This website uses cookies

Read our Privacy policy and Terms of use for more information.

For eight weeks this newsletter has argued that AI accountability turns on whether a named individual can be shown to have made a specific decision at a specific time, evidenced contemporaneously. Next Sunday, that stops being a governance principle and becomes a dated test. On 2 August the deployer obligations under Article 50 of the EU AI Act apply: disclosing to a natural person that they are interacting with an AI system, labelling deepfakes, and flagging AI-generated content published on matters of public interest. From that day, the question a regulator asks is no longer whether a firm intends to comply. It is whether the evidence of compliance carries a date earlier than the obligation it evidences.

Most of the commentary now circulating treats 2 August as an EU compliance date, which for the majority of organisations it is. For a UK financial services board, that reading is the first mistake, because a second regime has been waiting for this deadline the whole time, and it is domestic, older, and considerably sharper.

The regime that was already waiting

Under the Senior Managers and Certification Regime, a UK financial services firm is already required to map accountability to a named individual. Not to a function, not to a committee: to a person, recorded in a Statement of Responsibilities and filed with the regulator. The regime does not distinguish between a decision made by a human and a decision materially influenced by an AI system. The senior manager responsible for the relevant decision area retains personal accountability either way.

Set the two regimes side by side and the asymmetry is instructive. The EU AI Act asks who is accountable for a deployer's disclosure obligations. The domestic regime has already required the answer to be written down, attached to a named senior manager, and filed with the FCA. Most EU AI Act commentary treats the accountability question as open, a matter for each organisation to settle in its own governance design. For a regulated UK firm it was closed years ago. What remains open is something narrower and harder: whether the named individual can evidence that they discharged the responsibility, and when.

Two regimes, one requirement

SM&CR and Article 50 converge on the same requirement from two directions: a named person, a dated record, and a decision that predates the obligation rather than reconstructs it afterwards.

This is where the exposure concentrates. In most firms, Article 50 readiness has been mapped to a technical function. A compliance workstream, a model inventory exercise, a disclosure-wording review owned somewhere in the second line. That work may be entirely competent. But the Statement of Responsibilities does not name a workstream. It names a senior manager. If that senior manager holds no dated record of having reviewed the obligation, the firm has not one accountability gap but two that do not agree with each other. The EU regime will ask who was accountable and be pointed at a function. The domestic regime already holds a filed document pointing at a person. A regulator reading both does not need to construct a case. The firm has constructed it for them.

The firms most exposed on 3 August are not the ones that ignored Article 50. They are the ones that treated it as a technical compliance item while their own regulatory filings named an individual who never looked at it.

What the named senior manager needs on file before Saturday

The test is narrow enough to run as a single agenda item this week, and it has three parts.

The first is identity. Is the person named on the Statement of Responsibilities for the relevant decision area the same person the firm would identify, today, as accountable for Article 50 readiness? In a surprising number of firms the honest answer is that one accountability has been quietly split across two functions that do not reconcile: a senior manager holds the filed responsibility while a technology or compliance function holds the actual work. That split is invisible until a regulator reads both documents in the same afternoon.

The second is the record. Does the named senior manager hold a dated record showing they reviewed the specific obligations before they applied? Not a policy asserting that reviews occur. Not a committee terms of reference. A record of this person, this obligation, this date. The distinction between a firm that can produce the charter and a firm that can produce the record was last week's argument, and it decides this week's test.

The third is the anchor. A date the organisation asserts about itself and a date fixed by something outside the organisation's control are different evidentiary categories. Board minutes and decision logs carry dates the organisation itself generated and could, in principle, have generated later. A record whose date is held by something the firm does not administer, a regulatory filing, an external attestation, an independently held timestamp, is not making the same kind of claim. Optimising documentation for completeness is common. Optimising it for who could vouch for the date if it were challenged is rare, and it is the version that decides contested cases.

The register changes on Sunday

This is the last week the argument can be made on the proactive side of the deadline. From 3 August, prevention becomes consequence, and the useful question shifts from what a board should do before the obligation applies to what happened to the boards that did nothing. That shift is permanent. There will be no further week in which a dated record created now is, by construction, a record that predates the obligation.

The domestic backdrop does not soften any of this. Companies Act 2006 section 174 tests a director's care, skill and diligence against what they actually did, evidenced and dated, not against what a policy said they were responsible for. DORA Article 5 places responsibility for ICT risk management with the management body itself, not with a delegated function. Each of these instruments reaches the same conclusion from a different starting point: accountability that cannot produce evidence is an assertion, and assertions are what regulators are instructed to test rather than accept.

The deadline arrives on Sunday. The named individual was accountable before it did.

Regulatory references: EU AI Act Article 50(1), 50(3), 50(4); FCA Senior Managers and Certification Regime (SYSC, FCA Handbook); Companies Act 2006 section 174; DORA Article 5 (management body responsibility).

The Roche-Review is the weekly publication of Dr Ivan Roche FRSS FRSA MInstP, Founder of Otopoetic Limited. Subscribe at roche-review.com.

The Roche-Review is the weekly publication1 of Dr Ivan Roche FRSSy FRSA MInstP, Founder of Otopoetic Limited. Subscribe at roche-review.com.

1  

Keep Reading