For teams Agents Integrations Governed Runtime Pricing Enterprise Security Academy Compare Blog
Book a demo Sign in
AI Accountability

Output is not evidence.

An AI answer tells you the result. It does not tell you how the result was reached, which model produced it, what data it touched, or who authorised it. As regulators move to require proof that AI is controlled, that gap stops being academic.

The gap

Most enterprise AI is a straight line from prompt to output. The model is opaque, the steps are unrecorded, and the authority for any action it takes is implicit. You can read the answer. You cannot prove how it was produced.

Accountability is the record of the process, not the result. It is what lets you answer, later and under scrutiny: what did our AI do, on whose authority, with which model, and on what data.

Output versus evidence Top flow: prompt to opaque model to output, with no record. Bottom flow: prompt to governed action to output, with an audit record captured at every step. Most AI Prompt Model opaque Output no record Renly Prompt Governed action policy + approval Output Audit record
Two ways to run AI. Only one of them can be proven afterwards.

Four properties of accountable AI

Accountability is not a feeling. It is four concrete properties, each of which can be present or absent in any AI system.

Attributable

Every action ties to a specific user, agent, model, and moment. No anonymous AI actions.

Auditable

A durable, correlated record exists: inputs, outputs, the policy verdict, and the system the action touched.

Defensible

The record stands up when a regulator, an auditor, or the board asks you to account for it.

Private

The record is of AI actions, not surveillance of people. Data stays isolated per organisation and is not used to train models.

Chain of custody for an AI action An AI action moves through five recorded stages: request by a user, agent proposes, human approval gate, execution by a model and tool, and a final audit record. Request user Agent proposes model named Approval gate human Execute model + tool Audit record
Writes to a system of record pass through a human approval gate. Every stage is captured.

When controls fail, stop

The honest test of a governed system is what it does when the governance is unavailable. Two answers exist. Fail-open lets the request proceed ungoverned, preserving availability at the cost of control. Fail-closed blocks the request. Accountable systems fail closed.

Fail-open versus fail-closed When governance is degraded, a fail-open system lets the ungoverned request proceed, while a fail-closed system blocks it. Governance degraded controls unavailable Fail-open ungoverned action proceeds Fail-closed request blocked, held safe availability over control control over availability
On the Enterprise plan, Renly fails closed. If it cannot govern an action, it does not let it through.

Govern whatever model you use

Model choice changes every quarter. Accountability should not. The control and the audit trail belong in a layer above the model, so you can switch providers, or run several at once, without losing the record.

One accountability layer, any model Teams sit above a single governance and audit layer, which sits above interchangeable model providers including OpenAI, Anthropic, Azure OpenAI, Google Gemini, and customer-managed keys. Your teams Governance + audit layer policy, approval, attribution, record OpenAI Anthropic Azure OpenAI Gemini your keys
Switch models, or run several. The audit trail and the controls stay constant.

What the frameworks ask for

The major AI governance frameworks converge on one thing: a durable record of what AI systems decided, on what inputs, producing what outputs. They set the obligation. They do not, on their own, produce action-level attribution for agentic AI. That is the operational gap a deploying organisation has to close.

EU AI Act

High-risk obligations deferred to 2 Dec 2027 (2026 Omnibus)

Requires logging, traceability, and human oversight for high-risk AI. Conformity assessment before deployment.

NIST AI RMF

Govern, Map, Measure, Manage

A voluntary US framework built around documented governance and measurable, managed AI risk.

ISO/IEC 42001

Certifiable AI management system

An auditable management system for AI, certified by accredited bodies through a two-stage audit.

Renly does not certify your compliance. It produces the action-level evidence, the attribution and the audit trail, that a compliance program needs to draw on.

Renly is the governed runtime for AI agents. The agents run the work, and every action carries its provenance: who asked, which model acted, who approved, what happened.

Read: what AI provenance means Book a demo