Most AI governance frameworks tend to follow a familiar pattern: the board sets the high-level policies but rarely dives deeper than the executive summary; the audit committee reviews details intermittently; delivery teams focus on building and launching the system; and somewhere in between exists the ethics or governance function, tasked with reading the fine print, coordinating across teams, and reporting upward.
When an AI system causes tangible harm, pinpointing responsibility is rarely straightforward, because every layer of this structure played a role in the decision-making process that led to production.
What often happens next is troubling: the ethics or governance function becomes the default scapegoat, simply because it has a job title and a person attached, while others in the hierarchy maintain plausible deniability.
This injustice is compounded by the fact that this function typically lacks formal power to change course; it’s real authority lies in documenting concerns ahead of time.
Thus, the measure of success is not whether its advice was followed, but whether it can produce documentation warning of risks. Putting such heavy responsibility on a role is both unfair and ineffective.
This issue highlights why establishing a reporting line with genuine authority is critical, and it is the very first step we take when asked to advise organisations.
It is not about bigger budgets or grander titles; it is about creating clear, documented channels and escalation paths that endure even under the pressure of launch deadlines.
An ethics function designed to be the fall-back team does a disservice to its team members and, more importantly, leaves the organisation dangerously exposed, as real risks slip through unchecked while everyone assumes someone else already caught them.