Lens: the four publics
The accountability vacuum in agentic AI is a design failure.
The AIhub/ACM SIGAI working group defines the vacuum: "a condition in which an AI system's capacity for consequential autonomous action outpaces both the mechanisms for attributing responsibility and the means of remedying harm." Most people read that and reach for policy. Write a framework. Assign a committee. But the vacuum exists because the product was built without naming a human accountable to each public it touches. No policy fixes that after the fact.
Every product has four audiences: the user, the buyer, the regulator, and the ecosystem. Most teams design for one. Agentic products design for zero. They ship a capability and let the accountability question resolve itself through blame.
Consider the chain Berkeley Technology Law Journal describes: "When Company X's agent hands off to Company Y's agent, which invokes Company Z's tool, respondeat superior doctrine fails." The plaintiff faces what Berkeley calls a "near-impossible task" of establishing which agent caused harm. Every vendor in the chain points elsewhere, and no human is accountable.
Build a product that touches four publics and assign an owner to none of them. This is the result.
The user public
A CSA/Strata Identity survey collecting 228 responses from IT and security professionals found that 68% of organizations cannot clearly distinguish between human and AI agent activity. 31% allow agents to operate under human user identities. The user interacting with an agent often cannot tell whether a human approved the action that just affected them. No one owns that confusion. It shipped without a name attached.
The buyer public
Clifford Chance observes that "vendors release agentic capabilities faster than contracts can evolve." The buyer purchased passive software. They received an autonomous actor. The contract covers the first product, not the second.
The Accenture/Wharton report quantifies the exposure: over 50% of working hours across the American economy are subject to reshaping by the approximately 60 AI agents they studied. Their line is blunt: "In a badly designed agentic enterprise, one human could suddenly find themselves responsible for an exponential cascade of outcomes they never saw coming." That human is the buyer's operator. Elish would call them the moral crumple zone: the operator who absorbs blame after failures while the vendor avoids liability.
The regulator public
Baker McKenzie notes that a California statute explicitly forecloses the autonomy defense. Accountability generally runs to the company and its people.
CISA guidance emphasizes what that means in practice: "governance, human oversight, least-privilege access, logging, monitoring, auditability, and clear accountability." Yet 74% of organizations in the CSA survey say agents receive more access than necessary. The regulator has stated the standard. The product ignores it.
The ecosystem public
Berkeley describes agent-to-agent interactions as "typically opaque, unlogged, and difficult to reconstruct." That is an ecosystem problem. When your agent calls my agent calls a third party's tool, the ecosystem bears the compound risk. No single deployer sees the full chain. No single contract covers it.
Tasq.ai's analysis found that nearly four in five failures live in how the system was specified and how the agents talk to each other: 41.8% from specification and design issues, 36.9% from inter-agent misalignment. The failures are architectural. They happen before any policy could intervene.
The design requirement
The fix is a design requirement. Before deployment, every agentic product names four humans: one accountable to users, one to buyers, one to regulators, one to the ecosystem. A named human, with authority to stop the system, printed on the architecture diagram.
Forbes Tech Council is direct: each AI agent needs "explicit linkage to a human with delegated authority before deployment." That is a product design decision. And it is the one most agentic products skip.
If your agentic product ships without four names on it, you built a product that delegates to everyone and is accountable to no one. No agentic product should clear deployment review until those four names are printed on the architecture diagram.









.webp)
.webp)
.webp)

