<\/span><\/h2>\n“The agent did it.”<\/strong> A mistake is traced back and the explanation stops at the tool. This is the tribunal’s case in miniature. If your post-incident review ends with a system name instead of a role name, the remap is missing an Owner.<\/p>\nThe rubber stamp.<\/strong> A Verifier exists on paper but approves nearly everything, because the output reads well and the queue is long. A useful signal is the rejection rate: a verification step that almost never rejects anything is either reviewing unusually reliable work or not really reviewing.<\/p>\nThe orphaned chain.<\/strong> One agent’s output becomes another agent’s input, and no human owns the end-to-end result. Each step looks supervised; the whole is not. Assign ownership to the outcome, not to the individual steps.<\/p>\n<\/span>A 30-day remap for a team<\/span><\/h2>\n\n- Week 1: inventory.<\/strong> List every recurring task where an agent or AI tool now produces output that leaves the team. Ask people directly, and make clear that disclosure carries no penalty.<\/li>\n
- Week 2: name the roles.<\/strong> For each workflow, write down the Delegator, Verifier, Owner and Stop authority. Where the same person holds all four on consequential work, split at least the Verifier.<\/li>\n
- Week 3: set the verification standard.<\/strong> For each output class, define what the Verifier checks against, and start logging rejections and errors.<\/li>\n
- Week 4: run a drill.<\/strong> Pick one workflow and walk through a hypothetical error end to end: who notices, who pauses it, who explains it, which log shows what happened. Fix whatever step had no name.<\/li>\n<\/ul>\n
The result fits on one page per workflow. That page is also the document GOVERN 2.1 of the NIST framework describes, and the kind of oversight assignment Article 26(2) of the EU AI Act requires of high-risk deployers.<\/p>\n
<\/span>The CEO and the student<\/span><\/h2>\nThe CEO view.<\/strong> A chief executive cannot delegate accountability to a subordinate, and even less to software. What a CEO can do is design a structure in which every consequential output has a named owner who is competent, trained and empowered to stop it. Agents make that design job more important, not less, because they multiply the number of outputs a team produces without multiplying the number of people who can answer for them.<\/p>\nThe student view.<\/strong> The verification role is a skill, and like any skill it decays when unused. Teams that keep checking agent output against sources keep the judgement that makes checking possible. Teams that stop checking lose it, and discover the loss only when an error has already gone out. Staying the student means treating every rejected output as information about where the agent, the brief or the reviewer fell short.<\/p>\n<\/span>Frequently asked questions<\/span><\/h2>\nIf an AI agent makes a mistake, who is responsible?<\/strong>
\nThe organisation and the people who deployed and released the output, not the tool. The Moffatt v. Air Canada decision rejected the idea that a chatbot is responsible for its own statements. It is a single tribunal decision rather than a binding precedent across jurisdictions, and this is not legal advice, but its reasoning matches the logic of the EU AI Act and the NIST framework.<\/p>\nDoes the EU AI Act apply to the agents my team uses?<\/strong>
\nArticle 26 applies to deployers of high-risk AI systems, such as systems listed in Annex III, which includes certain employment uses. Most agents used to draft, summarise or research are not high-risk. Following the digital omnibus amendment in force since 27 July 2026, the Annex III high-risk obligations apply from 2 December 2027. The AI literacy duty in Article 4 has applied since 2 February 2025 and was amended to require measures that support AI literacy.<\/p>\nShould employees disclose when they use AI for their work?<\/strong>
\nFrom an accountability standpoint, yes. Invisible delegation means the manager’s view of who did what is wrong, and a risk that cannot be seen cannot be managed. The KPMG study found 57% of employees had hidden AI use or presented AI output as their own, which usually signals unclear rules rather than bad faith.<\/p>\nDoes every AI output need a second reviewer?<\/strong>
\nNo. Match the review to the consequence. Internal drafts can be checked by the person who briefed the agent. Output that reaches customers, affects money, or informs decisions about people should have a Verifier who is not the Delegator.<\/p>\nWhat is the minimum viable version of this?<\/strong>
\nOne page per agent workflow naming the Owner, the Verifier and the person who can stop it, plus a simple log of errors. That covers the core of what both frameworks ask for.<\/p>\nHow long should agent logs be kept?<\/strong>
\nFor high-risk systems under the EU AI Act, deployers must keep automatically generated logs under their control for at least six months unless other law provides otherwise. For ordinary workflows, keep logs long enough to reconstruct any output that could still be challenged.<\/p>\n<\/span>Sources<\/span><\/h2>\nRegulation (EU) 2024\/1689 of the European Parliament and of the Council (Artificial Intelligence Act), Articles 4, 14, 26 and 113, Official Journal of the European Union, 12 July 2024, and the consolidated text of 27 July 2026.<\/p>\n
Regulation (EU) 2026\/1744 amending Regulation (EU) 2024\/1689 (digital omnibus on AI), Official Journal of the European Union, 24 July 2026.<\/p>\n
National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1, January 2023, GOVERN categories 2 and 3.<\/p>\n
Nicole Gillespie, Steven Lockey, Tabi Ward, Alexandria Macdade and Gerard Hassed, Trust, attitudes and use of artificial intelligence: A global study 2025, The University of Melbourne and KPMG, 2025.<\/p>\n
Moffatt v. Air Canada, 2024 BCCRT 149, Civil Resolution Tribunal of British Columbia, decision of 14 February 2024.<\/p>\n
Stanford Institute for Human-Centered Artificial Intelligence, Artificial Intelligence Index Report 2025, Chapter 3, Responsible AI.<\/p>\n
\nThis content was compiled with the support of AI following in-depth research, then written and prepared for publication by the CEOtudent editorial team.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"When an AI agent does the work, the accountability does not move to the agent. A Canadian tribunal said so in plain words when an airline argued its chatbot was responsible for its own statements. Inside organisations, though, the responsibility map is quietly dissolving: in a 48,340-person global study, 66% of employees said they had relied on AI output without evaluating it and 56% said they had made mistakes in their work because of AI. This piece joins those behaviours to what the EU AI Act and the NIST AI Risk Management Framework already require, and gives managers a role-by-role remap for work that agents now perform.<\/p>\n","protected":false},"author":1,"featured_media":325954,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,18],"tags":[],"class_list":["post-325952","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-is","category-strateji"],"_links":{"self":[{"href":"https:\/\/ceotudent.com\/en\/wp-json\/wp\/v2\/posts\/325952","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ceotudent.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ceotudent.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ceotudent.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ceotudent.com\/en\/wp-json\/wp\/v2\/comments?post=325952"}],"version-history":[{"count":0,"href":"https:\/\/ceotudent.com\/en\/wp-json\/wp\/v2\/posts\/325952\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ceotudent.com\/en\/wp-json\/wp\/v2\/media\/325954"}],"wp:attachment":[{"href":"https:\/\/ceotudent.com\/en\/wp-json\/wp\/v2\/media?parent=325952"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ceotudent.com\/en\/wp-json\/wp\/v2\/categories?post=325952"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ceotudent.com\/en\/wp-json\/wp\/v2\/tags?post=325952"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}