Output is not evidence.
An AI answer tells you the result. It does not tell you how the result was reached, which model produced it, what data it touched, or who authorised it. As regulators move to require proof that AI is controlled, that gap stops being academic.
The gap
Most enterprise AI is a straight line from prompt to output. The model is opaque, the steps are unrecorded, and the authority for any action it takes is implicit. You can read the answer. You cannot prove how it was produced.
Accountability is the record of the process, not the result. It is what lets you answer, later and under scrutiny: what did our AI do, on whose authority, with which model, and on what data.
Four properties of accountable AI
Accountability is not a feeling. It is four concrete properties, each of which can be present or absent in any AI system.
Attributable
Every action ties to a specific user, agent, model, and moment. No anonymous AI actions.
Auditable
A durable, correlated record exists: inputs, outputs, the policy verdict, and the system the action touched.
Defensible
The record stands up when a regulator, an auditor, or the board asks you to account for it.
Private
The record is of AI actions, not surveillance of people. Data stays isolated per organisation and is not used to train models.
When controls fail, stop
The honest test of a governed system is what it does when the governance is unavailable. Two answers exist. Fail-open lets the request proceed ungoverned, preserving availability at the cost of control. Fail-closed blocks the request. Accountable systems fail closed.
Govern whatever model you use
Model choice changes every quarter. Accountability should not. The control and the audit trail belong in a layer above the model, so you can switch providers, or run several at once, without losing the record.
What the frameworks ask for
The major AI governance frameworks converge on one thing: a durable record of what AI systems decided, on what inputs, producing what outputs. They set the obligation. They do not, on their own, produce action-level attribution for agentic AI. That is the operational gap a deploying organisation has to close.
EU AI Act
Requires logging, traceability, and human oversight for high-risk AI. Conformity assessment before deployment.
NIST AI RMF
A voluntary US framework built around documented governance and measurable, managed AI risk.
ISO/IEC 42001
An auditable management system for AI, certified by accredited bodies through a two-stage audit.
Renly does not certify your compliance. It produces the action-level evidence, the attribution and the audit trail, that a compliance program needs to draw on.
Renly is the governed runtime for AI agents. The agents run the work, and every action carries its provenance: who asked, which model acted, who approved, what happened.
Read: what AI provenance means Book a demo