The Name Standard℠ is not limited to whose name appears on AI-assisted output. It asks who authorized an AI system to act within a defined domain, under specific capabilities, permissions, objectives, and limits—and who remains accountable when the system selects an unauthorized path.

Whose Reputation Is It Anyway?

When AI-assisted work product leaves an organization, it does not leave under the name of the large language model (LLM).

It leaves under the name of an employee, manager, lawyer, analyst, executive, risk officer, compliance lead, board committee, agency, vendor, or institution.

That is why human oversight cannot remain a vague governance principle. If a person’s name, approval, signature, professional judgment, or institutional authority attaches to AI-assisted output, there must be a standard for what that attachment means.

Lozen Advisory calls this the Name Standard℠.

When the AI gets it wrong, whose name is on it?

The Name Standard℠ defines what must be true before AI-assisted output can carry a person’s name, authority, professional judgment, or institutional sign-off.

It asks whether the person, or institution, responsible for the output had the time, authority, information, review capacity, documentation, escalation path, and refusal rights necessary to make oversight real.

Without those conditions, accountability becomes ceremonial. The name on the output belongs to a human being, while the governance behind it may be weak, undocumented, or nonexistent.

But agentic AI makes the question more difficult.

An AI system may not merely draft, summarize, rank, or recommend. It may select actions, use tools, cross system boundaries, delegate tasks, alter its approach, or pursue an objective through a path no person specifically approved.

In those cases, the Name Standard℠ should not ask only whose name appeared on the final decision.

It should ask:

Who authorized the system to act within this domain, under these capabilities, permissions, objectives, and limits—and who remained responsible when the system selected an unauthorized path?

There may be no human who chose the specific action. That does not mean there is no human or institutional accountability. It means accountability may attach to the conditions of delegated agency, not only to the final action selected by the system.

Accountability begins before the agent acts

For agentic AI, human attribution may attach to several distinct governance acts:

  • authorization to deploy or run the system;
  • approval of its objectives and decision boundaries;
  • acceptance of its permissions, tools, and operating environment;
  • acceptance of the containment design;
  • approval of reduced safeguards or expanded autonomy;
  • responsibility for monitoring and intervention;
  • authority to pause, override, or deactivate the system;
  • acceptance of residual risk;
  • ownership of incident response and recovery.

A guardrail may limit what an AI system can do. A policy may assign ownership of the AI program. A log may show what the system did.

The Name Standard℠ asks whether the organization can reconstruct the chain of authorization and control that made the conduct possible.

That is a different question from whether the AI acted autonomously. Autonomy describes the system’s conduct. Accountability requires identifying the people and institutions that authorized, bounded, supervised, monitored, and accepted the risks of that conduct.

The boardroom problem is evidence

Boards are being asked to oversee AI systems, AI agents, AI vendors, AI-generated records, AI-influenced disclosures, and AI-related legislation before many organizations have a repeatable evidence model for human accountability.

That gap is now visible in boardroom discussions. AI agents are no longer being treated as tools; they are being described as employee-like actors operating inside enterprise workflows. As that shift occurs, AI risk is being pushed into existing board structures, especially audit committees, while vendor systems, AI-generated records, proxy interpretation, and AI investment discipline are becoming part of the same oversight problem.

The common thread is evidence. Boards need to know:

  • who authorized the system;
  • what authority and permissions it received;
  • what limits were imposed;
  • who monitored its conduct;
  • who could intervene;
  • what evidence survived;
  • where responsibility became fragmented.

The Name Standard℠ sits within Lozen Advisory’s broader Disclosure-Independent Governance℠ methodology for evaluating whether AI-related work remains traceable to a responsible human or institutional actor. Apply the Name Standard℠ to a live AI-assisted workflow with Lozen Advisory’s free Human Accountability Trace (HAT) workbook.

Who authorized the agent, who supervises it, who can stop it, who documents its behavior, and who remains accountable when it exceeds its intended path?

5 questions GRC and governance leaders should ask

Evaluate your organization’s alignment with the Name Standard℠ by asking:

  1. Who authorized the system to act, and what domain, objective, permissions, and limits were approved?
  2. Who can pause, override, restrict, escalate, or deactivate the system?
  3. What evidence shows that monitoring and human review were real, not ceremonial?
  4. Who accepted the containment design, remaining uncertainty, and residual risk?
  5. When the system selects an unauthorized path, can the organization reconstruct who controlled the conditions that made it possible?

Responsibility without authority is not governance

The Mayo Clinic AI lawsuit shows why the Name Standard℠ is not limited to signatures, approvals, or final output. It also applies to the person inside the organization who is expected to identify AI risk before the system advances.

The complaint alleges that Traci Tamiko Eto, Mayo Clinic’s former Director of Research Operations, raised concerns that patient-data de-identification processes connected to the Mayo Clinic Platform had not been properly reviewed through Mayo’s IRB process. According to the complaint, a senior IRB leader did not challenge the substance of her concern, but resisted revisiting the issue because it would jeopardize the pace of ongoing research projects and compromise Mayo’s competitive advantage.

That is a Name Standard℠ problem: responsibility without authority.

A human reviewer who can identify AI risk but cannot slow, challenge, refuse, document, or escalate the system is not functioning as a governance control. They are functioning as an accountability surface.

The complaint also describes alleged pressure around IRB review, informed-consent waivers, review-panel assignment, software-device use, patient-data privacy, and the MAYA digital assistant study. In the MAYA allegations, the complaint says Eto reported mischaracterized outcomes, deleted unfavorable results, use of an unsanctioned software device, safety and data-security concerns, and efforts to disguise a 67% error rate.

For boards, general counsel, compliance leaders, and audit committees, the evidence question is direct: when a named human is responsible for AI compliance, does that person have the authority to interrupt deployment momentum?

Why this matters for corporate boards

Boards are increasingly being asked to oversee systems that can act without a human selecting each step.

That changes the accountability problem. The board cannot stop at asking who approved the final output. It must understand who authorized the system’s scope, who accepted its operating conditions, who monitored its conduct, who could intervene, and who remained responsible when the system exceeded its intended path.

Human oversight is not enough if no one can explain:

  • what authority was delegated;
  • what evidence supported that delegation;
  • what limits were imposed;
  • who could refuse or interrupt the system;
  • what happened when the system moved beyond those limits;
  • how responsibility was reconstructed afterward.

That is the gap the Name Standard℠ is designed to address.

Prepare your board for AI accountability questions before the next meeting.

Lozen Advisory’s Name Standard℠ Advisory evaluates whether AI-assisted decisions and agentic conduct remain attributable to the human and institutional actors who authorized, bounded, monitored, and accepted responsibility for them.