Every operating model in a company above $500 million in revenue was built around a human approval gate, and the AI systems now running pricing, scheduling, forecasting, and customer resolution do not pass through it. The gate is still there. The policy still cites it. Nothing was removed and nothing was overruled. A lane was simply built around it, and nobody said so out loud.

That is the operations exposure, stated plainly. It is not that AI made a bad decision. It is that the organization's entire architecture for catching a bad decision was calibrated to the speed at which a person makes one.

Consider what the gate was designed to intercept. A discount above a stated percentage escalates to a manager. A price move outside a band escalates to a director. A staffing exception escalates to a committee. Each threshold assumes a human being pausing at a decision, and each was tuned to a pace measured in hours and days. A model embedded in a pricing platform makes thousands of those same decisions in an hour, every one of them comfortably beneath every threshold, and the harm never appears in any individual decision. It appears in the shape of the whole distribution, which no gate in the operating model is pointed at.

The Second Question Is the One That Ends Careers

When the first question arrives, most operations leaders can answer it. Which system produced this outcome? That answer usually exists, because someone can trace the platform.

The second question is different. Who owns that system, what were they authorized to do about it, and when did they last look? Organizations that cannot answer the second question do not merely lose an argument with a regulator. They discover their own failure from outside the building, delivered by a reporter, a plaintiff's firm, or a Civil Investigative Demand, because nothing in the operating rhythm was designed to look for it first.

The size of that gap has been measured. Grant Thornton's survey of nearly 1,000 senior business leaders, published April 13, 2026, found that 78 percent lack full confidence their organization could pass an independent AI governance audit within 90 days. Read what that audit actually asks for: a system inventory, a named owner per system, review records, and vendor documentation, produced on a deadline. Every one of those is an operations artifact. The finding is usually read as a compliance statistic. It is an operations statistic wearing a compliance label.

Four Regulators Reached the Same Rule, and Operations Holds the Evidence for All Four

Four enforcement bodies that do not coordinate with each other, working under four separate bodies of law on four independent timelines, arrived at the same position inside eighteen months: the organization deploying an AI system owns what that system does, and the vendor who built it is not a defense.

Delaware's Caremark line, running through Marchand and Boeing to McDonald's, asks whether a reporting system existed and whether the board actually received what it produced. No Delaware court has yet decided an AI Caremark claim. That absence is not comfort. The mission-critical analysis those cases established does not require a new doctrine to reach an AI system running a core operating process, and the record that would satisfy it is generated in operations or not at all.

The Securities and Exchange Commission asks whether the capability the organization described publicly matches the capability it actually runs. Its enforcement volume has narrowed rather than expanded, with standalone actions down 30 percent year over year in fiscal 2025, which most readers misinterpret as retreat. A narrowing enforcement program is a concentrating one. The Delphia and Global Predictions settlements of March 18, 2024, and the Saniger action of April 9, 2025, with its parallel criminal charges, mark the shape of what it is concentrating on.

The Department of Justice Antitrust Division asks a procurement question that no procurement checklist contains. Daniel Glad, Acting Deputy Assistant Attorney General for Criminal Enforcement, stated the Division's scope on May 14, 2026: the posture "does not ban algorithmic pricing generally. It targets the ingestion of non-public competitor data." The variable is not whether competitors use the same vendor. It is what data moves into the platform, whose data it is, and whether this organization knowingly fed its own non-public commercial information into a system pricing on behalf of a rival.

The European Union asks whether the organization wrote down what it changed. Article 25 of the AI Act reassigns provider obligations to a deployer who substantially modifies a high-risk system. The Digital Omnibus on AI, in force July 27, 2026, defers those high-risk obligations to December 2, 2027 for Annex III systems and August 2, 2028 for Annex I. The deferral moved the enforcement date. It did not move the date by which the change log has to have been kept, because a record cannot be created retroactively for a modification made in 2026.

Four regimes, four vocabularies, one evidentiary demand. Each of them, at the decisive moment, asks operations for a document.

The Failure Is Upstream of Diligence

After an AI system produces an outcome the organization has to defend, the internal investigation almost always concludes that someone was not paying enough attention. That conclusion is wrong often enough to be dangerous, because it prescribes more reviews inside a structure where nobody was ever told precisely what they owned. More activity, same exposure.

The category manager running the pricing platform was never told, in words, that the platform's output distribution was theirs to watch. Nobody granted them authority to stop it. Nobody defined what a bad week looks like in numbers. Nobody set a date by which any of it had to be true. Six months later the organization held that manager accountable for something it never assigned them.

This is the Accountability Contract Model, and it is the governing correction here. Accountability is not a value. It is a conversation, and it has four elements that get settled before results are demanded: what needs to be done, what authority is granted, what success looks like, and what the timeline is. Skip the conversation and what remains is a title on an org chart.

Applied to an AI system, each element has a specific form.

What needs to be done is never "own the pricing system." That phrasing fails wherever it is tried, because it names a possession instead of a task. The assignment is to watch this system's output distribution against these named metrics, on this cadence, and to document what was seen. Price dispersion across clusters and geographies for a pricing engine. Shift allocation across protected categories for a scheduler. Resolution and escalation rates by segment for an automated service system. The owner should be able to recite the task without reading it.

What authority is granted is where most AI ownership quietly fails. The common defect is an owner who can observe but cannot act. Authority has to be stated in the form the organization actually operates in: this named person may halt or roll back this system, in whole or in a defined segment, without a committee vote, without a business case prepared in advance, and without prior approval from the executive they report to. If halting requires convening anyone, the authority does not exist, because the window in which halting matters closes faster than a meeting can be scheduled.

What success looks like is not the absence of incidents. No owner controls that. Success is the detection interval and the documentation record: anomalies found inside one review cycle rather than by an outside party, and every review written down, including the ones that find nothing. Under all four regimes, an empty review that was documented is worth more than a diligent review nobody recorded.

What the timeline is means actual dates. When the first review happens, when the cadence recurs, when halt authority gets tested, when the assignment is reconfirmed if the owner changes roles. Undated accountability decays to zero inside two quarters, because the people who agreed to it get promoted, reassigned, or absorbed by something more urgent.

Authority That Has Never Been Exercised Is Not Authority

There is a fifth requirement, and it belongs to the Chief Operating Officer alone.

A halt authority that has never been used is a policy sentence. Where stopping a revenue-producing system draws immediate executive pushback, no owner will use the authority they were granted, whatever the document says, and the organization will learn that faster than it learns any policy. The COO makes the authority real exactly one way: by visibly backing a named owner the first time that owner halts something, in front of the people who will have to decide whether to do the same next quarter.

The reverse is equally fast. A COO who quietly overturns that first halt without an unusually strong justification has taught the organization that escalation authority is decorative, and has undone in one afternoon what a year of policy work was built to establish.

This is why the halt test belongs on the calendar rather than in the handbook. Schedule it, run it on a live system in a defined segment, and let people watch what happens to the person who pulls it.

Move the Gate From the Decision to the Distribution

The Accountability Contract settles who. The operating model still has to settle how, because the gate itself is built at the wrong altitude.

Human approval thresholds inspect individual decisions: this discount, this refund, this exception. That design cannot work against a system making thousands of small decisions per hour, each one legitimately below every threshold, whose harm exists only in aggregate. So rebuild the gate one level up. Set the threshold on the shape of the output across a period rather than on any single output, and instrument it so drift outside tolerance notifies the named owner automatically, instead of producing a report the owner has to think to request.

That is a small piece of engineering and a large piece of governance. It is also the only version of an approval gate that survives contact with a system operating at machine speed, and it converts the owner's monthly review from an act of diligence into an act of confirmation.

Procurement needs the same relocation. Vendor selection for any AI system touching pricing, demand forecasting, or competitive analysis is now an antitrust decision, and it should stay inside the existing process with four questions added. Does this platform ingest non-public data from other customers, including our competitors, into any model, benchmark, or recommendation we receive? Do we contribute our own non-public commercial data, including prices, capacity, costs, or forward plans, in a form the platform can use on behalf of another customer? What does the contract say about both, and does the vendor's answer in the sales process match what the contract permits? Who inside this organization signed for that, and on what date?

Those four questions cost a procurement cycle nothing. Their absence from the file is what a Civil Investigative Demand is designed to find.

What This Buys, and What It Leaves Behind

None of this requires a new committee, a new policy statement, or a new compliance function. It requires three things buildable in one quarter with people already on payroll: a reconciled inventory of every AI system actually in production, one named human owner per system with halt authority that has been exercised at least once in view of the organization, and a procurement question set that treats data flow as the antitrust variable it has become.

Compliance is the floor. An organization that builds only to the floor is building to whatever the last regulator happened to require, which means the standard leaves when the regulator does.

The operations leader who builds this now hands successors an organization where people at the operating layer know what they own, know they may stop it, and have seen someone do it without being punished. That capability was not assembled in response to an investigation, a demand letter, or a headline, which is precisely why it will still be running after the executive who built it has moved on.