
Who Is Responsible When Everyone Uses ChatGPT in Software Development
Even if everyone uses ChatGPT, people are still responsible. The client must confirm the business need. The business analyst makes sure the specifications are understood. The project manager handles the delivery plan and evaluation. Engineers own the technical solution and approve the code. Quality assurance manages the verification strategy and evidence. Leaders oversee AI governance, security, and acceptable use policies. ChatGPT can generate content, identify gaps, suggest estimates, write code, and create test cases. It cannot accept contracts, approve business decisions, recognize all hidden constraints, or assume responsibility for product failures. The defining question is: Which authorized person reviewed, challenged, approved, and accepted responsibility for the output? The new software development chain A client shares an idea with ChatGPT, which turns it into a polished requirements document. The client then sends this document to a business analyst, who uses another AI tool to find gaps, create user stories, and define acceptance criteria. The project manager then asks AI to estimate the work, create a schedule, identify dependencies, and propose a team structure. An engineer asks an AI coding assistant to design the architecture, generate components, write APIs, and solve technical problems. Finally, the QA professional uses AI to create test cases, automate tests, and prepare a test report. Every stage appears faster, and every output looks organized. Yet the entire project may be built on an assumption invented during the first conversation. A vague client idea can become a detailed requirement. That requirement can become a confident estimate. The estimate can become a delivery commitment. Generated code can satisfy generated test cases, while the finished system still fails to solve the client’s real problem. This is an AI-assisted version of the telephone game. Each participant receives an interpretation, asks another AI system to reinterpret it, and passes the polished result to the next person. More documentation is created, but ownership becomes less visible. ChatGPT can produce an output, but it cannot own an outcome. An AI tool can produce a requirement document. It cannot confirm that the requirement represents the organization’s actual priorities. It can assist with project estimation, but it cannot commit to resources, budget, or delivery timelines. It can generate code, but it cannot accept responsibility for a security breach, data loss, licensing issue, or production failure. It can create test cases, but it cannot decide whether the delivered product is safe, useful, compliant, and ready for customers. Generation may be delegated to AI. Accountability cannot be delegated to AI. This principle is consistent with current guidance. The NIST AI Risk Management Framework organizes responsible AI activity around governing, mapping, measuring, and managing risk. OWASP secure coding guidance also stresses that organizations should not deploy AI-generated code without human review and approval. Who is responsible at each stage Assign responsibilities in an AI-assisted software development lifecycle based on authority, expertise, and the ability to verify output. Role What AI can support What the person owns Client or product owner Problem statements, feature ideas and initial requirements Business objective, priorities, constraints, scope approval and acceptance Business analyst Requirement drafts, user stories and gap analysis Accuracy, stakeholder alignment, assumptions, traceability and clarification Project manager Schedules, risk lists and estimation inputs Planning, dependencies, resources, risks, communication and commitments Technical lead Architecture options and design suggestions Security, scalability, integrations, maintainability and design approval Software engineer Code, unit tests and debugging support Correctness, security, dependency validation, review and production behavior QA professional Test scenarios, automation and defect summaries Test strategy, coverage, independent evidence and release recommendation Leadership Policy drafts and risk classifications Approved tools, data protection, access controls, compliance and governance The purpose is not to blame individuals. It is to prevent responsibility from disappearing among roles. Accountability should be clear before a problem occurs, not reconstructed after a failure. The client owns the business truth. A client may use ChatGPT to articulate an idea, especially when the client lacks experience writing software requirements. AI can ask questions, organize thoughts, and turn a conversation into a structured starting point. However, a generated requirement document is not automatically an approved requirement. · What problem must be solved, and who experiences it? · What measurable result should the project achieve? · Which features and constraints are essential? · What would make the project unsuccessful? · Who approves scope changes? · What criteria will determine final approval? The client does not need to understand every technical detail, but the client or product owner must own the business intent. If the first idea is unclear, every later AI-assisted activity will optimize an uncertain interpretation. The business analyst owns clarity plus traceability. A business analyst should never treat an AI-generated requirements document as an unquestionable source. The document is a hypothesis to investigate. The analyst must separate confirmed facts from generated assumptions through stakeholder interviews, process analysis, conflict resolution, domain validation, and linking each major requirement to the business objective. If ChatGPT fills a missing detail, that detail must remain an assumption until an authorized stakeholder confirms it. A polished sentence is not evidence. A detailed user story is not approval. A comprehensive document is not necessarily a valid document. The project manager owns the estimate. ChatGPT can suggest a work breakdown, identify common dependencies, and generate an initial estimation checklist. It does not know the team’s full reality, including skill levels, availability, legacy limitations, internal approvals, vendor response times, data quality, technical debt, security reviews, and changing priorities. An AI-generated estimate can create dangerous false precision. A responsible project manager should present estimates as ranges with assumptions and confidence levels. For example: Estimated delivery is 12 to 16 weeks, assuming the payment API is available, requirements are approved by the second week, and no historical data migration is required. AI can support the estimation process, but the project manager and delivery team remain responsible for validating, finalizing, and communicating the estimate; they own every line they approve. Treat








