Logo

If an AI system can act on its own, the most important governance question is not whether it is accurate enough or whether a human can review its outputs later. The real question is simpler and harder: If it gets something wrong, can the harm actually be undone? This article will explain why reversibility should be the organizing principle for accountability in agentic AI, and why — whilst not every deployment needs the same controls — every deployment needs controls proportional to the irreversibility of what the system is allowed to do.

This is the third article in a new series called the “AI Governance Gap,” where we cut through the noise to tackle one of the most urgent challenges facing businesses today: How do you harness the power of AI without losing control of it? 

In the first article, we discussed how AI’s biggest risk isn’t regulation but exclusion and that, within five years, only organizations that can explain every high-stakes AI decision will be allowed to compete in the most valuable markets. In the second article, we argued that traditional AI governance frameworks no longer work for agentic AI, and thus new governance structures built around auditability, real accountability, reversibility of actions, and multi-agent risk are needed.

The mistake many governance models make

A common instinct is to treat reversibility as a technical question. Can the action be rolled back? Can the record be restored? Can the model version be changed? Can the output be deleted? Those questions matter, but they are not enough as technical undo is only one part of reversibility. In practice, what matters is whether the consequences of the action can be meaningfully reversed in the real world.

This is the distinction many organizations still fail to capture, treating technical correction as if it were equivalent to meaningful reversal, when it is not. And when that distinction is missed, governance tends to be weakest exactly where the stakes are highest.

Reversibility is multi-dimensional

A more useful way to think about reversibility is across five dimensions.

  1. Technical reversibility asks whether the action can be undone within the system. Is there a rollback, restore, delete, or override function?

  2. Practical reversibility asks whether it can be undone fast enough to prevent real-world effects. A correction that comes after the customer has received the message, the regulator has received the filing, or the workflow has triggered downstream action may be too late to matter.

  3. Economic reversibility asks whether recovery is feasible at an acceptable cost. Even if an action can be fixed, the effort, disruption, or expense involved may make “reversibility” more theoretical than real.

  4. Legal and reputational reversibility asks whether the organization can actually unwind liability, regulatory exposure, or damage to trust. Often, it cannot. The correction may limit further harm, but not erase the fact that the event occurred.

  5. Human reversibility asks the most important question of all: Would the affected person experience the outcome as genuinely corrected or remediated?

That final dimension is the one most often ignored in technical governance discussions, and yet it is often the one that matters most to regulators, courts, customers, and the public. A system error that is later acknowledged is not the same as a harm that never happened. Governance frameworks that collapse those two things into one are incomplete and can create a dangerously misleading picture of control.

A better starting point: the reversibility diagnosis

For any action an agentic system is permitted to take, organizations should begin with five questions:

  1. Can the action be technically undone?

  2. Can it be undone before external effects occur?

  3. What is the cost of reversal?

  4. Does reversal remove legal, regulatory, or reputational exposure?

  5. Would the affected person experience the harm as meaningfully corrected?

These are five practical design questions, and they have a very direct governance implication: Weakness on any of the last four questions should move an action toward the low-reversibility category, even if a technical undo function exists.

That matters because many of the highest-risk agentic use cases will appear ‘recoverable’ if looked at only through a systems lens, but are much less recoverable when looked at through an operational, legal, or human lens.

Governance should scale with reversibility

Once reversibility is assessed, the accountability model should follow.

For highly reversible actions like internal drafting, low-stakes recommendations, edits to non-public materials, governance can be relatively distributed. A named system owner, audit logging, periodic review, and post-hoc sampling may be enough. These are contexts where operational autonomy is often appropriate.

For recoverable but consequential actions like routine external communications, cancellable bookings, or record modifications that can be fixed but not trivially, the controls need to be stronger. These systems should have a named operational owner, escalation paths, rollback playbooks, and monitoring for unusual rates or patterns. Errors may be recoverable, but not casually so.

For irreversible or high-cost-to-reverse actions like regulatory filings, financial transfers, deletion of critical data, customer-facing denials, disclosures of sensitive data, or actions affecting health, employment, or legal rights, the governance model must change completely. Here, accountability cannot depend on post-hoc detection. It has to exist before the action is taken which means named approval authority, hard technical guardrails, documented accountability, auditable approval context, and senior governance sign-off on the use case design itself.

This is the practical core of the reversibility framework: The less reversible the action, the more governance must happen upstream.

Why human-in-the-loop is not an accountability framework

The presence of a human somewhere in the process is not by itself an accountability control; what matters is whether that person has the time, context, authority, and practical ability to intervene.

For low-reversibility actions, the relevant questions are not:

  • Was there a human in the workflow?

  • Was the system described as human-supervised?

The real questions are:

  • Was the review specific to the action?

  • Did the reviewer have enough context to make a substantive judgement?

  • Could they actually stop execution?

  • Was the approval attributable and auditable?

  • Was the approval threshold calibrated to the stakes, rather than to operational convenience?

Without those conditions, human-in-the-loop becomes a way of creating the appearance of accountability without its substance.

The reversibility lens in practice

This becomes clearer when we look at the kinds of use cases now moving into production.

In healthcare, an AI triage or care-pathway system may look assistive on paper, but if it triggers downstream action before meaningful clinician review, reversibility collapses quickly. A later correction does not undo a delay in treatment or the consequences of an inappropriate pathway.

In lending and insurance, a denial is not simply a data point. It can affect access to housing, credit, business continuity, or financial resilience at a moment that matters. Later reversal may provide compensation or process correction, but not meaningful restoration. These are not low-stakes actions and should not be governed as if they are.

In regulatory reporting, firms often assume filings are reversible because correction mechanisms exist. But a corrected filing does not erase the fact that an incorrect filing was made, that a regulatory record was created, or that a breach may already have occurred. In sectors with personal accountability obligations, that distinction matters even more.

Across all of these domains, the same lesson holds: When agentic systems can create legal, financial, clinical, or human consequences that cannot be fully unwound, accountability cannot be retrospective.

What boards and regulators should be asking

For boards, regulators, and senior management, this framework has an important implication: The sufficiency of AI governance should increasingly be judged against the reversibility of the actions the system can take.

That means the key question is not “Do we have an AI policy?” or “Is there a human review step?” It is: “Do our controls match the reversibility profile of the action?”

A governance model that relies on correction after the fact for low-reversibility actions should be treated as inadequate on its face, as the key question is, “Did we have sufficient control before the action occurred?”

This is particularly important in regulated sectors and in organizations where named individuals carry formal accountability. Senior leaders approving agentic deployments need to understand not just what the system does, but what kinds of harm it could create before anyone has a realistic chance to intervene.

The real choice organizations face

Agentic AI should not be slowed down indiscriminately, as many uses of agentic AI are entirely compatible with distributed accountability, post-hoc review, and high operational autonomy. Heavy controls on low-stakes use cases are not responsible governance; they are badly targeted governance.

But the reverse error is more serious. A model that treats all agentic actions as equally reversible is mis-specified for the technology it is trying to govern. It will under-resource the controls that matter most and over-burden the places where flexibility would be safe.

That is why reversibility is such a powerful organizing principle. It brings precision to a debate that is often too abstract, telling organizations where autonomy is acceptable, where escalation is needed, and where prevention must take precedence over remediation.

Governance begins where “undo” stops being real

The key governance question in agentic AI is not whether organizations can explain or fix harm after the fact, but rather whether they know when after-the-fact correction is no longer enough. Reversibility is the line. If an action can be undone, governance can be lighter and rely more on post-hoc correction. If it can’t, accountability has to move upstream, becoming explicit, immediate, and operational before execution, not after impact.

That may become the defining distinction in AI governance: knowing when ‘undo’ stops being a real control.

Don’t wait for an incident to find the gap. See how Dataiku Govern helps you safely deploy agentic AI.

Explore now

Ready for AI success?