An AI system produces an output that causes harm, and identifying who answers for it is harder than it should be. The difficulty comes from how the layers are contractually arranged.
Why the chain has so many links
A typical deployment involves a model provider, a company building a product on it, an organisation deploying that product, and a person operating it.
Each layer makes decisions that affect the outcome, and none of them controls the whole system.
Traditional liability assumes a manufacturer, a seller and a user, and the mapping onto four independent parties with partial control is imperfect.
What the contracts already say
Provider terms disclaim responsibility for outputs comprehensively and require the customer to evaluate suitability for their own purpose.
Deploying organisations pass equivalent terms to their own customers, so disclaimers stack down the chain.
Where the chain ends is with the individual operator, who typically has the least information about how the system works and the least ability to have prevented anything.
Why the human in the loop is a weak answer
Requiring human review is the standard mitigation and the standard place responsibility is deposited.
It works when the reviewer has the time, information and authority to disagree, and it fails when the volume makes genuine review impossible.
A reviewer approving hundreds of outputs an hour is providing legal cover rather than oversight, and treating that arrangement as accountability is a recognised weakness in current practice.
How regulated sectors handle it differently
Medicine, aviation and finance already assign responsibility to a licensed individual or institution regardless of what tools were used.
A clinician remains accountable for a decision informed by a system, which resolves the question by refusing to distribute it.
This works because those sectors have licensing, insurance and established standards of care, and it does not transfer to sectors with none of that structure.
Where the responsibility is settling
The direction of travel places obligations on the deploying organisation, which is the party choosing to apply the system to a particular decision affecting particular people.
That party is identifiable, has a relationship with the affected person, and is in a position to decide whether the system should be used at all.
It also means a deployer cannot transfer accountability by pointing upstream at a provider it did not build and cannot inspect, which is uncomfortable for deployers and is the only arrangement that leaves someone answerable.