Essay · The accountable human
Who Answers When an AI Agent Gets It Wrong?
The question every company asks after its first agent incident. Liability is who pays, and courts will sort that slowly. Accountability is who answers, and most agent deployments have a vacant seat where that person should be.
It is the question of the year in every legal and industry conversation about AI agents, usually asked right after a specific agent has done a specific wrong thing to a specific customer: who answers for this? Notice the verb. Not who pays, that is liability, and courts and insurers will grind through it on their own timescale. Who answers: who explains, who owns the fix, whose judgment was on duty. Liability is being litigated. Accountability is being ignored, and the ignoring is a design choice that most companies do not remember making.
Two questions wearing one trench coat
Liability is backward-looking and financial: after the harm, allocate the cost. Accountability is forward-looking and personal: before and during the operation, a named human whose judgment governs and who can be asked why. The distinction matters because you can settle liability completely and still have a system nobody answers for; indemnities and insurance move money, not judgment. I wrote about the perverse version of this in Accountability Inversion: structures that concentrate blame on whoever touched the system last while dissolving answerability for everyone who designed it. The buyer's question, who answers, is how you detect that structure before it detects you.
Walking the chain
Take an agent that just made a bad call and walk the chain looking for the person who answers. The model provider answers for the model in general and disclaims your use in particular; read your terms. The platform that hosts the agent answers for uptime. The vendor who sold the agent answers, carefully, for the marketing claims. Your own engineering team answers for the integration. And the decision itself, the actual judgment that went wrong, belongs to none of them, because each can truthfully say the same sentence: I did not make that call. They are all correct. The chair where the caller of the call should sit is empty, and it was empty by default, not by decision.
The named-human principle
The fix is not a committee, a policy, or a fourth dashboard. It is a name. For every class of consequential decision an agent can make, one human whose name attaches to that class: who set its limits, who reviews its exceptions, who can halt it, who answers when it is wrong. Names do what structures cannot. A committee diffuses; a name concentrates. And the person named will immediately demand the two things every accountable human needs, which is how you know the principle is working: the authority to actually intervene, which is the human-in-command problem, and a record that shows what really happened, which is the evidence problem. An accountable human without evidence is a scapegoat with a title, the crumple zone I have written about before.
What an answerable deployment looks like
Concretely: every agent capability is mapped to a decision class; every class has a named owner with real authority; the escalation path from agent to owner is built and timed, not aspirational, because an escalation that takes a day is a postmortem, not an escalation; and the record keeps what the agent did, what it was running on, and what the human decided, kept in a form both sides of a dispute can cite. This is the architecture HumanChain exists to make routine: the hard call reaching a qualified, answerable human while the call is still warm. None of it is exotic. All of it is uncomfortable, because it converts a vague institutional risk into a set of names, and organizations flinch from names.
The question to ask before the incident
If you deploy agents, run the drill now: pick your worst plausible agent decision and ask who answers, by name. If the room goes quiet, you have your finding, and it cost you nothing. If the incident runs the drill for you, the same finding arrives with a customer attached, then a journalist, then a regulator, each asking the identical question in ascending order of publicity. Who answers is not a philosophy prompt. It is the first question of the rest of the decade, and the companies that thrive will be the ones that answered it while it was still cheap.
A last word to the executives who find this framing heavy: the named-human principle is also a shield. When the incident comes, and the drill has been run, and the record shows a real person exercising real judgment within real limits, that is the best defensible position a company can occupy in public. Nobody defends a diffuse process. Everybody understands a person who owned the call and can explain it.
Read on
The structural trap: Accountability Inversion. The four conditions of real control: Human-in-Command. When the agent acts alone: when the AI agent acted alone.