Essay · AI governance·6 min read

The accountability gap in AI governance

Policy frameworks were written for systems that produce advice. Increasingly we are deploying systems that take steps. That shift, not model capability, is where most governance frameworks quietly stop working.

Share X LinkedIn

When an AI system recommends something and a person acts on it, accountability is straightforward: the person decided. When the system searches, drafts, files, and sends on its own, the decision is distributed across a prompt, a toolset, a vendor's model, and whoever last approved the deployment. Ask who is responsible and you get four plausible answers, which in practice means none.

This is not a theoretical worry for me. Building agentic workflows means watching an autonomous loop do something reasonable-looking for the wrong reason, and realising that no existing document in the organisation says who owns that outcome.

01

Name a person, not a committee

Every deployed system should have one named owner who can be asked, in plain language, why it made a decision — and who has the authority to switch it off. Distributed responsibility reads well in a policy document and dissolves the moment something goes wrong.

02

Regulate the action, not the model

Model-tier thresholds date badly; the consequence of an action does not. A system that drafts a memo and a system that approves a loan deserve different oversight even when they share the same weights, so tie obligations to what the system is permitted to do on its own.

03

Make the audit trail a build requirement

Accountability after the fact is only possible if the prompts, tool calls, and intermediate outputs were recorded at the time. Logging is cheap to specify before launch and effectively impossible to reconstruct afterwards — which is why it belongs in procurement terms, not in guidance.

04

Write rules an implementer can pass or fail

"Meaningful human oversight" is untestable. "A named reviewer must approve any outbound payment, and the approval is logged" is testable. Governance that cannot be turned into an engineering checklist ends up being satisfied by paperwork rather than by practice.

Why this matters for emerging markets

Much of the agentic tooling now reaching African businesses arrives as a hosted product with no local accountability surface at all — no named owner in-country, no logs the buyer can inspect, no way to contest an automated outcome. Governance here has less to do with restricting frontier research and more to do with insisting that whoever deploys a system can explain and reverse what it did. That is a procurement question as much as a legislative one.