Connect with us

Artificial Intelligence (AI)

AI Agents Are Creating an Accountability Gap Inside Companies. General Counsel Are Being Pulled Into the Middle

startup info

Published

on

A group of glossy white humanoid robots against a dark blue background

Companies are moving from AI systems that answer questions to AI agents that can take actions.

Corporate governance has not necessarily moved at the same speed.

Research published by Open Future Forum, the Silicon Valley
executive community, points to an emerging accountability gap: companies are giving AI systems greater access and autonomy while responsibility for those systems can remain fragmented across technology, security, legal and business teams.

Open Future Forum’s General Counsel AI Report, September 2026 found that 11% of companies in its underlying executive data reported having no single owner for AI. Among respondents in technology roles, where many AI systems are deployed and operated, that figure reached 30%.

Its security research identified another pressure point. Sixty-seven percent of senior security leaders named securing AI agents and their access as their top AI-security problem, while only 37% reported having a dedicated AI-security budget.

Those numbers become more significant as AI moves beyond generating information.

An AI system that writes a draft is one type of risk.

An AI system that can act on behalf of a company is another.

AI Is Moving From Answers to Actions

The first wave of generative AI was relatively easy to understand from a governance perspective.

An employee asked a system a question. The system generated an answer. A person decided what to do with it.

AI agents can alter that sequence.

Depending on their configuration and permissions, agents can retrieve company information, interact with applications, communicate with customers or employees, modify records and execute parts of business processes.

The distinction matters because an incorrect answer and an incorrect action have very different consequences.

If an AI assistant drafts a poor email, an employee may catch it.

If an autonomous system sends the email, changes a customer record or initiates a financial or operational workflow, the question quickly becomes one of accountability.

Who authorized the action?

Who determined the agent’s permissions?

Who monitors what it does?

Who can stop it?

And who carries responsibility when it gets something wrong?

These are increasingly questions for the General Counsel as well as the CIO, CTO and CISO.

The Ownership Problem

Open Future Forum’s research suggests that AI ownership can appear clearer at the executive level than it does closer to implementation.

Across its underlying executive dataset, 11% of companies reported no single AI owner.

Among technology respondents, the figure was 30%.

That exposes an important distinction.

A company may have somebody responsible for its overall AI strategy while still lacking a clearly identified person responsible for an
individual AI system operating inside the business.

From a governance perspective, the second question may be more important.

For any consequential AI system, a company should be able to identify who approved it, who owns the business outcome, who controls its access and who has authority to stop it.

If those answers are unclear before deployment, they are unlikely to become clearer during an incident.

Why General Counsel Are Being Pulled Into the AI Conversation

Legal teams are increasingly dealing with issues that sit well beyond conventional technology procurement.

AI can touch contracts, intellectual property, employment, privacy, cybersecurity, M&A, regulatory exposure and corporate governance.

Agents add another dimension because software may be authorized to act rather than simply provide information.

That does not mean General Counsel should become the owner of enterprise AI.

In fact, making legal responsible for “AI governance” as a whole could create another accountability problem.

Legal teams cannot configure identity controls. They do not own enterprise architecture. They generally do not own the business processes AI systems are being introduced to change.

The more practical model is shared governance with specific
responsibilities.

Legal can own legal exposure, contractual risk and regulatory
interpretation.

Security can own technical controls, identity and access.

Technology leadership can own architecture and deployment.

Business leaders can own the workflow and its commercial outcome.

Senior management and boards can oversee material enterprise risk.

The objective is not to make everybody responsible.

It is to make responsibility specific enough that nobody assumes somebody else owns the problem.

The GC-CISO Relationship Is Becoming Critical

The relationship between the General Counsel and CISO is particularly important.

An agent’s access to company information can simultaneously create security, privacy, contractual and intellectual-property issues.

The CISO may determine whether an agent can technically access a system.

The General Counsel may need to determine whether it should be allowed to and what obligations follow from that access.

Neither perspective is sufficient on its own.

A contractual restriction that cannot be enforced technically provides limited protection.

A technically secure system operating without clear authority,
accountability or legal review creates a different category of risk.

Open Future Forum’s finding that 67% of senior security leaders identify agent access as their top AI-security concern suggests that this is already becoming an operational issue.

The Executive Conversation Is Changing

Open Future Forum has built its research program around this
cross-functional view of AI, drawing on perspectives from CEOs, CFOs, CISOs, CMOs, General Counsel and AI leaders rather than treating enterprise AI as a purely technical subject.

That approach has attracted attention from executives working directly
on enterprise AI.

Silvio Sangineto, a Microsoft executive and author of the forthcoming The AI Leader Mindset, has described Open Future Forum as helping to define the enterprise AI agenda in Silicon Valley, highlighting its ability to bring executives, investors and AI leaders into the same conversation.

That cross-functional approach becomes particularly relevant to governance.

An AI system can look successful to one executive and problematic to another.

Technology may see a successful deployment.

Finance may see an uncertain return.

Security may see excessive permissions.

Legal may see unresolved liability.

The business unit may see an opportunity to remove weeks of manual work.

All of those observations can be true at the same time.

Vendor Contracts Are Quietly Determining Who Carries the Risk

The accountability question also appears in AI vendor agreements.

The Open Future Forum General Counsel research notes that AI vendors are increasingly experimenting with usage and outcome-based pricing alongside conventional seat-based models.

That creates new contractual questions.

Usage pricing requires the parties to agree on what constitutes usage and how it is measured.

Outcome pricing can be harder.

If an AI system contributes to a commercial result alongside employees, existing software and other processes, how much of the outcome belongs to the AI?

Who measures it?

Can the customer audit the calculation?

What happens when the parties disagree?

Agents create another set of issues.

What is the agent authorized to do?

What happens if it acts incorrectly?

What audit trail exists?

Which third-party models sit underneath the product?

What happens to company data?

Who bears liability for an autonomous action?

Those questions are easier to negotiate before an agent becomes embedded in an important business process.

AI Is Also Changing M&A Diligence

The issue extends into transactions.

AI companies can have dependencies that are not immediately obvious from the product being sold.

A business may describe proprietary AI capabilities while depending heavily on third-party models, external datasets, open-source software or infrastructure controlled by other companies.

For General Counsel involved in M&A, that creates a different diligence problem.

What intellectual property does the target actually own?

What rights does it have to its training or operating data?

Which models does it depend on?

Can important supplier agreements survive a change of control?

Are customer claims about the product consistent with what the technology actually does?

What happens if a critical model provider changes its terms?

The value of an AI company can depend partly on the answers.

Louis Lehot, a Silicon Valley private equity and M&A lawyer who has worked with Open Future Forum’s executive communities, has argued for bringing General Counsel into strategic transaction discussions earlier
rather than treating legal review as something that begins after the commercial decision has effectively been made.

AI makes that argument stronger.

A legal or data dependency discovered late in diligence can change the economics of the transaction itself.

Boards Don’t Need a List of Every AI Tool

Greater legal involvement does not mean every AI deployment belongs in the boardroom.

Most do not.

Boards need visibility into material enterprise risk, not an inventory of software.

But management should be able to explain the governance structure around consequential AI systems.

Open Future Forum’s Board Director AI Governance Report illustrates why.

Its research found a substantial difference in expectations around AI payback: 70% of CEO-seat respondents expected payback within six months, compared with 42% of finance-seat respondents.

Different executives can therefore look at the same AI investment and reach different conclusions about its progress.

That makes ownership and measurement important.

For a material deployment, a board should be able to ask:

Who owns it?

What is it allowed to do?

How are we measuring whether it works?

What are the principal risks?

Who has authority to stop it?

Those questions may reveal more than a long presentation about the company’s AI strategy.

Five Questions That Expose the Accountability Gap

Companies do not necessarily need another large governance framework to discover whether they have a problem.

For any consequential AI system or agent, management should be able to answer five questions:

Who approved it?

What can it access?

What can it do without human approval?

Who owns the outcome?

Who can stop it?

If answering those questions requires assembling a committee simply to determine who is responsible, the governance problem already exists.

AI Governance Is Becoming an Operating Issue

AI governance is often discussed as compliance.

Agentic AI makes that definition too narrow.

Once software has access to enterprise systems and authority to perform actions, governance becomes part of the company’s operating model.

Legal matters.

Security matters.

Technology matters.

Business ownership matters.

Board oversight sometimes matters.

The difficult part is connecting them.

That is also why executive communities such as Open Future Forum are increasingly looking at AI across functions rather than treating it as a technology discussion.

The next stage of enterprise AI will not only test what the models can do.

It will test whether companies know who is responsible for what the models do.


About the Research

This article references the Open Future Forum General Counsel AI Report, September 2026, the CISO AI Leverage Report and the Board Director AI Governance Report.

The General Counsel AI Report is a synthesis report for General Counsel, Deputy General Counsel and legal operations leaders. It interprets findings from Open Future Forum’s broader enterprise AI research through the legal seat and does not claim a separate General Counsel survey sample.

By Sumbal Noor

We are a team of writers passionate about innovation and entrepreneur lifestyle. We are devoted to providing you the best insight into innovation trends and startups.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Ai Everything Abu Dhabi

Most Read Posts This Month

Copyright © 2024 STARTUP INFO - Privacy Policy - Terms and Conditions - Sitemap - Write for us

ABOUT US : Startup.info is STARTUP'S HALL OF FAME

We are a global Innovative startup's magazine & competitions host. 12,000+ startups from 58 countries already took part in our competitions. STARTUP.INFO is the first collaborative magazine dedicated to the promotion of startups with more than 400 000+ unique visitors per month. Our objective : Make startup companies known to the global business ecosystem, journalists, investors and early adopters. Thousands of startups already were funded after pitching on startup.info.

Get in touch : Email : contact(a)startup.info - Phone: +33 7 69 49 25 08 - Address : 2 rue de la bourse 75002 Paris, France