Board governance

Who is accountable when AI goes wrong

If AI makes a decision that costs you money, reputation, or a regulator's trust, who answers for it? If the board cannot name that person today, it is already too late.

By Zakir Hoosen, Director, Fuzzelogic Solutions. Board-level guidance in plain English.

Every board is one bad AI decision away from a difficult conversation. The question is not whether it will happen. It is whether the board can name, right now, who carries the consequence. If the answer is "we will figure that out when it happens," you are already behind.

Accountability is not blame. It is the pre-agreed answer to the question: when this goes wrong, who speaks to the regulator, who speaks to the customer, and who speaks to the press? If no one has that job, it defaults to the chair. That is not a plan.

Why boards avoid this conversation

Boards avoid accountability because it feels uncomfortable. It means naming someone and saying: this is your responsibility, and if it fails, you will answer for it. That is easier to dodge in a slide deck than in a one-page plan. So most boards dodge it.

AI also blurs the traditional lines. If an algorithm makes a lending decision that turns out to be biased, who is responsible? The data team that built the model? The business owner who signed off on the use case? The vendor who sold the software? Someone has to lead. If no one leads, no one acts.

"21% of organisations have no AI governance at all, and governance and risk is the fastest growing barrier to adoption."

Source: Deloitte, State of AI in the Enterprise

More than one in five organisations have no governance at all. That means one in five organisations have no pre-agreed answer to the question of who carries the consequence. The fastest growing barrier to adoption is not the technology. It is the governance gap.

The four questions before deployment

Before any AI use is approved, the board should answer four questions. Not in theory. For that specific use case.

  1. Who owns this? Name a single person, not a committee.
  2. What happens when it fails? Describe the failure, not the success.
  3. Who speaks for the company? Name the person who faces the customer, the regulator, and the press.
  4. What is the stop trigger? State the specific condition that causes a halt, and who has the authority to pull it.

If any answer is "we are still working on it," the use case is not ready for deployment.

The research says boards are divided

"61% of CEOs say boards are rushing AI transformation, and around 40% of boards lack an informed view."

Source: BCG, CEOs and Boards are aligned on AI in theory but divided in practice

Boards are rushing and underinformed. Vague accountability is no accountability at all.

Classify by consequence, not by technology

Not all AI uses carry the same risk. A chatbot that summarises internal documents is not the same as an algorithm that decides who gets a loan. The Palantir white paper on agentic governance makes this point clearly: classify every AI use by what happens when it fails and whether you can reverse the damage.

  1. Consequence low, reversible. An AI tool that drafts marketing copy and gets the tone wrong. Accountability sits with the marketing lead.
  2. Consequence low, irreversible. An AI tool that sends a personalised email to the wrong customer. Accountability sits with the data owner who controls the audience list.
  3. Consequence high, reversible. An AI system that flags the wrong transactions for review. Accountability sits with the operations lead and the compliance officer together.
  4. Consequence high, irreversible. An AI system that makes a lending decision, a clinical recommendation, or an insurance pricing decision that turns out to be wrong. Accountability sits with a named director and the board must agree it before deployment.

Write it down. Put it in the one-page plan. Make it part of the governance framework. When the failure comes, and it will, you do not want the first conversation to be about who was supposed to be watching.

The Fuzzelogic approach

Fuzzelogic works with a four-step framework for responsible AI adoption: Find it, Classify it, Govern it, Train for it. Find where AI already exists in your business, often under the radar. Classify each use by what happens if it fails. Govern the ones that matter. Train the people who have to live with the result.

You already have AI in your business. You just do not know where. Before you can assign accountability, you need to know what you are assigning accountability for. The assessment takes two to four weeks, is fixed price, and you own the verdict. The governance framework that comes out of it names the people, the triggers, and the stop authority.

Fuzzelogic is an Isle of Man firm that has spent nineteen years modernising banking, insurance, healthcare, retail, manufacturing, and government platforms. We tell boards what most consultants will not: the honest answer is often that AI should not touch a process, and when that is the case, we put it in writing rather than build it anyway.

What the Anthropic CISO got right

The Anthropic CISO made a point every board should hear: "Zero risk is not the job." The most effective controls are human approval on consequential actions. That is a governance answer, not a technology answer.

If an AI system can make a decision that costs more than the board is willing to lose without a human checking it, the system needs a human in the loop. That is a board decision. Make it before deployment, not after the incident.

The cost of vague accountability

When accountability is vague, no one acts quickly when things go wrong, because everyone assumes someone else is handling it. The board spends more time on the incident than on the fix. The regulator sees the gap and treats it as a governance failure, which it is.

The antidote is simple: name the person, name the trigger, name the stop authority. Put it on one page. Review it every quarter.

The strategy worth approving is the one that survives your questions. Accountability is the question that matters most. Answer it before you need to, not after.

Start with the assessment. Two to four weeks, fixed price, and you own the verdict and the roadmap whether or not we build any of it. When you are ready to talk AI, call Fuzzelogic Solutions and ask for Zak. www.FuzzelogicSolutions.com | info@FuzzelogicSolutions.com | +44 (0)1624 618950

For the fuller picture, read how boards should evaluate an AI strategy and the one-page AI plan. The full library is on our index. Our site explains how Fuzzelogic approaches AI for business. You can reach Zak directly via our contact page.

Start with the assessment

Two to four weeks, fixed price, and you own the verdict and the roadmap whether or not we build any of it.

When you are ready to talk AI, call Fuzzelogic Solutions and ask for Zak.

www.FuzzelogicSolutions.com | info@FuzzelogicSolutions.com | +44 (0)1624 618950