Autonomous AI in Operations: The Accountability Questions the Board Must Resolve
Article series: Limits of delegating to AI systems (Part 1)
AI now shapes operational decisions across companies: credit assessment, supply chain steering, customer interaction, compliance monitoring. In all these areas, companies deploy systems that use trained models and, depending on their design, adapt while running. For boards, the question goes well beyond technology: how do we secure accountability when decisions are only partly predictable and cannot be fully governed in advance?
Legal scholarship and ethics have debated this for over two decades. Andreas Matthias coined the term responsibility gap in 2004: situations in which classical attribution, built on direct control and foreseeability, reaches its limits. Markwalder and Simmler showed in 2017, from a criminal law perspective, that negligence and attribution come under particular strain with autonomous systems. Foreseeability, avoidability and adequate causation grow harder to prove in practice the more autonomous and adaptive a system becomes.
The debate has moved on. Santoni de Sio and Mecacci (2021) identify four interlinked dimensions: gaps in culpability, moral accountability, public accountability and active responsibility. These can arise even without any ‘learning’, for instance through organisational or regulatory shortfalls. Hindriks and Veluwenkamp (2023) shift the focus: not every situation is a responsibility gap. Often it is a control gap, the discrepancy between the control a system exercises and the control it should exercise; responsibility then often sits indirectly with design, operation or regulation. For the board, the label matters less. The governance requirement stays the same.
The stakes rise sharply with systems that adapt in operation (reinforcement learning, online learning), with agentic systems, or with models whose decision logic cannot be explained in a traceable way. Most AI in use today is either ‘frozen’ (parameters fixed after training and unchanged in operation) or rule-based. But exactly where autonomous systems promise the greatest value, the need for governance is highest: clear limits, oversight and accountability.
What this means for the board
AI governance is part of the board’s overall direction. The board does not need to build models. It does need to decide which degree of autonomy is acceptable. And which controls apply to it.
Art. 716a para. 1 OR sets out the board’s non-delegable duties (overall direction, organisation). Art. 754 OR establishes liability for breach of duty (breach, damage, adequate causation, fault). This assumes the board has a clear view of material risks and supervises management effectively.
That is exactly where the tension sits: once systems change decision parameters in operation, the organisation can no longer reliably predict behaviour for every situation. The board remains responsible for outcomes whose origin can no longer be fully explained, and which can only be steered through governance, limits and monitoring.
Three questions every board should ask
1) Control architecture: once management no longer fully understands what a system does, new control mechanisms are needed: independent audits, monitoring, escalation protocols.
- Checkpoint: which KPIs/KRIs are defined?
- Is there a documented stop or escalation criterion, automated or manual, that limits or interrupts operation?
2) Risk acceptance: social adequacy means that not every risk amounts to a breach of duty of care, provided the accepted risk level is not exceeded. That trade-off is a governance decision and belongs with the board.
- Checkpoint: which decision types are off-limits for autonomous systems (e.g. compliance sanctions, credit rejections without review)?
- Is this documented and binding?
3) Personal duty of care: the limits of traditional attribution do not protect board members. Anyone who fails to understand risks and fails to take adequate precautions acts negligently. A technical ‘gap’ does not reduce the board’s fiduciary duty of care, it raises the bar for demonstrable governance.
- Checkpoint: what evidence exists (model cards, risk assessments, vendor due diligence, monitoring logs, audit trail)?
Tasks can be delegated, responsibility cannot
The EU AI Act has been in force since 1 August 2024 and applies in stages (fully applicable from 2 August 2026; some obligations earlier). For high-risk AI, it requires human oversight, documented risk assessments and functioning risk management. It does not apply directly in Switzerland, but it sets a de facto standard for regulated sectors. And even human oversight within a process needs to be challenged critically (see The Danger of Automation Bias: Is Human-in-the-Loop an Illusion?).
Tasks can be delegated, responsibility cannot. Anyone deploying autonomous systems must clarify, before go-live: acceptable degrees of autonomy, escalation and stop criteria, monitoring and audit trail. If an incident occurs, whether AI was involved is not what counts. What counts is which controls the board demanded and documented.
References
- Matthias, A. (2004). The responsibility gap: Ascribing responsibility for the actions of learning automata. Ethics and Information Technology, 6, 175–183.
- Markwalder, N. & Simmler, M. (2017). Roboterstrafrecht: Zur strafrechtlichen Verantwortlichkeit von Robotern und künstlicher Intelligenz. AJP/PJA, 2/2017, 171–182.
- Santoni de Sio, F. & Mecacci, G. (2021). Four Responsibility Gaps with Artificial Intelligence: Why they Matter and How to Address them. Philosophy & Technology, 34(4), 1057–1084.
- Hindriks, F. & Veluwenkamp, H. (2023). The Risks of Autonomous Machines: From Responsibility Gaps to Control Gaps. Synthese, 201(1), 21.
- Swiss Code of Obligations (OR), Art. 716a, Art. 754.
- EU AI Act, Regulation (EU) 2024/1689 (in force since 1 August 2024, fully applicable from 2 August 2026).