Approval is not accountability
Organizations grant approval to projects and assume ownership follows. It does not, and the gap only becomes visible when something goes wrong.
Approval is a moment. Accountability is a state that has to persist after the moment has passed. Most organizations produce the first and assume they have produced the second.
They have not, and the difference shows up at the worst time.
What actually gets approved
When a committee approves an AI initiative, what is recorded is usually the name of the initiative, the amount, and the date. Sometimes a condition or two. What is rarely recorded is a person who owns the outcome, and what the system is permitted to do once it is live.
Both omissions feel reasonable at the time. The sponsor is obviously the owner, everyone in the room knows that, and writing it down feels like bureaucracy. The permission question feels premature, because the thing does not exist yet.
Six months later the sponsor has been promoted into a different function, the system is doing something adjacent to what was described, and the honest answer to who owns this is a shrug.
Why the permission part matters more than it seems
Approving a project and approving a boundary are different acts, and the second one is the one that protects you.
A project called “AI assisted customer resolution” can mean a system that drafts replies for a human to send, or a system that issues refunds on its own. Both are defensible. They carry entirely different risk. The approval record almost never distinguishes them, because at the time of approval the distinction had not been made yet.
The consequence is not usually a scandal. It is a slow drift, where the system does slightly more than anyone consciously agreed to, each step reasonable, no single moment where anyone crossed a line, because no line was drawn.
The cheap fix
Naming an accountable person at the moment of approval costs about ninety seconds and one uncomfortable pause.
Stating what the system is permitted to do costs a bit more, because it forces a conversation that people would rather have later. That is exactly why it is worth doing now. The conversation gets harder, not easier, once the thing is running and a team is attached to it.
Neither is a technical problem. Both are simply things that have to be written down at the point of decision, in a form that survives the people who made it.
The organizations that do this are not more cautious than the ones that do not. They are just going to have a much better afternoon when someone finally asks.