Pillar 06 of seven
Accountability
Accountability means a named party answers for the system, while the responsibilities for its design, deployment, operation, controls, and oversight are explicitly allocated and traceable.
What it means
Accountability is the property that for every AI system and every AI decision there is an identifiable party who is accountable for it, with the authority and the information needed to discharge that responsibility. It is the pillar that binds the other six together, because a control without an owner is not a control. The EU AI Act expresses accountability through the allocation of obligations between providers and deployers, the documentation and record-keeping duties of Art. 26, and the registration requirements that make high-risk systems visible to supervisors.
Accountability has a structural dimension and an evidential dimension. Structurally, it requires a clear allocation of roles: who owns each system, who performs oversight, who signs off on deployment, who is accountable to the board and to the regulator. Evidentially, it requires that the discharge of these responsibilities leaves a trail. An organization that cannot say who approved a given model, or cannot produce the records of how it was governed, has an accountability failure regardless of how well it performed on the other six pillars.
Why it matters
Accountability is the pillar a supervisory authority tests first, because it is the gateway to everything else. The opening question in any examination is "who is responsible for this system, and show me the evidence of how it was governed". An organization that answers that question crisply, with named owners and a coherent record, signals a program under control. An organization that cannot answer it signals the opposite, and invites the deeper scrutiny that surfaces every other weakness. Diffuse accountability, where everyone is vaguely responsible and no one is specifically accountable, is the most common root cause of governance failure.
Governing accountability
The controls establish ownership before deployment and preserve the evidence of governance throughout the lifecycle. This pillar depends heavily on the discipline of record-keeping, which is unglamorous and routinely neglected.
| Control layer | Control |
|---|---|
| Preventive | Maintain an AI inventory that names, for every system, the accountable owner, the oversight function, and the risk classification. Allocate roles formally: system owner, oversight personnel, approver, and the executive accountable to the board. Require documented sign-off before any high-risk system enters use, and verify EU database registration where Art. 49 and Art. 26.8 apply. |
| Detective | Audit the inventory for completeness, including the shadow AI that enters through procurement and departmental tooling without governance. Verify that documentation and records are current, not merely present. Review whether named owners are discharging their responsibilities or holding the title in name only. |
| Corrective | Where a system is found without an owner, assign one and bring it into governance before continued use. Where the record is incomplete, reconstruct it and fix the process that allowed the gap. Treat a recurring documentation failure as a program-level issue, not an individual lapse, and address the underlying process. |
- PrincipleClear, named ownership
- HarmDiffused responsibility, "no one owns it"
- RiskLikelihood of a gap, combined with its consequence
- ControlNamed owners, governance structure, and roles
- EvidenceRole register and a decision audit trail
* Article references are verified against the consolidated text of Regulation (EU) 2024/1689 and, where cited, Regulation (EU) 2016/679. The pillar itself is a general responsible-AI principle; these articles are where it anchors in EU law.
Accountability is controlled by naming who owns each system and decision, and proven through a role register and an audit trail of who decided what.
Assign named ownership per system and define roles, escalation, and the three lines of defense.
Maintain a decision trail and a role register so responsibility can always be located.
An agent takes a chain of actions across systems, often without a human at each step. Accountability has to survive that: who answers when the agent made the intermediate decision that caused the harm.
Assign a named owner to every agent, accountable for its mandate and limits, and define liability before it goes live.
Attribute every action to the agent, its owner, and its mandate, so "the agent did it" is never an answer on its own.