An HR manager at a trading company in Surabaya uses an AI-based recruiting tool to screen thousands of applications. The tool promises efficiency: only the best candidates proceed to interviews. After a few months, a pattern emerges: candidates from one age group and one gender always dominate the shortlist. Not because they were the best, but because the tool's training data contained historical bias — the company had indeed hired mostly from that group for years. The tool did not create the discrimination; it simply learned it from past data, then perpetuated it.
This story is not something we invented; patterns like this are documented in many countries, including Indonesia, as more companies use AI for decisions that touch human lives: who gets hired, who gets credit, who gets faster service.
The question is not whether Indonesian companies should use AI — the answer is clear: yes, because AI offers real efficiency gains. The question is how to use it responsibly. This article is a practical AI ethics guide for Indonesian companies: the core principles, the legal obligations, how to build governance, and the mistakes to avoid.
Why AI Ethics Is a Business Problem, Not Just Philosophy
There is a perception that AI ethics is an academic topic, not a practical concern. That perception is wrong, and it is becoming more obviously wrong every year. AI ethics is a business problem with real consequences on three fronts.
Front one: reputation and trust. A single case of discriminatory or misleading AI can go viral within hours. Companies using AI to deny insurance claims, charge different prices to different customers, or spread misinformation risk losing trust built over years. In the age of social media, this reputational damage arrives fast and is expensive to repair.
Front two: law and regulation. Indonesia now has the Personal Data Protection Law (UU PDP), which has come into full effect and governs how personal data must be managed. Most AI systems are trained on and run with personal data: names, phone numbers, shopping behavior, health histories. Using this data outside the legal framework risks administrative to criminal sanctions. Dedicated AI regulations are also being prepared in various countries, and the global trend shows oversight getting stricter, not looser.
Front three: decision quality. Biased AI or AI trained on poor data produces poor decisions, and companies pay for the consequences: credit given to customers who should have been rejected, products offered to people who do not need them, promising employees filtered out by a flawed screening system. AI ethics is ultimately about quality, not just morality.
Core AI Ethics Principles to Know
Around the world, various AI ethics frameworks have emerged, and while their authors differ, the core is consistent. The five principles below form a foundation usable by Indonesian companies of any size.
1. Transparency
Users, customers, and employees have the right to know when they are interacting with AI, and how that AI affects them. Transparency means: do not disguise a chatbot as a human, do not hide that a credit decision was made by an algorithm, and do not keep secret the criteria used to screen job applicants.
Transparency does not mean disclosing your entire codebase — that is neither possible nor necessary. It means honest explanation at an understandable level: what data this AI uses, for what purpose, and who is responsible for its outcomes.
2. Fairness and Non-discrimination
AI systems must not treat people unfairly based on age, gender, ethnicity, religion, social status, or other personal characteristics. The problem: bias often enters quietly through training data, like the recruiting example at the start of this article.
Fairness demands testing: before a system is deployed, test whether results differ suspiciously across groups. After deployment, monitor continuously, because new data can introduce new bias.
3. Accountability
AI cannot be held accountable; humans must be. Every AI system must have a clear owner: a person or team responsible for the system's decisions, who can answer when something goes wrong, and who has the authority to stop or fix the system.
A practical rule: if no one can answer "who is responsible if this system gets it wrong?", the system is not ready to deploy.
4. Data Privacy and Security
AI systems are data consumers, and that data is often personal. The privacy principle demands three things: collect only the data genuinely needed (minimization), store and process it with adequate security, and use the data only for purposes announced to the data owner.
In Indonesia, these three are no longer just ethics; they are legal obligations under the UU PDP.
5. Humans Keep Control
AI should strengthen human decisions, not replace them entirely, especially for decisions with major impact on people's lives. Credit decisions, recruitment, insurance claims, and employee termination should always have a human review path.
This principle also means humans must be able to overrule AI decisions when the system is clearly wrong. An "override the system's decision" button is the most important ethics feature.
UU PDP: Legal Obligations You Cannot Negotiate
AI ethics in Indonesia cannot be discussed without the UU PDP, because data is AI's fuel. The UU PDP governs how personal data is managed, and nearly every corporate AI system processes personal data in one form or another.
Key obligations relevant to AI systems:
- Lawful basis for processing. Personal data may not be processed without a clear legal basis: consent from the data owner, contract fulfillment, legal obligation, or a balanced legitimate interest. When AI processes data for a new purpose that was not announced, companies need a new basis.
- Minimization principle. Collect only the data necessary for the announced purpose. Do not collect data "just in case" or because "it might be useful later".
- Information transparency. Data owners have the right to know what data is collected, for what purpose, and with whom it is shared. An honest privacy statement is an obligation, not decoration.
- Data security. Companies must protect data confidentiality with adequate security measures. Data breaches caused by negligence carry sanction risks. This practice is closely related to website security, which we cover separately — many breaches start with systems that are never maintained.
- Data owner rights. Data owners have the right to access, correct, and request deletion of their data. Your AI systems must be able to fulfill these requests technically, not just on paper.
For companies using AI, the implications are concrete: every AI workflow involving customer data must be documented — what data, for what purpose, what legal basis, who has access. This documentation is what you will show if regulators ask.
Building AI Governance in Your Company
AI governance does not mean forming a new department with a large budget. For most Indonesian companies, it can start with simple things: a written policy, an oversight process, and a culture that values questions. Here is a staged framework.
Companies without an internal team handling this side can consider help from IT consultants to build governance that fits their business scale — without hiring full-time staff first.
Step 1: AI Usage Policy
Start with an internal policy document that answers basic questions:
- What AI may employees use, and for what? (For example: allowed for drafting, prohibited for recruitment decisions without human review.)
- What data may be entered into AI tools? (A critical rule: customer data must not be entered into public AI tools without a clear need and legal basis.)
- Who is responsible if an AI tool produces a harmful error?
This policy does not have to be perfect on day one; it must exist and be updated as AI usage grows. Many companies start with an employee AI policy, then expand to product policy.
Step 2: Risk Assessment Before Launch
Before an AI system is used for impactful decisions, conduct a simple risk assessment:
- What data is used? Does it include personal or sensitive data?
- What is the worst case if the system errs? (Wrong product recommendations vs. wrongly denying credit are different levels.)
- How could bias enter, and how do we test for it?
- Who reviews system decisions, and how often?
- How can system decisions be explained to affected people?
The higher the impact, the stricter the assessment. AI for non-sensitive internal tasks can run with light oversight; systems touching customers need thorough review.
Step 3: Continuous Monitoring
Launch is not the end. AI systems behave differently in the real world than in testing: data changes, users find loopholes, and new patterns emerge. Schedule periodic reviews: compare system decisions with actual outcomes, look for diverging patterns, and update the system or stop it if serious problems appear.
Keep documentation of important decisions: why the system was built, what data was used, what testing was done, and what decisions were made during oversight. Documentation is both evidence and a learning tool.
Step 4: Complaint Mechanism
People affected by AI decisions must have a channel to question the outcomes. Job applicants rejected by a recruiting system, customers whose credit was denied by an algorithm, customers whose service was slowed by AI — they deserve an explanation and a chance for human review.
A complaint mechanism does not just protect consumers; it protects the company from undetected wrong decisions.
Common Mistakes to Avoid
In the field, we often see recurring mistake patterns. Recognize and avoid them.
Assuming "AI is more objective". AI is free of emotion, but not free of bias — bias embedded through training data. A recruiting tool trained on the company's historical data inherits its historical preferences. Objective AI is a myth; AI that is tested and monitored is what can be trusted.
Using data without permission for new purposes. Customer data collected for service A gets used to train AI for service B without telling customers. This is an ethics violation and a UU PDP violation. Always ask: has this new purpose been announced, and does it have a legal basis?
Overpromising to customers. Marketing AI features with exaggerated claims — "100 percent accuracy", "error-free" — builds expectations that will certainly break. Being honest about system limitations is part of AI marketing ethics.
Ignoring environmental impact. Large AI models consume significant energy. At Indonesian company scale, the impact may be small, but the principle remains: calculate whether AI's benefits justify its computing costs, and choose efficient models.
No human oversight. An AI system running without human review is an accident waiting to happen. Important decisions always need a human path.
AI Ethics for Small and Medium Businesses
AI ethics discussions often feel focused on large companies, yet SMEs and mid-sized companies are increasingly heavy AI users: chatbots, customer analytics, marketing automation. The good news: ethics principles do not require a special department to apply.
For small and mid-sized scales, the practical translation is simple:
- One person appointed as responsible for AI usage in the company, even if it is part of their other duties.
- A one-page policy document on what may and may not be done with AI.
- One golden rule: customer data is not entered into public AI tools without a clear need and legal basis.
- One habit: before launching any AI feature, ask "who could be harmed, and how do we prevent it?"
AI ethics is not about company size; it is about discipline. A disciplined small company can maintain quality more easily than a large company struggling to coordinate thousands of employees.
Ethics in Development: The Builder's Responsibility
Companies that build or commission AI systems carry special responsibility. If you commission an AI system from a vendor, make sure your contract answers ethics questions:
- Who owns the data and the resulting model?
- What data was used to train the model, and where did it come from?
- Who is responsible if the system produces a harmful decision?
- Can the system be audited and explained?
- How can the system be stopped or replaced if needed?
A vendor reluctant to answer these questions is a red flag. An AI system purchased without understanding how it works is a liability you inherit without realizing it.
Before choosing a vendor, it is also important to understand the difference between custom software and off-the-shelf packages: custom systems give you full control over data and logic, while packaged products are often black boxes. For sensitive AI uses, this control is worth more than flexibility alone.
The Future of AI Regulation in Indonesia
Global AI regulation is moving fast. The European Union has enacted the AI Act, which classifies AI systems by risk and imposes different obligations on each class. Southeast Asian countries, including Indonesia, are also formulating their own AI regulatory frameworks, with various national policy initiatives being prepared by the government.
The direction is clear: AI ethics compliance will increasingly become a condition for operating, not just a value-add. Companies that build good AI governance practices now will not panic when regulation arrives — they are already ahead.
The principle we recommend: build ethical AI practices not because regulation forces you, but because it is sound business. Transparent, fair, and supervised systems produce better decisions, protect reputation, and prevent large costs down the road.
AI Ethics in Daily Practice
AI ethics does not always take the shape of big decisions; often it is the small decisions made every day. Here are concrete examples.
Customer emails. Is your system auto-replying to customer emails with AI? Make sure customers know they are communicating with a system, and give them a path to talk to a human. This is transparency in its smallest form — and it also prevents disappointment when a system answer does not satisfy.
Content creation. Is your marketing team using AI to write? Make sure there is human review before content is published, because AI can produce claims that are wrong or inaccurate. You are responsible for that content, not the tool. A simple policy — "AI may help, humans approve" — prevents a lot of reputational problems.
Data entry. Are employees entering customer data into public AI tools to speed up their work? Set clear rules about what data may and may not be entered. A single incident of customer data entering a third-party system without a legal basis is one UU PDP violation, regardless of good intentions.
Employee evaluation. Is there a system that assesses employee performance? Make sure the system is an aid, not a replacement for human judgment, and that employees know the evaluation criteria. Employees who do not know why they were rated poorly will lose trust in the process.
The pattern in all these examples is the same: AI helps, humans decide. Every time your workflow uses AI, ask one question: at what point does a human review, and can the affected person raise an objection? If both answers are clear, your ethical practice is on the right track.
Frequently Asked Questions
Do small businesses have to comply with AI ethics? The legal obligations of the UU PDP apply to the processing of personal data, regardless of business scale. Ethics principles are also not a burden; they prevent losses that are actually bigger for small businesses without a thick reputation buffer.
Does buying AI from a vendor free us from ethical obligations? No. The vendor provides the technology, but you are the one using it for decisions that matter. Responsibility stays with the user. That is why you should understand the systems you buy and ask the questions covered in the builder's responsibility section.
Does AI ethics slow down innovation? Actually the opposite. Systems that are transparent and supervised are easier to improve, develop, and trust. Regulations that arrive later will also be easier to satisfy for companies that already have good practices.
Who should handle AI ethics in our company? For a small company, one designated person is enough. For a larger one, combine people from legal, technology, and business sides. What matters is not the job title, but having someone who can answer when questions arise, with the authority to stop a system that causes harm.
Your First Step
AI ethics can feel like a big topic, but the first steps are small. Start this week with three things:
- Inventory. List every place in your company that uses AI: chatbots, recruiting tools, marketing automation, data analytics. You cannot govern what you do not know about.
- Pick one system. Take the AI system with the most impact on customers or employees and evaluate it against the five principles: transparent, fair, accountable, data-protective, human-controlled. Note what is missing.
- Write a one-page policy. Basic AI usage rules for the whole company: what is allowed, what is prohibited, who is responsible.
Perfection is not required. What matters is starting, then improving as you go.
The Kartech team in Bandar Lampung helps companies build responsible AI systems from initial design: data risk identification, transparent design, and governance matched to your business scale. We believe the best AI is the AI you can be accountable for. Discuss your needs through the contact page or explore our services.
AI is a remarkable tool, but like all tools, the quality of its output is determined by the hand holding it. AI ethics is not a limit on innovation; it is the foundation that lets innovation last.