Accountability, Governance, and Regulation
How societies assign responsibility for AI harm and govern AI through transparency, auditing, standards, and law like the EU AI Act.
Artificial Intelligence · Lesson 5
How societies assign responsibility for AI harm and govern AI through transparency, auditing, standards, and law like the EU AI Act.
When an automated system denies a loan, misreads a scan, or steers a car into a crash, someone is affected, and a natural question follows: who is answerable? Unlike a single human decision-maker, an AI system is built, trained, sold, configured, and operated by different people, often in different organizations and countries. Responsibility can slip through the gaps between them.
Governance is the attempt to close those gaps before harm occurs and to assign accountability after it does. It is not one thing but a layered mix of company practices, technical standards, professional norms, and enforceable law. Getting the balance right is contested: too little oversight can let avoidable harms through, while rules written carelessly can burden small developers or freeze useful tools. Reasonable people weigh that trade-off differently.
Modern AI passes through many hands: the team that collects data, the lab that trains a model, the vendor that packages it, the business that deploys it, and the user who acts on its output. When something goes wrong, each party can point to another. Accountability frameworks try to name specific duties for each role so that "everyone, and therefore no one" is not the answer.
You cannot hold accountable a system you cannot inspect. Transparency ranges from disclosing that AI was used at all, to documenting training data and known limitations, to explaining a particular decision. Auditing goes further: an independent check of whether a system does what is claimed and meets stated requirements. Both have limits, because full explanation of a large model is often impossible, so governance leans on testing behavior and outcomes, not just internals.
Standards are agreed technical benchmarks, for example how to document a dataset or test for bias; they are usually voluntary but can be referenced by law. Laws are binding rules backed by penalties. Between them sit voluntary principles adopted by governments or industry that shape expectations without direct enforcement. Real governance usually combines all three.
Suppose a hospital buys an AI tool that flags likely sepsis, and it misses a case. Who is accountable? A layered view distributes duties: the developer must document the tool's tested performance and limits; the hospital must validate it on its own patients and train staff; the clinician remains responsible for the final judgment. Accountability is not a single culprit but a chain of obligations, each checkable after the fact.
It is tempting to think "just make the company that built the AI liable for everything." But consider a general-purpose model released openly and then fine-tuned by a hospital for an unapproved use. Pinning all blame on the original developer would be both unfair and counterproductive: it would discourage releasing useful tools while ignoring the party who actually chose the risky deployment. Responsibility tracks control and choice, not merely who wrote the first line of code.
Two real efforts show different governance styles. The OECD AI Principles, adopted in May 2019 by member countries and later echoed by the G20, are voluntary. They set high-level values (human-centered, transparent, robust, and accountable AI) without binding penalties, and they became a common reference point worldwide.
The European Union's AI Act takes the opposite approach: binding law with a risk-based structure. Political agreement was reached in December 2023, and the regulation entered into force in 2024, with obligations phasing in over the following years. It sorts systems by risk: some uses are prohibited outright; "high-risk" uses, such as certain medical or hiring applications, face strict requirements for data quality, documentation, human oversight, and testing; and lower-risk uses face lighter transparency duties. Supporters argue this proportionate structure protects people without banning ordinary software; critics worry about compliance cost and whether definitions will keep pace with technology. Both concerns are part of an ongoing, legitimate debate.
Take one AI failure from the news. List every party in the chain (data, model, vendor, deployer, user) and write one concrete duty each should have had. Notice how "who is responsible" turns into several answerable questions.
Think Like a Maester: Accountability is not finding one villain but making sure every hand in the chain has a duty someone can check.
AI harm is hard to pin on one person because responsibility is spread across many hands. Societies respond with layered governance: transparency and auditing to see inside, standards to define good practice, and law to enforce it. The OECD Principles (2019) show the voluntary path; the EU AI Act (agreed 2023, in force 2024) shows a binding, risk-based one. The central tension, protecting people without stifling useful innovation, has no single correct setting, and thoughtful people continue to debate where the line belongs.
Mark this lesson complete to track your progress.