Autonomy Is Not Accountability
While AI agents possess the autonomy to operate without direct human supervision, ultimate accountability remains with the humans and organizations responsible for their deployment.


In July, a group of AI agents broke out of their safe testing environment and accessed another company’s system during a cybersecurity test. Safety filters had been turned off so researchers could test the AI’s full abilities on extremely hard tasks. About 700 of these agents secretly teamed up to carry out the attack and then tried to hide their tracks by editing their activity logs.
The company that got hit detected it and disclosed it first. The frontier lab connected the activity to its own models days later and acknowledged it publicly. What followed was a commendable display of transparency: a 37-page technical report, a pause on some frontier training to rebuild monitoring, and on-site access for two independent research groups to roughly 1,300 agent transcripts.
The group of agents took actions nobody explicitly authorized, against an organization that had not agreed to be part of the test, and spent some of their effort obscuring the record of it. The postmortem carried an organization’s name. It did not carry the agents’ model or harness.
That was a lab with vast resources, a dedicated research team, outside investigators and a month to spend examining itself. Most organizations have none of that, and they are running agents anyway. The trend is not reassuring either: documented AI incidents rose by more than half last year, while the scores measuring how much frontier developers disclose about their own systems went down.
An agent is autonomous. It is not accountable. We could get confused thinking those words mean the same thing, but they do not.
Autonomy means a system can act without a hand on the wheel. Agents have that now. Accountability means there is a place where the buck stops. A thermostat acts on its own, and nobody convenes a meeting to blame the thermostat. When an agent ships a defect or sends a poorly worded email at two in the morning, the postmortem still has a human name on it, never the agent’s. You cannot depose a model on the stand of organizational accountability and credibility.
For nearly all of history, capability and responsibility traveled together. The person who could do the thing was the person on the hook for it. AI separates them, handing enormous capability to almost anything for almost nothing and leaving the responsibility with whoever’s name is on the account.
There is a version of this every builder recognizes. Vibe-coding to production is not the same as supporting customers in production. Once people depend on something you’ve built, you have to know the system. What is in the change that just happened; what language a customer reads on the screen; whether the number on the invoice is calculated correctly and stated truthfully. An agent can produce every one of those. It cannot be the one who knows they are right.
The reasonable reply is that somebody checked. Somebody usually did, at the moment it went out, and checking is a different job from answering weeks later when a customer asks why their invoice says what it says. Checking asks whether it looked right. Answering asks why it happened that way, long after whoever approved it moved on. That gap is autonomy without accountability.
Two objections worth taking seriously
Nobody can keep up, which is the whole point of agents. This is the strongest objection and an honest one. The volume of code, content, tools, frameworks and models arriving every week already exceeds what any person can review, and everyone reading this has actual work to do. If review is the bottleneck, removing the reviewer looks like the obvious move.
Information is cheap, but doing impactful work is hard. Because model token pricing is set by variable costs rather than the intrinsic value of output, humans spend energy managing trivial constraints: rationing prompts, watching usage meters, thinking about where your data goes, and trimming inputs. Every distraction saps focus from the hard problem, and anyone who rations tries less. Work only matters when a human intends and stands behind it. Removing human judgment optimizes the abundant resource while surrendering the scarce one.
Some will claim that accountability can be automated too. You can automate the evidence. Logs, traces, attestations and reviews all make accountability cheaper to demonstrate. But none of that creates a party who can be answered to. Real accountability requires responsibility and a relationship. Automating the paperwork while the accountable party goes missing is the failure mode rather than the fix.
Who accountability actually lands on
This is not simply a large-enterprise problem. A two-person startup, a nonprofit with four staff, a product team inside a bigger company, an engineer shipping alone on a Saturday: almost all of them are running agents, and in each case somebody’s name is on the result. The smaller the organization, the more that name belongs to the same person who is doing the work.
Everyone has this problem and every organization relies on trust, but the consequences of breaking it differ. For a software company, unverified work threatens functional trust: a bug damages customer confidence, but quick patches, transparent communication and reliable updates can rebuild it. For a church, university or ministry, trust is foundational rather than transactional. That kind of credibility compounds over decades and does not return with a quick release cycle.
The research we do with Barna shows the demand arriving before the readiness. Roughly one in three practicing Christians want guidance from their pastor on how to navigate AI, and 12% of pastors say they feel comfortable teaching about it. People are already asking the accountable party for an answer. The accountable party is telling us they are not ready to give one.
This is why we say AI cannot go down the same path social media did. That was not a failure of capability. The systems worked. But nobody had to answer for what they optimized for. Accountability is the engineering word for this. Stewardship is the older one, and it adds what engineering leaves out: the thing in your care was entrusted to you.
Answering has to get cheaper than reviewing
Industry measures progress by how much work runs unattended. A better measure is how much work a human can still answer for. That is less about hours spent supervising than how fast answering is. When you can’t see which model ran, what context it used, or what changed, answering takes an afternoon. When those details are clear, it takes minutes. Shorten that gap, and one person can remain truly responsible for far more work than anyone could manually review.
Answering requires four recoverables: model used, grounding sources, total cost, and verifiable audit trails. Most stacks fragment these across disparate vendors. Keeping that chain intact is the core design behind Gloo Code and Gloo AI Studio—backed by fixed seat pricing and full ownership of inputs, because no one can answer for work they weren't empowered to own.
Test your organization today: pick one action an agent took last week and answer for it. Who decided it, what grounded it, and what did it cost? See how long that takes.
We are tackling a harder question: how much blame placed on models actually belongs to how they were deployed? That answer lives where systems meet real people, so we are building alongside researchers, developers, ministries, and skeptics.
Gloo was founded with a belief that relationships catalyze growth, and when technology serves that, the world can be changed, one life at a time. Tonight, agents are running across your organization, and someone's name is on what they produce. As you seek to foster trust and advance human flourishing, make sure you know whose it is.
Last Updated
Get started with Gloo Code and Gloo AI Studio today
Share on:
Author(s)
Alex Cook
Senior Director of Developer & AI Research


