Though Security Finds AI’s Weakness, HR Turns It Into Behavior People Actually Follow

Credit: BambooHR News

One thing we always have to remember is that our oversight is key, no matter how big or little the task is. We own that output. If there are errors, it's not going to be, 'The AI tool produced this.' My name is on it.

Keician Fields

Global Client Account HR Lead
Accenture

Workplace AI has an accountability gap, and most organizations are trying to close it with the wrong function. The instinct is to hand AI oversight to security or IT, but whether an AI system is technically safe and whether employees use it responsibly are two different questions. Only one of them is a technology problem. The other is a behavior problem, which puts it squarely inside HR’s mandate. The organizations getting this right are the ones where HR shapes how people actually use the systems, with a named human accountable for every output either way.

Keician Fields is Global Client Account HR Lead at Accenture, where she specializes in HR transformation and technology integration. For more than 20 years she’s partnered with executive leaders to build agile HR strategies, lead complex organizational redesigns, and integrate technology to enable data-driven talent decisions. Her recent focus has centered on establishing governance and risk frameworks that position HR as a strategic partner in tech-enabled business evolution. For Fields, navigating early adoption hurdles comes down to establishing firm human accountability.

“One thing we always have to remember is that our oversight is key, no matter how big or little the task is. We own that output. If there are errors, it’s not going to be, ‘The AI tool produced this.’ My name is on it,” she says. In her view, that principle of a human in the lead on every AI-assisted output is the foundation everything else is built on.

Human in the lead, not just in the loop

Fields draws a distinction between ‘human in the loop’ and ‘human in the lead’ that’s subtle, but consequential. Human in the loop can mean a person rubber-stamps whatever the system produces. Human in the lead means the person carries responsibility for the accuracy, judgment, and consequences of the output, regardless of how much of it the AI generated. “You can’t just take what the tool gives you and run with it. You have to look at it, question it, and make sure it reflects what you actually intended. The accountability doesn’t shift to the tool because the tool did the work,” Fields notes. 

That framing matters most in the parts of HR where the stakes are highest. When AI influences a performance evaluation, a compensation decision, or a separation, the AI may accelerate the process, but HR still owns the outcome. Fields is explicit that the presence of AI in the workflow changes nothing about who answers for the result. The ownership principle scales down as well as up. Even a low-stakes automation carries the same accountability logic, because the habit of verifying and owning output is what makes the high-stakes version reliable when it counts.

Security breaks it. HR builds the behavior around it.

Fields’ practical guidance is inspired by the working partnership she’s built with security colleagues. Whenever she creates an automation, she asks the security team to try to break it. “I’ll build something and then go to my security partners and say, ‘Break this apart. Tell me where the weaknesses are, where the data could leak, where someone could misuse it.’ They’re really good at finding those holes.”

Security exposes the technical vulnerabilities, but a list of vulnerabilities is not protection. What turns those findings into actual safety is HR translating them into clear expectations, training, and repeatable employee behavior. While a security team can identify that an automation could leak data through a particular input, HR is the function that turns that finding into a rule people understand and follow. “Security can tell you where the risk is, but then somebody has to turn that into how we actually work day to day. That’s the people side. That’s us,” she explains.

The division of labor is clear. Security answers whether the system is safe, and HR answers whether the people using it are behaving safely. Both questions have to be answered, and they require different expertise.

Responsible use must be routine

The failure mode Fields designs against is the one-time policy exercise: a document that’s circulated once, acknowledged, and then forgotten. Responsible AI use, she says, only survives as a habit built into ordinary work.

Her mechanism is a standing cadence. Weekly AI workshops give employees a regular venue to learn what the tools can do, surface questions, and hear how responsible use applies to their actual work rather than in the abstract. Automated security reminders keep the risk considerations present without depending on anyone remembering to raise them. “We do weekly workshops, and it’s not just, ‘Here’s a cool new feature.’ It’s ‘Here’s how you use it responsibly, here’s what to watch for.’ When it’s part of the rhythm, it becomes second nature instead of something people have to stop and think about,” she shares. 

The point of the cadence is normalization. When responsible use is reinforced weekly and risk reminders are built into the systems themselves, the behavior stops being an interruption and becomes the default. That’s the difference between a policy that simply exists and one that actually operates.

HR’s expanded mandate

The cost of getting this wrong isn’t hypothetical. Fields points to Ford’s walkback of its AI-driven layoffs as an example of what happens when companies lean too hard on technology and treat human oversight as a secondary consideration. The systems lacked the context that experienced people would have supplied, and the absence of that judgment showed up in the results.

The throughline is that AI has widened what HR is responsible for. The function that once owned hiring, policy, and employee relations now sits at the intersection of workforce behavior, ethical judgment, and security around AI. HR is the connective tissue between what the technology can do and how people are actually permitted and trained to use it. “This is our lane now. Not the technical security of the systems, that’s our partners. But how people use these tools, whether they use them ethically, whether they understand the accountability. That’s HR. And I think we should lean into it.”

She views the expanded mandate is an opportunity as much as an obligation. HR teams that claim this responsibility become central to how the organization adopts AI safely. The ones that cede it to technical functions leave the behavioral and ethical dimensions of AI use unowned, which is precisely where the risk concentrates.

Related articles

TL;DR

One thing we always have to remember is that our oversight is key, no matter how big or little the task is. We own that output. If there are errors, it’s not going to be, ‘The AI tool produced this.’ My name is on it.

Keician Fields

Accenture

Global Client Account HR Lead

One thing we always have to remember is that our oversight is key, no matter how big or little the task is. We own that output. If there are errors, it's not going to be, 'The AI tool produced this.' My name is on it.
Keician Fields
Accenture

Global Client Account HR Lead

Workplace AI has an accountability gap, and most organizations are trying to close it with the wrong function. The instinct is to hand AI oversight to security or IT, but whether an AI system is technically safe and whether employees use it responsibly are two different questions. Only one of them is a technology problem. The other is a behavior problem, which puts it squarely inside HR’s mandate. The organizations getting this right are the ones where HR shapes how people actually use the systems, with a named human accountable for every output either way.

Keician Fields is Global Client Account HR Lead at Accenture, where she specializes in HR transformation and technology integration. For more than 20 years she’s partnered with executive leaders to build agile HR strategies, lead complex organizational redesigns, and integrate technology to enable data-driven talent decisions. Her recent focus has centered on establishing governance and risk frameworks that position HR as a strategic partner in tech-enabled business evolution. For Fields, navigating early adoption hurdles comes down to establishing firm human accountability.

“One thing we always have to remember is that our oversight is key, no matter how big or little the task is. We own that output. If there are errors, it’s not going to be, ‘The AI tool produced this.’ My name is on it,” she says. In her view, that principle of a human in the lead on every AI-assisted output is the foundation everything else is built on.

Human in the lead, not just in the loop

Fields draws a distinction between ‘human in the loop’ and ‘human in the lead’ that’s subtle, but consequential. Human in the loop can mean a person rubber-stamps whatever the system produces. Human in the lead means the person carries responsibility for the accuracy, judgment, and consequences of the output, regardless of how much of it the AI generated. “You can’t just take what the tool gives you and run with it. You have to look at it, question it, and make sure it reflects what you actually intended. The accountability doesn’t shift to the tool because the tool did the work,” Fields notes. 

That framing matters most in the parts of HR where the stakes are highest. When AI influences a performance evaluation, a compensation decision, or a separation, the AI may accelerate the process, but HR still owns the outcome. Fields is explicit that the presence of AI in the workflow changes nothing about who answers for the result. The ownership principle scales down as well as up. Even a low-stakes automation carries the same accountability logic, because the habit of verifying and owning output is what makes the high-stakes version reliable when it counts.

Security breaks it. HR builds the behavior around it.

Fields’ practical guidance is inspired by the working partnership she’s built with security colleagues. Whenever she creates an automation, she asks the security team to try to break it. “I’ll build something and then go to my security partners and say, ‘Break this apart. Tell me where the weaknesses are, where the data could leak, where someone could misuse it.’ They’re really good at finding those holes.”

Security exposes the technical vulnerabilities, but a list of vulnerabilities is not protection. What turns those findings into actual safety is HR translating them into clear expectations, training, and repeatable employee behavior. While a security team can identify that an automation could leak data through a particular input, HR is the function that turns that finding into a rule people understand and follow. “Security can tell you where the risk is, but then somebody has to turn that into how we actually work day to day. That’s the people side. That’s us,” she explains.

The division of labor is clear. Security answers whether the system is safe, and HR answers whether the people using it are behaving safely. Both questions have to be answered, and they require different expertise.

Responsible use must be routine

The failure mode Fields designs against is the one-time policy exercise: a document that’s circulated once, acknowledged, and then forgotten. Responsible AI use, she says, only survives as a habit built into ordinary work.

Her mechanism is a standing cadence. Weekly AI workshops give employees a regular venue to learn what the tools can do, surface questions, and hear how responsible use applies to their actual work rather than in the abstract. Automated security reminders keep the risk considerations present without depending on anyone remembering to raise them. “We do weekly workshops, and it’s not just, ‘Here’s a cool new feature.’ It’s ‘Here’s how you use it responsibly, here’s what to watch for.’ When it’s part of the rhythm, it becomes second nature instead of something people have to stop and think about,” she shares. 

The point of the cadence is normalization. When responsible use is reinforced weekly and risk reminders are built into the systems themselves, the behavior stops being an interruption and becomes the default. That’s the difference between a policy that simply exists and one that actually operates.

HR’s expanded mandate

The cost of getting this wrong isn’t hypothetical. Fields points to Ford’s walkback of its AI-driven layoffs as an example of what happens when companies lean too hard on technology and treat human oversight as a secondary consideration. The systems lacked the context that experienced people would have supplied, and the absence of that judgment showed up in the results.

The throughline is that AI has widened what HR is responsible for. The function that once owned hiring, policy, and employee relations now sits at the intersection of workforce behavior, ethical judgment, and security around AI. HR is the connective tissue between what the technology can do and how people are actually permitted and trained to use it. “This is our lane now. Not the technical security of the systems, that’s our partners. But how people use these tools, whether they use them ethically, whether they understand the accountability. That’s HR. And I think we should lean into it.”

She views the expanded mandate is an opportunity as much as an obligation. HR teams that claim this responsibility become central to how the organization adopts AI safely. The ones that cede it to technical functions leave the behavioral and ethical dimensions of AI use unowned, which is precisely where the risk concentrates.