INNOVAREModule 6 · AI Project Management

Case 4: Whose Name Is On the Harm?

Miller's framework for managing AI projects — moral agents, the moral buffer, the four-stage lifecycle, the success factors, and the harms the whole discipline exists to prevent. The required reading, in full.

July 2026 · Case 4 of 6
As you read — hold this question

When a machine says no a hundred times and no human ever looked — who actually said no?

100+
job applications, all rejected — often within minutes, no human ever involved.

Derek Mobley applied for more than a hundred jobs after being laid off in his forties. Every time, the answer was no, often within minutes, screened by AI before a person ever saw him. He sued the company whose software did the screening. His question is the one Gloria Miller's framework is built to answer: when an AI system causes harm, whose name is on the decision? Miller (2025) embeds an AI perspective into a project-management standard and centres it on avoiding moral issues — harms, losses, and damages.

The central idea
Quiz: Miller Framework

Moral agents and the moral buffer

Miller starts from an idea that sounds philosophical until you have met Mobley: an AI system is a moral agent. Project actors — sponsors, project managers, team members — are not mere participants; their in-project decisions can affect life, liberty and rights, so they carry moral responsibility. The failure the framework exists to prevent is the moral buffer: the accountability gap where neither the people who use an AI system nor the engineers who built it are held accountable for the decisions it makes. Responsibility falls into the gap.

The lifecycle

Four stages — and the one classic project management forgets

StageWhat happens
PlanThe problem statement is defined — it acts like a contract setting the algorithm's goal and anticipated behaviour
DevelopmentData collection/processing, model and UI build, verification & validation against bias and false positives
UsagePeople trigger the algorithm (knowingly or not); performance is continually surveyed; monitoring and renewal refresh obsolete values
ConsequencePost-project. Outputs impact people, organisations and society — assessed for fairness, trustworthiness, transparency, explainability, accountability and sustainability
The distinctive move
Classic project management ends at closure. Miller adds Consequence — because the harm from an AI system arrives months or years after the team has gone home. Miller weaves this lifecycle through the project standard ISO 21502:2020 (alongside PMBOK 7, APM BoK, PRINCE2) and, for each stage, defines the success factors that close the moral buffer one named responsibility at a time.
What "harm" means

Harms, Losses, and Damages

Miller gets specific, splitting moral issues into three columns:

Harms — body & mind
Bodily harm, loss of life, limitation of rights or freedom of movement, surveillance, psychological impact.
Losses — rights
Violations of human/civil rights: loss of privacy, security, freedom, funds, and employment.
Damages
Damage to trust, reputation, and the environment.
The success factors (Planning)

Four frameworks that must be established up front

Ethics framework
Operationalises 11 ethical principle categories via ethics policies, training, an ombudsman, conflict-of-interest rules and professional standards.
Data governance framework
Manages the data lifecycle — authority/control, collection, use, retention and destruction (e.g. GDPR obligations).
Legal framework
Legal and privacy safeguards during execution for compliance, confidentiality and limiting liability; protects human rights.
Benefits / value framework
Identifies the ethical implications of turning data and algorithms into value, with guardrails against unethical behaviour.

The 11 ethical principle categories: beneficence · dignity · freedom & autonomy (incl. human rights, contestability) · justice & fairness (incl. diversity) · non-maleficence (incl. safety, security, reliability) · privacy · accountability/responsibility · solidarity · sustainability · transparency (incl. auditability) · trust.

Stakeholders & bias

Who counts as a stakeholder — and who speaks for the people affected

Miller says a party qualifies as an AI stakeholder if it holds at least one of four attributes — Power (ability to impose their will), Legitimacy (contractual or societal standing), Urgency (time-sensitivity, during Development, Usage or Consequence), and Harm (the harms, losses or damages they may suffer). Crucially, passive stakeholders — those affected by a system but not contributing to it — should participate through representation. If a system will affect a community of women, a representative from that community should be given the chance to judge whether it will help or harm them.

Bias is a human decision, not a machine one
Designers' personal biases, blind spots and design choices shape outcomes; training data may be biased, incomplete, or miss entire communities. Miller's defence is a diverse project team — people from numerous backgrounds, disciplines and specialisations — to protect the system from inbuilt bias, plus problem-reporting mechanisms that let users flag algorithmic bias once live.
Accountability — the course tool, and the practitioner reality

RACI: prescribed to close the buffer, capable of becoming one

The course view. Miller recommends a responsibility-assignment matrix — a RACI (Responsible, Accountable, Consulted, Informed) — as an essential tool to avoid moral hazard. It maps people and organisations to accountabilities and responsibilities; accountability ensures a task is done satisfactorily and, importantly, cannot be delegated.

The practitioner critique
In practice, a RACI is often used as a divisive tool that reinforces silos — and, worst of all, it lets people dodge responsibility because their name wasn't on the RACI. The irony is sharp: the very tool Miller prescribes to close the moral buffer can recreate it. A matrix spreads accountability across boxes; the buffer only truly closes when accountability is concentrated. The stronger answer is single-threaded ownership — one named person accountable for each decision (the "directly responsible individual" model) — so there is always exactly one name to answer for an outcome.
Take this away

Miller's framework is one long answer to Mobley's question: someone planned it, someone built it, someone is meant to be watching it now — so that at every stage there is a name. The success factors, the four frameworks, the stakeholder attributes and the accountability tools all exist to ensure it can never again be true that nobody is responsible.

Quick recall — without looking back

Test yourself on this case

Question 1 of 5

Define the moral buffer and moral agent in Miller's framework.

A moral agent, in Miller's terms, is any project actor (sponsor, project manager, team member) whose in-project decisions can affect people's lives, liberty and rights — so they bear moral responsibility, not just a task. The moral buffer is the accountability gap that occurs when neither the people who use an AI system nor the engineers who built it are held accountable for the harmful decisions it makes; responsibility falls into the gap. The framework's success factors exist to close that buffer.
Question 2 of 5

Name Miller's four AI-project lifecycle stages and explain why the last one matters.

Plan (the problem statement acts as a contract); Development (data, model and UI build, verification and validation against bias/false positives); Usage (people trigger the system; monitoring and renewal); and Consequence. Consequence matters because it is post-project — the impacts on people, organisations and society accrue months or years after the project closes, which classic project management never accounts for. It is assessed for fairness, trustworthiness, transparency, explainability, accountability and sustainability.
Question 3 of 5

What four frameworks must be established at planning, and what are the three categories of moral issue the framework prevents?

Four planning frameworks: Ethics, Data governance, Legal, and Benefits/Value. The three categories of moral issue are Harms (bodily harm, loss of life, surveillance, psychological impact), Losses (violations of rights — privacy, security, freedom, funds, employment), and Damages (trust, reputation, environment).
Question 4 of 5

How does Miller identify stakeholders, and what is a 'passive stakeholder'?

A party qualifies as an AI stakeholder if it holds at least one of four attributes: Power, Legitimacy, Urgency, or Harm. A passive stakeholder is one who may be affected by the project but does not actively contribute to its outcome; Miller argues they should participate through representation — e.g. a representative from an affected community judging whether the system benefits or harms them.
Question 5 of 5

State the course view of RACI and the practitioner critique of it.

Course view (Miller): a RACI responsibility-assignment matrix maps people/organisations to responsibilities and accountabilities to avoid moral hazard; accountability cannot be delegated. Practitioner critique: in practice RACI is often divisive, reinforces silos, and enables responsibility-dodging ('my name wasn't on the RACI') — so the tool meant to close the moral buffer can become one. The alternative that actually concentrates accountability is single-threaded ownership: one named, directly responsible individual per decision.

Module 6 Videos

Module 6 · Short · The Report That Made Itself Up
Module 6 · Long Form · Why AI Projects Fail

Sources

Required reading
Miller, G.J. (2025). Framework for Managing Artificial Intelligence (AI) Projects: Avoiding Harms, Losses, and Damages. In Strang & Vajjhala (eds), Springer, pp. 135–162. doi.org/10.1007/978-3-031-80275-1_7
Standard
ISO 21502:2020 — Project, programme and portfolio management — Guidance on project management.
Illustration
Mobley v. Workday — AI hiring-screening discrimination litigation (US).