Saluca Labs
Saluca Labs

The Accountable AI Security Officer

A role definition

August 2026


Organisations have started giving AI systems credentials and the ability to act on them. Almost none can name the person who is answerable when one of them acts wrongly. That accountability is a role, and in most estates it is currently held by nobody.

One role decides what the system may do. This one is answerable when it does it.

The role, against what it is not

Every adjacent role is filled. The accountability is still unassigned.

This is not a staffing oversight. Each role below is doing its own job correctly, and none of them can hold this one without a conflict, which is why the gap stays open even in well-run organisations.

CISO
Owns the security programme. AI arrives as one more item on a list that was already full, and is triaged accordingly.
CIO or CTO
Owns delivery. Asking the person measured on shipping the system to be accountable for stopping it is a conflict, not an assignment.
AI or ML lead
Builds the systems and owns the model. Cannot be the check on their own work, and should not be asked to be.
GRC and compliance
Maps the estate to frameworks. Produces a mapping, which is a different artifact from a halt.
Context engineer
Builds the pipe that feeds the model. Judged by whether it runs.
Accountable officer
Named, holds the authority to stop a deployment, and is measured against a published instrument rather than an opinion. Answerable for AI not blowing up, explicitly not for AI strategy.
The precedent is not a new skill, it is a named person who can be asked. Financial controls did not become better understood in 2002. They became somebody's signature, and the signature is what changed behaviour.

What they produce

The role is legible by its artifacts

None of these is a document about a decision. Each one is the decision itself, in a form somebody outside the organisation can check.

What breaks without one

Failures most teams will already recognise

The value of the role is easiest to see as a list of things that happen when it is vacant. Each of these gets attributed to something else at the time.

The fourth one is the expensive failure. Everything above it costs a quarter. An answer given to a customer, an auditor or a regulator that turns out to be unevidenced is not a gap, it is a statement, and statements have a different half-life.

Measurement

How a governance claim is prevented from flattering itself

Any competent consultancy can produce a maturity matrix in which an organisation scores respectably. The instrument behind this role is built to make that specific outcome difficult, and three rules do the work.

The first is that the score is the floor. Eight dimensions are measured independently and the reported number is the lowest, because the weak dimension is the blast radius and averaging is how it disappears.

D1

Identity and provenance.

D2

Memory governance.

D3

Capability and authorisation.

D4

Auditability and receipts. This is the score. Not the average of the eight, which would read comfortably. The one that is weakest, because that is where an incident goes.

D5

Substrate and model strategy.

D6

Safety and failure modes.

D7

Organisation and process.

D8

Compliance and risk.

The second rule is that claims are not evidence. Every criterion carries an evidence grade, and the grade gates what it is allowed to prove. This is enforced in the scoring code rather than left to the assessor's discipline, because assessor discipline is exactly what erodes in week four of an engagement the client is paying for.

A. Observed directlyconfiguration, logs, a test run in front of you
B. Produced from the systeman export, a report the system generated
C. Documenteda policy, a diagram, a runbook
D. Assertedsomeone told you it works

The gate. A criterion claimed at the enforced levels and supported only by C or D is recorded as not met, however credible the person saying it. This is the single most unpopular rule in the instrument and the one that makes the rest of it worth anything. A policy describing an enforcement is evidence that the policy exists.

The third rule is that levels are conjunctive. A level is reached only when every criterion at that level is met. There is no partial credit that promotes, because a control set with one hole is not eighty per cent of a control set; it is a control set with a hole, and the hole is what gets used.

Reach across estates

The measurement is invariant. What it is pointed at is not.

The same eight dimensions, the same criteria and the same arithmetic apply to a bank and to a ten-person company. Scope, evidence burden, target level and price scale. The measurement does not. The moment the standard softens for a smaller client, the score stops meaning anything to the enterprise reviewer it was built for, and that reviewer is the entire point.

EstateThe agent typicallyReachesWho asks for the evidence
Financial servicesReads positions, drafts client communicationsthe customer recordThe regulator, then the auditor
HealthcareSummarises notes, routes referralsthe patient recordThe privacy office, and eventually a patient
Software and SaaSWrites code, opens pull requests, deploysproductionEvery enterprise customer's security review
Legal practiceDrafts, researches, summarises discoveryprivileged materialThe client, the insurer, the bar
IndustrialSchedules, tunes, orders partsthe physical processSafety, and the incident investigator
Small businessRuns the inbox, the calendar, the billingthe whole companyNobody, until it matters

The last row is the honest one. A small estate is not a lower standard, it is a smaller surface, and the whole assessment fits in a fortnight rather than a month because there is genuinely less of it. That is a real reason for a lower fee. Scoring generously is not.

Why the role is fractional

What it costs to hold accountability honestly

Most organisations need the accountability, not a full-time hire to carry it. But a role sold as continuous accountability and backed by one person with a sleep schedule is a breach the provider commits on its own, without the client doing anything wrong, simply by that person being asleep or on another engagement when something happens.

So the conditions below are not fine print. They are what makes the arrangement real, and any provider offering this role without them is selling something they are not staffed to deliver.

Coverage

A stated window, and an explicit statement of what is not covered

"Accountable officer" invites a buyer to assume a pager. The gap between that assumption and the truth is where the unforced breach lives, so the hours are written down before signature and the absence of monitoring is stated in the same paragraph.

Independence

The halt must not depend on the officer being reachable

Every engagement requires a client-side stop mechanism, held by someone independent of the team that built the systems, tested during the engagement with the date recorded. An officer who becomes the single point of failure is the exact finding the instrument exists to raise.

Continuity

A named alternate, or the absence of one disclosed

Where no substitute exists, that is stated to the client before signature rather than discovered afterwards, and the client holds a right to terminate immediately if the named individual becomes unavailable beyond a stated period.

Ceiling

A concurrent engagement limit that is arithmetic, not ambition

Days per month, divided by days per engagement. A provider who cannot tell you their ceiling has not done the division, and the number they eventually give you under pressure will be the one that fits the deal in front of them.

Recognition

How to tell a real one from a maturity matrix

The category is filling with respectable-looking offerings. These five questions separate them, ordered by how hard they are to answer well without meaning it.

Can they show you a score they gave that cost them the follow-on work?
An assessment practice whose findings never inconvenience the buyer is a sales instrument wearing a rubric.
Is the headline number a floor or an average?
Ask which dimension it came from. If the answer is a blend, the weakest part of the estate has already been hidden and the number cannot be used for anything.
Will they hand you the instrument itself?
A score you cannot audit is an opinion with a number attached. The criteria, the levels and the arithmetic should be legible to the person being measured.
Will they write down what they do not do?
Coverage hours, the absence of monitoring, the limits of the evidence they saw. A provider who will only put the positives in writing has told you which of the two lists is longer.
Can you stop the system without them?
If the answer is no, you have not bought accountability. You have added a dependency and given it a title.
Expect the first assessment to score badly, and treat a comfortable first result as a reason for suspicion rather than relief. The most useful output is rarely the number. It is the list of things that turned out to be unevidenced, which is the work you will have to do regardless of who you hire.

The instrument

Ninety-three criteria, eight dimensions, versioned and frozen

The rubric is at v1.0 and is deliberately frozen through the first engagements. Adding a criterion changes the denominator and therefore every historical decimal in that dimension, so defects are logged and a version ships on purpose rather than continuously and invisibly.

The full criterion set is provided to anyone being assessed under it, because a measurement the measured party cannot audit is not a measurement. Every criterion carries a verdict, an evidence grade and a citation, and the arithmetic over them is published rather than described.

The measurement →

The eight dimensions, the four levels, the evidence grades and the gate, and the floor rule with its arithmetic. What a level means and what it takes to reach one.

The engagement →

What an assessment involves, what the retainer covers and does not, the artifacts produced, and the terms that make an accountable officer arrangement honest rather than notional.

A companion practice, the context scientist, addresses the adjacent question: not whether the system is governed, but whether what enters its context window is true. The two roles fail differently and an estate can need both.