/IEC 42001:2023 requires assessing the impact on people, groups, and society, with a focus on three dimensions explicitly identified in the standard—fairness, human rights, and accessibility—as well as social impacts that must also be documented: employment, democratic processes, and the environment. The standard even dedicates Annex A.5 to impact assessment controls and Annex B.5 to implementation guidance. Control A.5.2 requires a process to assess the potential consequences of AI systems throughout their lifecycle, distinguishing two levels: impact on individuals or groups of individuals (A.5.4) and social impact (A.5.5). Functionally, it operates as a specialized risk register that feeds the general risk management process (6.1.2) with a type of impact that a traditional security risk register does not capture by default.

The standard requires (B.5.2) consideration of whether the system affects: the individual's legal position or life opportunities; physical or psychological well-being; universal human rights; and, at a second level, societies as a whole.

According to ISO/IEC 24001:2023, an AI System Impact Assessment is defined in terms and definitions clause 3.24 as a formal process through which the impacts that an AI system may generate on individuals, groups, and societies are identified, assessed, and treated. Unlike other management controls, its starting point is not risk to the organization, but rather the question of who may be affected and in what way: Does this system limit access to opportunities? Does it violate rights? Does it exclude certain groups? Its results are input for subsequent risk analysis, but its value lies in making the human, social, and environmental impact of the system visible before it is deployed.

Thus, for example, in April 2026 Anthropic announced Claude Mythos Preview, its most advanced model for programming and agent tasks, which demonstrated an unusual ability to autonomously identify and chain zero-day vulnerabilities in operating systems, browsers, and critical open-source software, including a 27-year-old flaw in OpenBSD. Rather than releasing it generally, Anthropic decided to grant controlled access, initially to around 50 organizations—including AWS, Apple, Google, Microsoft, Cisco, CrowdStrike, JPMorganChase, NVIDIA, Palo Alto Networks, and the Linux Foundation—responsible for maintaining software on which billions of end users depend. Weeks later, access was expanded to approximately 150 additional organizations in more than 15 countries, including sectors such as energy, water, healthcare, and telecommunications.

Anthropic's decision reflects, in practice, the type of analysis required by an impact assessment: before defining the access model, the organization had to ask who might be affected and how. The first obvious impact concerned the rights and security of millions of people: a model capable of autonomously finding and chaining vulnerabilities in systems used daily by everyone could, in the wrong hands, become a tool for massive and indiscriminate harm. However, the impact was not limited to individuals. Anthropic also identified social-scale consequences: the uncontrolled proliferation of these capabilities could have severe effects on economies and on entire employment sectors that depend on secure digital infrastructure, and represented a direct threat to the stability of democratic states, which is why the organization maintained active discussions with the U.S. government regarding its national security implications. There was also an access tension: the same model that could cause harm was also the most powerful tool available for defense, raising the question of who should have access first and under what conditions, knowing that those excluded during the initial phase would be temporarily disadvantaged. The combination of all these impacts—on people, the economy, democratic processes, and fairness in access to protection—led Anthropic to choose a gradual and controlled deployment rather than immediate general availability.

The previous case illustrates how impact assessment is not a theoretical exercise, but rather a governance decision with real consequences. The following sections develop the six impact dimensions that the standard explicitly requires organizations to analyze: the three that directly affect individuals and groups—fairness, human rights, and accessibility—and the three social dimensions—the effects on employment, democratic processes, and the environment. Each raises different questions, requires different evidence, and may involve different stakeholders, but all share a common denominator: they must be assessed before system deployment, documented, and reviewed throughout the system lifecycle.

1. Fairness: From Access Control to Bias Control

Fairness appears in the standard as an organizational objective (C.2.5) and as a central dimension of impact assessment (B.5.4): “the inappropriate application of AI systems for automated decision-making can be unfair to specific individuals or groups.” Algorithmic bias can be treated, in risk management terms, similarly to a vulnerability: it has a root cause (data, architecture, or decision-making process), an exploitation vector (large-scale automated decisions), and measurable impact.

There is no single definition of fairness: demographic parity, equality of opportunity, calibrated equality, and individual fairness are metrics that may conflict with one another, and it is mathematically impossible to satisfy all of them simultaneously. The standard requires (B.6.1.2) that fairness be integrated from the design stage—requirements, data, training, validation—rather than as a subsequent verification. Control B.7.4 further requires adjusting the model and data until bias is acceptable for the use case, while A.8.3 requires enabling a channel through which third parties can report lack of fairness as an adverse impact.

The Office of the United Nations High Commissioner for Human Rights (OHCHR) has documented that biased datasets can produce discriminatory decisions, with greater risk for marginalized groups; in 2021, then High Commissioner Michelle Bachelet called for a ban on AI applications incompatible with international human rights law. Documented cases of bias in facial recognition, hiring, and criminal risk assessment create legal and reputational exposure and increase the level of due diligence expected from any organization deploying similar systems.

Examples include:
▪️An assessment of a recruitment system would examine whether the advancement rate of female candidates to the next stage is comparable to that of male candidates with equivalent qualifications.
▪️An assessment of a credit scoring system would review whether approval rates vary unjustifiably across postal codes or ethnic groups, a form of indirect discrimination known as algorithmic redlining.
▪️An assessment of a patient triage system would evaluate whether recommended waiting times systematically differ according to patient age or language beyond what is clinically justified.

2. Human Rights: A New Asset to Protect

The standard places human rights among the dimensions that every impact assessment must analyze (B.5.2), requiring organizations to identify which rights may be affected and adopt mitigation measures.

UNESCO’s Recommendation on the Ethics of Artificial Intelligence (2021) requires systems to respect, protect, and promote human rights. The OHCHR has identified significant impacts on privacy, health, education, freedom of movement, assembly, and expression.

The standard requires special attention to vulnerable groups—children, persons with disabilities, older people, and workers (B.5.4)—and explicitly identifies criminal justice and financial services as areas where AI can reinforce historical biases or alternatively improve access to services.

Examples include:
▪️A recidivism risk assessment system affecting the right to equal treatment under the law by assigning higher scores to people from specific neighborhoods or socioeconomic backgrounds.
▪️A content moderation system affecting freedom of expression by disproportionately removing content from certain linguistic or political groups.
▪️A biometric identity verification system affecting privacy and non-discrimination where error rates are higher for individuals with certain skin tones.

3. Accessibility: A Design Requirement, Not a User Experience Feature

Accessibility appears both among responsible-use objectives (B.9.3) and among impact dimensions (B.5.4), because an AI system can either widen or reduce access gaps depending on how it is designed. The standard requires that user information be accessible and easy to find (B.8.2), and that design include usability and controllability (B.6.1.3).

An inaccessible system has a double negative effect:

▪️It directly excludes people who cannot use it.
▪️It increases operational risk because users who do not understand the system
      properly tend to operate it incorrectly, generating more misuse incidents.

Accessibility combines three dimensions: functional (use by persons with disabilities on equal terms), cognitive (easy understanding for different educational levels), and economic (ensuring that the cost of access does not exclude communities with limited resources). The standard also links this to the diversity of the team that develops the system (B.4.6).

In this regard, the following accessibility assessment cases could be presented for systems that implement AI:
▪️An accessibility assessment of a virtual customer service assistant would review whether the system is compatible with screen readers and whether it offers alternatives for persons with visual or motor disabilities.
▪️An assessment of a government services system would evaluate whether the interface is understandable for people with low levels of digital literacy or who do not master the predominant language of the platform.
▪️An assessment of an AI-powered healthcare application would examine whether its use depends on a high-end smartphone or constant connectivity, which would effectively exclude communities with more limited access to technology or broadband internet.

4. Social Impacts That Must Be Included in the Risk Register

Annex A.5.5 (with guidance in B.5.5) is the core of the standard’s social approach: it recognizes that AI’s social impacts may be beneficial or harmful and requires documentation of those impacts.

4.1 Employment
The standard requires documenting effects on employment and workforce skills (B.5.3) as part of economic impact (B.5.5).

An employment impact assessment would examine, for example, how many first-level customer service positions could be absorbed by a conversational assistant and what happens to affected personnel: reassignment, retraining, or separation. The analysis must be documented along with mitigation strategies.

It would also evaluate whether introducing an AI system changes the competencies required of employees who remain in their roles—for example, shifting from directly resolving customer issues to supervising and correcting AI-generated responses.

4.2 Democratic Processes
The standard explicitly notes that AI has been used to influence elections and create disinformation—including deepfakes—with the potential for political and social unrest (B.5.5).

An impact assessment on democratic processes would examine whether an image or voice generation model could be used to create false content attributed to a political candidate shortly before an election, and what provenance or watermarking controls exist to mitigate that risk.

It would also assess whether a news recommendation algorithm increasingly presents users with a homogeneous view of reality, reducing exposure to diverse perspectives and hindering informed public debate.

4.3 Environment
ISO/IEC 42001:2023 requires (clause 4.1) that the organization determine whether climate change is a relevant issue for its management system, a provision without precedent in previous technology management standards. The standard identifies environmental sustainability—natural resources and emissions—as a category of social impact (B.5.5), recognizing that AI can be computationally intensive.

The evidence supports the urgency: the International Energy Agency (IEA) estimated the electricity consumption of data centers at 415 TWh in 2024 (1.5% of global consumption), with a projection of 945 TWh by 2030, driven largely by AI. A study published in Patterns (Cell Press, ScienceDirect, 2025) estimated the carbon footprint of AI systems at between 32.6 and 79.7 million tonnes of CO₂ in 2025, and their water footprint at between 312.5 and 764.6 billion liters. This demonstrates that environmental impact is becoming increasingly significant, both in terms of electricity consumption and carbon footprint.

For this reason, an environmental impact assessment may examine, for example, how much energy and water are consumed in training or operating an in-house model compared with using one already trained by an external provider, and where that energy originates from. It could also evaluate whether, for a specific task—such as classifying emails or summarizing documents—a smaller and more efficient model delivers a result equivalent to that of a large-scale model while requiring significantly lower computational consumption and therefore having a lower environmental impact, a decision that should be documented along with its technical and cost criteria.

5. Conclusions

ISO/IEC 42001:2023 largely speaks the language that security and compliance functions already understand: controls, documented evidence, internal audit, and management review. What changes is the universe of risks that must be covered. Fairness, human rights, and accessibility are not statements of good intent: they are design criteria that are enforceable and auditable. The same requirement extends to employment, democratic processes, and the environment, which must be documented and periodically reviewed rather than assessed only once before launch.

For security teams, the practical message is straightforward: the risk register must be expanded to cover these impacts, and the assessment required by the standard provides the structure to do so without building a parallel compliance process. Organizations that implement the standard rigorously will be better positioned not only to avoid sanctions, but also to maintain the trust that customers, employees, and regulators place in the responsible use of AI.

Referencias
🔗ISO/IEC 42001:2023. Information technology — Artificial intelligence — Management system. ISO/IEC. Ginebra, diciembre 2023.
🔗ISO/IEC 23894:2023. Information technology — Artificial intelligence — Guidance on risk management. ISO/IEC. Ginebra, 2023.
🔗UNESCO. Recommendation on the Ethics of Artificial Intelligence. París, noviembre 2021.
🔗OHCHR. The right to privacy in the digital age. A/HRC/48/31. Naciones Unidas, 2021. https://www.ohchr.org
🔗UN News. Urgent action needed over artificial intelligence risks to human rights. Septiembre 2021. https://news.un.org/en/story/2021/09/1099972
🔗OECD. Principles on Artificial Intelligence. 2019 (revisados 2024). https://oecd.ai/en/ai-principles
🔗Reglamento (UE) 2024/1689 (Reglamento de Inteligencia Artificial / EU AI Act). 🔗Diario Oficial de la Unión Europea, 12 de julio de 2024.
🔗OECD (2023). OECD Employment Outlook 2023: Artificial intelligence and the labour market. OECD Publishing, París. https://doi.org/10.1787/08785bba-en
🔗Lane, M., Williams, M. y Broecke, S. (2023). The impact of AI on the workplace: Main findings from the OECD AI surveys of employers and workers. OECD Working Papers No. 288.
🔗International Energy Agency (2025). Energy and AI / Global Energy Review: Data Centres and Energy. IEA. https://www.iea.org
🔗De Vries-Gao, A. (2025). The carbon and water footprints of data centers and what this could mean for artificial intelligence. Patterns, Cell Press. https://doi.org/10.1016/j.patter.2025.100278
🔗Anthropic. Expanding Project Glasswing. Mayo 2026. https://www.anthropic.com/news/expanding-project-glasswing
🔗CyberScoop. Anthropic expanding access to Project Glasswing. Junio 2026. https://cyberscoop.com/anthropic-project-glasswing-expansion-critical-infrastructure-claude-mythos/
🔗CNBC. Anthropic expands Mythos to 150 additional organizations in more than 15 countries. Junio 2026. https://www.cnbc.com/2026/06/02/anthropic-mythos-ai-project-glasswing.html