CIONET News

CIONET Trailblazer: When AI Makes the Decision, Who Owns the Outcome?

Written by Daniel Eycken | September 30, 2026 @ 11:17 AM

AI is moving quickly from experimentation into the core of the enterprise. But as AI systems increasingly move from advising to deciding and acting, a new question is emerging for CIOs: how do you let AI decide and act without losing accountability? AI is no longer something organisations are simply experimenting with. Across industries, it is already changing how people work, how decisions are made and how services are delivered.

But the technology is evolving quickly. We have moved from predictive and analytical AI to generative AI, and now towards agentic AI, where systems can increasingly act on the information they generate. That creates a different challenge for technology leaders. If an AI system is making or executing a decision, who owns the outcome? And can the organisation explain and defend that decision when it matters?

For this CIONET Trailblazer, we spoke with Anton Wilsens, Managing Director, Kyndryl BeNeLux, about the less visible side of putting AI to work in core operations: predictability, governance and accountability.

 

From recommendation to decision

AI is moving rapidly from experimentation into core business operations. What changes when AI moves from supporting decisions to actually making or executing them?

The stakes change materially. An AI system that helps an employee explore options is very different from one that makes a lending decision, determines eligibility, or triggers an action in a production environment. Many of the AI systems gaining traction today are probabilistic by design. Their outputs are based on patterns and likelihood rather than fixed rules. That is part of what makes them powerful, but it also means that results can change over time.

In a creative or exploratory context, that variability can be a strength because AI can surface possibilities that a human might not have considered. But in an operational environment, the same characteristic becomes much more significant. Imagine a customer applying for a personal loan through a digital channel: a model evaluates the customer's information and approves the application, but a week later, a very similar application produces a different result because new data was introduced or the model evolved. From the customer's perspective, that decision may feel arbitrary, while from the institution's perspective, it raises questions about predictability, fairness, explainability, and regulatory compliance. That is where the conversation needs to move beyond simply asking whether an AI system is accurate.

 

Not all AI decisions are the same

So how should organisations think about the distinction between probabilistic and deterministic approaches?

It is important not to treat AI as one single category of technology. Probabilistic models are extremely powerful for generating insight, identifying patterns, and supporting decisions, and there are many situations where variability is useful. But there are other situations where consistency is essential. If you are determining eligibility, applying a compliance rule, or taking an enforcement action, you need to know that the same defined conditions will lead to the same outcome. That is where deterministic decision logic becomes important, ensuring the same inputs lead to the same outcome based on clearly defined rules.

The answer is not to choose one approach over the other, but rather to understand where probabilistic AI adds value and where decisions need to be governed by deterministic logic. That distinction becomes increasingly important as AI moves from experimentation into production.

 

Governance needs to become part of the system

Many organisations are responding to AI risk by putting governance frameworks and guardrails around their AI systems. Is that enough?

Monitoring and oversight are important, but controls around a probabilistic model do not change its underlying nature. Guardrails manage risk, but they don't necessarily resolve structural inconsistency. The bigger question is how organisations embed compliance and accountability into the way decisions are actually made.

This is particularly relevant in regulated industries where a decision may need to be reviewed months or even years later, requiring an organisation to understand what happened, why it happened, and what factors influenced the outcome. That means governance cannot simply exist in a policy document; human oversight needs to be meaningful, with people understanding when they are expected to intervene and having the ability to do so.

 

Making policy executable

You have argued that policy as code can help address this challenge. What does that look like in practice?

Policy as code is about translating regulatory, business, and ethical intent into executable logic that can be embedded directly into systems. Instead of simply documenting a rule, you make that rule something the technology can enforce. The logic can be tested, versioned, and applied consistently, creating a structure in which probabilistic AI can provide intelligence while codified policy determines what actions are actually permitted. The goal isn't to prevent organisations from using AI, but to create the conditions in which they can use it with confidence.

A different role for the CIO

What does all of this mean for the CIO as AI becomes more autonomous?

The CIO needs to understand more than what an AI system can do—they need to understand what decisions are being delegated to it, what happens as a result, how those decisions can be challenged, and where accountability ultimately sits. That also means distinguishing between different types of AI use, because using AI to explore an idea is not the same as using it to make a decision that affects a customer's financial circumstances, and the governance model needs to reflect that difference.

And this isn't only a technology issue; it involves business leadership, risk, compliance, and organisational culture. As AI becomes more autonomous, the CIO has an increasingly important role in defining where autonomy is appropriate, where human judgement remains essential, and how the organisation maintains accountability.

 

Building AI we can stand behind

The future of AI in regulated industries will not be defined solely by how intelligent these systems become; it will also depend on how deliberately organisations design the systems around them. For technology leaders, the challenge is to find the balance between moving at AI speed and maintaining the trust, transparency, and accountability the business depends on.

The real question is therefore not simply how advanced AI can become, but whether organisations are building systems they can stand behind when a decision is questioned, audited, or challenged. And that starts with asking better questions about the technology we choose, the actions we allow it to take, and the accountability we design around it.

--