AI agents are moving beyond analysis and recommendations. They can now screen candidates, approve transactions, adjust prices, select suppliers, and initiate operational actions. As artificial intelligence gains decision-making authority, one question belongs at the top of every board agenda: Who is accountable when an AI-made decision causes harm?
The short answer is clear: accountability remains human. An AI system cannot accept legal liability, exercise fiduciary responsibility or answer to customers, regulators, and employees. The organisation deploying the system—and the leaders authorising its use—remain responsible for its outcomes.
What Is AI Accountability?
AI accountability is the assignment of clear human responsibility for the design, deployment, supervision and consequences of an AI system. It requires organisations to identify who owns each AI use case, who can approve or override its decisions and who must respond when something goes wrong.
This distinction matters because automated decisions can appear objective while reflecting incomplete data, hidden bias, incorrect assumptions or poorly defined business goals. Delegating a task to AI does not delegate accountability.
In Switzerland, the Federal Data Protection and Information Commissioner confirms that the Federal Data Protection Act applies directly to AI-supported data processing. Individuals may also have rights concerning decisions made solely through automated processing. Swiss businesses operating in or serving the European Union must additionally assess their obligations under the EU AI Act, which applies risk-based requirements to AI providers and deployers.
Who Is Responsible for an AI Decision?
Responsibility should be distributed clearly but never diluted.
The board is accountable for oversight, risk appetite and ensuring that AI governance supports the organisation’s strategy and values. Executive leadership owns the business outcomes of AI deployment. Technology and data teams are responsible for system performance, security, data quality and monitoring. Legal, compliance and risk teams must assess regulatory and ethical exposure. The business owner using the AI should remain answerable for the final decision.
A useful governance principle is simple: every AI agent must have a named human owner.
What Should Boards Do Now?
Effective AI governance does not mean reviewing every algorithm. It means creating decision rights and controls proportionate to risk. Boards should require management to:
- Maintain an inventory of AI systems and their business purposes.
- Classify each system by its potential financial, legal, operational and human impact.
- Assign a named executive owner to every material AI use case.
- Define when human approval is mandatory and when AI can act autonomously.
- Record inputs, outputs, overrides and incidents to support traceability.
- Test systems regularly for accuracy, bias, security and unintended consequences.
- Establish escalation, appeal and shutdown procedures.
These measures align with the NIST AI Risk Management Framework, which helps organisations govern, map, measure and manage AI risks, and with ISO/IEC 42001, the international standard for AI management systems.
The Boardroom Principle for Responsible AI
The central governance question is not whether AI made the decision. It is whether the organisation can explain why that decision was permitted, who supervised it and how affected people can challenge it.
AI agents may enter the boardroom, but they should never create an accountability vacuum. The organisations that benefit most from autonomous AI will be those that combine machine speed with human judgment, documented controls and visible executive ownership.
The Swiss CxO Forum supports executives and SMEs in navigating responsible digital transformation through knowledge-sharing, mentoring and practical leadership dialogue.

