Research note · AI and accountability

AI Is Probabilistic. Accountability Is Not.

Why enterprise AI must combine probabilistic intelligence with deterministic controls before a recommendation becomes an accountable decision or action.

Probability is a feature of AI

Modern AI does not work like a conventional business rule.

A deterministic rule is expected to produce the same defined result when the same governed conditions are met. A generative model evaluates possible continuations, classifications or actions and assigns relative likelihood across them. Its output is shaped by training data, model architecture, context, configuration and the path taken through inference.

This probabilistic character is not a defect to be removed from AI.

It is the source of much of its value.

Probability allows models to work with ambiguity, language, incomplete information, unfamiliar patterns and complex combinations that cannot be exhaustively described as conventional rules. It allows AI to classify, infer, summarise, generate and recommend across situations that would be impractical to program one by one.

The problem begins when a probabilistic output is treated as though it were already an accountable enterprise decision.

The enterprise remains deterministic where it matters

Companies operate through explicit obligations, authorities and outcomes.

A payment is approved or it is not. A person has the delegated authority or does not. Protected information is permitted to leave a boundary or it is not. A regulatory report is submitted by the deadline or it is not. A control was operating at the relevant moment or it was not.

Directors and officers may use judgement under uncertainty, but their duties are not expressed as a model confidence score. In Australia, directors must exercise care and diligence, act in good faith and for a proper purpose. Under the Financial Accountability Regime, accountable entities and accountable persons have defined responsibilities and accountability obligations that must be understood, accepted and evidenced.

An organisation cannot be 67 per cent compliant with a requirement that must be satisfied.

Nor can an accountable person discharge responsibility by saying that a model considered the action likely to be appropriate.

AI may inform judgement.

Accountability still requires an explicit decision, an authorised actor, an enforceable boundary and evidence of what occurred.

Do not force AI to become deterministic

A common response is to attempt to make the model itself fully predictable.

Configuration can reduce variation. Prompts can constrain form. Retrieval can improve grounding. Fine-tuning can improve domain behaviour. Evaluation can establish expected performance within defined conditions.

These measures are valuable.

They do not convert a probabilistic model into the complete control system for a deterministic enterprise obligation.

The stronger architecture preserves the strengths of both approaches:

Probabilistic intelligence

Interpret ambiguity, identify patterns, estimate risk, generate options and recommend action.

Deterministic control

Apply explicit authority, policy, thresholds, data boundaries, approvals, actions and evidence.

The model does not need to become the rule.

Its output needs to enter a governed decision architecture.

The architectural boundary is recommendation to consequence

The decisive point is not where AI produces an answer.

It is where that answer is allowed to create consequence.

  1. Observe the interaction
  2. Invoke probabilistic intelligence where useful
  3. Interpret confidence, context and limitations
  4. Apply deterministic policy and authority
  5. Allow, deny, transform, escalate or require approval
  6. Record the decision and resulting action

For a low-risk use case, deterministic control may be as simple as checking an output format or preventing a prohibited field from being returned.

For a consequential process, it may require multiple evidence sources, minimum confidence, deterministic validation, segregation of duties and human approval before the action can proceed.

The required control should follow the consequence—not the novelty of the model.

This is where TomorrowX began

TomorrowX began in online fraud, risk and interaction control.

Fraud is inherently probabilistic. A transaction can resemble known fraud without being fraudulent. A legitimate customer can behave unusually. A device, location, amount or sequence can increase risk without proving intent.

The decision still has deterministic consequences.

Allow the transaction. Deny it. Add authentication. Adjust the journey. Refer it for review. Record why the intervention occurred.

The early FMT capability combined risk intelligence with in-path control before a banking system committed the outcome. In solving that specific fraud problem, the company discovered that data entering and leaving a running system could be observed and altered without changing the application beneath it.

That discovery became the foundation of Data Mediation.

The original problem was not simply how to calculate a probability.

It was how to convert probabilistic intelligence into a safe, immediate and accountable enterprise action.

The power of and became the C in CAP

Enterprise decisions rarely belong entirely to one technology.

A fraud decision may combine a deterministic limit, a probabilistic risk score, a device-intelligence service, a customer profile, a sanctions rule, a human approval and a fallback process.

The required logic may be and:

The model identifies elevated risk and the transaction exceeds the threshold and the customer has not completed step-up authentication.

It may also be or:

Use the frontier model or the internally hosted model or the deterministic rule set, according to data classification, availability and required confidence.

This is the purpose of composition.

The C in the Composable Agentic Platform allows deterministic logic, probabilistic models, services, transformations, human decisions and approved actions to be assembled around an outcome rather than forced into one monolithic application or one model provider.

Composition preserves the strengths of each capability while making their relationship explicit, testable and changeable.

The A is agency under control

The A in CAP is Agentic.

Agency means more than generating content. It means that a capability can observe context, select or invoke intelligence, apply logic and influence what happens next.

The Programmable Data Agent is the distributed runtime through which that agency is exercised in the data path.

It can invoke a model, a deterministic capability or both. It can use the result to allow, deny, add, adjust, assist, advise, transform, route or request approval before an interaction completes.

This makes agency operationally useful without making autonomy absolute.

The model may recommend.

The composition determines what recommendation means.

The PDA enforces what may happen at the interaction point.

Modern and legacy systems become participants in the same composition

A governed AI process cannot depend on every enterprise system exposing a modern API or being rewritten for agentic access.

The systems that carry the greatest consequence are often the systems least able to absorb another invasive change.

TomorrowX therefore designed the PDA to operate at the protocol and data level: the common interaction surface beneath differences in application age, language, infrastructure and location.

A modern cloud service may communicate through HTTP and JSON. A mainframe, industrial device or older application may use a different protocol, sequence or data representation. At the architectural level, each still exchanges data across a boundary.

By understanding that exchange, the PDA can make modern and legacy systems participants in the same governed workflow without pretending that their internal implementations are the same.

The composition describes the outcome.

Protocol intelligence reconciles the systems involved.

Deterministic control can include uncertainty

Deterministic accountability does not require the enterprise to ignore uncertainty.

It requires the enterprise to define what it will do with uncertainty.

Above threshold

Permit the model recommendation to proceed within defined authority.

Within an uncertainty band

Invoke another model, deterministic check, additional evidence source or human review.

Below threshold

Do not act, fall back to the existing process or deny the request.

Policy conflict

Policy prevails regardless of model confidence.

Missing evidence

Stop or degrade safely rather than infer authority.

The probability may vary.

The organisation’s response to the probability can remain explicit.

Evidence must follow the decision

A compliant outcome cannot be established only from the final answer.

The organisation may need to know which request was made, what data was available, which model and version was used, what deterministic rules applied, what confidence or classification was returned, who approved the action and what the underlying system ultimately did.

This evidence is necessary for model evaluation, incident response, regulatory review, internal assurance and director or accountable-person oversight.

It also enables reversibility.

When a model changes, the same scenarios and controls can be replayed. When a result is challenged, the decision path can be reconstructed. When a policy changes, the organisation can identify which compositions and interactions are affected.

Accountability becomes part of the architecture rather than an explanation assembled after the event.

Probabilistic intelligence should compete; deterministic policy should govern

An interoperable enterprise can compare models through champion–challenger testing and select the route that produces the best observed value.

That competition should occur inside stable enterprise boundaries.

Models may compete on accuracy, reasoning, latency, price and domain performance. They may be externally hosted, platform-native or operated on premises. Different models may become champions for different requests.

The rules governing protected data, delegated authority, mandatory approvals, prohibited actions and evidentiary requirements should not be re-negotiated by each model response.

Intelligence can remain probabilistic and competitive. Accountability must remain explicit and governed.

Conclusion

AI is valuable because it can reason across ambiguity and probability.

Enterprises remain accountable because they must make explicit decisions and produce defensible outcomes.

These realities are not contradictory.

They require an architecture that uses both.

TomorrowX’s work began in fraud, risk and cybersecurity, where probabilistic intelligence had to become an immediate deterministic intervention before a running system created consequence.

That work led to a composable platform because enterprise outcomes require combinations of rules, models, services, people and actions. It led to the Programmable Data Agent because that composition had to operate across modern and legacy systems at their common interaction boundary.

CAP does not ask probabilistic technology to carry deterministic accountability alone.

It composes intelligence and control.

The model can estimate, interpret and recommend.

The enterprise can still decide, enforce and prove.

References

TomorrowX (2026). 20 years focused on what happens between systems.

TomorrowX (2026). From fraud control to Data Mediation.

TomorrowX (2026). Composable Agentic Platform and Programmable Data Agent.

TomorrowX (2026). The Control Plane Must Be Yours.

TomorrowX (2026). The Zero-Day Inversion.

Australian Securities and Investments Commission. Your company and the law: company officeholder duties ↗.

Australian Prudential Regulation Authority and Australian Securities and Investments Commission (2024). Financial Accountability Regime ↗.

Google AI for Developers (2026). Prompt design strategies: sampling and token probabilities ↗.

National Institute of Standards and Technology (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0) ↗.

National Institute of Standards and Technology. AI RMF Core: testing, evaluation, verification and validation ↗.

TomorrowX (2026). Data Mediation™ and Programmable Data Agents.

Next in AI, control and sovereignty · Step 4 of 4

Reality-Augmented Intelligence

See how governed enterprise interactions become a durable training, testing and learning asset across models.

Read the next paper