AI Decision Rights and Accountability
When AI takes over part of a judgment, the rights people held to decide, to correct and to stop do not disappear. They move, often to someone nobody chose. Decision rights make each move deliberate: many people responsible for the work, one accountable for the outcome, authority that scales with the stakes, and no vendor or agent ever holding the enterprise's accountability.
After this chapter you can
- Explain how deploying AI moves the rights to decide, correct and stop, and why expertise does not confer the business decision.
- Distinguish responsibility for the work from accountability for the outcome, and apply five questions to any AI decision.
- Set out which AI decisions the executive team reserves, which it delegates, and which triggers move a decision up.
- Show why a vendor or an agent can carry responsibility but never the enterprise's accountability.
Picture the last page of a launch pack at a specialty chemicals maker. The company is about to let an AI demand-planning model set next quarter’s production volumes for its coatings plants. The page is a sign-off sheet, and it is impressively complete. Data quality has signed. Model validation has signed. Security, legal, procurement, IT operations and the planning team have all signed, each for its own part. Two rows remain. Next to “Accountable owner” someone has typed “TBC”. Next to “Who can switch it off?” there is nothing at all.
The sheet is invented for illustration, but many executives have signed one like it. Every signature is honest, and every team did its job. Yet when the model over-produces a slow-selling product and the warehouses fill, each signatory will be able to say, truthfully, that its part worked. The sheet records involvement. It does not record who decided, who answers for the result, or who may stop the machine.
Decision rights turn involvement into ownership
A decision right is the explicit authority to make a specific decision, with known limits and a known route for escalation. Accountability is the other half: the obligation to answer for the outcome of that decision. Peter Weill and Jeanne Ross, studying how companies governed information technology, defined governance itself in these two terms: “specifying the decision rights and accountability framework to encourage desirable behavior”1.
Their research at MIT, covering more than 300 enterprises in over 20 countries, found that firms with above-average governance had more than 20 percent higher profits than firms with poor governance pursuing the same strategy1. The study predates modern AI and shows an association rather than proof of cause. Its point still carries: the same strategy delivers different results depending on whether people know who decides.
AI raises the stakes for a simple reason. AI Operating Model, the previous chapter, showed that an operating model is a system of owners, rights, funding and routines. Of those parts, decision rights are the ones AI disturbs most directly, because an AI system does not only support a decision. It takes over part of one. And every time it does, some authority that used to sit with a person moves somewhere else.
AI moves decision rights whether you plan it or not
Economists worked out the logic of decision rights long before machine learning. In 1992 Michael Jensen and William Meckling argued that every organization faces two problems when it hands out decisions. The first is assignment: who should hold each right. The second is control: how to make sure the holder uses it in the organization’s interest. A right works best where the relevant knowledge sits, so an organization either moves the knowledge to the decision-maker or moves the right to the person who has the knowledge. Either way, the right has to come with a way of measuring and rewarding how it is used2.
That framing exposes a common AI mistake. The data scientist holds deep knowledge of the model: how it was trained, where it is weak, what its error rate means. The commercial director holds a different kind of knowledge: which customers matter, which errors the business can afford, what a bad quarter would cost. Expertise in the model does not confer the right to make the business decision. It should inform that decision, loudly and early, and the person who holds the right should be the one who can weigh the trade-offs and answer for them.
A decade earlier, Eugene Fama and Michael Jensen had split any decision process into four steps: initiation, ratification, implementation and monitoring. Proposing and carrying out a decision they called decision management; approving it and checking how it turned out they called decision control. In complex organizations, they argued, the two should not sit in the same hands3.
AI tends to collapse that separation without anyone deciding to. A team proposes a model, builds it, tunes it, deploys it and then reports on how well it is doing. Nobody intended the same group to initiate, ratify, implement and monitor, but nobody stopped it either. The result is not bad people. It is a decision process with no control half, which is why problems surface late and land on whoever happens to be nearest.
Many are responsible; one is accountable
Two words do most of the work in this chapter, and organizations use them as if they meant the same thing. Responsible means doing the work. Accountable means owning the result and holding the authority to decide.
Go back to the chemicals maker. The data team is responsible for the pipeline. Engineering is responsible for running the model. The vendor is responsible for the software it licensed. The planners are responsible for using the forecast sensibly, and finance and risk for their reviews. Six responsible parties is normal for an AI system. But the outcome the system exists to improve, the right volume of the right product at each plant, needs one accountable owner. Here that is the supply-chain director.
Construction has a useful name for this. On a large building, dozens of specialists design parts of the structure, from foundations to steel connections, and many of them are excellent. One licensed engineer of record seals the structural drawings and answers for the whole. Specialists contribute; the seal does not move to them because they know their part better. Every consequential AI system needs an engineer of record on the business side, and everyone working on it should know who that is.
The familiar shorthand is RACI: responsible, accountable, consulted, informed. Paul Rogers and Marcia Blenko of Bain offered a sharper version, RAPID, which separates who recommends, who must agree, who performs, who gives input and who decides. In their scheme the decider is “the single point of accountability who commits the organization to action”, and the right to agree is a veto that must be used sparingly, because whoever holds it must offer an alternative or escalate4. Either tool helps. Both fail the same way: a matrix in which every decision has twelve stakeholders and five approvers, so that everyone is consulted and nobody decides.
Five questions make the rights explicit
The practical tool is short enough to use in any meeting. For each consequential AI decision, ask five questions.
Who decides? Who executes? Who is accountable for the outcome? Who must be consulted before the decision? Who must be informed after it? In most cases the decider and the accountable owner are the same person; when they differ, the gap should be deliberate and written down. If any answer is unclear, the decision will either stall or be made by whoever happens to speak first.
The questions apply to decisions, not to systems as a whole. A single AI system generates many decisions: whether to build it, whether to launch it, what it may do without a human, when a change needs fresh review, and when to retire it. Each can have a different decider. What Is AI Governance?, in Module 07, lists the full set of rights an AI system needs, and notes that the right to stop is the one most often left blank. The story later in this chapter shows what happens when it is.
Authority should scale with the stakes
Executives face a balance here, and both extremes fail. If every AI decision goes to the center for approval, a queue forms and teams start working around it. If every team decides for itself, risk builds where nobody can see it. Rogers and Blenko found that decisions most often stall at four boundaries: global versus local, center versus business unit, function versus function, and inside versus outside partners4. AI decisions often cross several of them at once, which helps explain why they stall so readily.
The healthy position is to delegate with boundaries and to set the approval thresholds in advance. A short list of decisions belongs to the executive team: the AI ambition, major investments, the risk appetite, dependencies on a single critical supplier, and any use with large consequences for customers or employees. The accountable owner of a system holds the decisions about that system: whether it launches, how much it may do on its own, and which business risks it will accept. Much more is delegated to qualified teams, such as configuration, prompt design, implementation and monitoring, within standards set centrally. Delegation is how an organization gets speed.
Thresholds are what make the delegation safe. Each delegated right should state its limits and the conditions that move a decision up a level automatically: material harm to customers, regulatory uncertainty, a new dependency on one supplier, or behavior outside agreed bounds. Agree those triggers before the first crisis, not during it. Executives already run money this way through a delegation of authority, as What Is AI Governance? points out. The mechanics for AI are taught where they belong: risk tiers in AI Inventory and Risk Classification, the evidence each approval gate needs in AI Evaluation and Approval Gates, and limits on what an agent may spend or do in Agentic AI and Autonomous Actions, in Module 06.
Vendors and agents carry responsibility, never accountability
Two shortcuts tempt many organizations: handing accountability to the supplier, or to the AI itself. Neither works.
A vendor can be responsible for its service under a contract, and a good contract makes that responsibility precise. It is not accountable for your decision to use that service on your customers. AI in Customer Service, in Module 05, recounts how a Canadian tribunal in 2024 rejected an airline’s argument that its website chatbot was responsible for its own words5. Regulators take the same line.
An agent sharpens the point because it does not only advise; it acts. Someone decided which actions it may take, even if nobody wrote the decision down, and that decision has an owner. Designing an agent’s authority means writing down five things: what it may do alone, what a human must review, when it must escalate, who owns the outcome, and what gets logged. Model and Third-Party Risk covers how to manage supplier exposure; this chapter’s claim is narrower and firmer.
Story: the point Wimbledon had to replay
In October 2024 the All England Club announced that, from the 2025 Championships, live electronic line calling would replace line judges on every match court, ending 147 years of tradition. The club’s chief executive, Sally Bolton, said the technology was “sufficiently robust” after testing at the 2024 tournament7. About 300 line judges were replaced; around 80 stayed on as court assistants, without the power to make calls8. Strictly, the system was not modern AI. It was camera-based ball tracking, ten cameras per court, and Bolton later stressed that “it’s not an artificial intelligence system” [@register-wimbledon-elc-2025; @bolton-elc-human-error-2025]. For decision rights the distinction barely matters. An automated system had taken over a judgment people used to make.
On Sunday 6 July 2025, on Centre Court, Anastasia Pavlyuchenkova led Sonay Kartal 4-4 in the first set and held game point. A Kartal shot landed long. No call came. The chair umpire, Nico Helwerth, stopped play, consulted the review official and announced that the system “was unable to track the last point”, so the point would be replayed. Pavlyuchenkova went on to lose the game and told the umpire, “They stole the game from me”9. She went on to win the match 7-6, 6-4.
The club chose the third option. Its statement said the live system, “which was working optimally, was deactivated in error on part of the server’s side of the court for one game”, and that three calls had been missed10. It apologized to both players. It did not reinstate line judges; in Bolton’s words, “We didn’t need to put line judges back on the court again. We needed the system to be active.” And it changed who held the switch: the club “removed the ability for Hawk-Eye operators to manually deactivate the ball tracking”11.
Read the episode through this chapter and three lessons stand out. First, when automation took over the calls, a right moved without anyone deciding it should. The power to switch off the decider sat with an operator role nobody thought of as a decision-maker, and Bolton herself named four parties with a part in the failure: the operator, the chair umpire, the review official and the Hawk-Eye official who should have alerted the umpire11. Many were responsible. Second, the club behaved as the accountable party. It spoke and apologized in its own name and did not pass the error to its supplier, even though the switch that failed belonged to the operators of the supplier’s system. Third, the fix was a decision-rights fix, not a technology fix. Nothing about the cameras changed. A right was removed from one role.
The fix also leaves an open question, and a good one for any leadership team. If nobody on court can now switch the system off, who holds the authority to suspend it when it genuinely malfunctions, and how fast can that person act? Pavlyuchenkova argued that the umpire could have called the ball himself10. Whether he had that right was unclear even to the players. That is what an unassigned right looks like from the outside.
What this means for leaders
Decision rights are the executive team’s own work. A technology team can build a sign-off workflow; it cannot appoint a business owner, set the risk appetite or decide which decisions the executive team keeps. Every AI deployment redistributes some authority, so the useful question is never whether rights will move. It is whether you will choose where they land.
Check yourself
- If a vendor’s model caused the error, the vendor is accountable for the outcome.
- The person who understands the model best should hold the right to make the business decision.
- A decision with many people responsible for the work can still have exactly one accountable owner.
- If twelve people were consulted, the decision was well governed.
- Every AI decision should be approved centrally to keep risk under control.
- Wimbledon fixed its line-calling failure by changing who held a right rather than by changing the technology.
Reflection
What comes next
Clear rights let a strategy execute. Execution, though, is not the same as advantage: competitors can buy the same models and copy the same governance. The next chapter, AI and Competitive Advantage, asks when AI creates an edge that rivals cannot easily reproduce, and when it simply raises the bar for everyone.
Laws referenced
Not legal advice. Laws change; verify before relying on this, and consult counsel for decisions.
EU AI Act · EU
Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744
Risk-based rules. Prohibited practices include social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). High-risk systems (Annex III: biometrics, safety components of critical infrastructure such as energy, water and traffic, employment and worker management, credit, education, essential services, law enforcement, migration, justice) need risk management, data governance, documentation, logging, human oversight, human oversight that keeps people able to understand the system, notice automation bias (over-reliance on its output), override it or stop it (Art. 14(4)), appropriate accuracy, robustness and cybersecurity (Art. 15), automatic logging of events (Art. 12), a provider quality-management system (Art. 17) and conformity assessment. An Annex III system is not high-risk if it poses no significant risk of harm, for example a narrow procedural or preparatory task that does not replace human assessment; systems that profile people are always high-risk, and a provider relying on this exception must document it and register (Art. 6(3)). Deployers of high-risk AI must use it as instructed, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents (Art. 26); employers must inform workers' representatives (Art. 26(7)). Public bodies, private providers of public services, and deployers of credit-scoring or life and health insurance pricing systems must carry out a fundamental-rights impact assessment before first use (Art. 27). Providers must run post-market monitoring (Art. 72). A deployer that puts its name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk takes on the provider's obligations (Art. 25(1)). A substantial modification (Art. 3(23)) of a high-risk system needs a new conformity assessment, unless the change was pre-determined and documented at the first assessment, as with planned continuous learning (Art. 43(4)). Providers of general-purpose AI models (from 2 Aug 2025) must keep technical documentation, have a policy to comply with EU copyright law including text-and-data-mining opt-outs, and publish a sufficiently detailed summary of training content (Art. 53). Research, testing and development before a system is placed on the market or put into service is outside the Act, except testing in real-world conditions (Art. 2(8)). Since the 2026 Omnibus, the Art. 4 AI-literacy duty is an obligation of effort (take measures to support literacy), not of result. Fines reach EUR 35 million or 7% of global turnover for prohibited practices.
- 2024-08-01 — Entered into force
- 2025-02-02 — Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply
- 2026-07-27 — Omnibus softens Art. 4: providers and deployers must take measures to support AI literacy; no specific level must be guaranteed
- 2025-08-02 — General-purpose AI model obligations apply; governance and penalties regime in place
- 2026-08-02 — Transparency duties (Art. 50) apply: disclose AI interaction, label synthetic and deepfake content (marking for generative systems already on the market: 2 Dec 2026)
- 2027-12-02 — High-risk obligations for Annex III systems (e.g. hiring, credit, education, essential services) - moved from 2 Aug 2026 by the 2026 Omnibus
- 2028-08-02 — High-risk obligations for AI in products regulated under Annex I
Last verified 2026-10-06 · official text
References
- Peter Weill and Jeanne W. Ross. IT Governance: How Top Performers Manage IT Decision Rights for Superior Results. Harvard Business School Press. 2004.
- Michael C. Jensen and William H. Meckling. Specific and General Knowledge, and Organizational Structure. In L. Werin and H. Wijkander (eds.), Contract Economics, Blackwell. 1992.
- Eugene F. Fama and Michael C. Jensen. Separation of Ownership and Control. Journal of Law and Economics 26(2), 301-325. 1983.
- Paul Rogers and Marcia Blenko. Who Has the D? How Clear Decision Roles Enhance Organizational Performance. Harvard Business Review, January 2006. 2006.
- Civil Resolution Tribunal (British Columbia). Moffatt v. Air Canada, 2024 BCCRT 149. CanLII. 2024.
- European Parliament and Council of the European Union. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union. 2024.
- Al Jazeera (reporting the All England Lawn Tennis Club announcement). Wimbledon to replace tennis line judges with electronic system from 2025. Al Jazeera. 2024.
- Feng Li. Wimbledon's electronic line-calling system shows we still can't replace human judgment. The Conversation. 2025.
- The Register. Game, set, botch: AI umpiring at Wimbledon goes long. The Register. 2025.
- SportsPro. Wimbledon apologises after electronic line-calling tech failure. SportsPro. 2025.
- Outlook India (Associated Press reporting). Wimbledon blames human error for Hawk-Eye glitch in electronic line-calling controversy. Outlook India. 2025.
Further reading
- Paul Rogers and Marcia Blenko. Who Has the D? How Clear Decision Roles Enhance Organizational Performance. Harvard Business Review, January 2006. 2006.
- Peter Weill and Jeanne W. Ross. IT Governance: How Top Performers Manage IT Decision Rights for Superior Results. Harvard Business School Press. 2004.
- Michael C. Jensen and William H. Meckling. Specific and General Knowledge, and Organizational Structure. In L. Werin and H. Wijkander (eds.), Contract Economics, Blackwell. 1992.
Sources last verified 2026-10-08.