Before You Deploy an AI Agent, Ask Who Answers for It

An AI system that drafts a reply and an AI system that sends one differ in kind, not in degree. The first produces a recommendation a person can accept, amend, or discard. The second acts. It sends the message, approves the request, quotes the price, escalates the complaint – or fails to. By the time anyone reviews the decision, it has already been executed.

This is what the industry calls an agent, and African businesses are now offered them in volume: agents that handle WhatsApp customer service, take orders, confirm payments, schedule appointments. The pitch is capacity – one system carrying the workload of a large team. The clause the pitch leaves unexamined is accountability. When an agent acts, someone answers for the action: to the customer, to a regulator, in some cases to a court. The open question in most deployments is who.

Most organizations settle that question forensically – after an incident, when the money has moved or the customer has been harmed, and the vendor, the integrator, and the deploying business are each pointing at the other. Ethical review before deployment exists to settle it the other way: deliberately, in writing, before the agent takes its first action.

The difference between an answer and an action

A static model, however capable, sits behind human judgment. It classifies, predicts, or drafts, and a person decides what happens next. An agent operates under delegated authority. Delegation is a familiar management act: organizations delegate to staff every day, and they do it with job descriptions, spending limits, supervision, and consequences. Agents are routinely deployed with none of these. The delegation happens implicitly, in a configuration, and nobody signs it.

The errors compound differently too. A wrong answer costs the reader some time. A wrong action creates facts. A misquoted price, once accepted by a customer, is a commercial commitment. A refund wrongly approved moves money. A complaint the agent classifies as routine – and therefore never escalates — harms the customer twice: once through the original problem, again through the silence. An agent also errs at machine speed. A single flawed rule can act on hundreds of customers before anyone notices.

Five questions that name people

Pre-deployment review of an agent is not a compliance ceremony, and it does not require a large budget. It requires the deploying organization to answer a short set of questions honestly, in writing. The questions are uncomfortable because their answers are names, not features.

  • Purpose and appropriateness. What is this agent for, whom does it serve, and is an autonomous agent the right tool – or would a simpler system with a person in the loop serve those users better?
  • Boundaries of authority. What may the agent commit the organization to – prices, refunds, bookings, promises – and what must it never do without human sign-off? Is that boundary written down, and does the technical configuration actually enforce it?
  • Redress. When the agent errs against a customer, how is the error discovered, who corrects it, and what does the customer receive? A named person must own this duty.
  • Escalation. How does a user reach a human being, how quickly, and in which languages? Does the path still work when volumes spike?
  • Monitoring. What is logged, who reviews it and how often, which patterns trigger intervention, and who holds the authority to pause the agent without convening a meeting?

Working through these questions honestly tends to change the deployment itself: the agent launches with narrower authority, clearer disclosures, and an escalation path that was an afterthought in the original design. Sometimes the honest conclusion is that the agent should not launch in its proposed form at all. That is not the review failing. That is the review working.

Why the question is sharper in African markets

In markets with dense consumer-protection infrastructure, a customer wronged by an automated system has somewhere else to go – an ombudsman, a regulator with an established complaints desk, small-claims procedures that function. Across much of Africa those channels are thinner or slower in practice. The redress mechanism a business builds into its agent may be the only redress its customers effectively have. That raises the standard for the deployer. It does not lower it.

Regulation is moving, but the ground is still being prepared. Kenya’s Data Protection Act of 2019 created enforceable duties around personal data and an office to enforce them. Kenya has since published a national artificial intelligence strategy, and the African Union has adopted a continental AI strategy – real signposts of regulatory direction. But detailed rules on autonomous agents do not yet exist here, and the international direction of travel, visible in instruments such as the European Union’s AI Act, is toward holding deployers responsible, not only developers. A business that waits for a regulator to tell it who answers for its agent will have the answer assigned retroactively, on someone else’s timetable.

There is a third reason, and it is practical. Many of the agents offered to African businesses were built and evaluated elsewhere, and their testing may never have covered Swahili or code-switched conversation, local names, local phone-number and currency formats, or the conventions of mobile-money commerce that platforms such as M-Pesa have made ordinary. In a static system these gaps are quality problems. In an agent they become actions: an order confirmed for the wrong amount, a payment reference mangled, a customer’s name mishandled on a record that follows them. An agent that was never tested against its actual users does not merely misunderstand them. It acts on the misunderstanding.

Deliberate now, or forensic later

The trade-off deserves honesty. Review before deployment costs time, and it can narrow the launch scope a vendor promised. What it buys is an accountability structure that exists before it is needed: agreed boundaries, a named owner for redress, an escalation path that has been tested rather than assumed. Organizations that skip this step do not avoid the work. They defer it to the worst possible moment and do it under pressure, in public, with an aggrieved customer waiting.

Adili AI conducts independent ethical review of AI systems, agents included, before and after deployment. We also build conversational AI for African organizations under the same discipline we apply in review – and we do not review systems we have built, because independence is the point. If you are preparing to deploy an agent, or already operate one and cannot yet say who answers for it, that is a conversation worth having before it becomes an incident report. Get in touch.

Leave a Comment