A decision-rights register records, for each AI-assisted workflow, which agent may take or recommend which decisions, who is accountable as named owner, which check the reviewer performs and how the decision is retained. Without such a register, an AI policy does not show who owned an investment decision or how to reconstruct it.
In an analysis published on 7 October 2026, the IAPP says private-capital firms should record which AI systems can make decisions, who is responsible for reviewing or approving their outputs and how those decisions are documented for accountability. The IAPP therefore advocates a decision-rights register. In our analysis, this shows how a written AI policy can require human oversight without creating the operational evidence needed to demonstrate it. In our analysis, the register provides an operational link between an agent's authority, a named accountable party and the retained decision.
Which concrete gap in AI policy does the IAPP flag at private-capital firms?
The IAPP identifies the need for private-capital firms to record which AI systems can make decisions, who is responsible for reviewing or approving their outputs and how those decisions are documented for accountability. In our analysis, this exposes a concrete gap: an AI policy can mandate human oversight without creating that operational evidence.
The core is that policy and evidence are two different things. A policy document says there must be oversight; it does not show that a specific agent stayed within its authority for a specific decision and that an identifiable person tested the outcome. In our assessment, that difference is particularly important in investment workflows: a limited partner, regulator or other reviewer may later need to understand how a decision was made, while the original context may no longer be readily available.
Which fields belong in a decision-rights register per AI workflow?
The register is a living document per agent workflow, not per supplier. That distinction is essential: one language model can appear in multiple workflows with different authorities, and only at workflow level is it clear what an agent may do there.
- Identity and purpose of the agent and the workflow in which it operates.
- Decision rights: which decisions the agent may take, which it may only recommend and which actions are prohibited. A right to recommend is different from a right to execute.
- Data and tools the agent may use.
- Named owners: the executive sponsor, the business owner, the technical owner and the control owner. In its private-equity report of October 2026, Open Future Forum recommends recording for every material production AI workflow a decision-rights record with accountable owners, including the executive sponsor, business owner, technical owner and control owner.
- The reviewer's duty to check: which checks the human must perform before an output counts.
- Approval and escalation thresholds, plus who is authorised to override and shut down.
- Retained evidence with which the decision can later be reconstructed.
Open Future Forum additionally recommends documenting the production inventory, the identity and access map, permissions, logs, revocation procedures, incidents, exceptions and remediation owners. In our analysis, that is the evidence that makes the register operational.
What does this news mean for managing partners, general counsels and CISOs?
Our analysis: because an AI policy without a register may not demonstrate who owned an investment decision, a firm faced with an LP questionnaire or transaction due diligence runs the risk that it cannot show a clear owner and decision trail; we therefore advise managing partners and general counsels to appoint a single accountable owner per workflow, even where the review is distributed across several people. Because recommendation and execution rights can be defined differently, the compliance leader must explicitly separate those two rights in the register and record per workflow which actions are prohibited. Because models and tools change without authorities automatically moving with them, the CIO must tie a review moment to every model or tool change, so that the authority is tested again before the modified agent remains in production. In our analysis, operating partners should suspend deployment of an agent while the register for that workflow remains incomplete, because the firm cannot yet demonstrate the agent's authority or accountability. A practical sequence:
- Inventory agents per workflow, not per supplier.
- Separate the right to recommend from the right to execute and name prohibited actions.
- Appoint a single accountable owner per workflow alongside the distributed review.
- Record evidence-based approval criteria, exceptions and overrides as mandatory in logs.
- Review authorities at every model or tool change.
Moreover, in our analysis, agents with system access should have clearly defined authority, ownership, override arrangements and, where appropriate, tested procedures for intervention or shutdown. Related background is in our articles on an AI agent with system access governed as a privileged identity and on an enforced emergency stop and rollback for AI agents. More background is in our topic hub on agentic AI and AI agents.
How does the register connect to due diligence and board oversight?
In our analysis, the register gives investment committees, LP questionnaires and transaction due diligence a concrete evidence object, and the Open Future Forum fields can translate the register concept into diligence evidence; a complete and current register could give the board a clearer view of ownership and the decision trail.
At board level this connects to the KPMG analysis of board oversight of agentic AI. KPMG says governance should address delegated authority, accountability, escalation, intervention and shutdown, and that agentic actions should be recorded in a traceable and explainable way for audit or regulatory review. In our reading, these controls support the decision-rights-register approach. KPMG states that responsibility remains with management and the board. Our reading is that a decision-rights register can give a practical operational form to the governance elements KPMG describes and to the information Open Future Forum recommends documenting for diligence. That the reconstruction of a decision itself demands discipline we set out earlier in reliably reconstructing the actions of an autonomous AI agent. Bear in mind the applicable legal, contractual and internal retention periods; let legal and privacy advice determine which rules apply to the evidence in question.
Sources and references
Sources: The article draws on the IAPP analysis of 7 October 2026, the Open Future Forum private-equity due-diligence report and the KPMG board analysis of agentic AI.