The liability doesn't move: why AI governance can't be delegated to IT

Share
The liability doesn't move: why AI governance can't be delegated to IT

I've watched this pattern repeat across financial services, investment operations, and regulated industries: the board approves an AI initiative, leadership assigns it to IT, and everyone assumes the governance problem is solved.

It isn't.

The legal accountability for AI decisions sits exactly where it always has—with the board, the company, and the individuals who deploy the system. The software can't be sued. The vendor can't absorb your liability. The AI can't appear in court.

This isn't a technical prediction. It's the current state of law.

The accountability gap most boards haven't closed

Only 36% of boards have implemented a formal AI governance framework. Just 6% have established AI-related management reporting metrics, according to the NACD's 2025 Board Practices survey.

That means 94% of boards lack basic AI oversight metrics even as they move to enterprise-wide implementation in 2026.

This isn't a technical gap. It's a fiduciary exposure waiting to materialize.

Under the Caremark doctrine, board members face personal liability if they fail to implement a functioning system for reporting or compliance, or if they consciously ignore red flags within an existing system. This Delaware precedent now extends to AI systems.

The accountability isn't theoretical. It's enforceable.

Why the IT delegation pattern fails

The standard move is to hand AI to IT because it's software, and IT handles software. The logic seems clean until you realize governance isn't about managing servers or deploying models.

It's about legal accountability for decisions those systems make.

When courts sanction lawyers for AI hallucinations, they hold counsel responsible regardless of which department selected the tool or how sophisticated the vendor's claims were. Professional responsibility cannot be outsourced to IT, no matter how capable the technical team.

The pattern I see: Legal assumes IT owns the risk because IT owns the deployment. IT assumes Legal owns the risk because Legal understands compliance. Neither owns it structurally.

The board assumes someone below them has it covered.

No one does.

There's a persistent hope that AI will eventually be granted legal personhood—that courts or legislatures will create a new category of liability that sits between human and corporate responsibility.

It hasn't happened. No judge has been asked to declare an AI system a legal person. Case law suggests that without explicit legislation, courts are unlikely to grant AI legal personhood on their own.

The philosophical debate is irrelevant to current legal reality.

AI cannot be sued. AI cannot be held liable. AI cannot satisfy legal accountability requirements.

The fiction that "the AI did it" has zero legal standing. The system that made the decision was deployed by someone. That someone is accountable.

Vendor reliance doesn't transfer liability

Using OpenAI, Anthropic, or any third-party model doesn't transfer accountability to the vendor. Federal and state agencies—including the EEOC, FTC, and state civil rights departments—have made this explicit.

Existing employment, credit, housing, disability, and consumer protection laws apply equally to AI-mediated decisions. Organizations face liability for disparate impact, failure to accommodate, or unfair practices even when they rely on third-party models.

The contract with the vendor doesn't shield you. The vendor's assurances about model safety don't protect you. The technical sophistication of the system doesn't matter.

You deployed it. You're accountable.

What governance actually requires

Governance isn't a compliance exercise. It's an operating model.

The failure mode I see most often: Legal and privacy teams write the policy, IT implements the controls, and leadership assumes governance is complete. It isn't.

Governance requires cross-functional authority, not departmental ownership. It requires decision rights that span strategy, risk, operations, and technology. It requires metrics that surface problems before they become legal exposure.

Singapore's Model AI Governance Framework for Agentic AI—the world's first national governance framework specifically designed for agentic systems—establishes that organizations remain legally accountable for their agents' behaviors regardless of voluntary compliance.

AI autonomy doesn't dilute human liability. It concentrates it.

The immutable layer

I've built governance structures for regulated investment platforms, high-stakes project recovery, and AI systems that need tamper-evidence and constitutional reasoning embedded at the substrate level.

The pattern that works: governance as infrastructure, not as policy.

You need decision rights encoded in the system. You need evidence chains that can't be altered after the fact. You need independence properties that prevent the AI from modifying its own governance constraints.

This isn't theory. It's buildable. I've implemented hash-chaining, WORM evidence structures, and constitutional layers that make governance verifiable rather than aspirational.

The technical implementation matters because governance that can't be audited isn't governance. It's documentation.

What doesn't change

Technology changes. Legal structures don't move at the same speed.

The board is accountable. The company is accountable. The individuals who deploy the system are accountable.

AI doesn't change that. The software can't appear in court. The vendor can't absorb your liability. The model can't be held responsible for the decisions it makes.

Governance is governance. People are people. Technology is software.

The liability doesn't move just because the system is more sophisticated. It stays exactly where it's always been—with the humans who decided to deploy it.

If your governance model assumes otherwise, you're building on a foundation that doesn't exist.

Read more