Who is accountable if an AI system causes harm or makes a bad decision?

Answered

Your organisation (the controller) remains accountable for data-protection compliance. Name an SRO as the primary risk owner, plus data and AI asset owners. Senior management and DPOs cannot leave this to engineers. Record the SRO as a role title, not a named individual, on ATRS records.

From the guidance

Primary (how) Data and AI Ethics Framework

You need strong oversight and clear responsibilities to ensure accountability across the life cycle of your data or AI project. You must set out who is responsible at each stage of the project. This includes naming senior responsible owners (SROs)– as the primary risk owners for the project.

Section: Set clear roles and responsibilities

Read this in Data and AI Ethics Framework (opens in new tab)

Secondary (normative) ICO: Accountability and governance implications of AI

You cannot delegate these issues to data scientists or engineering teams. Your senior management, including DPOs, are also accountable for understanding and addressing them appropriately and promptly (although overall accountability for data protection compliance lies with the controller, ie your organisation).

Section: How should we approach AI governance and risk management?

Read this in ICO: Accountability and governance implications of AI (opens in new tab)

Secondary (normative) ATRS: Guidance for public sector bodies

The SRO should be a role title, not a named individual, for business continuity and security purposes. It should be the role which is ultimately accountable for the tool in an operational context.

Secondary (normative) AI Playbook for the UK Government

Accountability is a key principle that establishes ownership of risk, responsibility for mitigations, compliance with legislation, the ability to demonstrate compliance, and high standards for privacy.

Related questions