Follow this publication in Google.Select this site to see more of its articles in eligible Google news and AI surfaces.
This article expands an edition of The Chill AI guy on LinkedIn.
A demo hides the operating boundaries
A demo shows an input and an output. Production includes the data, instructions, tools, permissions, evaluation, monitoring, escalation and rollback around that output.
The dangerous assumption is that if every team owns its piece, the system as a whole has an owner. It does not. The handoffs between those teams become the operating system of the agent.
The NIST AI Risk Management Framework treats accountability and human oversight as lifecycle concerns. A project sponsor alone is not enough once the project becomes a service.
Five decisions need an owner
1. Scope and acceptable risk
This owner decides what the agent may do, what it must never do and which failure triggers a stop. Without that decision, every function optimises a different definition of success.
2. Quality and evaluation
Someone must own the evaluation set, failure categories, acceptance criteria and release decision. Domain experts need to help define what a harmful or misleading answer looks like before release.
3. Data, access and tools
Every new permission increases the possible effect of a mistake. Ownership includes granting access, reviewing it, setting expiry and being able to revoke it.
4. Incident and rollback
Rollback cannot begin with a meeting after the problem is found. It needs a visible trigger, a person authorised to act and a path tested before the incident.
5. Adoption and operating change
A technically available agent can still be operationally irrelevant. This owner covers training, procedure changes, feedback and whether real use produces the intended outcome.
Turn the matrix into a production test
For every critical decision, name one accountable person. The responsible person must be able to act without waiting for a new governance forum to be created.
Then stage a deviation. Imagine an internal assistant citing last year's travel policy because the source was not refreshed. Who detects it, who decides, who acts and what evidence is retained?
If the answer is vague, the RACI is describing an organisation chart rather than governing a service. The EU AI Act and the NIST framework differ in purpose, but both make clear that responsibility cannot disappear behind technical complexity.
A compact production RACI
- Business or process owner: accountable for scope, acceptable residual risk and the operating outcome.
- Product or delivery lead: responsible for release coordination, evaluation readiness and adoption work.
- Engineering and data owners: responsible for runtime reliability, data boundaries, permissions and rollback mechanics.
- Risk, security or legal specialists: consulted where the use case, data or impact requires their judgement.
- Users and operations: informed about limits and equipped to recognise, report and handle failure.
The job titles will change. The decisions should not remain implicit.