No. 26 · JUL 2026 · 6 Min Read
Responsible Charge
Abstract
Every field that solved delegated work solved it with a name on a line and a license that can be taken. AI governance is a hunt for a way to skip that step.
An engineer stamps a set of drawings they did not draw. Twenty people worked those sheets, plus software that sized half the members, and everyone in the building knows it. The seal goes on anyway, and the moment it does one named person is personally accountable for every line. Not the firm. Them, and a license a state board can revoke. The term of art is responsible charge.1 The rule that makes it worth anything is that you may not stamp what you did not supervise, and doing it as a favor for another firm can cost you the license. A stamp you can hand out freely certifies nothing.
Software never had this. We had the EULA. Provided as is, without warranty of any kind, in capital letters, at the bottom, where nobody reads. Forty years of shipping under a disclaimer whose entire content is that no one is responsible for anything. It was defensible for a while, because software was a tool a human picked up and operated. Nothing happened until a person made it happen.
Then we shipped agents, and things started happening without anyone doing anything.
The Committee Cannot Sign
Ask around right now and you hear the same question everywhere. Who is accountable when the agent gets it wrong? It is the correct question. The answers are almost uniformly the wrong shape.
The answers are frameworks. An AI governance council. A risk tiering matrix. A model registry, an approval workflow, an ethics review, an audit trail, a policy document with numbered sections that three people read once. Enormous effort, real money, genuine sincerity behind most of it.
What a framework does with accountability is spread it. The council reviewed the use case, the security team approved the permissions, the vendor certified the model, the business owner accepted the risk, and the audit trail recorded all of it faithfully. Then the agent does something expensive on a Thursday and you find that six parties each own a slice and no party owns the outcome. Spreading accountability thin enough dilutes it to nothing. Six slices is zero.
This is why Gartner can find only about 130 real agentic vendors among thousands claiming the label, and can forecast that over 40 percent of agentic projects get canceled by 2027 on cost, unclear value, and inadequate risk controls.2 Those cancellations are not usually a story about the model being too dumb. They are a story about a pilot that worked reaching the point where somebody has to own it in production, and discovering that the org chart contains no such person, and quietly dying there.
The Law Already Made the Call
California AB 316 took effect on January 1, 2026. It is two sentences of substance. In an action alleging harm caused by AI, a defendant who developed, modified, or used that AI may not assert as a defense that the AI autonomously caused the harm.3
Most of the commentary treated this as a new compliance burden. It is closer to the opposite. It removes an excuse that was never going to work, and in doing so it says out loud what tort law was always going to say: an agent is not a person, cannot hold intent, cannot be sued, cannot be deterred, and therefore cannot absorb consequence. Consequence does not evaporate because the actor was software. It travels up until it finds a party with assets and a name.
The legislature did not invent accountability here. It closed the last door people were hoping to walk through. What comes back through that door is the oldest arrangement in professional practice: someone signs.
But I Can’t Read Everything It Produces
Here is where the engineer’s objection fires, and it is a serious one. An agent produces more in an hour than I can review in a day. I cannot read every diff, every email it sent, every record it touched. Asking me to sign for that is asking me to sign blind.
The structural engineer cannot check every line either.
Nobody re-derives twenty thousand sheets by hand. Responsible charge never meant reading every character. It means you designed the review. You know which failure modes are load bearing and which are cosmetic. You spot check where the risk concentrates, you set the standards the junior work has to clear, and you have refused to stamp things before. That discipline is what lets one named human be accountable for the output of twenty people and a pile of software.
So the job is building the apparatus that makes the output checkable, then being personally on the hook when the apparatus misses. The processes that compress first are the ones where verification is cheap, because cheap verification is what makes signing survivable. People with management experience get more out of these systems faster because they already know how to be accountable for work they did not personally do. They have done it with humans for years. They know it does not require reading every line. It does require a clear definition of done, sampling, and a willingness to send things back.
Nobody has to reinvent this. It has been solved, in medicine, in aviation maintenance, in accounting, in structural design, and it always resolves to the same primitive. A name, a signature, and a consequence that lands on the person who signed.
The Rubber Stamp
There is a failure mode here worse than having no signer, and organizations reach for it instinctively because it is cheap.
You can name an accountable human and give them nothing. No authority to halt the rollout, no budget for the evaluation harness, no standing to say the thing is not ready, a quota that assumes the agent’s output ships. What you have named is a designated defendant. Everyone in the building understands the arrangement within a week, the signature becomes a formality, and the first real incident reveals the org bought an appearance of accountability rather than the thing itself.
The engineer’s seal works because refusal is available and occasionally used. A stamp that cannot be withheld is decoration. If your accountable human cannot stop the deployment on their own signature, you do not have an accountable human. You have a name in a box on a slide.
The test is short. For each agent running against production, name the person. Not the team, not the council, not the platform vendor. The person. Then ask whether that person can stop it by themselves, whether they have the tooling to know when to, and whether anything bad reaches them when they get it wrong.
If you cannot answer all three, the agent is running unsupervised, and the governance program is documentation of an unsupervised system. That is worse than no program. It reads as diligence in a deposition and does nothing the rest of the time.
Every profession that learned to be responsible for delegated work learned it the same way, usually after something fell down. Software got to skip that century because its output was inert until a human touched it. That exemption expired the moment the software started acting. The stamp is old, unglamorous technology, and we never built it.
Footnotes
-
See the NSPE Committee on Policy and Advocacy on what a PE says with their signature and stamp, and New York’s professional seals and signatures guideline for the responsible-charge standard and the prohibition on sealing others’ work. ↩
-
Gartner, Over 40% of Agentic AI Projects Will Be Canceled by End of 2027 (June 2025), which also coined “agent washing” for the rebranding of chatbots and RPA as agents. ↩
-
AB 316, effective January 1, 2026. It does not create strict liability. Causation and foreseeability still have to be proven, and other defenses remain available. ↩