Analyst Spotlight
Neil Hare-Brown
CEO
STORM Guidance
AI Risk Is No Longer Theoretical: Governance Before the Incident, Investigation After It
Artificial Intelligence is already embedded within everyday organisational activity. Employees use it to research, analyse, summarise, draft, classify and recommend. More advanced systems can make decisions, communicate with customers, initiate transactions and undertake multi-stage activities with limited human involvement.
The risks are well recognised: inaccurate outputs, hallucination, bias, privacy issues, intellectual property concerns, security vulnerabilities and regulatory breaches. But beneath these risks sits a more fundamental governance question: when AI is used to perform work for an organisation, who is responsible for what it does?
This is not only a question for autonomous AI agents of the future. It exists whenever AI is used in organisational activity today. Even when an employee uses AI to summarise a report or support a recommendation, part of the cognitive work behind the organisation’s eventual advice has been delegated. The employee acts on behalf of the organisation, and AI sits within that same chain of delegated responsibility.
This is the basis of On-Behalf-Of, or OBO, Governance. The governance question is not whether AI is acting on behalf of the organisation. When AI performs organisational activity, it already sits within an OBO chain. The real question is what capability, discretion and authority have been delegated to AI, by whom, and subject to what controls.
Capability can be delegated. Authority can be delegated. Accountability cannot simply disappear into the delegation chain.
Standards such as ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 38507 and the NIST AI Risk Management Framework provide useful foundations for AI governance. However, organisations must also establish clear traceability of responsibility: what AI systems are being used, who is using them, what information they can access, what decisions they can influence, what actions they can perform, and where responsibility ultimately sits.
The same principle applies after something goes wrong. Insurance may transfer some financial consequences of an AI incident, but it cannot establish causation. That requires investigation. AI incidents introduce new investigative challenges because models, prompts, retrieved information, configurations and external services may change, while outputs may be probabilistic.
Governance and investigation are two sides of the same problem. Before an incident, governance should establish who delegated what, to whom or what, for what purpose, within what limits, and subject to what controls. After an incident, investigation works backwards through that same chain to determine what happened, what AI contributed, what authority it had, what controls operated, and where responsibility resides.
AI risk does not need to be eliminated to be manageable. But it does need to be governed, and when it fails, it needs to be investigated properly.