Accountability & decision rights

Who is allowed to deploy what, and who answers when it goes wrong.

30documents on this topic
20organizations represented
4issues named
21sourced citations
4sourced statistics

The state of it

One of 7 topics within Governance & oversight.

30 documents from 20 organizations address who is allowed to deploy what, and who answers when it goes wrong. The research is unusually blunt here, and unusually consistent: the failure is not that nobody is accountable, it is that accountability is split across roles that do not meet.

The Cloud Security Alliance puts numbers on it - funding for AI security tools is overseen by the CISO in about half of organizations, the CTO in a third, the CIO in a third - and calls the resulting fragmentation an ongoing need for clearer accountability. Heidrick & Struggles describes the same thing from the top: without explicit ownership across policy, infrastructure, business outcomes and risk, adoption becomes fragmented, and board discussions turn reactive.

The Australian Government's CAIO handbook is the one document here that separates the two words most organizations use interchangeably. It distinguishes the Accountable Official, who answers for policy implementation, from the Chief AI Officer, who drives adoption - deliberately different people wherever possible.

The issues, by agreement

How many independent organizations name each issue as a problem. An issue is only as real as the number of separate publishers that identify it, so the count is the ranking. Bars are organizations, not documents. Where the count reads ours, no publisher here states the issue and the analysis is our own.

Who takes which position

The chart above counts positions; this shows whose they are. Read down a column for what one organization holds across the whole topic, and across a row for who lines up on one issue. Where a cell carries more than one position, the strongest is shown and the rest are in the tooltip.

Ddisputes it Qqualifies it Nnames it as a problem Pproposes a fix
Accountability & decision rights: 4 issues against the 15 organizations cited on them. The number under each name is how many of these issues it is cited on.
Issue Cloud Security Alliance · 3 Heidrick & Struggles · 2 IBM · 2 Institute of Directors · 2 AWS · 1 Accenture · 1 Anthropic · 1 Australian Government · 1 Clifford Chance · 1 Deloitte · 1 McKinsey & Company · 1 NIST · 1 OpenAI · 1 PwC · 1 UC Berkeley · 1
Autonomy widens the gap between the decision and the person answerable for it N · N · · P N · N · P · · · ·
No one person owns policy, infrastructure, outcome and risk together N N Q P · · · · · · · · P · ·
Activity is being mistaken for a change in the operating model Q N · · · · · · · · · · · · N
Executives are held accountable for AI without an agreed standard of care · · · N P · · P · P · P · P ·

A dot means this organization is not cited on that issue. It does not mean they are silent on it: an organization is cited where its document takes a position we could locate, and the absence of a citation is the absence of a finding, not a finding of absence. Who is represented lists everyone working on this topic, including those not cited above.

Where they disagree

No contradictions recorded on this topic yet.

The issues in full

Each issue carries the organizations that name it, the numbers behind it, and the remedies proposed - with the concrete steps under each. Every citation points at a section of a named document, so any count here can be checked.

Issue 014 organizations name it2026 evidence

Autonomy widens the gap between the decision and the person answerable for it

The further an outcome sits from a human instruction, the harder it becomes to attribute - and agentic systems are increasing that distance faster than accountability structures are adapting.

How to fix it — 1 approach, 3 steps

Give every agent an identity that maps to a person

An action taken by an unidentified process cannot be attributed. Identity is the precondition of accountability, not a security detail.

Done when Every production agent runs under a distinct provisioned identity rather than a shared service account, each maps to an accountable human owner in the register, and agent credentials rotate and de-provision on the same schedule as human ones.

  1. Require every agent in production to run under a distinct, provisioned identity - never a shared service account.0-30 daysCISO
  2. Map each agent identity to an accountable human owner in the register.30-90 daysCIO
  3. Rotate and de-provision agent credentials on the same schedule as human ones.ongoingCISO
The evidence — 7 documents
OrganizationDocumentPosition
AnthropicFrontier lab · July 2026Anthropic’s CISO guide to agentic AIOur reading Puts identity at the centre - something acted, and you must be able to say what - with each added capability, from read-only through tool calls, code execution and network egress, widening what that identity can reach.Four questions: what actions, and on whose behalfnames it
Clifford ChanceConsultancy · May 2025Agentic AI responsibilitiesOur reading Traces accountability thinning with distance: the more steps between a person and what the system did, the harder responsibility is to attach, and rising autonomy widens the gap.The AI responsibility gapnames it
Cloud Security AllianceInstitution · July 2026Defining non-human identityOur reading Notes that non-human identities are created by systems rather than business processes and run continuously without direct human oversight: a person reading a screen and pausing between actions creates natural moments to catch a mistake, while an identity executing thousands of operations a second offers no such window.Why NHI risks differ from human identity risksnames it
IBMHyperscalerAgentic AI risk and opportunityOur reading Notes agentic systems can optimise for unintended objectives and behave unpredictably, complicating assurance and therefore attribution.Risks and key mitigations of autonomous actionnames it
AccentureConsultancy · January 2025AI agent identity managementOur reading Proposes treating agent credentials with the rigour applied to human identity, making the acting entity attributable by construction.AI agent identity managementproposes a fix
Cloud Security AllianceInstitution · July 2026Defining non-human identityOur reading Proposes that where an agent acts for a human principal its actions be scoped by that person's permissions and recorded with delegator, intent and action in the audit log, so accountability survives the delegation.Agent identities; delegated accessproposes a fix
McKinsey & CompanyConsultancyMcKinsey: Rethinking AI decision-makingOur reading Proposes holding agents to the same scrutiny as employees - measured, monitored, retrained or retired - which locates accountability with whoever owns that management loop.Governance and oversight of agentsproposes a fix

Issue 022 organizations name it1 qualifies it2026 evidence

No one person owns policy, infrastructure, outcome and risk together

Ownership is distributed across four functions that each hold one quarter of the problem, so no single person can answer for a system end to end.

Heidrick & Struggles states the consequence plainly: as AI spreads into customer interactions, pricing, hiring and operational planning, an organization must define who owns the system - and without explicit ownership across policy, infrastructure, business outcomes and risk, adoption fragments. The failure mode is not conflict but silence: each function reasonably believes another one has it.

57%Chief AI Officers reporting to the CEO or the boardIBM · Jul 2025
33%Organizations where the CIO oversees that fundingCloud Security Alliance · Sep 2025
49%Organizations where the CISO oversees funding for AI security toolsCloud Security Alliance · Sep 2025
36%Organizations where the CTO oversees that fundingCloud Security Alliance · Sep 2025
How to fix it — 2 approaches, 5 steps

One name per system, across all four dimensions

Assign a single accountable owner per production system who answers for policy, infrastructure, outcome and risk together - even where the work is done by four teams.

Done when Every production system in the register names one accountable person rather than a team, cases split across four functions record which one is accountable, and a system is reviewed when its owner changes role.

  1. Add an accountable-owner column to the estate register; a team name is not an acceptable entry.0-30 daysCIO
  2. Where four functions each hold a quarter, name one of them as accountable and say so in writing.0-30 daysCEO
  3. Review any system whose owner has changed role, at the point of change.ongoingCIO

Separate the person accountable from the person driving adoption

Keep the two deliberately distinct. Combining them puts the same person in charge of the accelerator and the brake.

Done when The Accountable Official for policy implementation and the executive driving adoption are named separately, or where they are the same person the reason and the compensating oversight are recorded.

  1. Name the Accountable Official for policy implementation and the executive driving adoption separately.30-90 daysCEO
  2. Where they must be the same person, record why and what compensating oversight applies.30-90 daysBoard Chair
The evidence — 5 documents
OrganizationDocumentPosition
Cloud Security AllianceInstitution · December 2025The State of AI Security and GovernanceOur reading Reports responsibility for AI deployment distributed across functions, with funding oversight split between CISO, CTO and CIO, and describes the fragmentation as requiring clearer accountability and coordination.AI ownership is diffusenames it
Heidrick & StrugglesConsultancyAI CEO LeadershipOur reading Ties fragmentation to ownership left unassigned across four things at once - policy, infrastructure, outcome and risk - and calls for naming who holds the system.Unclear ownership and accountabilitynames it
IBMHyperscalerC-suite synergies for AI ROIOur reading Reports 57% of Chief AI Officers reporting directly to the CEO or board, suggesting that where a dedicated role exists the ownership problem is partly addressed.CAIO reporting linesqualifies it
Institute of DirectorsInstitutionAI in the boardroomOur reading Proposes establishing board accountability explicitly and empowering a cross-functional ethics committee with the power to veto.Essential questions: establish board accountabilityproposes a fix
OpenAIFrontier lab · July 2026How to control AI usage and spendOur reading Proposes governance as the operating layer that decides which work can scale, defining what context a system may use, which tools it may reach, what actions it may take, and specifically who approves higher-risk steps.Govern advanced workflows before they scaleproposes a fix

Issue 032 organizations name it1 qualifies itnewest evidence Dec 2025

Activity is being mistaken for a change in the operating model

Pilots, centres of excellence and appointments accumulate while decision rights, budgets and escalation paths stay exactly as they were.

How to fix it — 1 approach, 3 steps

Test the change by naming a decision that moved

If no decision right, budget line or escalation path changed, the operating model did not change. Make that the test.

Done when A list names the decisions whose owner changed in the last year as a result of AI, or states plainly that it is empty, at least one funding decision has moved to the accountable owner with the authority attached, and the list goes to the board annually.

  1. List the decisions whose owner changed in the last year as a result of AI. If the list is empty, say so.0-30 daysCompany Secretary
  2. Move at least one funding decision to the accountable owner, with the authority that goes with it.30-90 daysCFO
  3. Report the list to the board annually alongside the activity metrics.ongoingCEO
The evidence — 3 documents
OrganizationDocumentPosition
Heidrick & StrugglesConsultancyAI CEO LeadershipOur reading Identifies organizations generating substantial AI activity without changing the operating model, and reframes the leadership task from strategy alone to system design.Activity without operating model changenames it
UC BerkeleyAcademic · May 2025An AI governance maturity matrix for boardsOur reading Warns that sound process fails against an unchanged culture, where AI is received as a threat to how things are already done.Dimension 5: Culture & Collaborationnames it
Cloud Security AllianceInstitution · December 2025The State of AI Security and GovernanceOur reading Reports security ownership consolidating while deployment and funding responsibility stay dispersed, and offers the consolidation as a possible structural shift rather than a settled one - its own reading of the same numbers is that fragmentation still points to a need for clearer accountability.How accountability is formingqualifies it

Issue 041 organization name itnewest evidence Apr 2026

Executives are held accountable for AI without an agreed standard of care

Boards are told to hold management accountable, but no document in this research defines what a reasonable executive was supposed to have done. Accountability without a standard is hindsight.

How to fix it — 1 approach, 3 steps

Write down what a reasonable owner is expected to have done

Convert the recurring checklist items into an explicit, testable standard, so accountability can be assessed prospectively rather than after an incident.

Done when A ratified standard states what a reasonable owner is expected to have done - impact assessment, documented data sources, recorded evaluation, review date - and owners have been assessed against it before anything went wrong.

  1. Draft the standard: impact assessment completed, data sources documented, evaluation run and recorded, review date set.0-30 daysRisk
  2. Ratify it so it is the organization's stated expectation, not one function's view.30-90 daysBoard Chair
  3. Assess owners against it annually, before anything goes wrong.ongoingRisk
The evidence — 6 documents
OrganizationDocumentPosition
Institute of DirectorsInstitutionAI in the boardroomOur reading Offers a sequence of questions - impact assessments, documented data sources, testing and removal on discovering bias, regular review - which functions as a de facto standard of care.Essential questions for your next board meetingnames it
Australian GovernmentInstitution · November 2025Gov Australia published a CAIO handbookOur reading Defines the two roles and what each is accountable for, which is the closest thing in the research to a written standard.Accountable Officials and Chief AI Officersproposes a fix
AWSHyperscaler · April 2026Governance, risk and compliance for responsible AI in financial servicesOur reading Supplies the artefact the standard of care is otherwise missing: an appetite for AI risk that the board or a committee it delegates to has actually set, approved and communicated, so what a reasonable owner was working to is on paper before anything goes wrong rather than reconstructed afterwards. Adds that the people running risk activities for these systems are expected to be trained and credentialed for it, which is itself part of what the standard would be measured against.A board-approved appetite is the written standardproposes a fix
DeloitteConsultancyStrategic governance of AIOur reading Sets out governance responsibilities across the board and its committees as an allocation model rather than leaving it to convention.Roadmap: governance and performanceproposes a fix
NISTInstitutionAI Risk Management Framework PlaybookOur reading Supplies the half of a standard of care that is hardest to write from scratch: a public catalogue of suggested actions against each outcome in the risk framework, across governing, mapping, measuring and managing. Because it is published and revised rather than internal, it can be pointed at - an owner can show which actions were taken and which were considered and declined, which is a stronger position than describing what felt reasonable at the time. It states plainly that it is neither a checklist nor a sequence to be followed entire, so adopting it wholesale misreads it.A published reference for what a careful owner would have doneproposes a fix
PwCConsultancy · May 2025AI leadership playbook overviewOur reading Positions accountability as something embedded into design, deployment and governance rather than assessed after the fact.Accountability in the leadership playbookproposes a fix

Who is represented

This dossier is drawn from 25 organizations working on the subject, 15 of which are cited directly in the issues above.

Consultancy — 10

Accenture 2 Clifford Chance 1 Deloitte 1 Heidrick & Struggles 1 McKinsey & Company 1 PwC 1 Capgemini 2 EY 1 Infosys 1 UST 1

Institution — 7

Cloud Security Alliance 3 NIST 3 Australian Government 1 Institute of Directors 1 World Economic Forum 3 Association of Corporate Counsel 1 Marketing AI Institute 1

Academic — 2

UC Berkeley 1 Carnegie Mellon SEI 1

Hyperscaler — 4

IBM 5 AWS 1 Google Cloud 1 Microsoft 1

Frontier lab — 2

Anthropic 1 OpenAI 1