Assigning an owner for AI risk is common advice by now, and rightly so. What’s less understood is that this is moving beyond best practices. AI adviser and emeritus professor Paul Noon explores the named accountability requirements in the UK, which can apply not just to technical AI experts but to senior managers across the business.
Most compliance and risk leaders never applied for the job of “named AI accountability owner.” A growing number are getting it anyway — not through a title change but through the ordinary mechanics of oversight regimes that were not built for AI but are being pointed squarely at it anyway.
The clearest example is happening in UK financial services right now, and it is more striking than a new job title. When the UK Financial Conduct Authority and the Bank of England’s Prudential Regulation Authority consulted on the senior managers and certification regime and whether AI needed its own distinct prescribed responsibility under the senior managers and certification regime a few years ago, the feedback ran against creating one.
So the regulators confirmed something more consequential instead: The senior manager already accountable for a business area is automatically accountable for how AI is used inside it, whether or not anyone ever asked them to own that specifically.
That means the senior manager responsible for retail lending decisions is accountable for the AI used in retail lending decisions. Nobody updated a job description or signed a new appointment letter. That person, frequently someone who already holds a compliance or risk oversight function, now has to be able to show they took reasonable steps to oversee that system and can be personally investigated and sanctioned if they cannot.
Not every organization sits inside the senior managers and certification regime, but the underlying pattern is spreading well beyond financial services. When something goes wrong with an AI system and a regulator or a court starts asking who was accountable, they do not start with an org chart. They start with the trail: Who raised the risk internally, who had oversight of that function, who reviewed the output and signed off. In most organizations, that trail runs straight through compliance and risk, whether or not anyone formally assigned it there.
Note I didn’t say they’ll look first for your policy document. You need one, yes, but that only states the rules; it doesn’t answer the questions regulators will ask after the fact. Organizations that haven’t answered the who in all those questions are leaving it open to whomever is in the room when it counts.
Put the General Counsel in Charge of AI Strategy
The conventional play for enterprise AI strategies is IT leads, committees advise, everyone weighs in. That produces strategies that live in slide decks and die in execution, writes Eric Dodson Greenberg, Cox Media Group’s chief legal officer.
Read moreDetailsDelayed EU AI Act doesn’t buy time
It is tempting to read the recent EU AI Act timeline change as room to breathe. In June, the Council of the EU gave its final sign-off to the digital omnibus package following the European Parliament’s endorsement earlier in the month. Those moves confirm that high-risk obligations for stand-alone systems are deferred to December 2027, and that AI embedded in regulated products is deferred further to August 2028. That is a genuine, now-final change, not a provisional one, which does provide some relief.
But it only moves one clock. It says nothing about the clocks that were never tied to that deadline in the first place.
In the UK, for example, Section 80 of the Data (Use and Access) Act 2025 came into force in February 2026, replacing part of the GDPR, that gives individuals a right to transparency, human review and to contest automated decisions made about them. That obligation is live for any organization using AI in hiring, credit, insurance or similar automated decisions, regardless of what the AI Act’s high-risk deadline says. The AI Act’s own Article 50 transparency obligation, requiring disclosure that a person is interacting with an AI system, is also unaffected by the omnibus delay and went into effect just this month.
New tech, same governance fundamentals
When boards ask me to review their AI governance, three gaps show up more often than any others, and none of them require a new law to become a problem.
- The first is no named owner. Plenty of organizations have an AI policy but nobody who could tell you, without checking, who is accountable if a specific system produces a biased or harmful output next week.
- The second is no documented risk register with an owner attached to each entry. A list of the AI tools in use is a start. A list with a named accountable person for each entry, reviewed on a defined schedule, is a governance record a regulator or a court can actually rely on.
- The third is a review cadence that exists on paper but produces no real discussion. An AI update tacked onto the end of a routine meeting, with no substantive minutes, is not evidence of oversight. It is evidence that oversight was scheduled then skipped.
None of these gaps are technical or require specialized AI knowledge. They are the same governance fundamentals that compliance and risk functions already apply to every other material risk category. The difference is that AI is moving much faster than most governance calendars.
These aren’t simple matters, but organizations can start with a simple question asked out loud before the next use of AI goes live: If this goes wrong, who is the named person who was watching it, and can they prove it?


Paul Noon, OBE, is emeritus professor of AI and innovation and a former deputy vice chancellor at Coventry University in London. He advises UK boards on governance and AI strategy. 








