← Latest papers
🤖 AI

LAAF: A Layered Accountability Architecture Framework for LLM Applications

This paper presents LAAF, a Layered Accountability Architecture Framework for LLM applications, derived from a systematic review of 122 studies and regulatory documents, which synthesizes technical, human, organizational, and documentation mechanisms into a four-layer model aligned with global standards like the EU AI Act and NIST AI RMF to address critical gaps in accountability for high-risk AI deployments.

Original authors: Prachi Chaturvedi, Shahnawaz Ahmad, Ehsan Nowroozi, Muhammad Waqas, George Loukas, Alireza Jolfaei, Lucas Cordeiro, Pierre Dantas

Published 2026-08-28
📖 4 min read☕ Coffee break read

Original authors: Prachi Chaturvedi, Shahnawaz Ahmad, Ehsan Nowroozi, Muhammad Waqas, George Loukas, Alireza Jolfaei, Lucas Cordeiro, Pierre Dantas

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

In the modern world, powerful computer programs known as large language models have become common tools for writing, planning, and answering questions. These systems do not simply search a database for a matching fact; instead, they predict the next word in a sentence based on patterns learned from vast amounts of text. This ability allows them to speak with a fluency that feels human, often producing paragraphs that sound confident and authoritative. However, this fluency comes with a hidden flaw: the system can generate statements that are grammatically perfect but completely false, a phenomenon researchers call a hallucination. In casual conversation, a wrong answer is merely annoying, but in critical settings like hospitals, banks, or courts, a confident mistake can cause real harm. When such an error occurs, a difficult question arises: who is responsible? Is it the person who wrote the prompt, the company that built the software, or the institution that deployed it? For years, the answer has been unclear, leaving a gap between the technology's rapid advancement and the rules needed to manage it.

A team of researchers set out to solve this puzzle by conducting a massive review of the existing literature on how to hold these systems accountable. They examined thousands of documents published between early 2022 and early 2026, narrowing their focus to 122 key studies and 12 official regulatory documents. Their goal was not just to list the problems, but to map out exactly how responsibility could be traced, explained, and acted upon when things go wrong. They found that the current approach is fragmented. Technical experts focus on how to detect errors in the code, while policy experts focus on laws and ethics, but the two groups rarely speak the same language. Furthermore, the literature often assumes that simply having a human look at the output is enough, without specifying what that human should actually do, what information they need, or what authority they have to stop a bad decision.

To bring order to this confusion, the researchers proposed a new framework called LAAF, which stands for the Layered Accountability Architecture Framework. They organized the entire process of using these AI systems into four distinct layers, moving from the bottom up. The first layer deals with the origin of the software itself, requiring clear records of where the model came from and what data it was trained on. The second layer focuses on how the software is used in a specific application, ensuring that the system checks its own answers against trusted sources and logs every step it takes. The third layer places a human in the loop, not just as a passive observer, but as an active reviewer who has the power to override the machine if the output seems unsafe or incorrect. The final layer is the organizational level, where companies establish rules, assign specific roles to individuals, and create pathways for fixing mistakes and compensating those who were harmed.

The study revealed that while we have many tools to check for errors, they are often used in isolation. For instance, a system might have excellent logging capabilities but lack a clear plan for who reviews those logs when a problem arises. The researchers identified four major gaps that prevent us from being truly accountable: we do not have clear rules for how humans should oversee these systems, we lack shared ways to measure success, the technical and legal fields remain disconnected, and most proposed solutions have only been tested in simulations rather than in the real world. They also highlighted five deep tensions that are difficult to resolve, such as the conflict between being transparent enough to prove accountability and keeping enough information secret to protect security and business interests.

The framework the team built is designed to work alongside existing laws, such as the European Union's AI Act and standards from the United States and international bodies. It treats cybersecurity as a core part of accountability, recognizing that if a system can be tricked or manipulated, no one can truly be held responsible for its output. By aligning technical controls with human oversight and organizational governance, the framework offers a way to trace a single mistake back through the layers to find exactly who made a decision and why. The authors are careful to note that this is a blueprint based on current evidence, not a finished product that has been proven to work in every situation. However, by turning a vague concept of responsibility into a structured, four-layer system, they have provided the first comprehensive map for navigating the complex relationship between powerful artificial intelligence and the humans who must answer for it.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →