← VuduVationsThe Intelligence Bureau
VuduIntelConsulting-AI Intelligence
← Edition No. 7
Legal Frame

Wipro's privacy chief named the rule that makes AI governance mandatory: you cannot hand off responsibility for an agent you deployed.

Ivana Bartoletti's non-delegable responsibility says accountability for an autonomous agent stays with the organization that deployed it, not the agent, the vendor down the chain, or the user who clicked go.

VuduVations Intelligence Bureau · May 15, 2026 · 2 min read
Governance & AuthorityOwn vs Rent
Share

In an interview with AI Magazine, Ivana Bartoletti, Wipro's global chief privacy and AI governance officer, introduced a principle with a deliberately plain name: non-delegable responsibility. Her formulation is precise. When an organization deploys an autonomous agent, it cannot transfer accountability for that agent's actions to the agent itself, to another organization in the supply chain, or to the user who triggered the activity. In other words, no matter how many hands the work passes through, the buck stops with the company that turned the agent on.

This reads like a thought-leadership line, but it functions as a liability frame, and that is what makes it consequential. If accountability cannot be pushed down the chain to a vendor, a subcontractor, or an employee, then governance stops being an optional add-on and becomes a requirement of deploying agents at all. An enterprise running agents at scale now needs a way to enforce that responsibility, and a requirement that every serious buyer shares is the raw material of a product.

The hard part is that agentic systems do not decide the way people do. Bartoletti's point is that these systems produce outcomes through long chains of small decisions that are not individually explainable in any meaningful way, so oversight has to judge behavior over time rather than one choice at a time. That pushes governance earlier: it has to be built into how the system runs, not reviewed after the fact, with an auditable trail that travels alongside every agent action. Structured for review, in other words, before anyone has to ask.

Expect the enterprise legal function to start asking the uncomfortable question first: when this agent does something wrong, whose name is on it, and where is the record. The firm that can answer with a clear accountability chain, and the evidence to back it, owns that conversation. The firm that answers with a governance philosophy does not.

Responsibility you cannot delegate is responsibility you have to build. That turns governance from a slide into a system.
VuduVations Intelligence Bureau
The VuduVations Read
If accountability legally stops with the client, then the client is the one exposed, and exposure is the last thing anyone should rent. The evidence that proves an agent behaved should belong to the party on the hook for it, not sit in a consultant's environment billed by the hour. Consulting-as-Code, delivered by MCOS, gives the client an auditable, source-cited accountability procedure it owns and can run without the vendor or the bench, structured for review the day a regulator asks. When the responsibility cannot be handed off, the record of it should not be either.
Share
Sources
The AI Interview: Ivana Bartoletti, Wipro, AI Magazine
Firms in this story: Wipro← Back to Edition No. 7