AI bias is a systematic and unfair difference in an AI system's outputs that disadvantages particular individuals or groups, often in ways that correlate with race, sex, age, disability, or other protected characteristics. It is rarely the product of intent: bias typically enters through skewed training data, proxy variables that stand in for what a model is really trying to predict, or feedback loops that compound existing inequities each time the system is used. In its 2022 report on the subject, the US National Institute of Standards and Technology (NIST) argued that AI bias cannot be solved as a purely technical "fix the dataset" problem, because statistical, human, and institutional biases interact and reinforce one another throughout a system's lifecycle. That framing now underpins how regulators approach the issue: the EU AI Act will require providers of high-risk AI systems to examine their training data for bias (from 2 December 2027, following the Digital Omnibus's deferral of the original 2 August 2026 date), and New York City requires independent bias audits before certain hiring algorithms can be used. For any organisation deploying AI in decisions that affect people, unmanaged bias is simultaneously a fairness failure, a legal exposure, and increasingly an audit finding waiting to happen.
Run the free AI Health CheckAI Bias, systematic and unfair differences in AI system outputs that disadvantage particular individuals or groups, often correlated with protected characteristics.
AI bias is rarely the result of intent. It typically arises from biased training data, flawed proxy variables, or feedback loops that amplify existing inequities. Most jurisdictions treat AI-driven indirect discrimination as unlawful regardless of intent: the EU AI Act, the Equality Act 2010, US Title VII, and Australian anti-discrimination law all extend to AI-mediated decisions. Bias auditing is increasingly mandated (e.g., NYC Local Law 144).
Source: NIST SP 1270; EU AI Act, Article 10
NIST Special Publication 1270, Towards a Standard for Identifying and Managing Bias in Artificial Intelligence (released March 2022), moved the field beyond treating bias as a data-cleaning problem. It groups the drivers of AI bias into three interacting categories and warns that when human, systemic, and computational biases combine, they form a mixture that purely technical fixes will not resolve.
Statistical and computational bias
Systematic errors from non-representative samples, flawed labels, or algorithms that cannot generalise beyond the data they were trained on. This is the category most bias-mitigation tooling targets, and it can occur with zero prejudicial intent.
Human and cognitive bias
The heuristics and mental shortcuts that designers, annotators, and decision-makers bring to every stage of the AI lifecycle, from how a problem is framed to how a model's output is interpreted, trusted, or overridden.
Systemic bias
Bias embedded in the institutional practices, norms, and broader social structures an AI system operates within, present even when no individual involved acts with conscious prejudice.
Hiring and recruitment
Amazon scrapped an internal AI recruiting tool in 2018 after discovering it had taught itself to penalise resumes containing the word "women's" or the names of all-women colleges, having been trained on a decade of resumes skewed toward male applicants.
Healthcare resource allocation
A 2019 study published in Science found a widely used US healthcare algorithm systematically under-referred Black patients for extra care because it used historical healthcare spending, itself shaped by unequal access, as a proxy for medical need.
High-stakes risk scoring
Automated risk-scoring tools used in areas like criminal justice and lending have faced sustained scrutiny over race- or income-correlated error rates, driving demand for pre-deployment and ongoing bias testing of high-stakes automated decision tools.
Proxy discrimination
Variables such as postcode, school attended, or purchase history can reintroduce race- or income-correlated effects even when protected characteristics are explicitly excluded from a model's inputs.
The EU AI Act (Regulation (EU) 2024/1689) is the first horizontal law to make bias examination a binding data-governance duty, once its high-risk provisions take effect. Article 10 requires that training, validation, and testing data for high-risk AI systems be relevant, sufficiently representative, and, to the best extent possible, free of errors and complete. Under Article 10(2)(f), those datasets must be examined for biases likely to affect health and safety, harm fundamental rights, or lead to discrimination prohibited under EU law, and providers must take appropriate measures to detect, prevent, and mitigate any bias identified. Providers may process special categories of personal data for that narrow bias-detection purpose only under strict safeguards. These Article 10 obligations, along with the rest of the Annex III high-risk-system requirements, were originally due to apply from 2 August 2026, but the Digital Omnibus (given final Council approval on 29 June 2026) deferred that date to 2 December 2027 for standalone high-risk systems (2 August 2028 for AI embedded in regulated products under Annex I). As of mid-2026 the bias-examination duty is not yet enforceable, though it will become so on that later date. Non-compliance with high-risk system obligations is enforceable under the Act's penalty regime (Article 99), which scales fines to a company's global turnover.
In the United States, NIST's approach is voluntary rather than binding: the AI Risk Management Framework and its companion SP 1270 give organisations a structure for identifying and managing bias but impose no legal duty to do so. Binding US bias-audit obligations have instead emerged at the state and local level, most notably New York City's Local Law 144, which requires employers using an "automated employment decision tool" to obtain an independent bias audit within the year before use, publish a summary of the results, and notify candidates that such a tool is in use. New York's Department of Consumer and Worker Protection began enforcing the law on 5 July 2023.
Is AI bias illegal?
Not automatically, but most jurisdictions prohibit discrimination on protected grounds regardless of whether a human or an algorithm made the decision. If an AI system's output disparately harms people based on race, sex, age, disability, or another protected characteristic, it can trigger anti-discrimination liability even without any intent to discriminate.
What causes AI bias?
NIST's framework (SP 1270) groups the causes into three interacting sources: statistical/computational bias (unrepresentative or flawed training data), human/cognitive bias (the heuristics of the people who build and use the system), and systemic bias (the institutional and societal context the system operates in).
What is an AI bias audit?
An independent, third-party evaluation of an AI system's outputs to check whether it produces disparate outcomes across protected groups. New York City's Local Law 144 is the first legal mandate of this kind, requiring bias audits of automated hiring tools before they can be used.
Does the EU AI Act require bias testing?
It will, for high-risk AI systems -- but the application date for this Article 10 duty was deferred by the 2026 Digital Omnibus from 2 August 2026 to 2 December 2027, so it is not yet in force. Article 10 requires that training, validation, and testing data be examined for biases that could harm health, safety, or fundamental rights, or lead to unlawful discrimination, and that providers take measures to detect, prevent, and mitigate any bias found once the obligation takes effect.
Can AI bias be completely eliminated?
No. Bias mitigation reduces and manages disparities; it does not guarantee a bias-free system. Because bias can re-enter through proxy variables, shifting populations, or feedback loops, frameworks like the NIST AI RMF and ISO/IEC 42001 treat bias management as continuous monitoring across the AI lifecycle rather than a one-time fix.
What's the difference between "AI bias" and "algorithmic bias"?
The terms are often used interchangeably. "Algorithmic bias" tends to refer more narrowly to bias introduced by a model's logic or optimisation process itself, while "AI bias" is typically the broader governance term covering data, human, and systemic sources of bias across the whole AI lifecycle, the framing NIST SP 1270 uses.
Last reviewed July 2026
This page is general information about What Is AI Bias?, not legal, regulatory, or professional advice, and does not capture every nuance or exception. Requirements change and can be fact-specific. Always verify against primary sources and your own qualified legal counsel before relying on it.