All insights

Governance & Audit

Who Is Accountable When an Agent Errs?

· 11 minute read

When an agent is wrong, 'the model did it' is not an answer. Split fiduciary, competent authority, processor and the human who skipped a gate — then write that split before the error.

A scholarship rejection went out with the wrong reason. The family arrived with a printout. The helpdesk blamed the agent. The vendor blamed 'hallucination, which is expected'. The officer said they had clicked through a queue of forty. The DPO said nobody had named a fiduciary owner for that workflow. Everyone was sincere. Nobody was accountable. The collector asked a question that should have been in the sanction note three months earlier: if this is wrong, whose file is it?

This is an opinionated map, not a liability treatise. Models are not legal persons. Indian public accountability already knows how to treat a wrong noting, a wrong sanction, a leak, and a bad procurement. An agent does not invent a new moral subject. It invents a new way for old subjects to hide. Write the split before the error: the department as fiduciary and public authority, the competent officer for the act, the vendor as processor and contractor, and the human who bypassed a gate if one was bypassed.

The India AI Governance Guidelines list Accountability as a sutra. That is a reminder, not a section you can prosecute. DPDP, service rules, contract damages, CAG findings, and sometimes criminal or contempt paths — those are the real instruments. Use them by name.

Not legal advice.

Four seats at the table, none of them the model

The public authority / Data Fiduciary. The department chose to run the workflow, chose the purpose, chose to connect the data. Citizen-facing wrongs and DPDP duties sit here first. 'The vendor's model' does not answer a family at the counter.

The competent authority. If a sanction or a rejection needed a human under your delegation, that human owns the act they released. A tired click is still a click. If they never saw it because you auto-routed, the design owner shares the seat — which is why gates exist.

The vendor as processor and contractor. They own defects they warranted: undeclared egress, a missing trail, a training use they promised not to do, a hash that was not the hash. They do not own your unlawful purpose. Do not sign a clause that says they own 'all AI errors'; it will be fake and it will make your officers lazy. Do not sign a clause that says they own nothing; it will be fake the other way.

The officer who skipped a control. If a gate existed and was bypassed — shared password, WhatsApp override, production peek — service rules still work. New technology does not retire old discipline.

Use this after an error, and, better, in the charter before one.
What went wrongFirst seatDo not say
Wrong citizen-facing reason / leak of personal dataFiduciary / department, then processor if they broke instructions'The AI decided'
Wrong sanction releasedCompetent authority who released; design owner if no gate existed'Hallucination, expected'
Undeclared hop or training useVendor as contractor / processor'Industry standard telemetry'
Bypassed gate, shared admin, laptop dumpThe human who bypassed, plus whoever left the bypass easy'Change management issue' with no name

What accountability is not

It is not a percentage in a model card. It is not a vendor insurance certificate you have never read. It is not a Guideline sutra quoted in a press release after the fact.

It is not collective 'the steering committee'. Committees steer. Persons sign.

Write it while everyone is still friends

The charter and the MSA should say which seat owns which class of error, how a citizen correction is made, how a CAG query is answered, and how a vendor defect is paid. After the family is in the corridor, you will invent a story that protects the people in the room. Invent the story now, on paper, when it can still be fair.

  • Name the fiduciary owner per workflow, a person, not a cell.
  • Name the competent authority per commitment.
  • Name the vendor warranties that attract damages.
  • Name the bypasses that attract service-rule action.
  • Name the correction path for the citizen.

CAG and the missing story

An auditor who cannot reconstruct will hold the department, not the model. The seven-field trail is how you have a story. Without it, accountability collapses onto the public authority by default — which is legally tidy and operationally brutal.

Objections you will hear — and what to do with them

These are the lines that stall the file. Answer them in the room, then put the answer in the note. A spoken answer without paper will be forgotten by the next officer.

If officers are personally accountable they will never click.

They already are accountable for notings they sign. The agent does not change that. It should reduce the draft work, not the ownership. If they will not click, you have learned that the gate is in the right place.

We will hold the vendor fully liable. That is simpler.

It is simpler on a slide. It is not how public law treats a sanction. The family is still your family. Take the warranties that are real. Keep the public seat.

Accountability will be clear once the AI Act arrives.

India's current public instruments are DPDP, Guidelines-as-guidelines, service rules, contracts, and audit. Waiting for a future Act is how you run a year of unowned errors. Write the split now.

This will scare the political leadership.

Leadership is already accountable in the newspaper. A written split is less scary than a corridor with no owner.

A one-week accountability table

Do it as part of the charter, not as an incident report template you will fill in anger.

  1. Day 1: list error classes you can already imagine.
  2. Day 2: assign seats. Persons, not cells.
  3. Day 3: counsel and vendor redline the warranties.
  4. Day 4: write the citizen correction path.
  5. Day 5: competent authority signs the table. Publish it internally.

How this shows up in the file

The table lives in the governance charter. The MSA points to it. The incident SOP uses the same seats. Three documents, one split.

If a press note is needed after an error, it should be able to name the seat without inventing a new theory of 'the AI'.

This article is informational field guidance for Indian public institutions, not legal, procurement, security-accreditation or engineering advice. Confirm against the current Gazette, GFR, GeM term, CVC instruction, CERT-In direction, DPDP text, departmental manual and your counsel before you file it.

How this survives CAG, RTI or the Board

“Who Is Accountable When an Agent Errs?” is not a workshop slide. A P6 Compliance/DPO will have to reconstruct a decision after the officer who clicked approve has been transferred. Write the artefact that lets a stranger replay the case: the log fields, the approval, the override, the register row.

When an agent is wrong, 'the model did it' is not an answer. Split fiduciary, competent authority, processor and the human who skipped a gate — then write that split before the error. India AI Governance Guidelines (November 2025) are guidelines, not a statute. DPDP still allocates fiduciary duty. Delegation of Financial Powers still allocates who may spend. Do not hide those instruments behind the word governance.

If you cannot show who acted, on which purpose, with which data class, and who could have refused, you do not have accountability. You have a chatbot with a charter PDF.

  • Name the owner of “AI accountability government” inside the department, not the vendor.
  • Keep CERT-In-relevant logs in India for the required period.
  • Store overrides with a reason an auditor can read.
  • Put the workflow on the AI register before it touches a citizen.

Close this loop before the next CAB

Put “Who Is Accountable When an Agent Errs?” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P6 Compliance/DPO, not “the vendor.”

Revisit the item when the model, the GeM term, the region, or the SI changes. “AI accountability government” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.

What the next noting must contain

“Who Is Accountable When an Agent Errs?” belongs in a file, not only in a search result. A P6 Compliance/DPO should be able to point at one artefact that proves “AI accountability government”: a packet capture, a processing schedule, a scored evaluation row, a dated notice, or a refusal rule. If the only evidence is a slide, you have a heading.

When an agent is wrong, 'the model did it' is not an answer. Split fiduciary, competent authority, processor and the human who skipped a gate — then write that split before the error. DPDP 2023 does not define sovereign AI and does not write a blanket localisation rule for every model hop. CERT-In’s 28 April 2022 directions still set specified incident clocks and 180-day log retention in India for in-scope events. The November 2025 AI governance text is guidance, not a statute. A Proprietary Article Certificate, when it is lawful, lives in GFR Rule 166 — not Rule 161.

Write three dated sentences under C6 Governance & Audit: what was decided, which designation owns it after the next posting order, and when it will be re-checked. Unsigned sentences are souvenirs. Dated sentences are controls.

  • Name the designation that owns “AI accountability government”, plus a deputy.
  • Attach one artefact a stranger can open next year.
  • Name the instrument you are actually using — Act, direction, GFR clause, GeM term, or guideline paragraph.
  • Leave unsourced percentages, GMV slides and house forecasts out of the noting.
  • Revisit when the model, the SI, the notice, the region or the posting changes.

Questions this usually raises

Is the AI vendor legally responsible when the agent is wrong?
They are responsible for what they warranted and for processor duties. They are not a substitute competent authority. The department remains the public face and usually the fiduciary. Write both.
Can we say the model is accountable in the RFP?
No. A model is not a legal person. Name humans and organisations. Put that in the file next to “AI accountability government” so a stranger can reconstruct it. A one-line yes/no under “Who Is Accountable When an Agent Errs?” is not an answer a secretary can defend. Confirm against the live Gazette, circular or GeM term; this is not legal advice.
Does the Accountability sutra in the 2025 Guidelines create a new offence?
No. It is a guideline principle. Use existing instruments: DPDP, contract, service rules, audit.
What should we tell a citizen who was wrongly rejected?
Who will reopen the file, how to apply, and that a person owns the review. Do not send them to a chatbot to appeal a chatbot.

Sources