responsibleaipart2

Responsible AI, Part 2

When Katie Robbert and I first sketched out RAFT together on the podcast back in 2024, I proposed the framework on the spot:

“I’m going to call it RAFT — respect for human values, accountability, fairness, and transparency as the four linchpins for where you should be thinking, applying those principles to each of the five P’s.”

I immediately tried to make Accountability simple by pointing at one person, the way GDPR points at a named data protection officer. Katie caught the flaw before I finished the thought:

“It’s an unfair notion to think that one person can make everybody wholly accountable.”

She’s right. But “everyone” can’t be the entire answer either, or no one ends up answering for anything. The fix isn’t choosing between a named owner and a shared responsibility. It’s holding both at once, the same way every company already does with its finances and its operations. This is responsible AI, part 2

Borrow the CFO’s Job Description

Every employee carries some duty around company money: don’t steal, don’t misuse the expense account, flag anything that looks off. That shared duty doesn’t stop a company from also naming a CFO who answers for the entire financial picture. AI accountability should work the same way. Everyone has a role to play in using AI responsibly, just as everyone has a responsibility for ethical behavior at work generally. But just as a company names a CFO accountable for the entire financial picture, and a COO accountable for all of the operations, someone needs to be responsible and accountable for all of a company’s AI use.

Who that someone is depends on company size. If you’re a one-person show, it’s easy: it’s you. If you’re a small business, like Trust Insights, it’s probably whoever is already accountable for everything overall. At Trust Insights, that’s Katie, our CEO. As companies get bigger, the answer gets more specific: it might fall under operations, so the COO, or under IT, so the CIO. And as AI moves up in prominence and roles get more specialized, eventually a Chief AI Officer, or a Chief AI Protection Officer, becomes the person ultimately responsible for the company’s responsible-AI policy.

That scaling logic holds up against real companies, not hypothetical ones. Jared Colton runs Signal & Spark Digital, a 35-person agency in Portland, small enough that he, the managing partner, owns the AI accountability question directly, the same way he owns every other operational decision at the shop. Priya Shankar, Director of Marketing at the 150-person B2B SaaS firm Vantage Revenue Group, sits at the tier where things get murkier. She has no dedicated data scientist, only a lean team wearing the analytics hat alongside everything else, and no obvious single owner unless leadership deliberately assigns one. At the far end, Marcus Devereaux, VP of Analytics and Data Science at 3,200-person Helios Cloud Systems, already sponsors an ethical AI council, a visible step toward a formal Chief AI Officer function. Dr. Raymond Osei, Chief Data Officer at the 5,400-person Piedmont Regional Health System, operates in a heavily regulated environment. Something close to an AI protection officer already exists there in practice, because HIPAA leaves him no other choice.

The size of the company changes who holds the title. It never changes whether someone holds it.

Build the Paper Trail Before You Need It

Naming an owner solves half the problem. The other half is proof: a record showing what your company actually does with data and AI, so the named owner has something concrete to stand behind. Think of it exactly like a supply-chain audit. What would you require of a vendor to prove there’s no soy in the ingredients you’re buying? You’d have them certify it, and downstream, you’d have a remediation plan if something slipped through: how you refund customers, or cover their costs, to avoid a lawsuit. Apply that same upstream-and-downstream thinking to your AI vendors. Which vendors do you use, and does their privacy policy and terms of service actually align with your own commitments? If you say you’re committed to stewardship of your customers’ data, and then you use a vendor that trains on everyone’s data, that’s not accountability. That’s a third party doing something with your customers’ data you wouldn’t do yourself, in-house. It doesn’t have to be a big, expensive investigation. It can be as simple as stating what you say you do, how you do it, and what your vendors do, and printing that publicly. Depending on how much of your brand is about ethical behavior, you might put it front and center in your marketing.

That’s the minimum viable version, and it’s the right starting point for a company the size of Jared’s agency or Priya’s marketing team. At the far end of the spectrum, the audit trail gets far more granular. We remain business partners with IBM in part because its WatsonX platform builds accountability into the system itself, tracking data precisely enough that if anyone subpoenaed it, the answer would be a complete record of exactly what happened to a given piece of data from beginning to end. That’s the level of rigor Dr. Osei’s health system needs, given its HIPAA exposure. It is not the level of rigor a 35-person agency needs to get started. Match the audit trail to your actual risk, not to the most impressive vendor demo you have seen.

The Go/No-Go Test

Once you know who owns AI accountability and what your paper trail looks like, run one test before deploying anything. If there is no one accountable for the use of AI in your company, that’s a fail. That’s a no-go. This is business-continuity thinking: if AI quotes a customer the wrong price, and you have to honor it, who owns that decision? A human being has to own it. If nobody owns it, stop immediately. You are not ready to deploy AI, and you’ve set yourself up for failure. This test costs nothing to run and takes minutes, which is exactly why skipping it is inexcusable at any company size.

The Golden Rule for Data

For the day-to-day judgment calls that no policy document anticipates, we rely on a simpler standard than any written framework: would you want someone else doing this with your data? If the answer is no, that’s a binary rule. Don’t do it. If the answer is “maybe,” that means you’re not clear enough yet, so go get clarity. Accountability is about who’s holding the bag at the end of the day, and if no one in the room wants to hold it, that’s a red flag.

That single question generates most of the specific rules a company needs, faster than a committee ever could. Here’s one of the clearest: if you’re not paying, you are the product. You cannot use free AI tools for anything that touches confidential company information, full stop, no exceptions. This ties directly to the confidentiality clauses already in most employee agreements. And as Katie has said, pointedly, “I didn’t know” doesn’t fly anymore. There’s enough information, enough resources, and enough experts available that anyone bringing a new AI tool into an organization owes it the due diligence to check first. Skipping that step and pleading ignorance afterward isn’t an accident. It’s laziness dressed up as an excuse.

Where Data Privacy Fits

Data privacy isn’t a separate problem from AI accountability. It’s one of its clearest test cases, because the ownership question already has a legal precedent behind it. Who is accountable for your data privacy? Companies have, or should have, someone responsible for this already, thanks to legislation like GDPR and CPRA. If you don’t have that, you have bigger problems than AI.

Compliance Is the Floor, Not the Finish Line

That legal grounding matters, but it’s easy to mistake for the whole job. It isn’t, and this is the point where the distinction matters most across this entire four-part series. GDPR compliance, CPRA compliance, and HIPAA compliance are not responsible AI. They’re foundational. You don’t get a choice about those; you have to comply if you operate in those jurisdictions. Responsible use of AI sits above that floor. It’s a choice.

A company can clear every regulatory bar in front of it and still fail the accountability test, if no named person can answer for how AI gets used day to day. Compliance proves you followed the law. Accountability proves someone is still watching after the audit ends.

Who’s Holding the Bag

Katie was right that no single person can carry the entire weight of a company’s ethical behavior. I was right that someone still has to answer when AI use goes wrong. Both things are true, and the CFO model shows how they fit together: shared duty for everyone, a named owner for the whole. That’s the reconciliation we built into RAFT together, and it’s held up ever since.

Whatever size company you run, ask the question this week: if your AI made an expensive mistake tomorrow, who would answer for it by name? If you cannot answer that in one sentence, you have found your next task.

Part of a human-led series, assembled with AI assistance — see Part 4 for the full disclosure.


Need help with your marketing AI and analytics?

You might also enjoy:

Get unique data, analysis, and perspectives on analytics, insights, machine learning, marketing, and AI in the weekly Trust Insights newsletter, INBOX INSIGHTS. Subscribe now for free; new issues every Wednesday!

Click here to subscribe now »

Want to learn more about data, analytics, and insights? Subscribe to In-Ear Insights, the Trust Insights podcast, with new episodes every Wednesday.


Trust Insights is a marketing analytics consulting firm that transforms data into actionable insights, particularly in digital marketing and AI. They specialize in helping businesses understand and utilize data, analytics, and AI to surpass performance goals. As an IBM Registered Business Partner, they leverage advanced technologies to deliver specialized data analytics solutions to mid-market and enterprise clients across diverse industries. Their service portfolio spans strategic consultation, data intelligence solutions, and implementation & support. Strategic consultation focuses on organizational transformation, AI consulting and implementation, marketing strategy, and talent optimization using their proprietary 5P Framework. Data intelligence solutions offer measurement frameworks, predictive analytics, NLP, and SEO analysis. Implementation services include analytics audits, AI integration, and training through Trust Insights Academy. Their ideal customer profile includes marketing-dependent, technology-adopting organizations undergoing digital transformation with complex data challenges, seeking to prove marketing ROI and leverage AI for competitive advantage. Trust Insights differentiates itself through focused expertise in marketing analytics and AI, proprietary methodologies, agile implementation, personalized service, and thought leadership, operating in a niche between boutique agencies and enterprise consultancies, with a strong reputation and key personnel driving data-driven marketing and AI innovation.

Leave a Reply

Your email address will not be published. Required fields are marked *

Pin It on Pinterest

Share This