When the machine decides: AI accountability and legal responsibility
When an AI system makes a consequential decision and something goes wrong, the question is not whether someone is accountable. The question is who. Following the Data (Use and Access) Act 2025, it is now a statutory requirement to be able to demonstrate an answer before harm occurs, not after.
The fundamental legal position
English law does not recognise AI systems as legal persons. An AI cannot be sued. Whatever a machine decides, recommends or generates, the legal responsibility for its outputs rests with the humans and organisations who designed, deployed and depended on it. Automation does not dilute legal responsibility; it intensifies it. ‘The AI made the decision’ is not a defence. It is a description of a governance failure.
What the DUAA 2025 requires
The Data (Use and Access) Act 2025 introduces a new framework for automated decision-making under UK GDPR. Decisions that have legal or similarly significant effects on individuals are subject to safeguards, with the legislation defining solely automated decisions as those taken without meaningful human involvement. This places greater emphasis on the ability of organisations to demonstrate competent human oversight, independent judgement and accountability when using AI-assisted decision-making tools.
A rubber stamp is not meaningful involvement. A governance record that shows human sign-off without documenting the basis for that review will not satisfy the statutory standard. Research suggests that a majority of organisations expect AI-related litigation to increase in the next two years. The governance documentation question is not theoretical.
Mapping the accountability chain
AI accountability in project environments involves multiple parties. The developer or provider is responsible for system design, training data quality and documented behaviour. The deploying organisation is responsible for appropriate use and ongoing oversight. The project professional carries professional accountability for the governance decisions within their programme, including which AI systems to use, what validation processes to apply and how AI outputs are presented to boards.
These accountabilities are concurrent, not sequential. A project professional cannot discharge their accountability by pointing to the vendor’s documentation. They are accountable for how the system was used and what oversight was applied to its outputs.
The rubber-stamp problem
The most common governance failure in AI-enabled project environments is the rubber stamp: a human signing off an AI recommendation without meaningful review. This can happen for entirely understandable reasons. Time pressure, cognitive load, deference to algorithmic authority and a governance culture that treats sign-off as a formality rather than a substantive act.
But the rubber stamp does not discharge accountability. It compounds it. Under the DUAA standard, the sign-off that does not involve genuine review is not just a governance weakness. It is evidence of a failure to meet the statutory duty. Project professionals need governance processes that make genuine review the default, not the exception.
Practice checklist
- Map your accountability chain: For each AI tool in your governance environment, document clearly who is responsible for design, deployment, ongoing oversight and specific decision governance.
- Document the basis for sign-off: Governance records should note not just that a human approved an AI-assisted decision, but on what basis: what they reviewed, what they queried and what independent judgement they applied.
- Train governance participants: Board members and governance leads need to understand what meaningful human involvement requires, and what it means for their professional accountability. This is not optional.
- Review vendor contracts: Ensure AI vendor contracts allocate liability clearly for system failures, hallucination events and misrepresentation of capabilities. Do not assume the standard terms are adequate.
- Do not rubber-stamp: Build governance processes that make genuine review of AI outputs the default. Time pressure and cognitive load are predictable conditions: design your governance for the reality, not the ideal.
0 comments
Log in to post a comment, or create an account if you don't have one already.