Your legal team has thought about AI liability. They’ve probably built a framework around it.
They probably haven’t thought hard enough about the scenario where the liability is clear and there’s nothing to sue.
This is the quiet liability that keeps me engaged with this space: not what happens when someone gets wronged by your AI system, but what happens when everyone knows someone got wronged and there’s nobody to hold accountable.
The accountability dissolution problem
Here’s the pattern: Your organization deploys an AI system. It makes a bad decision. Someone is harmed. The decision was technically made by the AI system, which is a tool.
Your company says: “We didn’t make the decision. The model did. We relied on the model’s recommendation because it had been validated and it was operating as designed.”
The individual who was harmed says: “I was harmed. Someone should fix this.”
Your company says: “We didn’t intend harm. We built reasonable controls. The model was performing as expected.”
The individual says: “I don’t care about your controls. I was denied credit, fired, or denied medical treatment. Someone should be accountable.”
At this point, the organization has an accountability void. The individual was harmed. The organization says it didn’t make the decision (the model did). So who made the decision?
Usually the answer is: nobody. The decision happened. Nobody made it. Nobody can be held accountable.
This is different from negligence liability, where you could argue the organization was careless. This is structural liability, where you could argue the organization constructed a system where decisions happen without anyone deciding.
Why this matters legally
You might think: “This is actually good for us. If nobody made the decision, nobody can be held liable.”
That’s backwards. Courts and regulators care about this differently than you’d expect.
The emerging pattern in how regulators and courts approach this is: If you’ve deployed a system that makes decisions affecting people, someone at your organization bears responsibility for those decisions.
The legal challenge is that companies are trying to distribute responsibility so widely that it disappears. The model recommends. A human reviews (but only if there’s time). The system flags concerns (but only for certain kinds of concerns). Business rules override the model (in certain cases).
At each step, someone is supposed to be responsible. In practice, nobody is.
A lending officer reviews a model recommendation for a loan that gets denied. If they just accept the recommendation without independent judgment, they haven’t made a decision. They’ve deferred to the model. If something goes wrong, can you hold them accountable for a decision they didn’t make? Not really.
A compliance officer reviews the model for bias. They check statistical metrics, see that the model is performing as expected overall, and approve deployment. Six months later, the model is producing disparate impact. The compliance officer says: “I reviewed it carefully and it was performing as expected.” The business says: “We followed the compliance officer’s assessment.”
Who’s accountable? Nobody really. Everybody did their job.
How regulators are approaching this
The regulatory approach is starting to shift. Instead of asking “who made the bad decision,” they’re asking “why did your system make a bad decision without anyone noticing?”
The focus is moving from individual accountability to system accountability.
Organizations that have been through regulatory reviews often discover a pattern. A regulator asks: “Your lending model denied this application. Walk me through how someone with decision authority reviewed this recommendation.”
The organization responds: “Our model is trained to be reliable. We monitor it quarterly. If it falls below performance thresholds, we retrain.”
The regulator pushes back: “That’s not what I asked. Someone made this specific decision. Tell me who. Tell me what they knew. Tell me what decision authority they had.”
The organization can’t answer, because nobody actually had decision authority for that decision. The model recommended it. If the recommendation fell outside certain parameters, it escalated to a human. But in this case, it didn’t. So the decision happened without anyone deciding.
The regulatory position is clear: “You can’t build a system where decisions happen without someone deciding. Either the model has authority (in which case you need to defend the model’s decision) or someone has authority (in which case you need to show they exercised it).”
This is the liability that most companies haven’t thought through. Not “the model was wrong,” but “nobody had the authority to decide this, yet a decision was made.”
Why traditional frameworks miss this
Most companies approach AI liability through the lens of traditional product liability. You build something, it fails, you’re liable if you were negligent. Your defense is: “We were careful. We tested it. We built reasonable controls.”
This works fine for physical products. A car has a brake failure, you’re liable if you failed to test the brakes adequately.
It doesn’t work for AI systems because the question isn’t just whether the system was tested, but whether anyone was actually responsible for using it.
A framework that addresses traditional product liability but doesn’t address decision authority liability is incomplete.
Organizations usually have the product liability framework: testing, monitoring, control standards. They rarely have the decision authority framework: who decides what, under what authority, with what information.
What actually protects you
The liability structure that actually protects an organization isn’t “we have no responsibility because the model decided.” It’s “someone in the organization had clear authority and responsibility, and they made a conscious decision.”
This sounds crazy until you realize what it means: You’re more protected legally if you have one person who decides “we’re going to use this model and here’s why I’m comfortable with that decision” than if you have elaborate controls but nobody clearly deciding.
The elaborate controls are good. But they don’t protect you if they’re controls without decision authority.
Organizations that handle this well usually:
1) Make decision authority explicit
There’s a person (not a committee, ideally not a meeting) who has the authority to decide “we use this model for this decision.”
2) Document the conscious choice
That person writes down (or records) why they made that choice. What did they know about the model? What risks were they accepting? What monitoring would they put in place?
3) Hold people accountable for that decision
If something goes wrong, the question is: Was that decision reasonable given what was known at the time? Not: Did the model fail? Did the model work properly?
4) Design escalation appropriately
If the model produces an unexpected outcome, there’s a clear escalation path. Someone with authority reviews it. They decide whether to override, whether to investigate further, whether the original decision authority still stands.
The liability protection comes from showing that someone thought about the risks and decided to proceed anyway. Not from showing that you had no responsibility.
What this means for governance
This fundamentally changes how you should think about AI governance.
It’s not just about frameworks and controls. It’s about clear decision authority and conscious choice.
If your governance structure is a matrix of approvals where nobody clearly decides, you’re building liability, not protecting against it.
If you have clear decision authority and clear documentation of conscious choice, you’re in a much better position.
This is why the accountability structure from Day 31 matters. If you don’t have clear decision authority and clear escalation processes, you’re not just failing at governance—you’re building legal exposure.
Where to start
If you have AI systems in production, start here:
For each system, answer: – Who has the authority to decide whether we deploy this? – What did they know about the model’s risks when they decided? – If something goes wrong, who reviews that outcome and decides what to do?
If you can’t answer these clearly, you have a liability problem. Not because your model is bad, but because nobody decided to use the model.
Fix that first, before you invest in more controls or more comprehensive frameworks.