The Accountability Gap at the Heart of AI

Posted on July 22, 2026

0


Person reaching toward a glowing blue energy sphere held by a robotic arm in a dark laboratory

Before a nation deploys a new weapon, Article 36 of Additional Protocol I to the Geneva Conventions requires it to determine whether that weapon would be lawful under international law. Should AI face its own Article 36 moment?  It is a simple but powerful principle, before delegating the ability to cause significant harm, independent scrutiny is required.

Whilst I have referenced this before (AI’s Tightrope Walk, When Capability Starts to Look Like a Weapon) the latest OpenAI debacle over the loss of control of its AI creations I feel it is time to ask whether frontier AI deserves an equivalent standard.

Today’s AI systems are no longer just productivity tools. They are increasingly being entrusted with decisions that influence healthcare, finance, critical infrastructure, military operations and national security. In many cases, the real question is no longer whether the software functions correctly but whether it can be trusted with the authority it has been given.

Current AI regulation largely emphasises documentation, transparency and corporate governance. Yet for organisations worth hundreds of billions of dollars, financial penalties alone risk becoming just a cost of doing  business rather than a meaningful deterrent. A stronger model would focus on accountability.

Before deploying high consequence AI, organisations should be required to undergo an independent assurance process that evaluates the system’s intended authority, operational boundaries, failure modes, security, governance and residual risk. Crucially, a named executive should personally certify that assurance.

Where executives knowingly bypass mandatory assurance, conceal material risks or recklessly deploy systems capable of causing significant harm, the consequences should extend beyond corporate fines to include personal civil and, where appropriate, criminal liability, together with disqualification from holding future executive or technology leadership positions.

The future challenge is not regulating AI itself. It is ensuring that those who delegate authority to autonomous systems remain personally accountable for the consequences of that decision.

The delegation of autonomous decision making should never transfer the non-delegable duty of care owed by those who authorise its use.

Qui facit per alium, facit per se

(He who acts through another, acts himself)