Who's Accountable When AI Writes the Code?
When AI-authored code ships and something breaks, whose name is on the change? Accountability doesn't transfer to a tool. Here's how to turn it from a feeling into a record you can produce on demand.

Part of our AI Code Governance: A 2026 Field Guide series — the operating model for attributing, classifying, deciding, and proving AI-written code.
A change goes to production. Two weeks later it fails — a bad query, a mishandled edge case, a quiet data leak. Someone pulls up the merge to find out who made the call and why.
The author field says an AI agent. The reviewer field is empty. And the room goes quiet, because the honest answer to "who's accountable for this?" is nobody wrote it down.
That silence is the real problem. Not that AI wrote the code — that no one can say who owned it.
Who is accountable when AI writes the code?
The organization that shipped the code is accountable — and in practice, so is whoever can produce the record of how it got there. Accountability does not transfer to a tool. An AI agent is not a legal person, cannot be disciplined, cannot testify, and cannot be held liable. Every regulator, auditor, and court treats the agent as an instrument; responsibility stays with the humans and the organization that deployed it.
So the question was never whether you're accountable. You are. The only question is whether you can prove how a given change came to exist when someone asks — and today, for most AI-authored changes, you can't.
The accountability gap AI opened
For decades, accountability rode on a simple fact: a human wrote the code and a human reviewed it. Two names, two moments of judgment, both recorded. The system of record was a byproduct of how the work was done.
AI coding agents broke that byproduct. Now:
• A change can be authored by an agent with no human keystroke behind it.
• It can be merged with no approving reviewer — one of dozens that landed that week.
• The reasoning — why this change, why now — lives in a chat transcript that isn't attached to anything durable.
None of this is malicious. It's just that the accountability that used to come free now has to be built on purpose.
"The AI did it" is not a defense
It's tempting to treat the agent as a shield: the model wrote it, so the mistake belongs to the model. That argument collapses the moment it's tested.
A board asking about a failed release, an auditor sampling your change history, a customer's security team running due diligence — none of them will accept "our AI did it" as an answer. What they want is unglamorous and specific: which changes were AI-authored, were they reviewed, against what controls, and can you show us the record? An answer that points at the tool isn't an answer. It's the absence of one.
Accountability is a record, not a feeling
You make AI-written code accountable the same way you always made anything accountable — by producing a record. Concretely, that means running a loop over every AI-touched change. We call it the Accountability Loop:
Attribute — which changes were AI-authored, in which repositories?
Classify — which of those repos actually matter, and how sensitive are they?
Decide — against your controls, what's proven, what's a gap, what's a violation?
Prove — produce a record you can hand to a board, an auditor, or a client's due-diligence team.
The point isn't to slow the agents down or to put a human back in front of every keystroke. It's to make sure that for anything that matters, there is a name, a decision, and evidence — attached to the change, not lost in a transcript.
What good looks like
You don't need every AI change reviewed by hand. You need the important ones to be attributable, evidenced, and — where it counts — reviewed.
Attributable. Every merge carries whether it was AI-authored and in what context. No mystery changes.
Reviewed where it matters. High-sensitivity repositories require a human approver on AI-authored merges; low-risk ones don't. Accountability scaled to stakes, not applied flat.
Evidenced. The controls that govern AI code turn green because a fact was observed, and the whole picture freezes into a record you can produce on demand.
That's the difference between hoping nobody asks and being ready when they do.
Where Provenance fits
Diwo Provenance makes AI-written code accountable without slowing your developers down. It attributes AI-authored changes across your estate, weights them by business criticality, decides them against your controls, and freezes the evidence into a sealed record — so the answer to "who's accountable for this change?" is a document, not a shrug.
It's a coach, not a blocker: it governs the decision and freezes the record, so accountability is something you can show, not just assert.
Seeing your own estate takes about 15 minutes with a free, read-only connection: connect your estate free and see which AI-authored changes in your code have no owner today.
When AI writes the code, someone still has to sign it.
Related reading
The pillar: AI Code Governance: A 2026 Field Guide — the full operating model and the three risks to govern first.
Your AI Agent Has Your Production Keys — Here's How to Find Out
Slopsquatting: The Supply-Chain Attack Your AI Agent Invites In
FAQ
Can an AI be held legally accountable for the code it writes? No. AI is treated as a tool. Accountability stays with the organization that deployed it and the people responsible for shipping the change.
Does making AI code accountable mean reviewing every AI change by hand? No. It means every change is attributable, and the ones that matter — by sensitivity — carry a human approver and evidence. Accountability scaled to risk, not applied uniformly.
What record actually satisfies an auditor? One that shows which changes were AI-authored, whether they were reviewed, which controls they were judged against, and evidence that the record hasn't been altered since.
Diwo helps organizations govern AI-written code: attribute it, classify it, decide against your controls, and prove it — as sealed evidence, mapped to the frameworks you already answer to.
