There is a question I now put to every board I sit on: when the system you have deployed makes a consequential call — about a customer, a candidate, a price — who, exactly, answers for it? The pause that usually follows is the whole problem.
Agentic AI has crossed a line. It no longer waits to be asked; it plans, decides and acts. In doing so it has opened a gap at the centre of corporate governance — between what the machine does and who is accountable for it. In August 2025, the law stopped letting us pretend that gap was theoretical.
This is not a compliance footnote. It is, I think, the defining governance question of the decade — and the honest answer is less comfortable than most leaders hope.
You cannot fine an algorithm. So the liability stops with you.
What follows: the accountability gap, why the law puts it on people, what the EU AI Act now requires, and how to govern the machine as a discipline — not an afterthought.
Authority without accountability
An agentic system can exercise real authority. It shapes what an organisation knows, recommends what it should do, and increasingly executes the decision itself — what a philosopher would call epistemic authority. What it cannot do is be responsible. It has no duties, no conscience, nothing to lose.
That is the structural fault line under every serious AI deployment: authority without accountability. We have built tools that can act with consequence but cannot bear it — and the more of the decision we hand over, the wider the gap grows.
It is tempting to treat this as the vendor’s problem, or the regulator’s. It is neither. It is a governance problem, and it sits with whoever switched the system on.

We have built tools that can act with consequence — but cannot bear it.
No person, no liability
The law is admirably blunt here. Responsibility attaches only to a legal person — a human, or an entity the law treats as one — capable of holding rights and duties, and usually of a guilty mind. A model has none of these. You cannot fine, sue or imprison an algorithm.
So liability does not vanish; it passes through the system to the people behind it — the developer who built it, the deployer who put it to work, the organisation that owns the outcome. Europe chose this deliberately: it considered, and rejected, the idea of “electronic personhood,” precisely because it might let companies hide behind their tools. The accountability lands on people. It always did.

The law has arrived
For years, all of this was a philosophical point. As of August 2025, it is a statutory one. The EU AI Act — in force since August 2024 — now bites: its rules on general-purpose AI and governance apply, prohibited practices are already enforceable, and the obligations for high-risk systems follow in 2026.
The Act sorts systems by risk, and the stakes are not trivial: penalties reach €35 million or 7% of global turnover. Crucially for most organisations, AI used to hire, monitor and manage people is classed high-risk. If you let a system decide who gets the job, you are squarely in scope — wherever you sit, if your people or customers are in Europe.
Govern the machine deliberately
None of this is a reason to slow down. It is a reason to govern on purpose. The approaches that work treat oversight as a leadership discipline, not a legal box-tick — a simple framework, applied consistently, and paired with one non-negotiable: the absolute right to halt.
The shift in posture matters most. We are moving from human-in-the-loop — a person approving each step — to human-on-the-loop: a person who sets the boundaries, monitors the system, and can stop it. A lighter touch at higher stakes — and credible only if the off-switch is real.
The more authority we delegate to a machine, the more robust — and the more rehearsed — our right to halt it must become.

Five moves to govern the machine
I use a simple discipline — CARE — for seeing clearly, and one hard rule for staying in control. Four moves to understand what the system does; one to make sure you can stop it.
Control
Define decision rights and escalation: who may deploy a system, who may override it, and who may switch it off.
Awareness
Know the bias, impact and externalities of every system in scope — before, not after, it shapes a decision.
Responsibility
Name a human owner for each AI decision. Accountability is a person, not a policy — and never the vendor.
Evaluation
Test for equity and long-term impact, not just accuracy. What you measure is what you answer for.
The right to halt
Retain — and rehearse — the authority to stop any system. An off-switch you have never tested is not an off-switch.
Do this and AI becomes what it should be: leverage you direct, not authority you have quietly surrendered.
The machine can do almost anything now. The one thing it cannot do is answer for it. That, still, is our job.
- European Commission. “Navigating the AI Act” — obligations & application dates.
- EU Artificial Intelligence Act. Article 99 — Penalties (up to €35m / 7% of worldwide turnover).
- White & Case. “EU AI Act becomes law after publication in the Official Journal,” 2024.
- Bloomberg Law (2025) & Yale Law Journal forum (2024) — legal personhood and AI.
- NIST. AI Risk Management Framework, 2023.
