FIELD NOTE
Who Is Accountable When an AI Agent Makes a Mistake in a Small Business?
A practical framework for assigning accountability when AI agents make mistakes, using a human-led operating model with three work categories.
Accountability stays with the human who authorises the action. When an AI agent makes a mistake in a small business, the accountable person is the operator or owner who defined the agent's permissions, approved its deployment, and failed to put adequate human oversight in place. The AI agent is a tool, not a legal or moral actor; it cannot be fired, sued, or held responsible in any meaningful business sense.

This article outlines a human-led AI operating model for small businesses. It separates work into three categories—human only, AI assisted, and agent executable—and shows how to map a workflow, set approvals and logs, and decide who answers when something goes wrong.

Start with a Human-Led AI Operating Model
In a human-led AI operating model, people remain accountable for outcomes, while AI agents handle bounded, well-defined tasks under supervision. This model is built on three categories of work:

- Human only: Decisions that require judgment, accountability, or legal responsibility. Examples: signing contracts, approving refunds above a threshold, handling a sensitive customer complaint.
- AI assisted: AI drafts, suggests, or summarises, but a human reviews and approves before anything goes out. Examples: drafting an email reply, generating a social media caption, summarising a support ticket.
- Agent executable: AI acts autonomously within strict rules and guardrails, with logs and escalation paths. Examples: sending a standard order confirmation, updating a CRM field, posting a pre-approved product update.
Most small business mistakes happen when an agent is allowed to act in the third category without the necessary guardrails. The fix is not to avoid agents, but to classify work honestly and design controls that match the risk.

Map One Workflow Before You Automate It
To see where accountability sits, map a real workflow before automating any part of it. This is an illustration, not a client result.

Example: Inbound lead response

- Objective: Respond to a new website lead within 10 minutes, qualify them, and book a meeting.
- Inputs: Lead name, email, message, source, time stamp.
- Decisions: Is this lead a good fit? What service do they need? Who should handle the reply?
- Handoffs: From website form to CRM, from CRM to salesperson, from salesperson to calendar.
- Systems: Website form, CRM, email, calendar, maybe an AI agent.
- Permissions: Can the agent send an email? Can it book a meeting? Can it offer a discount?
- Evidence: Logs of what the agent did, what it said, and what the human approved.
Now classify each step:

- Human only: Deciding whether to offer a discount or accept a lead outside your service area.
- AI assisted: Drafting a personalised reply based on the lead's message; a human reviews and sends.
- Agent executable: Sending a standard acknowledgement email immediately, logging the lead in the CRM, and creating a task for follow-up.
If the agent sends a wrong acknowledgement or logs the lead incorrectly, accountability sits with the person who set the agent's permissions and failed to monitor the logs. The agent cannot be blamed; the process owner can.

Set Approvals, Logs, and Escalation Paths Before the Agent Acts
Before any agent is allowed to act, three things must exist:

- Approval rules: Who must approve which actions? For example, an agent may send a standard reply, but any message containing pricing or a promise must go to a human for review.
- Logs: Every agent action must be recorded with timestamp, input, output, and the rule that triggered it. Logs are your evidence when something goes wrong.
- Escalation paths: What happens when the agent encounters something outside its rules? It must stop and notify a human, not guess.
These controls are not bureaucratic overhead; they are the difference between a tool you can trust and a liability you cannot explain. In a small business, the owner or manager is usually the one who sets these rules, so accountability naturally rests there.

What the Evidence Says About AI Accountability
Regulators and standards bodies consistently place accountability on the organisation deploying the AI, not the AI itself. The OECD AI Principles state that organisations should be accountable for the proper functioning of AI systems and for the respect of the principles, based on their roles and context. The NIST AI Risk Management Framework similarly treats AI risks as organisational risks to be managed through governance, mapping, and measurement. Australia's Voluntary AI Safety Standard advises businesses to assign clear accountability for AI outcomes and to maintain human oversight for high-impact decisions.

These frameworks do not require a dedicated compliance team. For a small business, they translate into simple practices: document what the agent is allowed to do, keep logs, and have a named human who reviews those logs regularly. That named human is the accountable party.

Common Follow-Up Questions
Below are answers to questions founders often ask after reading this framework.

Can I just blame the AI vendor when something goes wrong?
No. The vendor provides the tool, but you configure it, grant it permissions, and decide when it acts without human review. Unless the vendor's product has a defect that directly causes harm, accountability remains with your business.

What if I didn't know the agent would do that?
That is precisely the failure of governance. If you did not know what the agent could do, you did not map the workflow or set permissions correctly. The accountable person is the one who deployed the agent without understanding its capabilities and limits.

How much human oversight is enough?
It depends on the risk of the action. For low-risk, reversible actions like sending a standard acknowledgement, logs and periodic review may suffice. For high-risk actions like issuing refunds or making promises to customers, human approval should be required every time. The key is to match oversight to consequence.

What should I do immediately after an AI mistake?
First, stop the agent from repeating the action. Second, review the logs to understand what happened and why. Third, fix the permission or rule that allowed the mistake. Fourth, communicate with any affected customers honestly. Finally, update your workflow map and controls to prevent recurrence.

A Practical Next Step
If you are unsure where to start, bring one real workflow to a process review. Mapping a single workflow—like inbound lead response—will reveal where you can safely use AI and where you need human judgment. For more on how I approach this, see my background or what I am working on now. If you want a structured review of your AI automation plans, get in touch.

FAQ
Who is legally responsible for AI mistakes in a small business?
The business owner or operator who deployed the AI agent is legally responsible. AI agents are not legal persons and cannot be held liable; accountability rests with the human who authorised the agent's actions.
What is a human-in-the-loop AI workflow?
A human-in-the-loop AI workflow is a process where AI assists or acts but a human reviews, approves, or can intervene at critical steps. This ensures that consequential decisions remain under human control.
How do I decide which tasks an AI agent can do autonomously?
Classify each task by risk: low-risk, reversible tasks with clear rules can be agent executable; higher-risk tasks should be AI assisted or human only. Map the workflow and set permissions accordingly.
What logs should I keep for AI agent actions?
Keep a timestamped record of every agent action, including input, output, the rule or permission that allowed it, and any human approvals. Logs provide evidence for review and accountability.
Sources
- OECD AI Principles — OECD
- AI Risk Management Framework — NIST
- Artificial Intelligence Risk Management Framework (AI RMF 1.0) — NIST
- Ethics guidelines for trustworthy AI — European Commission
- Who is liable when AI kills? — Scientific American