The widely accepted advice for organizations navigating the complexities of artificial intelligence (AI) is to assign a clear owner for AI-related risks. While this directive has become commonplace, a deeper understanding of its implications is emerging, revealing that this is no longer merely a best practice but a burgeoning requirement with significant legal and operational ramifications. AI advisor and emeritus professor Paul Noon highlights the evolving accountability landscape in the UK, where named responsibility for AI risks is increasingly falling not just on technical AI specialists but on senior managers across the entire business. This shift underscores a fundamental change in how regulatory oversight is being applied to emerging technologies, compelling a re-evaluation of existing governance structures.

The Unforeseen Burden of AI Accountability

For many compliance and risk leaders, the prospect of becoming the "named AI accountability owner" was never part of their career aspirations. Yet, a growing number are finding themselves in this position, not through a formal title change or the creation of a new role, but through the natural evolution of oversight regimes. These regimes, originally designed for traditional business operations, are now being strategically applied to address the unique challenges posed by AI. This phenomenon is particularly evident in the UK’s financial services sector, where regulatory bodies are proactively ensuring that accountability for AI is embedded within existing senior management frameworks.

The Financial Conduct Authority (FCA) and the Prudential Regulation Authority (PRA), the UK’s primary financial regulators, initiated a consultation a few years ago regarding the Senior Managers and Certification Regime (SM&CR). The consultation specifically explored whether AI warranted its own distinct prescribed responsibility under the SM&CR. The feedback received from the industry, however, leaned against creating a standalone AI-specific responsibility. Instead, the regulators opted for a more consequential approach: confirming that senior managers already accountable for specific business areas would automatically be held responsible for the AI deployed within those areas. This decision was formalized and has profound implications for how AI governance is perceived and implemented.

The Automatic Extension of Senior Manager Responsibility

This regulatory stance means that a senior manager responsible for, for instance, retail lending decisions is now automatically accountable for any AI systems employed in that same domain. The onus does not rest on the creation of a new job description or the signing of a new appointment letter. The individual, often already holding significant compliance or risk oversight functions, must now be able to demonstrate that they have taken reasonable steps to oversee the AI system in question. Failure to do so can lead to personal investigation and sanctions. This proactive regulatory approach aims to ensure that AI is not treated as an isolated technological issue but as an integral part of the business operations for which senior leadership is already answerable.

While not all organizations operate under the stringent SM&CR framework, the underlying principle is rapidly spreading beyond the financial services sector. When an AI system malfunctions or leads to an adverse outcome, regulators and legal bodies will not solely rely on organizational charts to assign blame. Instead, they will trace the "trail of accountability." This involves identifying who internally flagged the risk, who had oversight of the relevant function, and who reviewed and approved the AI system’s output. In the majority of organizations, this investigative path will inevitably lead to the compliance and risk departments, irrespective of whether a formal assignment of AI oversight was ever made.

It is crucial to understand that a well-defined AI policy, while essential for outlining operational rules, is insufficient on its own. Such policies articulate the ‘what’ and ‘how’ but do not adequately address the critical ‘who’ when issues arise. Organizations that have not clearly defined individual accountability for AI risks leave themselves vulnerable, with the responsibility defaulting to whoever is present and able to take ownership during a crisis. This highlights the need for proactive, rather than reactive, approaches to AI governance.

The EU AI Act’s Delayed Implementation and Unforeseen Deadlines

The recent adjustments to the timeline for the European Union’s AI Act have been met with a mixture of relief and caution. In June, the Council of the EU provided its final approval to the digital omnibus package, following endorsement from the European Parliament earlier in the month. This move officially defers the high-risk obligations for standalone AI systems to December 2027 and pushes back the requirements for AI embedded in regulated products to August 2028. This represents a concrete and finalized change, offering some breathing room for businesses to adapt.

However, this timeline adjustment addresses only one facet of the evolving AI regulatory landscape. It does not account for numerous other obligations that were never tied to the AI Act’s deadlines in the first place. For example, in the UK, Section 80 of the Data (Use and Access) Act 2025, which came into force in February 2026, has already replaced pertinent sections of the GDPR. This legislation grants individuals the right to transparency, human review, and the ability to contest automated decisions made about them. This obligation is immediately applicable to any organization utilizing AI for automated decisions in areas such as hiring, credit scoring, or insurance, regardless of the EU AI Act’s deferred deadlines. Furthermore, Article 50 of the EU AI Act itself, which mandates disclosure when individuals are interacting with an AI system, is unaffected by the omnibus package delay and became effective this month. These existing and imminent regulations underscore that the pace of AI governance is dictated by multiple, independent regulatory streams.

Foundational Governance Principles Remain Paramount

When boards of directors engage with AI governance, a recurring theme emerges: the identification of persistent gaps that do not necessitate new legislation to become problematic. These fundamental governance challenges are not technical in nature and do not require specialized AI expertise to address. They are, in fact, the same core governance principles that compliance and risk functions have long applied to all other material risk categories. The key differentiator is the accelerated pace at which AI evolves, often outpacing the traditional timelines of governance frameworks.

The recurring governance gaps observed include:

  • Lack of Clear Ownership for AI Outputs and Decisions: Many organizations struggle to define who is ultimately responsible for the outcomes generated by AI systems. This includes not only the technical accuracy of AI outputs but also the ethical and business implications of decisions made or informed by AI. Without clear ownership, it becomes difficult to establish accountability when errors or biases occur.
  • Inadequate Processes for Ongoing Monitoring and Review of AI Performance: AI systems are not static; they learn and adapt over time. Organizations often lack robust mechanisms to continuously monitor AI performance, identify drift, detect emergent biases, or assess the ongoing suitability of the AI model for its intended purpose. This oversight is crucial for mitigating risks associated with evolving data patterns or algorithmic changes.
  • Insufficient Understanding of AI’s Impact on Existing Risk Frameworks: Many organizations have not fully integrated AI into their existing enterprise-wide risk management frameworks. This leads to a disconnect where AI-specific risks are either overlooked or managed in a siloed manner, failing to consider their potential interdependencies with other business risks.

These are not trivial issues, but organizations can begin to address them with a simple, yet profound, question posed aloud before the next AI application goes live: "If this AI system fails or produces an unacceptable outcome, who is the named individual who was actively overseeing it, and can they provide evidence of their oversight?" This straightforward inquiry forces a direct confrontation with the "who" of AI accountability, prompting the necessary dialogue and documentation to ensure that responsibility is clearly defined and demonstrable.

The implications of this evolving regulatory environment are far-reaching. Businesses are compelled to move beyond superficial AI risk management strategies and embed accountability deeply within their organizational structures. This requires a cultural shift where AI is viewed not as an independent technological entity but as a powerful tool whose deployment and impact are directly tied to senior leadership’s responsibilities. As regulatory scrutiny intensifies and legal precedents are established, organizations that proactively address these named accountability requirements will be better positioned to navigate the complex AI landscape, mitigate potential liabilities, and foster responsible innovation. The journey towards effective AI governance is not about adopting new technologies, but about reinforcing and adapting fundamental governance principles to the digital age.

By