For many organisations, AI accountability will first become real not through an enforcement notice, but through a question.
Does AI touch the product or service we are buying?
Does AI influence recruitment, assessment or monitoring?
How is the board governing AI risk and opportunity?
What does “human oversight” actually mean in practice?
The difficulty is that there is rarely one simple answer. AI may already be embedded in software the organisation buys. Different systems may touch different decisions. Some risks arise from how the organisation deploys the technology; others arrive embedded in the model or product it has been supplied.
Reassurance becomes a claim.
Blanket silence carries a different risk. Once procurement, diligence, employees, investors or media begin asking direct questions, saying nothing can be read as uncertainty or absence of governance.
The strongest position begins with evidence. Know where AI sits, what it touches, what the organisation controls, what depends on suppliers, what has been tested and what remains uncertain. Then decide what to say.
Four different problems are often collapsed into one debate.
Bias, discrimination, fraud, surveillance, abusive synthetic imagery, privacy loss and unfair decisions. AI can change the scale, speed and reach of harms we already understand.
The system may work as intended; the problem is the user’s objective. Powerful AI can increase the capability of bad actors in fraud, cyber operations, surveillance and potentially dangerous weapons-related activity.
More autonomous systems may find unforeseen routes to an objective: exploiting loopholes, bypassing controls, obtaining credentials, modifying code or taking actions that were not intended.
The most uncertain category: whether future systems could become sufficiently capable and autonomous that meaningful human control becomes difficult. Uncertain does not mean irrelevant.
Much of existing law reaches artificial intelligence at the point where it is deployed: the employer, lender, insurer, public authority or business using the system.
The absence of a single UK AI Act does not mean an absence of law. Depending on the use and the facts, existing data protection, equality, employment, consumer, sector-specific and public-law obligations can already bear on AI-touched activity and decisions.
For central government, transparency has already moved further. The Algorithmic Transparency Recording Standard is mandatory for government departments and in-scope arm’s-length bodies, and for qualifying algorithmic tools with significant influence on public-effect decisions or direct interaction with the public.
But the cause of a harmful outcome may sit much further upstream. A model developer controls some capabilities. A product company determines how those capabilities are packaged and constrained. An integrator decides what the system connects to. A deployer determines how it is used in practice.
Parliament’s Joint Committee on Human Rights has recommended differentiated obligations across the AI lifecycle and supply chain, alongside stronger scrutiny of high-risk and powerful systems. Those recommendations are not yet UK law.
That matters to external positioning. A company cannot credibly explain the safety, limitations or oversight of a system if critical information stops with its supplier. An AI provider cannot credibly treat every downstream consequence as somebody else’s problem while controlling the evidence its customers need.
Building the environment creates responsibilities of its own.
The analogy with social media is imperfect but useful. Regulation eventually moved beyond a binary argument about whether platforms were responsible for everything users posted. It began examining the systems and processes through which harms were created, amplified and managed.
AI takes the question further because the system can contribute directly to the outcome rather than merely distribute somebody else’s content.
The model may be developed in one country, run on infrastructure in another, incorporated into a product elsewhere and deployed across Britain and Europe. The person attempting to misuse it may be anywhere.
Countries will keep different laws. But evaluation standards, incident information, dangerous capabilities and minimum safeguards cannot sensibly stop at borders.
Capability, evaluation, safeguards and the evidence made available downstream are central. The external challenge is to explain capability without exaggeration, safety without false certainty and uncertainty without making the product impossible to trust.
Some risk comes from the underlying model; some from your own product design, permissions, integrations and data. Distinguish what you have established yourself from what you rely on the model provider to tell you.
Credit, insurance, recruitment, claims, public services and assessment create immediate questions about fairness, transparency, contestability and whether human review is meaningful in practice.
You may be an AI deployer without having consciously decided to become one. The first challenge is discovery: where is AI operating, what does it affect, what does the supplier know, and what changes when the model changes?
Drafting, research, analysis, coding and summarisation generally create a lighter position, but clients and counterparties may still ask whether AI touches the work they receive and how confidentiality and review are controlled.
The board does not need to understand every model architecture. It does need to know where consequential AI sits, what the organisation depends on, who owns the risk and what evidence supports the external account.
A customer may ask whether AI touches the product they are buying. An employee may care whether it affects hiring or monitoring. An investor may focus on governance and operational risk. A regulator may ask for evidence about a particular decision. A procurer may ask about evaluation, data and suppliers.
Identify which risks bear on your position, what you need to understand upstream, what others may need from you and what you should be able to evidence.
If anything on this page looks wrong, incomplete or unclear — particularly a regulatory status, source or description of where responsibility sits — please tell us.