Why this framework exists
When an AI system produces a harmful output, the natural organizational response is to look toward the vendor. The vendor's terms of service have already answered that question. The answer is almost always no. This is the Accountability Assumption in practice: the implicit organizational belief that accountability for an AI agent's decisions resides with the team that built it, the vendor that supplied it, or the platform that hosts it - rather than with the business owner who authorized its deployment.
AI providers disclaim liability for outputs used in consequential decisions. The governance infrastructure through which agents are deployed provides visibility, audit trails, and policy enforcement, but it does not make the organizational decisions about what an agent is authorized to do. The deploying organization makes those decisions. The problem is that most organizations have not recorded what those decisions were, who made them, or on what authority they acted.




