AI NEWS SOCIAL · The Longer View · 2026-08-30 International/LATAM
The Passive Voice of Protection

The Passive Voice of Protection

I. The question of the week

“Protect the vulnerable” is one of those phrases that sounds like a policy and functions like a mood. It names a class of people — children, teenagers, the isolated elderly, the disabled, the poor, the newly arrived — and it names a threat, but it leaves out the two words that decide everything: who, and how. The verb sits in the passive voice. Someone or something will be protected. By whom, at whose expense, and against which specific harm goes conveniently unstated, and into that silence a great deal of comfortable talk has flowed.

The topic this week is exactly that talk, and the reality underneath it, traced over two years. The vocabulary of protecting the vulnerable from AI has clustered around a recurring set of scenes — the chatbot a lonely fourteen-year-old confides in, the cloned voice on a grandmother’s phone, the toy that listens, the welfare algorithm that decides — and around a recurring evasion about who is on the hook when the protection fails.

The arc has a distinct shape. The conversation began hopeful in late 2024, with AI cast as the guardian; it turned sharply critical through the first half of 2025, as the vulnerable were recast from beneficiaries into casualties; and then, through the third quarter of 2025, it swung back toward optimism — but in a different key, one that had learned to say “harm reduction” and “designing for fairness” where it once said “shield.” Two inversions, roughly a year apart, and a reality that accumulated underneath all three moods without much regard for any of them. The question worth holding through the whole arc is whether the return of optimism represents a lesson learned or a subject changed.

II. What we’ve been saying

The late-2024 register was protective in the most literal sense: AI as the thing doing the protecting. In July of that year Neil Sahota argued in Forbes that “AI Shields Kids By Revolutionizing Child Safety And Online Protection”, a title that tells you almost the entire theory of the case in its verb. The vulnerable child was the object of protection, and the technology was the subject — the guardian, not the threat. That same season, North Carolina State University announced a $500,000 grant to study “How the Use of AI Impacts Marginalized Populations in Child Welfare”, and a survey in ScienceDirect catalogued “The Role of Artificial Intelligence in Enhancing Healthcare for People with Disabilities” as a “transformative opportunity.” Writing by invitation in The Economist that December, David Patterson set out “an agenda to maximise AI’s benefits and minimise harms”, framing the task as one of reassuring an anxious public. The genre was reassurance; the vulnerable appeared mainly as evidence of AI’s good heart.

A single dissonant note sounded from the Harvard Business Review, whose “AI Regulation Is Coming” observed that public concern was migrating from the misuse of personal data toward the potential of the systems themselves. It read, at the time, as a caution against the prevailing optimism.

By the first quarter of 2025 that caution had become the prevailing sound. The framing inverted. Where the vulnerable had been beneficiaries, they were now the people to whom things were done. Common Dreams laid out “3 Reasons Using AI in Decision-Making Harms Low-Income Americans” — note the verb has changed hands; now AI harms, and the poor are its object. Tata Elxsi turned to “The Intersection of AI and Human Rights”, warning that misuse “can exacerbate societal disparities.” A journal survey on “Navigating the Risks of Artificial Intelligence” and a practitioner guide on how to “build safe, secure and trustworthy AI” rounded out a quarter in which risk, not rescue, was the organizing noun. The probe counts register the swing plainly: from a slight optimistic tilt in late 2024 to critical framings outnumbering optimistic ones three to one by early 2025.

The second quarter deepened it. The American Psychological Association, in guidance relayed under the heading “How to support students’ well-being in the age of AI”, urged caution and explicit guidance to protect young people ages ten to twenty-five — a specific age band, a specific population, a named professional body committing to a claim. HEC’s faculty took up the “conundrums” of unregulated adoption. The critical framings peaked here, outnumbering optimistic ones two to one. Yet even in this quarter the older, hopeful register survived at the margins: a study from Serbia on “Perspectives of AI in empowering persons with disabilities” and a paper on “Harnessing AI’s Potential” kept insisting the technology could still be an instrument of equity rather than its solvent.

Then, in the third quarter of 2025, optimism returned — and this is the inversion worth watching, because the vocabulary had changed. The word was no longer “shield” but “mitigate,” “design,” “reduce.” A healthcare piece advised adopters “implementing LLMs” to “first, do some harm reduction”, borrowing a phrase from public-health practice that assumes harm is a constant to be managed rather than a wrong to be prevented. KPMG offered guidance on “Designing AI for social fairness”. Even the sceptical entries arrived pre-domesticated: when experts in Abu Dhabi warned of “risks that could shake public trust” in AI social work, the warning was folded inside an account of AI as “a key tool in social work and social protection.” The optimistic framings now outnumbered the critical ones, nine to six, but the optimism was no longer naive. It had absorbed the criticism of the middle quarters and metabolized it into a project — a set of design problems for the responsible adopter to solve. The mood had recovered. The question was whether anything else had.

III. What’s been happening

While the register cycled through guardian, victim, and manager, the material facts moved in one direction, and it was not the direction of any of the moods. The harms named at the start of this arc were not hypothetical, and they did not wait for the discourse to settle.

The clearest evidence sits in the ledger. The “AI Index Report 2024” documented tools that draw on training data, “which often include nude images and celebrity photographs, to produce nude images of celebrities, even when images of the targeted celebrity are absent from the original dataset.” The report notes that filters exist to prevent such output — and that these filters “can usually be circumvented with relative ease.” Read that against the protective optimism of the same period and the gap is stark: the guardian technology of the Forbes headline and the technology that generates non-consensual intimate imagery of people who were never in the dataset are, frequently, the same technology. The protection and the harm ship in one box.

The response, when it came, came from states. The World Economic Forum, asking “how we can keep children safe as AI reshapes the internet”, reported that governments including the United Kingdom, Australia, Singapore, and Spain were answering with “a wave of online safety measures.” In March 2025 the Pontifical Academy of Sciences, working with the World Childhood Foundation, convened a summit and issued a statement on the “Risks and Opportunities of AI for Children” — a Church, a royal foundation, and an academy of scientists jointly asserting that children were exposed and that the exposure was addressable. Advocacy organizations formed around the single mission: Keep AI Safe exists, by its own account, “to protect children and adolescents from AI-related harm through targeted awareness, critical research, and systemic change.” The institutional machinery of protection was assembling in real time.

But the machinery had a design flaw the rhetoric rarely acknowledged: most of it was advisory, and the advisory instruments were pointed at the least powerful actors in the chain. The APA’s guidance to protect those aged ten to twenty-five is addressed, in practice, to parents, teachers, and the young people themselves — the people with the least leverage over how a chatbot is engineered to maximize engagement. UNESCO, in its “AI competency framework for teachers”, is blunter about where enforcement actually has to live: “a certain level of risk requires independent institutional mechanisms for the validation of AI systems,” and “most AI applications” in education “are considered to be high-risk, requiring strict regulation.” The framework says out loud what the softer guidance elides — that awareness campaigns aimed at families are not a substitute for validating the systems before they reach the family. Protection that depends on the vigilance of a tired parent or a ten-year-old is not protection; it is the appearance of protection with the liability quietly reassigned.

Meanwhile the presumption that lets the harm accumulate remained largely intact. Kate Crawford, in “The Atlas of AI” (2021), identifies it precisely: for the datasets that decide “who should receive welfare benefits,” she writes, “the potential harms expanded” and “those harms affect entire communities as well as individuals,” yet “there is still a strong presumption that publicly available datasets pose minimal risks and therefore should be exempt from ethics review.” She calls this presumption “the product of an earlier era, when it was harder to move data between locations and very expensive to store it.” The child-welfare algorithm that the NC State grant set out to study, the low-income decision systems that Common Dreams warned about, the deepfake pipelines the AI Index catalogued — all of them run, in significant part, on data that the governing presumption still treats as harmless because it is available. The reality has been an expansion of harm operating under an inherited assumption of innocence, and the wave of online-safety measures has been chasing consequences downstream of a source it mostly declines to inspect.

IV. Where they meet, where they miss

The rhetoric and the reality meet on the noun and part ways on the verb. Everyone agrees on who the vulnerable are — the lists are remarkably stable across every quarter of this arc, children first, then teenagers, then the disabled, the elderly, the poor, the immigrant. The MIT Press primer “AI Ethics” codifies the consensus: the no-harm principle, it explains, is “interpreted as requiring that AI algorithms must avoid discrimination, manipulation, and negative profiling, and must protect vulnerable groups such as children and immigrants.” Note the word doing the load-bearing: interpreted. A principle interpreted is not a principle enforced, and the distance between those two conditions is where this entire topic lives.

That distance is a diffusion of responsibility, and it has a canonical form. Crawford recounts, again in “The Atlas of AI”, a computer scientist presenting a tool who, asked how it might be misused, “responded that he couldn’t know,” being just “a researcher” — “the sort of ethical questions that I don’t know how to answer appropriately.” An audience member answered him with a line from Tom Lehrer’s satire of the rocket engineer Wernher von Braun: once the rockets are up, who cares where they come down. The passive voice of protection is the institutional version of that shrug. The child will be protected — by the platform, which points to the regulator; by the regulator, which issues guidance to the parent; by the parent, who is handed a chatbot engineered against her attention and told to supervise. Each actor is, in his own account, just a researcher.

This is why the third-quarter return to optimism should be read with a cold eye rather than a warm one. The swing back was real, but it was not a swing back to the guardian fantasy of 2024. It was a swing to management — to “harm reduction” and “designing for fairness”, vocabularies that concede the harm is structural and then propose to administer it responsibly. That is a genuine advance over denial. It is also, read less generously, the moment the vendor reclaims the narrative: having absorbed a year of criticism, the responsible-deployment frame turns protection into a professional competence — something adopters do, a maturity model, a checklist — rather than a limit that anyone outside the deploying institution gets to impose. When the frameworks that “academics answer” treat premature deployment as a management challenge, the vulnerable have quietly changed roles again: no longer the guardian’s ward, no longer the victim, but a risk factor in someone else’s compliance posture.

The publication has tracked the same substitution on the equity side of the ledger. As an earlier essay on the social aspects of AI noted in our briefing of September 28, 2025, the promise to “democratize access to resources and opportunities” for the disadvantaged has a way of standing in for the harder work of not extracting from them first. The pattern holds here. The strongest empirical instrument in this whole arc — UNESCO’s insistence on “independent institutional mechanisms” that validate high-risk systems before they reach a classroom — is precisely the instrument the optimistic frame keeps declining to name, because it locates the responsibility upstream, before deployment, where the least talk and the most power are.

V. The longer view

Two years of this conversation have produced a stable list of the vulnerable and an unstable account of who owes them anything. The moods rotated — guardian, casualty, managed risk — and each rotation kept the same people in the object position of the sentence and rotated only the subject, or dropped the subject entirely. The one framing that never took hold is the one that would matter most: the vulnerable as the party whose consent is required, whose testimony is decisive, whose interests set the limit rather than illustrate the pitch. UNESCO reached for it in the language of validation. Crawford reached for it in the refusal to accept “just a researcher” as an answer. The MIT primer reached for it and then handed it back with the word “interpreted.”

Protection is a transitive verb; it needs a subject and it takes an object, and for two years the public conversation has been remarkably willing to speak the object and swallow the subject. The measure of whether the next two years are better will not be the mood of the discourse, which has already proven it can turn hopeful again without anything underneath it changing. The measure is grammatical. Watch for the sentences that name who protects, and hold still long enough to be answerable. Everything else is weather.

The vulnerable are always named and almost never consulted; protection stays a promise for exactly as long as no one has to say, out loud, whose job it was.

References

  1. About Keep AI Safe — Our Story, Mission & AI Safety Approach
  2. AI Shields Kids By Revolutionizing Child Safety And Online Protection — Forbes
  3. Risks and Opportunities of AI for Children: A Common Commitment (Pontifical Academy of Sciences)
  4. How can we keep children safe as AI reshapes the internet? — World Economic Forum
  5. How the Use of AI Impacts Marginalized Populations in Child Welfare — NC State
  6. The Role of Artificial Intelligence in Enhancing Healthcare for People with Disabilities — ScienceDirect
  7. An agenda to maximise AI’s benefits and minimise harms, by David Patterson — The Economist
  8. AI Regulation Is Coming — Harvard Business Review
  9. The Intersection of AI and Human Rights: Ensuring Ethical Standards — Tata Elxsi
  10. How to build safe, secure and trustworthy AI capabilities — Health Data Management
  11. Navigating the Risks of Artificial Intelligence: Challenges and Strategies for Mitigation
  12. Opinion: 3 Reasons Using AI in Decision-Making Harms Low-Income Americans — Common Dreams
  13. How to support students’ well-being in the age of AI — University Business
  14. AI and Ethics: Academics Answer the Conundrums — HEC
  15. Perspectives of AI in empowering persons with disabilities in Serbia
  16. Harnessing AI’s Potential: Building Pathways to Social Justice and Economic Equity — Toronto Metropolitan University
  17. UAE: AI in social work? Experts warn of risks that could shake public trust — Khaleej Times
  18. Beyond the bias: Designing AI for social fairness — KPMG
  19. Implementing LLMs in healthcare? First, do some harm reduction — AI in Healthcare
  20. Determinants of Ethical and Scalable AI for the Sustainable Development Goals: A Qualitative Framework from the Global South
← Back to this edition