What does accountability require of a board once a model can act?

On 22 May 2019 the OECD Council, meeting at ministerial level, adopted the Recommendation on Artificial Intelligence. It was the first intergovernmental standard on AI. The Council revised the definition of an AI system on 8 November 2023, and revised the Recommendation again on 3 May 2024 so that it would still match the technology, including generative systems. In the current text, an AI system is a machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions. Those outputs can influence physical or virtual environments. Systems differ in autonomy, and in whether they keep adapting after they are deployed.
That definition already includes tools a board will not think of as "a model". A feature that drafts, ranks, routes, or recommends is in scope if it infers an output that can change what someone does next. The Recommendation then names the people around that system. AI actors are organisations and individuals who play an active role in the lifecycle, including those who deploy or operate AI. Stakeholders are wider: anyone involved in, or affected by, the system. Actors are a subset. A vendor can be an actor. So can the team inside your firm that switched the feature on and left it running.
The lifecycle in the text is not a ribbon you cut at launch. It runs through planning and design, data, building or adapting a model, testing and validation, making the system available, operating and monitoring it, and retiring it. The phases iterate. They are not a neat sequence. The decision to retire a system can be taken at any point while it is operating. A board that treats go-live as the end of its attention has already left the document.
The principle is about a role, not a binder
The principles are meant to be read together. Accountability is the fifth. The Recommendation says AI actors should be accountable for the proper functioning of AI systems, and for respect of the other principles, based on their roles, the context, and the state of the art. To that end they should keep enough traceability, of datasets, processes, and decisions across the lifecycle, that someone can analyse an output and answer an inquiry. They should also run risk management at each phase, on an ongoing basis, within their role and their ability to act, and they should deal with other actors, suppliers, users, and people affected. The risks named include harmful bias, human rights, safety, security, privacy, labour rights, and intellectual property.
None of that appoints your chief executive. None of it names the clerk who can pull a feature on a Thursday. "Based on their roles" and "their ability to act" are the cultural clauses. A role without the ability to act is a title. An ability to act that nobody is rewarded for using is a story you tell after something goes wrong. The Recommendation can give you a shared sentence. It cannot sit in the room when a fluent draft is about to leave the building.
A different essay on this site asks what the NIST framework is for if you are not a model-risk team. That question still stands. A framework is a shelf for decisions. The OECD text is a standard countries can adhere to, and a vocabulary your suppliers will recognise. Adherence by a government is not a culture inside your firm. If the only place the accountability principle appears is a citation in a board pack, you have decorated a decision. You have not taken one.
Traceability is a habit, or it is a folder
Traceability, in the Recommendation, exists so an output can be examined and an inquiry answered. The inquiry that matters is rarely a historian's. It is a customer, a worker, a regulator, or a director asking why this recommendation, this denial, this sentence went out. If the only trace is a vendor's technical PDF from the month you bought the tool, you cannot answer. The decision was local. The data that shaped it may have been local. The person who accepted it was local. A folder that cannot reconstruct those three is not traceability. It is storage.
This is where culture shows. People record a check when recording it is normal, and when a miss is cheaper to admit than to hide. They stop recording when the last person who said "this output is wrong" was treated as disloyal. The belief that you can say that in the room is the subject of what a team owes each other once a model is in the work. Without that belief, the accountability file stays clean and the risk stays live. You will have traceability of the successes. The failures will live in side channels, where the board cannot see them and the next team cannot learn.
The 2024 revision elaborated the text on traceability and risk management and placed it in the accountability principle, on the view that this is where those duties belong. The current text also asks for information that lets a person affected by a system challenge the output, and for people to know when they are interacting with an AI system, including at work. A board can ask for that challenge path in one sentence. Who, other than the vendor's help desk, can a staff member or a customer contest, and what changes if they do? If the answer is "we will review it at the quarterly", you do not have a challenge. You have a waiting room.
Ability to act includes the ability to stop
The same 2024 revision is explicit about harm and misbehaviour. If a system risks undue harm, or behaves in a way you do not want, there should be a way for people to override it, repair it, or decommission it safely. Separate language covers uses outside the intended purpose, intentional misuse, and unintentional misuse. Human agency and oversight are named as safeguards, not as a slogan beside a logo.
Read "ability to act" against your actual calendar. A team that must wait a month for a steering committee to pause a rollout does not have the ability the principle assumes. A sponsor who can start a use, and a risk function that can only comment, have split the role from the act. The culture is visible in the last thing you turned off. If you cannot remember a decommission, the lifecycle in the Recommendation is, in your firm, a launch process with extra slides. Retirement is part of operation. A system you are afraid to retire will keep acting after its reason has gone.
Unsanctioned tools belong in the same picture. The Recommendation's actor is whoever plays an active role, not whoever is on the approved list. A staff member running a personal account on live work is deploying a system. Pretending otherwise makes the register look governed and leaves the real use unowned. The cultural question is whether that person can surface the tool without being punished for the surfacing, and whether someone with authority will then decide, in the open, to adopt it, constrain it, or stop it.
Collective Campus teaches critical thinking for people who have to interrogate a claim, including a claim that arrived fluent and finished. The session will not give a board a substitute for a named stop. It will make the next pack harder to wave through on tone alone. That is the right size of help. A class that replaces the argument is another binder.
What to ask when the pack is already printed
You do not need a new principle. You need the existing one pointed at your systems, in language a director can use without a glossary.
- For each system that can touch a customer, a worker, or a record, who deploys it and who operates it? Name a person. "The business" is not an actor you can call.
- Who can override or decommission it this month, without the permission of the sponsor who wanted the launch?
- Take one output from the last month. Reconstruct the data, the process, and the human check. If you cannot, say so in the minutes. A gap written down is more accountable than a gap implied.
- Where are people using tools the register does not name? Decide, for one of them, to adopt, constrain, or stop. Leaving it in the grey is a decision too. It is the decision that nobody owns the harm.
- What is a junior person punished for saying? If "the model was sure and still wrong" is expensive, your trace will not include the cases you most need.
Then look at the agenda you actually run. If the AI item is a spend line and a citation, the culture is that risk is a document. If the item is a near miss, a stop, or a use you did not know about, the culture is that risk is a decision with a name on it. The Recommendation will not choose which meeting you are in. It will only make the pretence harder to sustain, because it already told you that accountability follows the role, the context, and the ability to act.
A last distinction, because boards are offered a lot of paper. The text says the principles are complementary and should be taken as a whole, and that actors implement them according to their roles. You can quote one clause and ignore the role. You can fund a policy office and leave the operating team unable to pause the system the policy describes. You can adhere, in a country sense, and still have no one who will answer an inquiry about Tuesday's output. None of those are small gaps in drafting. They are the culture. The standard is public. The habit is not. Build the habit where the system already runs, or stop claiming the sentence.
Source: OECD, "Recommendation of the Council on Artificial Intelligence", adopted 22 May 2019, revised 8 November 2023 and 3 May 2024. https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449
News and insights for innovation, digital transformation, future of work and L&D leaders.
Stay ahead of learning and development, corporate innovation and digital transformation news. Plus the future of work. For leaders in AU, NZ, HK, SG, the US, the UK and Canada.





