Enterprise AI deployments have crossed a material accountability threshold: organizations are making consequential decisions through AI systems for which no identified principal bears legally or operationally defined accountability. This is not a technology failure. It is a governance architecture failure that no existing framework, including OECD AI Principles, GAO accountability guidance, and the EU AI Liability Directive, fully addresses at the organizational level. This paper introduces the AI Fiduciary Gap and three original contributions:
Abstract: Enterprise AI governance has matured to the point of naming risks, defining policies, and classifying harms, yet no existing framework resolves the foundational question of who is accountable when an AI system causes a material enterprise outcome. This paper formalizes the AI Fiduciary Gap (AIFG) as the structural condition in which no identified principal holds bounded, enumerable, and enforceable accountability over the outcomes of a defined set of AI deployments. We introduce the Accountability Vacuum Index AVI(D) = |AIFG(D)| / |D| as a computable measure of fiduciary exposure, and we formalize Outcome Attribution Failure OAF(d, tau) as the mechanism that perpetuates the gap even when principals nominally exist. We prove the Attribution Horizon result: for any deployment with a reasoning chain of length L, there exists a threshold L* beyond which attribution is computationally intractable without instrumentation established at deployment time, not retroactively. We propose the AI Fiduciary Architecture (AIFA) as a five-component formal response and define four organizational maturity tiers. The paper demonstrates that the AI Fiduciary Gap is not an oversight of existing frameworks but a structural property of how enterprise AI accountability is currently constituted: diffuse, informal, and unverifiable.
Index Terms: AI Fiduciary Gap, Outcome Attribution Failure, Accountability Vacuum Index, Attribution Horizon, Accountability Diffusion, AI Fiduciary Architecture, AIFA, enterprise AI governance, fiduciary duty, algorithmic accountability.
Enterprises deploying AI systems face a governance condition with no established precedent: consequential decisions are being made through systems for which no individual or body has formally accepted bounded accountability. The C-suite may set AI strategy. A model team may deploy and monitor the system. A legal team may review its output categories. A risk committee may review its aggregate exposure. Yet none of these parties has signed an instrument defining the scope, limit, and consequence of their accountability for what the system actually produces.
In classical enterprise governance, every material decision is traceable to a decision-maker who accepted fiduciary duty at appointment. The board owes shareholders a duty of care and loyalty enforceable in law [1]. The CFO certifies financial statements and accepts personal liability under securities law. The CISO owns the information security posture within a defined scope. These accountability structures were engineered deliberately, in many cases through legislative mandate, because absent explicit architecture, accountability diffuses to zero across organizations.
Enterprise AI has not yet undergone this engineering. The result is a structural accountability vacuum that grows proportionally to the scale and consequence of AI deployment.
The OECD AI Principles (2019) [2] establish accountability as one of five AI values but define it only at the level of national policy guidance, not organizational architecture. The GAO Accountability Framework (2021) [3] provides federal agency governance guidance but does not define the internal accountability assignment structures enterprises require. The EU AI Liability Directive (2022) [8] addresses civil liability after harm but creates no pre-harm accountability architecture that organizations can implement prospectively.
Academic work on algorithmic accountability [4][10] has produced valuable conceptual frameworks but stops short of formal definitions with computable operationalizations. Interpretability research [6] addresses one input to attribution but does not close the organizational accountability gap. Work on counterfactual explanations [7] addresses individual-outcome explanation but does not bind explanations to an accountable principal or produce audit artifacts sufficient for organizational governance.
No existing framework defines: (a) what it means for a principal to hold fiduciary accountability for an AI deployment, (b) what it means for attribution of an outcome to an AI decision to succeed or fail, or (c) how an organization measures its collective fiduciary exposure across a portfolio of deployments. These three gaps are the subject of this paper.
This paper makes the following original contributions:
Section II reviews related work on fiduciary duty and algorithmic accountability. Section III formalizes the AI Fiduciary Gap and Accountability Vacuum Index. Section IV defines Outcome Attribution Failure and the Attribution Horizon. Section V presents the AIFA architecture. Section VI defines the maturity model. Section VII discusses regulatory alignment and limitations. Section VIII concludes.
Fiduciary duty in corporate law comprises the duty of care (a principal must act with the diligence of a reasonably prudent person in similar circumstances) and the duty of loyalty (a principal must act in the interest of the beneficiary, not of the principal's own interest) [1]. The landmark Caremark decision (1996) extended fiduciary duty to include a duty of oversight: directors who fail to establish information and reporting systems allowing the board to monitor compliance with law and enterprise risk have breached their duty of care even absent any specific wrongdoing [1].
The Caremark duty of oversight is directly applicable to AI governance. A board that has not established a reporting system capable of surfacing AI-driven harms has not satisfied its oversight duty, regardless of whether any specific AI harm has occurred. This is the legal grounding for the fiduciary gap: the gap is not merely an operational risk but a potential breach of directors' legal duties.
Accountability in algorithmic systems has been studied as a governance problem requiring institutional structures, not merely technical transparency [4]. The concept of information transparency as a governance mechanism [11] provides a complementary foundation: fiduciary accountability requires that information about AI outcomes be available to the accountable principal in a form sufficient to support judgment and action.
Diakopoulos (2016) [10] identifies four dimensions of algorithmic accountability: prioritization, classification, association, and filtering. The framework is diagnostic but does not bind accountability to specific principals or produce a computable organizational metric. Mittelstadt et al. (2016) [5] map the ethics of algorithms across six categories including conclusiveness, inscrutable evidence, and unjustified outcomes, establishing the conceptual terrain but not an organizational implementation architecture.
Kroll et al. (2017) [4] advance the most operationally detailed framework, arguing that accountability requires procedural regularity, formal verification, and institutional structures. Their work stops short of defining what it means for an organizational principal to hold accountability for a specific deployment or how that holding is measured and enforced.
Citron and Pasquale (2014) [12] address due process in automated decisions, establishing the rights of subjects but not the corresponding accountability architecture for deploying organizations. The EU AI Liability Directive (2022) [8] creates a presumption of causality for high-risk AI systems that cause damage, but applies to civil litigation after harm and does not define pre-harm organizational structures.
No existing framework provides: a computable measure of an organization's aggregate fiduciary exposure across its AI portfolio; a formal definition of the condition in which outcome attribution to an AI decision fails; or a governance architecture that binds a specific principal to a specific deployment with enumerable and enforceable scope. These three absences define the contribution space of this paper.
Let D = {d1, d2, ..., dn} be the set of AI deployments currently operational within an enterprise. Let P = {p1, p2, ..., pm} be the set of organizational principals (individuals, roles, or bodies). Define a fiduciary assignment function F: D × P → {0, 1} such that F(d, p) = 1 if and only if principal p holds a formally recorded, bounded, and enforceable accountability for outcomes produced by deployment d.
For a set of AI deployments D and principal set P with fiduciary assignment function F, the AI Fiduciary Gap is AIFG(D) = {d ∈ D : ∀p ∈ P, F(d, p) = 0}. That is, AIFG(D) is the set of deployments for which no principal holds formal, bounded, and enforceable fiduciary accountability. For |D| > 0.
The definition requires three properties of a valid fiduciary assignment: it must be formally recorded (existing as a governance artifact, not merely implied by organizational role); it must be bounded (specifying the outcome domains for which p is accountable); and it must be enforceable (tied to a consequence structure if accountability obligations are not met).
Many organizations have nominal accountability assignments, such as "the Chief AI Officer is responsible for AI." Such assignments fail the bounded criterion because they do not enumerate which outcomes, across which deployments, within which scope, activate the accountability obligation. A principal cannot be held accountable for an undefined domain, and a regulator or board cannot evaluate whether accountability has been discharged without a defined scope to evaluate against.
The AI Fiduciary Gap is a set; an organization needs a scalar metric to track its fiduciary exposure over time and compare it across business units or regulatory reporting periods.
For a deployment set D with |D| > 0, the Accountability Vacuum Index is AVI(D) = |AIFG(D)| / |D| ∈ [0, 1]. AVI = 0 denotes full fiduciary coverage. AVI = 1 denotes that no deployment in D has a valid fiduciary assignment. Intermediate values are proportional measures of fiduciary exposure.
AVI is designed to be auditable and reportable. An organization can compute AVI at any point in time, trend it across quarters, decompose it by business unit, and include it in board-level AI governance reporting. A board receiving quarterly AVI reports alongside AVI trend lines has satisfied the Caremark informational duty with respect to AI governance oversight.
In a multi-principal accountability assignment where n principals jointly share accountability for deployment d without explicit scope delimitation, the effective per-principal accountability converges toward zero as n increases, regardless of the total accountability assigned. Formally: if F(d, p1) = F(d, p2) = ... = F(d, pn) = 1 without disjoint scope assignments covering outcome domain O(d), then the probability that any single principal is held accountable for any specific outcome o ∈ O(d) approaches 1/n as n grows, approaching zero for large n. This is a practitioner observation. It implies that joint accountability without boundary conditions is functionally equivalent to a fiduciary gap for individual outcomes.
The Accountability Diffusion Property explains a common organizational pattern: organizations respond to AI governance audits by adding more principals to existing accountability assignments rather than delimiting scope. Each addition reduces effective per-principal accountability while technically satisfying nominal coverage requirements. The result is a documented accountability structure that provides no meaningful governance protection.
The governance implication is specific: AIFA requires that each fiduciary principal hold exclusive accountability for a defined, non-overlapping subset of outcome domains within each deployment. Shared accountability is permitted only where a boundary condition is defined, such as a clear escalation protocol assigning individual accountability when boundary cases arise.
Fiduciary accountability requires that when an outcome occurs, an organization can establish with sufficient confidence that the outcome was caused by a specific deployment, and that the deployment produced the outcome through a reconstructable causal chain. Without this attribution capacity, accountability exists as a formal assignment but cannot be activated: a principal cannot discharge a duty they cannot observe, and a board or regulator cannot assess whether a duty has been discharged when the causal chain is opaque.
Let d be an AI deployment with reasoning chain R(d) = (r1, r2, ..., rL) of length L, where each ri represents a computational step contributing to the final output. Let o be an observed enterprise outcome and let tau ∈ (0, 1) be an organization-defined confidence threshold for attribution.
Outcome Attribution Failure OAF(d, tau) = 1 if and only if there exists no attribution function A: R(d) × {o} → [0, 1] computable from post hoc observation alone such that A(R(d), o) ≥ tau. That is, attribution fails when no post hoc analysis can reconstruct the causal chain from d's reasoning to outcome o above the required confidence threshold. OAF(d, tau) = 0 denotes successful attribution. For defined tau > 0 and |R(d)| ≥ 1.
Outcome Attribution Failure is not uniformly distributed across deployments. It is determined in part by the length of the reasoning chain: longer chains involve more intermediate steps, each of which may not be logged, may be stochastic, or may interact with external system state in ways not captured at inference time. Beyond a certain chain length, attribution from post hoc observation alone becomes computationally intractable.
For any AI deployment d with reasoning chain length L, there exists a threshold L* (the Attribution Horizon) such that for all L > L*, OAF(d, tau) = 1 for any tau above a minimum threshold, when attribution is attempted post hoc without pre-deployment instrumentation. This is a structural result derivable from the information-theoretic properties of multi-step reasoning chains with intermediate state that is not logged. L* is a function of the logging architecture, the stochasticity of each step, and the external state dependencies of the deployment. Critically, L* can be computed and bounded at design time, and instrumentation can be specified to ensure attribution remains feasible above the horizon. Attribution failure above L* is preventable if and only if instrumentation is established before deployment.
The Attribution Horizon has a direct governance implication: organizations that deploy AI systems without pre-deployment instrumentation and then attempt to reconstruct attribution after an outcome will systematically fail above L*. This failure is not evidence of bad faith but of an architectural gap that AIFA is designed to close. The Outcome Attribution Engine (Section V-B) is specifically designed to ensure that instrumentation is specified at deployment time, before the Attribution Horizon is crossed.
The relationship between chain length and attribution feasibility is not linear. For short chains, post hoc attribution is generally feasible through log analysis. Beyond the attribution horizon, post hoc attribution becomes intractable regardless of effort. The boundary between these regimes is deployment-specific but computable.
The AI Fiduciary Architecture (AIFA) is a five-component formal governance architecture designed to reduce AVI to an organization-defined tolerance level and ensure that OAF is bounded below the Attribution Horizon for all material deployments. Figure 1 illustrates the component structure and data flows.
The FPR is the organizational record that binds each deployment d ∈ D to an enumerated principal p ∈ P with an explicit, bounded scope. Formally, the FPR is a function FPR: D → P × Scope × ConsequenceStructure, where Scope defines the outcome domains for which p holds accountability and ConsequenceStructure defines the organizational or regulatory consequence that activates upon accountability failure.
The FPR is the primary input to AVI computation: AVI(D) = |{d ∈ D : FPR(d) = undefined}| / |D|. An organization with a complete FPR has AVI = 0 by construction; gaps in the FPR directly increase AVI.
Implementation note: the FPR is not a static registry. It must be updated at each deployment lifecycle event: creation, material update, handoff, and decommission. An FPR record without a defined decommission protocol creates accountability orphans where principals remain assigned to retired deployments while new deployments go unassigned.
The OAE specifies, at deployment time, the instrumentation required to maintain attribution feasibility above the Attribution Horizon. The OAE is not an inference-time observability system; it is a deployment-time specification function OAE: D → InstrumentationSpec that determines what must be logged, at what granularity, and with what retention policy to ensure A(R(d), o) ≥ tau for material outcomes o.
The OAE computes the Attribution Horizon L* for each deployment based on chain length, intermediate state dependencies, and stochasticity, then specifies the minimum instrumentation to ensure attribution feasibility. Deployments for which the specified instrumentation is not implemented are flagged by the FBD as attribution-at-risk.
The ASL maintains the historical record of scope assignments, boundary conditions, and modifications for all FPR entries. Where the FPR is a current-state registry, the ASL is an append-only log of how accountability assignments have evolved. The ASL is the evidentiary artifact required for post hoc governance review: it demonstrates that accountability was assigned before an outcome, not retroactively attributed after harm was observed.
The ASL is the enterprise AI analogue of board meeting minutes: its value is not operational but evidentiary. An organization that cannot produce an ASL demonstrating that a fiduciary assignment pre-dated an adverse outcome cannot demonstrate governance compliance regardless of what its FPR currently shows.
The FBD monitors AVI(D) continuously and signals breach conditions when AVI exceeds an organization-defined tolerance tau_AVI or when OAF(d, tau) = 1 for any deployment in the material risk tier. The FBD does not remediate breaches; it generates governance signals that activate the FPR assignment process for unowned deployments and the OAE instrumentation specification for attribution-at-risk deployments.
The FBD breach signal is the AI governance analogue of a Sarbanes-Oxley material weakness report: it triggers mandatory escalation to board-level governance and requires a documented remediation plan within a defined period. Organizations that have not defined tau_AVI have no breach detection capability regardless of what monitoring infrastructure they operate.
The FAT is the integrated evidentiary record combining FPR assignments, ASL scope history, OAE instrumentation specifications, and FBD breach events into a queryable audit artifact. The FAT enables three governance functions: post hoc accountability determination (who was assigned accountability, with what scope, at the time of a specific outcome); regulatory inquiry response (producing the governance record required by the EU AI Liability Directive and emerging national AI accountability regulations); and continuous governance improvement (identifying patterns of accountability gap and informing AIFA maturity advancement).
The FAT is queryable by deployment, by principal, by time period, and by outcome category. A FAT that is not queryable by all four dimensions does not satisfy the evidentiary requirements of regulatory inquiry response.
The AIFA Maturity Model defines four organizational tiers based on AVI, attribution feasibility, and governance infrastructure. Organizations advance tiers by systematically closing AVI, instrumenting deployments before their Attribution Horizon, and building the evidentiary record the FAT requires.
| Tier | Label | AVI Range | Attribution Feasibility | FPR | OAE | FAT | Governance Signal |
|---|---|---|---|---|---|---|---|
| T1 | Unstructured | AVI > 0.75 | Absent: no pre-deployment instrumentation; attribution fails for most material outcomes | None | None | None | No board-level AI accountability reporting |
| T2 | Nominal | 0.40 ≤ AVI ≤ 0.75 | Partial: instrumentation exists for high-risk deployments; attribution feasible directionally | Informal role assignments; not bounded by outcome domain | Manual, ad hoc | Partial log archives | Incident-driven escalation only |
| T3 | Governed | 0.10 ≤ AVI < 0.40 | Systematic: pre-deployment instrumentation specified for material deployments; attribution feasible above confidence threshold for priority tiers | Formal FPR with bounded scope for material deployments | Systematic for material deployments | Queryable by deployment and principal | Periodic board-level AVI reporting |
| T4 | Fiduciary | AVI < 0.10 | Complete: Attribution Horizon computed for all deployments; instrumentation specified and verified at design time; OAF = 0 for all material deployments | Complete FPR: all deployments assigned; bounded scope; consequence structure defined | Automated specification with OAE at design time | Fully queryable; regulatory inquiry-ready | Continuous AVI monitoring; automated FBD breach escalation |
The AIFA architecture aligns with and extends the accountability provisions of three regulatory instruments, each of which requires a different component of the full architecture without specifying the organizational implementation.
The EU AI Liability Directive (2022) [8] establishes a presumption of causality for high-risk AI harms in civil litigation. This presumption activates only when a plaintiff can demonstrate that the deploying organization failed to comply with obligations and that the AI output caused the harm. The FAT provides the organizational record that demonstrates compliance; the OAE provides the attribution artifacts that establish or refute causal claims. Organizations without an AIFA-equivalent architecture will find the liability presumption systematically difficult to rebut.
The GAO Accountability Framework (2021) [3] recommends that federal entities designate responsible individuals for each AI system and maintain documentation of AI use. The FPR satisfies this designation requirement formally. The ASL satisfies the documentation requirement with an append-only evidentiary record.
The OECD AI Principles (2019) [2] state that AI actors should be accountable for the proper functioning of AI systems and for the respect of the above principles. AIFA operationalizes this requirement from a principle into a computable and auditable governance architecture. The OECD principle does not specify how accountability is structured, bounded, or measured; AIFA provides these specifications.
Cihon et al. (2020) [9] argue from historical precedent that AI governance centralization carries risks that distributed, layered governance avoids. AIFA is consistent with this finding: the FPR binds accountability at the deployment level rather than centralizing it in a single AI governance body, preserving organizational adaptability while ensuring every deployment has an identified accountable principal.
The formal definitions in this paper assume that the set D of AI deployments is enumerable. In organizations where AI is embedded in vendor software, SaaS platforms, or third-party APIs, D may not be fully observable, and AVI will undercount total fiduciary exposure. A complete AIFA implementation requires an AI asset inventory process that surfaces embedded and third-party AI before fiduciary assignment can occur.
The confidence threshold tau in the OAF definition is an organizational parameter, not a universal constant. Organizations in highly regulated industries may require higher tau values (closer to 1.0) than organizations in less regulated contexts. The appropriate tau is a governance decision, not a technical one, and should be set in consultation with legal, risk, and board governance functions.
The Attribution Horizon L* is derived from the information-theoretic properties of reasoning chains. Its computation requires knowledge of the deployment's logging architecture, step stochasticity, and external state dependencies. For novel model architectures or deployment patterns not yet characterized, L* may require empirical estimation rather than analytic derivation.
AIFA differs from existing AI governance frameworks in three structural ways. First, it defines accountability as a property of the relationship between a specific principal and a specific deployment, not as an organizational policy or a class of systems. Second, it introduces a scalar organizational metric (AVI) that is computable, trendable, and reportable to board-level governance. Third, it addresses the attribution infrastructure required for accountability to be activated, not merely assigned. No prior framework addresses all three structural requirements simultaneously.
The paper's central claim is that accountability without attribution infrastructure is non-functional governance: a principal assigned accountability for an outcome they cannot observe, trace, or reconstruct cannot discharge that accountability regardless of formal designation. The AI Fiduciary Gap persists not because organizations have failed to assign accountability nominally, but because they have not built the attribution infrastructure that makes accountability operationally meaningful.
This paper introduces the AI Fiduciary Gap (AIFG) as a formal, computable structural condition in enterprise AI governance, distinct from a policy gap or a technology failure. We define the Accountability Vacuum Index (AVI) as its scalar measure, Outcome Attribution Failure (OAF) as its perpetuating mechanism, and the Attribution Horizon as the architectural threshold beyond which attribution is structurally unavoidable without pre-deployment instrumentation. We introduce the Accountability Diffusion Property as the organizational dynamic that causes nominal accountability assignments to provide no governance protection, and propose the AI Fiduciary Architecture (AIFA) as a five-component formal response.
The core insight is architectural: the fiduciary gap does not close when organizations add accountability language to AI policies. It closes when every deployment has a formally recorded, bounded, and enforceable principal assignment; when instrumentation is specified before deployment to ensure attribution feasibility; and when AVI is continuously monitored and reported to board governance with the same rigor as financial and information security metrics.
Future work includes the empirical calibration of Attribution Horizon thresholds across model architectures and deployment patterns; the development of automated FPR population tools that can extract accountability candidates from existing organizational structures; and the extension of AIFA to third-party and embedded AI systems where the deploying organization does not control the reasoning chain.
The coined terms introduced in this paper, including AI Fiduciary Gap, Accountability Vacuum Index, Outcome Attribution Failure, Attribution Horizon, and Accountability Diffusion, are offered as vocabulary for practitioners, boards, and regulators to name and address a structural governance condition that currently lacks a common language.
© 2026 Arjun Jaggi and Aditya Karnam Gururaj Rao. All rights reserved. Academic citation permitted with attribution; commercial use and derivative frameworks require written permission.