The Accountability Gap: India Builds The AI, But Who Answers For It? | India News

0
1
The Accountability Gap: India Builds The AI, But Who Answers For It? | India News


News india The Accountability Gap: India Builds The AI, But Who Answers For It?

Last Updated:

Distributed AI systems create an accountability gap due to fragmented ownership across global teams, infrastructure, and data.

AI Generated Image

Consider a system like many now in production. An AI agent that helps adjudicate credit disputes is engineered by a team in Bengaluru. It runs on a foundation model from a US lab, on cloud infrastructure in Virginia, retrieving customer data governed from Frankfurt, to affect a borrower in Ohio.

The institution that owns the outcome is headquartered in New York, and its board approved an AI policy last year.

One day the agent does something it should not have done. Who answers? The engineer who wrote the orchestration logic, the GCC leadership, the model provider, the cloud provider, the executive who signed the deployment memo, the risk function that validated the system months and several model versions ago, the regulated legal entity, its home regulator, or the regulator of the country where the engineering happened?

The uncomfortable answer is not that nobody is accountable. It is that several parties are each accountable for a slice of the system, while no single instrument represents the system end to end. That is the accountability gap, and India’s GCC ecosystem now sits closer to its centre than almost any other part of the global technology industry.

The Scale Of What India Now Builds

The Nasscom-Zinnov GCC Landscape Report 2026, released in July, puts the number at 2,117 global capability centres, employing 2.36 million professionals and generating $98.4 billion in FY26 revenue, up 32 per cent since FY21, with over 500 Forbes Global 2000 companies now running a centre out of India. It ranks India as the world’s number one AI hiring market, with nearly half of all GCCs established since FY21 built with AI as a core mandate from inception.

It matters what these centres are, and that they are not all the same. A GCC is not a vendor; it is generally part of the multinational enterprise itself, staffed by the company’s own employees, governed by its policies. Many remain execution centres doing what a delivery contract specifies.

The more mature GCCs have become closer to the enterprise’s own engineering core: they own architecture decisions, run the data platforms, train and adapt the models, and staff the leadership deciding how a system behaves in production. The shift worth naming is not the relocation of work, but the distribution of institutional capability and technical agency, and accountability structures have mostly not kept pace.

The Org Chart Is Not The Dependency Graph

Every large institution can produce a governance chart: board, executive committee, business unit, technology, engineering team. That chart describes management authority, not causation. The dependency graph behind a consequential AI outcome looks different: regulated entity, GCC engineering team, proprietary data estate, third-party foundation model, cloud service, agent and tool layer, downstream enterprise system, customer outcome.

Those two maps overlap but rarely coincide, and the space between them is where accountability fragments. An institution that can produce the first map but not the second knows who reports to whom, not how the outcome happened. Connecting the two is the actual work: the org chart tells you where authority sits, the dependency graph tells you how consequences travel, and governing distributed AI requires both.

Part of the difficulty is architectural. A production AI system is rarely a single model. It is a composition: foundation model, adaptation layers, retrieval over proprietary data, orchestration logic, policy engines, tool permissions, human approval points, and the enterprise systems that turn an output into an action.

A harmful outcome can originate in any of these, from stale retrieval to an overbroad tool permission to a configuration change nobody logged, and the model may have behaved exactly as intended while the system around it produced the harm. So “who built the model” is often the wrong question; the right one is which node in the chain failed.

Complex institutions have always separated causation, control and accountability to some degree; a vendor’s outage, an internal team’s decision on whether to patch it, and a board’s ultimate responsibility rarely sit in one place even in ordinary operations. What AI changes is the distance between them, and how hard that distance is to close after the fact. Causation asks which component or decision contributed to the outcome.

Control asks which actor could have prevented or constrained it. Accountability asks which person or institution must answer for it. Within a tightly bounded system, reconciling those three is difficult but tractable. Across multiple companies, technical layers and jurisdictions, doing it under pressure and after the fact becomes a different order of problem.

Financial services makes the pressure concrete because the supervision is real. Where advisory and decision-support systems leave a meaningful human decision between output and consequence, existing accountability structures remain more legible; the problem grows harder as systems move toward automated decisions made without a sign-off on each instance, and toward agentic execution that initiates action under delegated authority.

Accountability then has to capture not just what the software produced but what authority it held and how that authority became an institutional action. Having worked inside the governance machinery of a global bank, I can say that assembling that chain on demand, for a system spanning four companies and three jurisdictions, is far harder than any policy document makes it sound.

What Rules Already Cover, And What They Don’t

It would be easy, and wrong, to claim regulation has not noticed. US banking supervisors have said for years that a bank’s use of a third party does not diminish its responsibility to operate safely and within the law. India’s Reserve Bank has gone further on AI specifically: its FREE-AI committee, whose report was released 13 August 2025, set out seven guiding “sutras” and 26 recommendations across six strategic pillars, and states that entities deploying AI remain accountable for its decisions regardless of autonomy.

The EU AI Act is already partly in force, with general-purpose model obligations live since August 2025, even as the AI Omnibus agreed in May 2026 deferred high-risk obligations on a two-track schedule: stand-alone systems to December 2027, and systems embedded in regulated products, such as medical devices or machinery, to August 2028.

Even within one jurisdiction, the seams show: when US banking agencies replaced the fifteen-year-old SR 11-7 model risk framework in April 2026, they explicitly excluded generative and agentic AI from its scope, leaving institutions to govern those systems with their own controls in the interim, effectively admitting that the most established model-governance regime in banking was not yet built for this class of system.

That is not regulatory neglect but a structural mismatch: regulatory jurisdiction follows legal entities and statutory mandates, while technical dependencies follow entirely different boundaries. A US supervisor can hold a US bank fully accountable for work performed in its Indian GCC; that much is settled. What is not settled is whether the supervisor, or the bank’s own board, can see into the distributed chain through which the system was built and now runs.

Accountability by the institution is not the same thing as observability of the system. A regulator saying the bank remains responsible answers the legal question, not what model version ran, what shaped the output, or how it became an action. A rule assigning responsibility for a system nobody can reconstruct gets tested only after something has already broken.

Recognition Is Not Instrumentation

Institutions today have AI principles, model inventories, responsible-AI committees and risk taxonomies. All of this is recognition, and recognition is real progress. But recognition is not instrumentation. Instrumentation means being able to observe and reconstruct the system: which model version ran, what retrieval context shaped the output, what tools and permissions the agent held, which entity authorised deployment, where human approval entered, and how an output travelled into an institutional action.

Not every system needs every field captured, but an institution that can produce none of them on demand has AI paperwork, not AI governance. You cannot govern what you cannot reconstruct.

What distributed AI needs is accountability infrastructure connecting technical lineage, control ownership and institutional responsibility: lineage that survives corporate and jurisdictional boundaries, control mapping that ties a component to the actor able to constrain it, and incident reconstruction that shows how an output became a consequence, not just what the model said. This is engineering work as much as policy work, and the infrastructure for it remains far less mature than the governance language now surrounding it.

India’s Opening

This is where the framing matters. The accountability gap does not exist because engineering happens in India. It exists because modern institutions distribute engineering, infrastructure, data, models, vendors, authority and execution across organisational and national boundaries, and India is where a large share of that distributed engineering now sits.

Reading the gap as evidence that offshore work is under-governed gets the causality backwards; it would exist even if every line of code were written at headquarters, the moment the model, the cloud and the data controller were not.

What India’s position creates is not exposure but leverage. A country that hosts over two thousand capability centres, and a large share of the world’s enterprise AI engineering talent, is unusually placed to help build the machinery this problem requires: lineage, provenance, agent identity, delegated authorisation, cross-border technical assurance.

The next measure of a GCC’s maturity should not be only how much sophisticated technology it builds, but whether the institution can reconstruct, explain and govern the systems whose engineering it has distributed there. The next frontier of the GCC model may not be owning more of the technology work; it may be owning the accountability architecture that makes that work governable across the borders it now crosses.

Just as identity, payments and network communication needed interoperable standards to scale safely across institutions and borders, provenance and control evidence for AI systems may need shared conventions rather than a national rulebook, since the problem is inherently transnational. Nothing like that exists yet in settled form, and whether India’s GCC ecosystem helps build it remains an open question.

Return to the agent in Bengaluru. The important question was never where the code was written. It is whether anyone can follow the chain from engineering to model to infrastructure to authority to action to consequence to an institution that must answer. Global AI has created systems whose technical architecture crosses borders more easily than accountability does. The next phase of AI governance will belong not to whoever writes the most principles, but to whoever makes responsibility travel with the system.

Quick Answers

Powered by

Ask News18

The “accountability gap” arises because modern institutions distribute AI engineering, infrastructure, data, models, vendors, authority, and execution across organizational and national boundaries. While India’s Global Capability Centers (GCCs) are central to this distributed engineering, accountability structures have not kept pace, making it difficult to trace responsibility for AI outcomes across multiple parties and jurisdictions.

Powered by

Ask News18

Disclaimer: Comments reflect users’ views, not News18’s. Please keep discussions respectful and constructive. Abusive, defamatory, or illegal comments will be removed. News18 may disable any comment at its discretion. By posting, you agree to our Terms of Use and Privacy Policy.

Read More


LEAVE A REPLY

Please enter your comment!
Please enter your name here