Blog
AI Accountability Needs an Operating Model
CoSAI has published version 1.0 of the AI Shared Responsibility Framework, and it asks a simple operating question: who is accountable for which part of an AI system? For DACH organizations, this matters because agents, RAG applications and model APIs rarely stay inside one clean responsibility boundary.
What the framework structures
The CoSAI model divides AI responsibility into five layers: Business & Usage, Information, Application, Platform and Model Provider. Every activity should have exactly one accountable party. That turns “shared responsibility” from a soft phrase into an assignment that can be tested in contracts, operating models and approval processes.
The difference from classic cloud governance is important. For AI, the split between provider and customer is no longer enough. Data quality, prompt boundaries, RAG sources, agent permissions, model risks and platform controls interact. If a chatbot makes a wrong commitment or an agent uses a tool too broadly, a vague “shared” answer will not help much in an audit.
Why this matters for governance
The European Commission describes the AI Act as a risk-based framework for AI providers and deployers. OWASP lists concrete risks for GenAI applications, including prompt injection, sensitive information disclosure, supply-chain risks and excessive agency. Together, they show that organizations need more than policy documents. They need a durable mapping between risk, control point and owner.
That is where the SRF can become practical. It does not replace the AI Act, ISO 42001 or the NIST AI RMF. It adds the operating question of who actually owns a control.
What DACH organizations should check now
Do not start with another board paper. Pick one near-production use case: a copilot, customer-service bot, internal RAG assistant or coding agent. For each layer, name an owner, the key controls and the remaining gaps.
The decisive question is: can you explain before rollout who owns data access, model boundaries, agent permissions, logging and incident decisions — or will that answer only appear after the first incident?