I cannot recommend it enough: “AI Liability Along the Value Chain” by Beatriz Botero Arcila – a sharp, Mozilla-supported analysis proposing a baseline of fault-based joint and several liability for AI systems, with targeted strict liability for high-risk cases. Her framework brilliantly examines the “many hands” problem: how to assign responsibility when harm emerges from developers, providers, deployers, and users operating across complex AI value chains.
From my standpoint, these questions take on an even more critical dimension when AI systems enter public bureaucracies. Consider automated benefits systems that blend vendor-supplied models, agency-defined parameters, and civil service oversight. When decisions go wrong – benefits are wrongfully denied, or privacy is compromised – responsibility fragments across departmental lines, contractor relationships, and technical infrastructures.
In these contexts, no single actor holds both the authority and the technical understanding necessary for meaningful accountability. This kind of institutional fragmentation risks creating a new banality of evil. One that is not born of malice, but of systemic complexity. Harm becomes everyone’s fault and no one’s responsibility. The problem isn’t just algorithmic opacity, it’s institutional displacement: procedures that automate decisions while quietly dissolving answerability.
Beatriz’s liability framework offers valuable tools for structuring private sector accountability. But in the public sector, we may need even deeper reforms. Effective AI governance requires more than rules for allocating liability – it demands institutions where responsibility is anchored in actors who are both empowered and equipped to understand and reshape the systems they oversee.
Also important, accountability shouldn’t only mean punishing wrongful deployment. It must also recognize the cost of inaction: of failing to deploy AI when it could reduce harm, increase equity, or improve service delivery. In the public sector, blame-avoidance cultures create strong disincentives to act. The safest path often becomes doing nothing – especially when “doing something” involves algorithms.
But doing nothing is also a choice – and it carries consequences. A mature approach to accountability must grapple with that too.