Jess Montgomery, Joshua Copeland · The Pinnacle A Journal by Scholar-Practitioners 2026 · 2026
DOI: 10.61643/c79060
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Artificial intelligence (AI) system failures are often silent. Applications may remain operational and continue to generate polished outputs even as recommendations degrade, manipulated inputs alter behavior, or automated agents exceed their intended authority. This lack of transparency creates a governance vacuum, obscuring responsibility when AI systems malfunction. The primary concern is not ownership of the AI system itself, but ownership of the consequential decisions the system informs or executes. Drawing on cybersecurity incident research, AI governance literature, and legal case studies, including Robodebt and SyRI, this paper distinguishes system ownership, which concerns maintenance and operation, from decision ownership, which concerns accountability for outcomes. Further, this discussion addresses three structural failures that undermine AI accountability: capability without authority, inclusion without operational integration, and detection without execution. The common assumption that human-in-the-loop oversight provides meaningful control also is challenged, as automation bias frequently renders this safeguard ineffective. As agentic AI systems acquire greater autonomous authority, these accountability gaps become increasingly consequential. This paper proposes an AI Decision Authority Charter for each significant AI use case. The charter assigns decision rights by domain, identifies a single accountable owner for each consequential decision, defines required cross-functional participation and concurrence, and establishes escalation and containment authority before deployment. Within this distributed governance model, the Chief Information Security Officer (CISO) should possess bounded preauthorized stop-work authority when defined security conditions are exceeded. This authority does not make the CISO the owner of enterprise AI or its business outcomes; it provides the authority necessary to contain systems during security events.
No comments yet — start the discussion below.