Step 4: Review
Review extracted entities and commit to OntServe
Commit to OntServe
Phase 2A: Code Provisions
code provision reference 5
Hold paramount the safety, health, and welfare of the public.
DetailsEngineers shall hold paramount the safety, health, and welfare of the public.
DetailsEngineers shall approve only those engineering documents that are in conformity with applicable standards.
DetailsEngineers may express publicly technical opinions that are founded upon knowledge of the facts and competence in the subject matter.
DetailsEngineers shall advise their clients or employers when they believe a project will not be successful.
DetailsPhase 2B: Precedent Cases
precedent case reference 1
The Board cited this prior case involving software design testing to illustrate the principle that engineers must balance business pressures against technical findings and make recommendations based solely on technical concerns to protect public health, safety, and welfare, applying similar reasoning to the autonomous vehicle scenario.
DetailsPhase 2C: Questions & Conclusions
ethical conclusion 9
Engineer A has a responsibility to fully and actively participate as a member of the engineering risk management team, clearly and unambiguously express any and all concerns he has regarding the safety of the proposed autonomous vehicle operation system, and explore additional potential technical options that could mitigate the risks identified in the proposed system. In light of the fact that engineers should strive to do no harm in the performance of their professional services, if necessary, Engineer A should propose that further study be undertaken by the company before the autonomous vehicle operating system is utilized. That being said, to address the specific question posed in the case, Engineer A has an obligation to state that the prime ethical obligation of the vehicle operation is to minimize harm to affect the least number of persons.
DetailsThe Board's conclusion that Engineer A must actively participate and voice concerns presumes that individual advocacy within the team is sufficient to discharge his ethical duty. However, this leaves unresolved the question of ultimate accountability: because the final crash-algorithm decision will be implemented by the manufacturer as a corporate entity, Engineer A's personal obligation to hold paramount public safety may not translate into control over the outcome. The Board's framework should be extended to recognize a layered responsibility structure in which the individual engineer's duty is to ensure his professional judgment is fully and transparently placed into the corporate decision-making record, while ultimate accountability for the adopted algorithm rests with the manufacturer and the collective risk assessment team, not with Engineer A alone.
DetailsThe Board's conclusion establishes a substantive ethical standard (minimize harm to the least number of persons) but does not address a procedural dimension: whether the adoption of a harm-minimizing algorithm that may expose vehicle passengers to greater risk than they might otherwise expect creates an independent obligation of disclosure to purchasers or users. Engineer A's duty to avoid doing harm arguably extends beyond the design phase into ensuring that the ethical trade-off embedded in the system is not concealed from those who will rely on it, since informed consent and transparency are foundational to the profession's broader public welfare obligations even though the Board's conclusion is silent on this communicative dimension.
DetailsThe Board's conclusion treats 'minimize harm to the least number of persons' as a stable ethical rule, but this formulation may not hold uniformly across all crash configurations. Where the relative severity of harm is reversed—for example, a certain fatality to passengers versus a probable but non-life-threatening injury to a third party—the same aggregate-minimization logic could yield a different, even opposite, recommendation. This suggests the Board's stated obligation should be understood as a general orientation toward harm minimization rather than a fixed hierarchy favoring third parties over passengers, and that Engineer A's duty to explore additional technical options must include stress-testing the algorithm's ethical logic against varied severity and probability combinations, not just the single scenario presented.
DetailsRegarding Q101, responsibility for the ethical trade-offs encoded in the crash-decision algorithm is not solely Engineer A's individual burden, but he cannot delegate away his personal professional duty. As a licensed professional serving on the risk assessment team, Engineer A retains an individual, non-transferable obligation under his paramount duty to the public to ensure his own professional judgment is clearly voiced within the team process. The team and the manufacturer as a corporate entity bear collective and organizational responsibility for the final decision, but this does not relieve Engineer A of his individual duty to actively shape that decision through full participation and clear expression of concerns.
DetailsRegarding Q104, if the manufacturer rejects the team's safety concerns and proceeds with a crash algorithm Engineer A believes is unsafe, his obligations do not end with internal advocacy. Consistent with the duty to advise employers when a project will not be successful or may pose undue risk, Engineer A must formally document his objections and, if the safety concerns are serious enough to threaten the safety, health, or welfare of the public, he may need to escalate the matter within the organization or ultimately decline further participation in a manner that does not violate confidentiality obligations, since his paramount duty to the public survives any rejection of his recommendation by the client.
DetailsThe Board resolves the apparent conflict between a passenger-favoring 'Safety in Crash Algorithm Recommendation' principle and the broader 'Public Safety in Autonomous Vehicle Risk Assessment' principle by subordinating passenger-specific safety to aggregate harm minimization. In effect, the Code's paramount public safety duty is interpreted expansively to include all road users—pedestrians, cyclists, and motorcyclists—not just the vehicle's own occupants, meaning the manufacturer's client-facing interest in passenger protection cannot override the engineer's broader obligation to the public at large.
DetailsThe 'Do No Harm in Autonomous Vehicle Case' principle functions as the tie-breaker that operationalizes the paramount safety duty into a concrete decision rule: when harm is unavoidable, the ethically preferred algorithmic outcome is the one causing harm to the fewest people, even if that harm falls disproportionately on the vehicle's own passengers. This shows that in situations of genuine trade-off between identifiable groups, the Board prioritizes a utilitarian minimization-of-harm calculus over a duty-based obligation to protect a specific class of persons (the client's passengers), effectively ranking aggregate welfare above particularized loyalty.
DetailsThe Board's resolution is procedural rather than fully substantive: it prioritizes minimizing harm as the answer to the narrow crash-algorithm question, but leaves unresolved how this principle interacts with other principles such as informed consent of vehicle purchasers, corporate accountability for encoded ethical trade-offs, and the reversibility of risk distribution (e.g., if passengers faced the lesser harm). This suggests the case establishes a priority ordering for principles only within the specific fact pattern presented, without generalizing a fixed hierarchy applicable to all autonomous vehicle risk scenarios.
Detailsethical question 14
What are Engineer A’s ethical obligations?
DetailsWho should bear ultimate responsibility for the ethical trade-offs encoded in the autonomous vehicle's crash-decision algorithm—the individual engineer, the risk assessment team, or the manufacturer as a corporate entity?
DetailsShould vehicle purchasers or passengers be informed that the autonomous system may be designed to prioritize minimizing total harm rather than maximizing their personal safety?
DetailsGiven the significant uncertainty surrounding autonomous vehicle technology, does the risk assessment team have an obligation to recommend delaying deployment entirely rather than merely proposing further study?
DetailsWhat obligations does Engineer A have if the manufacturer rejects the team's safety concerns and proceeds with a crash algorithm the engineer believes is unsafe?
DetailsHow should the principle of prioritizing vehicle passenger safety in the crash algorithm be balanced against the broader principle of minimizing total harm to all persons involved, including pedestrians and cyclists?
DetailsDoes the principle of public safety in autonomous vehicle risk assessment, which considers all road users, conflict with a crash algorithm principle that specifically favors protecting the vehicle's own passengers?
DetailsIf minimizing overall harm sometimes requires exposing vehicle passengers to greater risk than pedestrians, does this create tension with an engineer's duty to hold paramount the safety of the client's own product users?
DetailsFrom a deontological perspective, did Engineer A fulfill his duty to hold paramount the safety, health, and welfare of the public while serving on the autonomous vehicle risk assessment team?
DetailsFrom a consequentialist standpoint, does programming the vehicle to minimize harm to the greatest number of people (potentially sacrificing passenger safety) produce the best overall outcome compared to prioritizing passenger safety above all else?
DetailsDid Engineer A act with professional integrity, in the virtue-ethics sense, by committing to clearly and unambiguously voice his safety concerns and press for further study rather than deferring silently to the team's momentum toward a recommendation?
DetailsIf Engineer A had not been formally assigned as a member of the engineering risk assessment team but instead only reviewed the recommendation after it was finalized, would the Board still conclude he had a duty to fully and actively participate in shaping the team's recommendation?
DetailsIf the crash scenario under consideration were avoidable rather than unavoidable, would the Board's conclusion that the prime ethical obligation is to minimize harm to the least number of persons still apply in the same way?
DetailsIf the scenario instead posed a choice between a certain fatality for the vehicle's passengers versus a probable but non-life-threatening injury to a pedestrian or cyclist (reversing which party bears the greater risk), would the Board still hold that minimizing harm to the least number of persons is the prime ethical obligation?
DetailsPhase 2E: Rich Analysis
causal normative link 5
Because New Technology Uncertainty drives the manufacturer to form the consultant team, this action carries no direct normative weight itself but sets in motion the causal chain that places Engineer A in a position where subsequent ethical obligations become active, so its neutrality is appropriate since responsibility only attaches once participation begins.
DetailsBecause Risk Team Participation causally leads to Safety Concern Expression, Engineer A's active engagement fulfills the responsibility to fully participate and is guided by holding paramount public safety, which matters because without this participation the safety concerns that could mitigate Passenger Injury and Pedestrian Fatality downstream would never surface.
DetailsSince Safety Concern Expression arises directly from Risk Team Participation and precedes the manufacturer's System Outcome Selection that causes both Passenger Injury and Pedestrian Fatality, fulfilling the responsibility to clearly express concerns under the guidance of do no harm and public safety is critical because it represents Engineer A's key opportunity to influence the harmful outcome before it is finalized.
DetailsTechnical Options Exploration fulfills the responsibility to explore risk-mitigating alternatives and, guided by do no harm and public safety, causally enables the Further Study Proposal, meaning this action matters because it is the constructive engineering response that could have altered the System Outcome Selection and thereby reduced the eventual passenger and pedestrian harms.
DetailsFurther Study Proposal fulfills the responsibility to propose additional study when needed and, following causally from Technical Options Exploration, matters because it represents Engineer A's final documented attempt, guided by do no harm and public safety, to prevent the harmful System Outcome Selection from being adopted without further risk mitigation.
Detailsquestion emergence 14
The question arises because Engineer A sits within a Pre-Utilization Study Window facing a Crash Outcome Objective Conflict where the paramount duty to protect the public collides with the practical duty to work within a team under conditions of genuine technical uncertainty about which outcome is safer.
DetailsThe question arises because the crash-decision algorithm embeds an ethical trade-off that no single actor fully controls, so the same data supports both individual-level and institutional-level warrants for assigning responsibility, and the uncertainty of new autonomous vehicle technology leaves no settled precedent for which warrant should dominate.
DetailsThe question arises because the engineer's paramount duty to public welfare (minimizing total harm) structurally conflicts with the individual purchaser's expectation of personal protection, and the unresolved gap between these two warrants generates uncertainty about what informed consent obligations exist.
DetailsBecause the case data leaves the actual level of danger and the adequacy of further study both unresolved, it is unclear whether the paramount safety warrant demands a stronger, more absolute response than the narrower duty to propose further study, producing the ethical question.
DetailsThe question arises because Engineer A has fulfilled his procedural duties to raise concerns and propose mitigation, yet the manufacturer's rejection creates an unresolved gap between his personal safety judgment and his authority to act once the employer proceeds anyway.
DetailsThe question arises because Autonomous Vehicle Technology Uncertainty and the Crash Outcome Objective Conflict expose that no single algorithmic rule can satisfy both the duty to protect vehicle occupants and the broader public safety obligation to all persons at risk, forcing engineers to weigh competing interpretations of the same paramount safety principle.
DetailsThe question arises because Engineer A must recommend a crash algorithm where no outcome avoids harm, exposing an unresolved conflict between a public welfare principle and a design assumption that vehicles should prioritize their own occupants.
DetailsThe question arises because the same crash scenario data supports two plausible but conflicting readings of the engineer's paramount safety obligation, one aggregate and one occupant-focused, and the case does not specify which warrant should govern.
DetailsThe question arises because an unavoidable crash scenario forces a choice between competing harms, and the ethical assessment of Engineer A's conduct depends on which specific sub-duty (participation, expression, or proposing further study) is treated as sufficient evidence of upholding the paramount safety obligation.
DetailsThe question arises because the Crash Outcome Objective Conflict exposes a structural disagreement over which ethical framework, aggregate welfare versus protected-party obligation, should govern algorithmic design under Unavoidable Crash Harm Exposure.
DetailsThe question arises because the Pre-Utilization Study Window created a choice point where silent deference and vocal advocacy both seemed like plausible professional responses, and virtue ethics asks whether Engineer A's character was tested and met by clear communication rather than passive agreement.
DetailsThe question arises because the Board's conclusion rests on Engineer A's formal team assignment as the basis for his participation duty, and altering that factual predicate exposes tension between a role based warrant and a broader safety principle based warrant.
DetailsThe question arose because the Board's ethical conclusion was built specifically on the assumption of an unavoidable crash, and changing that foundational fact challenges whether the same warrant and conclusion still hold.
DetailsThis question arose because BER Case 96-4 established a principle under one specific risk distribution, and reversing that distribution tests whether the Board's stated ethical obligation was a general principle or was contingent on the particular facts of who was originally more exposed.
Detailsresolution pattern 9
Given that Engineer A sits on the risk assessment team and the crash scenario is unavoidable, the board concluded he must actively participate, voice concerns, explore mitigations, and if needed propose further study, treating aggregate harm minimization as the operative ethical rule for this unavoidable-crash configuration.
DetailsBecause the manufacturer, not Engineer A individually, will implement the final crash algorithm, the board's extension concludes that his personal obligation is limited to transparent participation in the decision record, while ultimate accountability shifts to the corporate and team level.
DetailsGiven that the algorithm's harm-minimizing logic could subject passengers to unexpected risk, this analysis extends Engineer A's do-no-harm duty to require disclosure, reasoning that the board's silence on this point leaves a gap the profession's transparency norms should fill.
DetailsBecause the board's harm-minimization rule was grounded in one specific severity configuration, this analysis concludes that reversing which party bears the greater harm could flip the recommended outcome, so Engineer A's technical exploration duty must include stress-testing the algorithm across varied scenarios rather than treating the original rule as universal.
DetailsGiven Engineer A's status as a licensed team member alongside a corporate entity holding final authority, the board's reasoning concludes that his personal duty to voice concerns remains intact and non-delegable even though ultimate responsibility for the adopted algorithm is shared collectively.
DetailsGiven that the manufacturer rejected the team's safety concerns and Engineer A still believed the algorithm unsafe, the board concluded his duty does not end with internal advocacy, but requires formal documentation, escalation, or ultimately declining further participation, because the paramount duty to the public survives client rejection even though confidentiality still constrains the mode of disclosure.
DetailsGiven that pedestrians, cyclists, and motorcyclists were also exposed to risk from the algorithm, the board concluded that the passenger-favoring principle must yield to the broader public safety principle, because the Code's paramount safety duty is not limited to the client's own product users.
DetailsGiven that harm could not be avoided and the team faced a genuine trade-off between groups, the board concluded that minimizing the number of people harmed operationalizes the paramount safety duty, even though this meant passengers bore disproportionate risk in this particular fact pattern.
DetailsGiven that the board only had before it the narrow crash-algorithm trade-off, it concluded that minimizing harm answers that specific question, while explicitly leaving open how this principle would interact with informed consent, corporate accountability, or a reversed risk scenario, because those issues were not squarely presented in this case.
DetailsPhase 3: Decision Points
canonical decision point 6
Should Engineer A fully and actively participate on the risk assessment team and clearly voice his safety concerns about the crash algorithm, or defer quietly to the team's emerging consensus?
DetailsShould Engineer A explore additional technical options to mitigate identified risks and propose further study before deployment, or accept the team's current recommendation as sufficient, or instead recommend that deployment be delayed outright?
DetailsShould Engineer A endorse an algorithm design that minimizes harm to the fewest number of persons overall, or one that prioritizes protecting the vehicle's own passengers even if this increases harm to pedestrians or cyclists?
DetailsShould Engineer A advocate that purchasers and passengers be informed that the autonomous system may be designed to minimize total harm rather than maximize their personal safety, or treat this design logic as proprietary information not requiring disclosure?
DetailsIf the manufacturer rejects the team's safety concerns and proceeds with an algorithm Engineer A believes is unsafe, should Engineer A formally document and escalate his objections, or accept the manufacturer's decision and continue participating as before?
DetailsShould Engineer A treat the ethical trade-offs encoded in the crash algorithm as his individual ultimate responsibility, or as a layered responsibility shared with the risk assessment team and the manufacturer?
DetailsPhase 4: Narrative Elements
Characters 5
Guided by: Safety in Crash Algorithm Recommendation, Public Safety in Autonomous Vehicle Risk Assessment, Do No Harm in Autonomous Vehicle Case
Timeline Events 20 -- synthesized from Step 3 temporal dynamics
The case is set within the development of autonomous vehicle systems, where engineers must confront the reality that some crash scenarios cannot be entirely avoided and difficult choices must be made about how harm is distributed when a collision is unavoidable. This establishes the central ethical tension between competing safety objectives that the engineering team will need to navigate.
A team of engineering consultants is brought onto the project to help design and evaluate the decision making algorithms that will govern the vehicle's behavior in crash scenarios. Their assignment places them at the center of decisions with significant public safety implications.
A separate risk assessment team joins the project to analyze potential hazards and evaluate the safety tradeoffs associated with different crash response strategies. Their involvement signals that the organization recognizes the complexity and seriousness of the safety questions at hand.
One or more engineers on the project raise concerns that the current approach to handling unavoidable crash scenarios may not adequately protect public safety. This marks a pivotal moment where professional obligations to safeguard the public come into tension with project timelines or design constraints.
The engineering team begins investigating alternative technical solutions that might reduce the severity or likelihood of harm in unavoidable crash situations. This reflects a good faith effort to address the safety concerns that had been raised.
Rather than proceeding immediately with the current design, engineers propose that additional research and analysis be conducted before finalizing the crash response algorithms. This proposal represents an attempt to ensure decisions are grounded in sufficient evidence and careful deliberation.
A pedestrian is killed in an incident involving the autonomous vehicle system, transforming the previously theoretical safety concerns into a real world tragedy with serious consequences. This event intensifies scrutiny of the engineering decisions and processes that led to this outcome.
The vehicle encounters a scenario in which a crash cannot be avoided, forcing the system to act according to its programmed decision making logic. This event serves as a real world test of the ethical and technical choices embedded in the vehicle's design.
System Outcome Selection
Passenger Injury
New Technology Uncertainty
Tension between Engineer A Risk Mitigation Exploration Duty and Further Study Proposal Duty and Engineer A Do No Harm Boundary
Tension between Engineer A Paramount Safety Duty and Engineer A Do No Harm Boundary
Should Engineer A fully and actively participate on the risk assessment team and clearly voice his safety concerns about the crash algorithm, or defer quietly to the team's emerging consensus?
Should Engineer A explore additional technical options to mitigate identified risks and propose further study before deployment, or accept the team's current recommendation as sufficient, or instead recommend that deployment be delayed outright?
Should Engineer A endorse an algorithm design that minimizes harm to the fewest number of persons overall, or one that prioritizes protecting the vehicle's own passengers even if this increases harm to pedestrians or cyclists?
Should Engineer A advocate that purchasers and passengers be informed that the autonomous system may be designed to minimize total harm rather than maximize their personal safety, or treat this design logic as proprietary information not requiring disclosure?
If the manufacturer rejects the team's safety concerns and proceeds with an algorithm Engineer A believes is unsafe, should Engineer A formally document and escalate his objections, or accept the manufacturer's decision and continue participating as before?
Should Engineer A treat the ethical trade-offs encoded in the crash algorithm as his individual ultimate responsibility, or as a layered responsibility shared with the risk assessment team and the manufacturer?
Engineer A has a responsibility to fully and actively participate as a member of the engineering risk management team, clearly and unambiguously express any and all concerns he has regarding the safet
Ethical Tensions 6
Decision Moments 6
- Actively Participate and Voice Concerns board choice
- Defer Quietly to Team Consensus
- Raise Concerns Informally Outside the Team Process
- Propose Further Study Before Deployment board choice
- Accept Current Recommendation as Adequate
- Recommend Outright Delay of Deployment
- Minimize Harm to Fewest Persons Overall board choice
- Prioritize Vehicle Passenger Protection
- Design Context-Sensitive Weighting of Severity and Probability
- Advocate Full Disclosure to Purchasers
- Treat Design Logic as Proprietary
- Disclose Only Through General Documentation
- Formally Document and Escalate Objections board choice
- Accept Decision and Continue Participation
- Report to an External Regulatory Body
- Treat Responsibility as Layered and Shared board choice
- Treat Responsibility as Entirely Individual
- Disclaim Personal Responsibility Entirely