A long-standing principle from Apple’s management playbook has fresh relevance as organisations deploy autonomous AI agents into operational workflows.
Summary
- The ‘Directly Responsible Individual’ (DRI) concept, originating at Apple, designates one human as ultimately accountable for the success or failure of any project or initiative.
- Technologist Simon Willison argues that an AI agent should never hold the DRI role, because machines cannot bear genuine accountability for their actions.
- An IBM training slide from 1979 makes the same point plainly: a computer must never make a management decision precisely because it cannot be held accountable.
- As LLM-powered agents take on more autonomous tasks inside organisations, the absence of a clear human DRI creates a governance gap with real risk consequences.
- CISOs should ensure every AI-assisted workflow has a named human owner who can answer for outcomes, not just a system or a vendor.
An Old Concept Meets a New Problem
The term ‘Directly Responsible Individual’ has its roots at Apple, where it describes the single person who is ultimately accountable for the success or failure of a specific project, initiative, or activity. The GitLab handbook offers one of the cleaner public definitions. The concept is straightforward in a traditional management context: one human, one outcome, clear accountability.
Why AI Agents Change the Question
Technologist Simon Willison has been applying the DRI lens to the growing deployment of LLM-powered agents inside organisations. His conclusion is direct: an AI agent should never be considered the DRI for any project. The reasoning is not about capability. It is about accountability. A human can answer for a decision — professionally, legally, ethically. A machine cannot.
IBM Said It in 1979
This is not a novel observation. Willison points to an IBM training slide from 1979 that states the matter with memorable economy: ‘A computer can never be held accountable, therefore a computer must never make a management decision.’ Forty-five years later, that sentence reads less like a historical footnote and more like an unheeded warning. The framing has become freshly relevant as organisations begin treating AI agents as participants in consequential workflows rather than as tools operated by humans.
The Governance Gap This Creates
For security executives, the practical concern is not philosophical. When an LLM-powered agent takes an action — escalating an alert, drafting a communication, executing a code change, interacting with a third-party system — someone in the organisation is exposed to the consequences if that action is wrong. If no human has been designated as the accountable owner of that agent’s behaviour in context, accountability diffuses across teams, or disappears entirely. Neither outcome is acceptable in a regulated environment or during an incident response.
The Temptation to Blur the Lines
There is a genuine temptation, as AI agents become more capable and more autonomous, to treat them as quasi-colleagues rather than as automated systems operating under human direction. Vendors encourage this framing. Workflow diagrams increasingly show agents alongside human roles. But the DRI principle cuts through that framing cleanly: no matter how sophisticated the agent, it cannot answer to a board, a regulator, a customer, or a court. The human who deployed it, configured it, or authorised its actions can.
Accountability Structures Must Precede Deployment
The practical implication is that accountability structures for AI agents need to be defined before deployment, not retrofitted after an incident. That means naming a human DRI for every agent-assisted workflow: the person who owns the agent’s scope, reviews its outputs, and answers for failures. It also means documenting that ownership clearly enough that it survives personnel changes and organisational restructuring.
Why it matters
CISOs are increasingly responsible for AI governance as well as information security. As LLM agents are embedded into security operations, IT workflows, and business processes, the absence of a named human accountable for each agent’s behaviour is itself a risk. Regulatory frameworks, incident response obligations, and basic duty-of-care requirements all assume a human can answer for system behaviour. The DRI model offers a simple, proven structure to ensure that assumption holds.
What to do now
- For every LLM-powered agent deployed in your organisation, designate a named human as the Directly Responsible Individual — the person accountable for its behaviour, scope, and outcomes.
- Document DRI ownership for AI agents in your governance register, and ensure that documentation is updated when personnel or organisational structures change.
- Review existing AI-assisted workflows to identify any where accountability for agent actions is ambiguous or distributed across multiple teams without a single owner.
- Include DRI designation as a mandatory step in your AI procurement and deployment approval process, before any agent is moved into production.
- Brief leadership and relevant stakeholders that capability and accountability are separate questions: an agent can be highly capable while remaining unable to bear accountability — that gap is always a human responsibility to fill.
