Back to Resources

AI is spreading decision making but not accountability

AI is spreading decision making but not accountability

Editor's Note: This is a summary of an external article. We've captured the core ideas below to save you time, focusing on how these concepts align with modern AI deployment and intelligence layer architecture.

Picture a critical AI-driven system failing over a long weekend — misfiring on pricing, or leaking sensitive data — while most of the company is offline. In that moment, according to a recent CIO.com feature by Pat Brans, all the careful language in corporate governance frameworks tends to evaporate, and one blunt question takes over: who's actually responsible?

That question is becoming urgent as AI moves from pilot projects into real production systems. The uncomfortable truth the article lays out: AI may spread decision-making across an organization, but the law isn't likely to spread liability nearly as evenly.

The algorithm won't be the one in court

IP attorney Jessica Eaves Mathews, founder of Leverage Legal Group, makes the point that when an AI system shapes a major decision, it's the people who built, deployed, or used it who end up answering for it legally — not the system itself. The bigger problem, in her view, is that there's barely any legal precedent yet to define exactly how that responsibility gets divided among vendors, the companies deploying the tools, and executives. She compares the current moment to the early internet, when courts were still working out how old rules applied to new technology — and predicts a handful of high-profile cases will end up defining the rules for everyone else.

One point she's clear on: buying the system from a vendor isn't likely to work as a legal shield. Responsibility tends to land on whoever was in the best position to prevent the harm — usually, that's the organization actually using the AI in its operations.

Why it lands on the CIO's desk

Even though CIOs rarely "own" AI on paper, they typically own the infrastructure it runs on — which is why, in practice, they're often the ones left holding the bag when something breaks. Chris Drumgoole, president of global infrastructure services at DXC Technology, describes a familiar cycle: business teams start experimenting with AI informally, adoption speeds up faster than proper controls, and then something fails — at which point everyone turns to the CIO first to fix it, then to explain it.

That dynamic is made worse by "shadow AI" — employees using AI tools on their own, outside any formal process — which creates risks around data leakage and compliance that go well beyond old-fashioned shadow IT.

Distributed governance, concentrated blame

Ojas Rege of OneTrust argues that no single department can realistically own AI governance end-to-end, since it touches legal, compliance, risk, IT, and the business all at once. But he's clear that responsibility for outcomes still needs to rest with whoever owns the business results, even if AI is doing part of the work. In reality, though, governance ends up fragmented across departments — and Simon Elcham of Trustpair frames the risk simply: AI doesn't remove responsibility, it just multiplies the number of places where something can go wrong.

Can a Chief AI Officer fix this?

Some companies are experimenting with formal Chief AI Officer roles to bring order to the chaos. At Hi Marley, CTO Jonathan Tushman expanded his role to include CAIO duties, deliberately splitting responsibilities: one team builds and runs internal AI systems, product leadership owns AI inside the actual product, and legal/compliance act as an independent check. He frames the tension between these groups as a feature, not a bug — you need people pushing AI forward and others pumping the brakes, and real value comes from that friction. But even this structure has a ceiling: when teams disagree, the decision to move forward, pause, or reverse usually escalates all the way to the CEO or CFO.

The gap that's still growing

Mathews sums up the core tension: businesses are deploying AI at full production speed, while governing it at the much slower pace of committees — and that gap is where the real risk lives. Many companies still don't have a clear inventory of which AI systems are even running across their business, and shadow AI only deepens that blind spot.

The bottom line

Authority over AI may be spread across an organization, and new roles may emerge to coordinate it — but accountability doesn't stay diffuse forever. When something breaks, or regulators step in, the finger ultimately points at the executives closest to the systems involved. AI can decentralize decisions and blur how they were made, but it doesn't erase who's responsible for them. If anything, it raises the stakes.

Transform Your Business with AI Shield

Contact our experts to discuss your enterprise AI strategy.