Who is accountable if an AI system causes harm or makes a bad decision?
Answered
Your organisation (the controller) remains accountable for data-protection compliance. Name an SRO as the primary risk owner, plus data and AI asset owners. Senior management and DPOs cannot leave this to engineers. Record the SRO as a role title, not a named individual, on ATRS records.
From the guidance
Primary (how) Data and AI Ethics Framework
Section: Set clear roles and responsibilities
Read this in Data and AI Ethics Framework (opens in new tab)
Secondary (normative) ICO: Accountability and governance implications of AI
Section: How should we approach AI governance and risk management?
Read this in ICO: Accountability and governance implications of AI (opens in new tab)
Secondary (normative) ATRS: Guidance for public sector bodies
Section: Owner and responsibility (Tier 2)
Read this in ATRS: Guidance for public sector bodies (opens in new tab)
Secondary (normative) AI Playbook for the UK Government
Section: Accountability
Read this in AI Playbook for the UK Government (opens in new tab)
Related questions
- How often should we formally review an automated decision-making system? Lawful, ethical and responsible use
- How do people challenge or seek redress for an AI-influenced decision?
- How do I monitor an AI system once it is live?
- Should we monitor AI system inputs as well as outputs?
- How do I keep an inventory of AI systems in my organisation?