top of page

When AI Acts, Who Owns the Decision? The Human Algorithm™ Problem

  • Writer: Heather Fricke
    Heather Fricke
  • Aug 10
  • 2 min read

The most important AI question inside a business is quietly changing. It used to be, “What can the model generate?” Now it is becoming, “What can the system do without asking us first?”

Agentic systems can search, compare, recommend, initiate workflows, and increasingly complete actions. Google is building agentic shopping and checkout experiences. OpenAI’s commerce systems are designed to move users from product discovery toward transactions. Capability is accelerating. Accountability is not automatically accelerating with it.

NIST’s AI Risk Management Framework treats governance as a cross-cutting function that should inform the rest of AI risk management. Its core model is organized around Govern, Map, Measure, and Manage, and its Generative AI Profile extends that risk-management approach to generative systems. That matters because autonomy without defined authority is not governance. It is permission by accident.

The Human Algorithm™ is the human judgment layer that should exist before a machine is allowed to act. It asks what the system may know, what it may recommend, what requires evidence, what requires human approval, what must be escalated, and what the machine may never touch. Those decisions are not technical leftovers. They are business decisions about responsibility.

Speed makes this harder, not easier. When an AI system produces a paragraph, the cost of a bad answer may be embarrassment. When an AI system changes a price, sends a message, approves a workflow, ranks a supplier, recommends a product, or triggers a transaction, the cost moves into operations. A faster system can create a faster failure.

NIST’s framework is useful here because it does not treat trustworthy AI as a one-time compliance exercise. It describes risk management as continuous across the AI lifecycle. That is exactly where businesses get into trouble when they reduce governance to a policy document written after deployment. The machine is already operating inside a living system of people, data, incentives, customers, and consequences.

The Human Algorithm™ does not mean a human must manually approve every low-risk action forever. That would turn automation into an expensive intern with excellent typing speed. It means the human organization decides the boundaries before automation scales: where autonomy begins, where it stops, what evidence is sufficient, and who owns the release when the decision matters.

The market is going to spend years debating how intelligent agents become. Businesses have a more immediate problem. They need to know what authority they have already handed over, whether anyone deliberately defined that authority, and what happens when the machine is confidently wrong at operational speed.

Sources: NIST, “Artificial Intelligence Risk Management Framework,” https://www.nist.gov/itl/ai-risk-management-framework ; NIST, “AI RMF Core,” https://airc.nist.gov/airmf-resources/airmf/5-sec-core/ ; NIST, “Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile,” https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence ; Google, “Introducing the Universal Cart and more ways to help you shop,” https://blog.google/products-and-platforms/products/shopping/google-shopping-cart/ ; OpenAI, “Powering Product Discovery in ChatGPT,” https://openai.com/index/powering-product-discovery-in-chatgpt/

Human Algorithm™ was created by Heather Fricke through Frick-E Energy™.

 
 
 

Recent Posts

See All

Comments


bottom of page