An options library: these pages compare approaches without selecting one. Nothing here is an approved Maha position, a personal commitment, or a declaration of candidacy.

draft option · Options brief — not an approved position

Who should be accountable when an AI system causes harm?

Drafted 2026-09-19 · No personal position approval · Uncosted

Short answer

A draft option is to assign responsibilities to the organizations and people controlling design, deployment and use, rather than allowing responsibility to disappear behind the word AI. Require records sufficient to investigate incidents, a responsible contact, a route to challenge consequential decisions and proportionate oversight. Those controls do not by themselves determine legal liability, prove that an output is correct or require buying Maha’s products. Liability depends on the facts and applicable law. Compare existing sector-specific enforcement with possible new duties before proposing legislation. Independent review and access to remedy should be evaluated alongside compliance costs and the risk of excluding smaller providers.

What the evidence establishes

Baseline: 2021/2023 frameworks; overview and revision notice inspected 2026-09-19. Access date is not the observation or effective date.

source description

GAO’s framework organizes accountability around governance, data, performance and monitoring.

GAO-21-519SP: Artificial Intelligence — An Accountability Framework

source description

NIST describes its AI RMF as voluntary. A risk-management framework is not an enacted liability rule.

NIST: AI Risk Management Framework

Options and mechanism

New options under consideration—not approved commitments

  • Improve incident records, responsible contacts and routes to challenge decisions.
  • Compare existing sector enforcement with new statutory duties.
  • Use proportionate independent assessment rather than treating a receipt as proof of correctness.

Proposed mechanism

Map control and responsibilities across the supply chain; test whether an affected person can obtain an explanation and remedy without requiring disclosure of unrelated personal data.

Who could act

Legislatures, regulators and courts

Specific duties, enforcement and remedies require jurisdiction- and sector-specific analysis; frameworks alone create no new authority.

Requires legal review NIST: AI Risk Management Framework

Public purchasers and deploying organizations

Contractual controls may be considered within procurement and privacy law; their enforceability has not been reviewed here.

Requires legal review

Costs and who is affected

Uncosted. No independent budget score or savings promise.

Cost assumptions
Estimate record retention, security, assessment, complaint handling and remediation separately.
Funding
No mandated provider, certification fee or public appropriation proposed.
Distributional effects to assess
Consider affected people, small suppliers, deploying organizations and public enforcement capacity.
Uncertainty
A heavier process can create cost without improving detection or remedy.

Strongest objection

Broad duties may concentrate the market and create a paperwork defence while affected people still lack practical remedies.

A reasonable alternative

Start with enforceable sector-specific obligations and test whether additional duties close a demonstrated gap.

These are reasoned objections prepared for review, not an invented consensus or an attributed opponent’s statement.

Implementation and tests

  1. Identify a consequential use and applicable law.
  2. Map control, incidents and access to remedy.
  3. Compare enforceable options and administrative burden.
  4. Evaluate investigation and remedy outcomes.

Outcomes to measure

  • Time to investigate and remedy substantiated harm.
  • Record usefulness, privacy incidents and compliance burden.

Failure conditions and reasons to reconsider

  • Documentation increases without better remedies.
  • Requirements expose sensitive data or exclude smaller providers unnecessarily.

Sources and review

AI-assisted source inspection and drafting; no independent expert, legal or budget review; no personal position approval.

Unresolved before publication

  • No jurisdiction-specific liability survey or legal opinion.
  • Maha’s evidence/governance services create a disclosed commercial interest.
GAO-21-519SP: Artificial Intelligence — An Accountability Framework

Open source ↗

Exact locator
Highlights: What GAO Found; Why GAO Developed This Framework
Version and inspection
June 2021 framework, highlights inspected September 19, 2026; section inspected 2026-09-19.
Supports
GAO organizes accountability practices around governance, data, performance and monitoring.
Does not establish
Highlights-level framework inspection does not establish legal liability or verify a particular system.
Rights boundary
Link and original bounded paraphrase only; no full text, photographs or third-party figures redistributed. Public availability is not a blanket reuse licence.
NIST: AI Risk Management Framework

Open source ↗

Exact locator
Overview of the AI RMF, first three paragraphs; revision notice
Version and inspection
AI RMF 1.0 released January 26, 2023; revision notice observed September 19, 2026; section inspected 2026-09-19.
Supports
The framework is voluntary and addresses trustworthiness across AI design, development, use and evaluation.
Does not establish
Not a certification, liability safe harbor, enacted law or independent endorsement of Maha.
Rights boundary
Link and original bounded paraphrase only; no full text, photographs or third-party figures redistributed. Public availability is not a blanket reuse licence.
Revision history and interests

v1 · 2026-09-19: initial options brief and source-bound baseline; no prior decision or review inherited.

Maha Strategies develops and offers evidence and AI-governance services. That commercial interest is relevant to its AI policy analysis; these briefs are not product endorsements or purchasing requirements.

Related questions