Governed autonomy · risk & insurance

When an AI acts at 3 a.m., who’s liable?

Control evidence by design. The autonomous SOC your risk committee can actually sign off on.

How it holds

Read-only investigation

Assembles evidence, takes no action.


Approval-gated actions

Consequential actions pass a governing gate.


One audit trail per incident

The investigation is the record.

In one paragraph

What a governed autonomous SOC actually means

A governed autonomous SOC is one whose every autonomous decision is retraceable and whose every consequential action ran with a human in command.

Morpheus is built for that standard: read-only investigation takes no action on its own; consequential actions run only through risk-tiered approval gates across four autonomy modes, reversible and logged; and the investigation itself becomes a single audit trail per incident. The result is control evidence by design, an organization can demonstrate to a regulator, an auditor, or a board not only what the AI decided, but how, and where a human was in the loop, aligning with human-oversight obligations such as EU AI Act Article 14, DORA, and NIS2.

Who is liable when an AI acts in the SOC?

Liability doesn’t disappear because a machine acted. It sits with the organization that deployed it.

The indefensible answer

“The AI did it.”

A record scattered across logs and reconstructed after an incident, if it can be reconstructed at all.

The defensible position

Show precisely what the AI did, that a human could oversee it, and that consequential actions passed a governing gate.

Morpheus is designed so that record exists by default.

How do you prove what an autonomous system did?

You make the investigation itself the record. One chain of custody per incident.

Query
Every query the engine runs
Evidence
Every item it weighs
Judgment
Every confidence call
Action
Every action, as one chain

Because the work and the audit record are the same artifact, there’s nothing to assemble after the fact. The proof is a property of how the system runs.

Regulatory context

What do EU AI Act Article 14, DORA, and NIS2 expect here?

You cannot oversee what you cannot retrace.

These regimes converge on meaningful human oversight of high-stakes systems, the ability for a person to understand, monitor, and intervene. Morpheus aligns through read-only investigation, human-in-command approval gates, and a complete per-incident record. This is oversight framing to discuss with your GRC team, not a certification Morpheus holds.

What does the board actually get?

The board decision log

A record it can stand behind

For any incident, the risk committee can see the full record without a fire drill to reconstruct it, which turns “we deployed autonomy” from an open question in a risk review into a documented, defensible control.

Per-incident decision log

  • What the automated system decided
  • The evidence behind it
  • Where a human approved the action
  • Where a human overrode it, reversible and logged

Control mapping

Map your oversight obligations to the mechanism

RegimeOversight obligationMorpheus mechanism
EU AI Act Article 14Understand the systemRead-only investigation record
DORAIntervene in decisionsApproval gates, override at any stage
DORA / NIS2Reverse a consequential actionReversible, logged, human-in-command actions
NIS2Monitor and account afterwardOne audit trail per incident

How Morpheus mechanisms map to human-oversight obligations. Oversight framing to confirm with your GRC team, not a certification.

faqs

Frequently Asked Questions

The questions risk, GRC, and legal ask first about autonomy in the SOC.

Autonomy your risk committee can actually sign off on.

See the per-incident audit trail on a live investigation, and the obligation-to-mechanism mapping your GRC team can work from.