You have 0 free articles left this month.
Corporate Counsel

The AI Accountability Gap: No Ownership, No Evidence, No Defence

July 31, 2026 By Candy Lau, Partner, and Tessia Tan, Associate, Ironbridge Legal
Share this article on:
expand image

As frontier AI adoption accelerates, APRA's 30 April 2026 letter to industry and ASIC's 8 May 2026 open letter have prompted plenty of commentary on regulatory expectations. Boards must govern AI. Risk frameworks must keep pace. Cyber controls must be uplifted. The direction is clear.

What the commentary hasn't answered are the more confronting and practical questions:

  1. In your organisation, right now, who is actually accountable when something goes wrong during or as a result of the use of an AI model?

  2. If a regulator asked your organisation today for evidence that your AI controls are actually working, what can you produce?

Neither question has an easy answer. Let's tackle them one by one.

1. Everyone's Risk, No One's Responsibility – Who’s Accountable When AI Goes Wrong?

For most organisations, in financial services, healthcare, energy, retail and beyond, the honest answer is no one. That gap itself invites regulatory scrutiny.

Consider a typical bank, insurer or superannuation trustee deploying AI at scale. The Chief Information Officer owns technology infrastructure. The Chief Data Officer governs data pipelines. The Chief Risk Officer owns the risk framework. Legal reviews vendor contracts. Compliance monitors obligations. Every one of these functions touches AI risk. None owns it end-to-end.

The result is a fragmented architecture in which responsibility for an AI model's full lifecycle (e.g. procurement, deployment, monitoring and decommissioning) is scattered across teams with no shared framework or escalation path. When something goes wrong, accountability is either contested or absent entirely.

Would creating a new Chief AI Officer role be the solution? It may or may not. What matters is whether a single line of oversight exists, with well-defined roles and clear handoffs. APRA's April letter names a lag in governance maturity as AI adoption increases as a key concern, with specific gaps in lifecycle management. It also flags a tendency to treat AI risk as an ordinary technology risk, thereby missing what actually sets AI risk apart: predictive modelling, adaptive behaviour, embedded bias, and heightened privacy exposure.

Tellingly, APRA lists clear ownership and accountability across the AI lifecycle as a minimum governance expectation, not an aspiration. This isn't hypothetical. Existing regimes, including the Financial Accountability Regime, CPS 234, CPS 230, and the Australian privacy framework already apply to AI use. As illustrated by recent Federal Court judgments, cyber resilience is not simply ‘nice to have’ – it is a core regulatory obligation for licensees and market participants.

The Architecture of Accountability

There is no single correct model and the right design will vary depending on an organisation’s size and complexity. But a defensible accountability structure for AI risk needs to address three things clearly:

  • A designated owner. An explicit, documented mandate covering the full AI lifecycle, and clearly linked to the entity's accountability and risk governance framework.

  • Clear handoff points. Defined boundaries between Chief Information Officer, Chief Data Officer, business units and other risk owner(s), with documented escalation triggers relating to what constitutes a material model change, what requires the risk owner’s sign-off before deployment, and what automatically gets escalated to the board.

  • Independent challenge at board level. Board-level visibility that isn't filtered through the functions being overseen. Board reporting should include independent challenge, whether from internal audit, external technical assurance, or a board-level AI advisory function. Ultimately, the operational realities of AI within the organisation should reflect its risk appetite.

2. Can You Prove It – The Evidence Perspective

A governance framework is only the starting point. Regulators will ask for evidence: that controls exist, that assurance is ongoing and proportionate, and that both can withstand scrutiny. APRA has found AI adoption outpacing governance, assurance and security capability, and the gap cuts across operational risk, cyber, data governance, model risk, legal compliance and privacy alike.

Traditional assurance - sample, test, report periodically - was built for stable, deterministic systems. AI is often probabilistic and can drift or degrade silently between reviews. Critically, a single point-in-time assessment says little about current performance. The better alternative is “assurance-by-design”: ongoing, near-real-time validation embedded into AI systems, with every autonomous decision logged against a clear evidence trail of who authorised it, what testing occurred, and how bias and error were assessed.

Again, there is no single correct operating model. The design will vary with the scale and complexity of AI systems in use and the criticality of the decisions they support. However, a refreshed assurance approach should address three aspects clearly if it is to produce credible evidence:

  • Continuous, embedded monitoring. Ongoing validation in place of periodic, point-in-time reviews.

  • Human ownership of AI-enabled assurance. Judgment, professional scepticism and assurance findings remain with accountable people, with documented records of what AI-generated assurance output was relied on, who reviewed it, and why it was accepted or challenged.

  • Traceable performance gates for higher autonomy systems. AI starts assisted, earns autonomy only through logged evidence of stability, low error and control, with every gate documented and auditable.

Ask Before the Regulator Does

Put these two questions to your C-suite:

  1. Who owns AI risk in our organisation, and what does that ownership specifically cover?
  2. For each AI model we have in production, what assurance do we have that it is performing as validated, and when did that assurance last detect an issue?

The Strategic View

Accountability and assurance are not just compliance checkboxes. Reframed as a proactive discipline, they become a source of competitive confidence: organisations that can demonstrate defensible assurance will adopt AI further and faster, and earn the trust of regulators, boards and customers alike.

Regulators across Australia, Europe, the UK and US now expect assurance that's operational, measurable, auditable. That only works when someone owns it and evidence proves it.

Name the owner. Build the trail. Do both, and you're not just regulator-ready, you're setting the terms on which AI gets trusted.
.

Get in touch with our team to discuss whether your AI governance arrangements are ready for regulatory scrutiny. Click Here


Authors:
Candy Lau, Partner, Ironbridge Legal
Tessia Tan, Associate, Ironbridge Legal

LW discover
Latest articles