AI is not responsible: the organization that uses it is. When a wrong output creates damage (customer, decision, compliance), someone must be able to answer. If that is unclear, the risk stays systemic.
The problem is not technical—it is ownership
In practice many companies have:
- a team that “put AI in place”;
- users who use it;
- no clear name for who answers for quality and consequences.
Research and surveys from 2025–2026 show that a relevant share of organizations have no formal AI oversight roles. When an incident arrives, responsibility becomes collective—and therefore, in effect, nobody’s.
The AI Act and GDPR do not remove this problem: they make it more explicit. Whoever puts a system into production must be able to demonstrate accountability.

What operational accountability means (not only policy)
Useful accountability means:
- A clear name for every relevant system or use case (who is Accountable for the outcome).
- Predefined escalation rules (when to stop, who decides, who communicates).
- Enough traceability (who used what, on which sources, with which output).
- A periodic review process (not only at launch).
You do not need an ethics committee from a large bank. You need clarity proportionate to risk.
Three practical levels for an SME
Level 1 – Individual assisted use
Personal or company tools with strong human supervision. Accountability stays mainly with the user + basic policy.
Level 2 – System integrated into a process
E.g. document search, ticket classification, report generation. You need a process owner + someone responsible for source and output quality.
Level 3 – Automatic or semi-automatic actions
Agents that modify data or take decisions. Here you need tight permissions, human-in-the-loop on critical points, and a named Accountable person.
How to assign it without bureaucracy
- Inventory real AI use cases (including “shadow” ones).
- For each, note: risk, process owner, who validates quality, who intervenes if something goes wrong.
- Write 5–10 operational rules (not a 40-page policy).
- Train people on the “why”, not only on the ban.
- Review every 6–12 months or after relevant incidents.
Clarity reduces both legal risk and internal resistance: people know what they can do and who answers.
FAQ
Can AI be legally “responsible”?
No. Responsibility stays with the organization and the people who govern and use it.
Do you need a full-time AI Officer in an SME?
Not necessarily. You do need someone with explicit ownership (often the process owner or a combined IT/compliance role).
What if a wrong output has already created a problem?
Have a predefined escalation path, accessible logs, and the ability to reconstruct sources and decisions. It is much harder to improvise afterward.
Does accountability slow adoption?
On the contrary: when it is clear and proportionate, it increases trust and reduces hidden uses (Shadow AI).
Sources
- Regulation (EU) 2024/1689 – AI Act: responsibility framework and obligations.
- KPMG and 2026 survey on AI agent accountability: need for operational governance.
- General accountability and RACI principles applied to AI (enterprise practice 2025–2026).
Dig deeper in the series
- Deployer vs provider under the AI Act
- AI Act: practical company guide
- Data security and Shadow AI
- From pilot to production
If you want to map existing AI use cases and assign ownership and escalation rules in a light, operational way, we can run a half-day workshop. Write to info@zendata.it or visit zendata.it.
Pietro Ciattaglia, CEO of Zendata AI, Rome

