Who Should Lead AI Governance? The Accountability Gap No One Wants to Own
Here's a question most organisations can't answer cleanly: when an AI system does something unlawful, unfair or just plain wrong, who's actually accountable? Not in theory. In practice, with their name on the decision.
AI has moved out of the sandbox. It's making calls in recruitment, healthcare, finance, education, public administration and fraud detection. These aren't experiments anymore. They shape whether someone gets a loan, a job interview, or access to a public service. And yet the question of who actually owns AI governance tends to sit in a strange no man's land between legal, engineering, compliance and the business.
In Episode 11 of The Future State, we dug into this with a data scientist and technology law specialist. Their argument, in short: you don't just need a governance team, you need someone who can connect the team's work into a single, defensible decision.
Why nobody feels responsible for the whole system
When an AI system goes live, responsibility gets sliced up. Engineers own technical performance. Lawyers handle legal interpretation. The data protection team looks at personal data. Procurement manages the supplier. The business owner decides what the system is for.
Everyone inspects their own slice, and that's exactly the problem. Nobody stands back and asks whether the complete system is fit to deploy.
So you get failure modes that slip through every individual check:
- A model can be accurate and still unlawful.
- It can be legally permissible in principle but technically unreliable in the field.
- It can pass an overall performance benchmark while producing significantly worse outcomes for one group.
- It can claim to have human oversight when the human reviewer has no real ability to challenge the output.
Each specialist assumes someone else is watching the wider consequences. Add commercial and political pressure to ship fast, and you've got an organisation racing toward deployment with a governance gap right in the middle.
The full-stack lead, not the full-stack signer
The key idea from the episode: AI governance needs a full-stack lead, but never a full-stack signer.
What's the difference? One person coordinates the governance process and integrates the evidence from across the organisation. That's the lead. But that same person shouldn't personally validate every part of the system. You still need layered sign-off, where the people with the right expertise vouch for their piece.
Think of the lead as the one who makes sure the right questions get asked, the answers actually connect, and the deployment decision reflects all of it. Not a hero who claims to understand the model's error matrix, the discrimination law and the procurement contract all at once.
A framework is not governance
This is where a lot of organisations fool themselves. They have an AI policy, an ethics statement, a risk framework and a committee. All useful. None of it proves that a particular system was actually governed.
A framework describes what good governance should contain. Real governance produces evidence that those activities happened.
Take a principle like "AI must be fair and transparent." Nice sentence. Operational governance turns it into hard questions: Fair to whom? Measured how? On which data? Against what legal or business standard? What happens when two fairness measures conflict? Who reviewed the evidence, and could they have stopped the deployment?
As the guest put it, governance is not what an organisation says and documents. Governance is what it can prove when challenged.
That line is worth sitting with. If a regulator or a court asks you to show your working, a glossy policy document won't save you. You need records: who owned the use case, who approved it, who could challenge it, what evidence was produced, who accepted the residual risk, and what happens when the system changes.
Human oversight that actually means something
Human oversight is the classic example of governance theatre. A framework requires it, so an organisation assigns a person to sign things off. Done, right?
Not quite. The real question is whether that reviewer has enough information, training, time and authority to genuinely challenge the system. If they don't, the oversight is performative. Someone rubber-stamps outputs, and the moment it's tested in front of a court, the whole thing falls apart.
Good governance also watches the pattern. Are overrides recorded? When staff consistently reject the AI's recommendation, does anyone investigate why? That's the difference between a control that works and a statement that sounds good.
Why governance has to start before deployment
Here's a trap worth flagging. Governance that begins at deployment is barely governance at all. Once money's been spent, staff have been trained and the whole process has been reorganised around a supplier, stopping the system becomes commercially and politically painful. At that point governance turns into retrospective justification.
Good governance starts while the organisation still has real choices. It connects the proposed use case, the data, the model and the legal position early, and it captures what was examined and why the decision was made. It's not enough to intend to do the right thing. You have to be able to prove you did.
Where lawyers help, and where they can't
Lawyers are essential here. They understand duties, liability, evidence and the structure of accountability. They can spot when data protection, discrimination law, employment law, consumer protection, procurement, public law or sector regulation come into play. And they ask the question that matters most: could the organisation defend this decision before a regulator or an affected person?
But a purely legal approach has limits. A lawyer might know a system must be accurate, fair and secure without being able to judge whether the technical evidence actually shows those qualities. A technical report full of accuracy figures, confidence intervals and subgroup breakdowns doesn't, by itself, prove the right questions were tested. Was the training data representative? Is the model being used outside the context it was validated in? What's the real error rate, and can the monitoring catch a serious failure?
This is the translation problem. Data scientists speak in precise probabilities. Law is a human, experience-driven discipline. Two very different domains trying to talk to each other, and if the lawyer signs off without understanding the technical evidence, and the technical team never understood the legal exposure, that's how you get burned.
Legal sign-off without technical evidence isn't assurance. It's confidence without visibility.
So the answer to "who is accountable for AI" isn't the lawyers or the engineers. It's a governance structure where someone can read both languages, connect the evidence, and produce a decision you can actually defend.
The bottom line
AI governance leadership isn't about having more documents. It's about having someone who owns the whole picture, backed by layered sign-off from people who genuinely understand their part, with evidence you can put in front of a court. Start before deployment, make oversight real, and make sure your legal and technical teams are actually talking.
If you're a leader wrestling with how to make AI accountability real rather than performative, this is the conversation to have with your board now, not after something breaks.
Listen to Episode 11 of The Future State for the full discussion, and subscribe to the newsletter at thefuturestate.net for more on where technology, law and leadership meet.
Frequently asked
Who should be accountable for an AI system in an organisation?
No single specialist can own it alone. The best model is a full-stack lead who coordinates governance and integrates evidence, supported by layered sign-off from experts who vouch for their own part. Accountability sits with the person who owns the deployment decision, not just each isolated check.
What's the difference between an AI governance framework and actual governance?
A framework describes what good governance should contain. Actual governance produces evidence that those activities really happened. As the episode puts it, governance is not what you document, it's what you can prove when challenged.
Why should AI governance start before deployment?
Once money is spent and staff are trained around a supplier, stopping a system becomes commercially and politically hard, so governance turns into after-the-fact justification. Starting early, while real choices still exist, keeps governance a control rather than a formality.