The signal
The Center’s August submission to NIST asks a concrete oversight question: who grants an AI system authority to operate, and who can withdraw that authority? The question becomes more demanding when the model developer, the organization adapting the system, and the enterprise using it are different institutions.
The NIST AI Risk Management Framework (AI RMF 1.0) describes the AI lifecycle as interdependent activities whose participants often lack full visibility or control across the whole process. A warning discovered in one part of that process therefore needs an accountable recipient in another. NIST AI RMF Core, Section 5.2.
The insight
Distributed Accountability assigns responsibility to the decisions each institution controls. The developer answers for its representations and release decisions. The enterprise answers for the use it authorizes, the limits it establishes, and the response to information that calls that authorization into question. Builders and Buyers need to know where their responsibilities meet.
This is also a communal need. Customers, patients, employees, and other affected people can experience consequences created across several organizations, without having chosen the system. Their concerns need a route to a named party with authority. Their role in reporting a problem does not transfer the institution’s oversight responsibility to them.
The AI Oversight Program must make those responsibilities and reporting relationships explicit. Shared learning depends on evidence reaching the institutions able to respond. The program is the governance.
The action item
Ask management to trace one consequential use of a third-party AI system from supplier to enterprise decision. Identify who must communicate a material limitation, who receives the warning, who can constrain or withdraw the enterprise’s authorization, and where an affected person can raise a concern. Record any handoff at which either the recipient or the authority is undefined, and assign responsibility for resolving it.