Printing PressAI
← Back to front page
Business & Enterprise AI

Who owns AI risk at work? Business and tech leaders can’t agree, PwC survey finds

Original reporting by ZDNet

Image via ZDNet

AI accountability refers to the critical task of assigning clear responsibility for the security, governance, and ethical deployment of artificial intelligence systems within an organization. While the rapid adoption of AI, from agentic models to large language models, offers immense benefits—streamlining operations, boosting productivity, and enhancing analysis—this integration also introduces significant new risks. Businesses are grappling with the implications of rogue AI models, potential security incidents, and AI agents acting as new entry points into corporate networks. A new PwC Digital Trust Insights 2027 report, surveying 4,000 business and tech leaders globally, underscores a fundamental challenge: businesses cannot agree on who is ultimately responsible when things go wrong.

Addressing Accountability Gaps The research reveals a stark division, with no single role clearly owning the management of agentic AI or its security. While a portion of leaders suggest accountability lies with CIOs or CTOs (29%), others point to CISOs (17%), and a significant number advocate for dedicated AI leaders or functions (26%). Troublingly, 11% confess responsibility remains unclear or is shared across multiple functions, hindering effective oversight. This ambiguity parallels the early evolution of cybersecurity leadership. Experts now propose both human-centric solutions, such as dedicated Chief AI Security Officers, and technological safeguards, like applying established identity controls to AI agents, to close this critical gap. Without clear accountability and robust governance, companies deploying AI risk exposing themselves to significant security vulnerabilities and compliance challenges.

The PwC report starkly illuminates a critical leadership vacuum in the enterprise AI landscape: the absence of clear, unified accountability for AI security and governance. While the benefits of AI are undeniable, the current state of diffused responsibility—split across CIOs, CISOs, and nascent AI-specific roles—sets a perilous precedent. This lack of defined ownership not only increases an organization’s vulnerability to rogue AI incidents and compliance breaches but also stifles the potential for truly secure and responsible AI innovation. As AI agents gain more autonomy and access within corporate networks, the imperative for robust oversight becomes non-negotiable.

Defining AI leadership

The historical precedent of the CISO role, once a novel concept, offers a crucial parallel. Just as cybersecurity evolved from a niche concern to a board-level imperative demanding dedicated executive leadership, AI governance is poised for a similar transformation. The fragmented responsibility observed today is unsustainable. Forward-thinking enterprises will not only adopt advanced identity controls and governance frameworks for their AI agents but also recognize the urgent need to establish an executive-level role solely dedicated to the strategic oversight, security, and ethical deployment of AI. This new wave of leadership, whether a Chief AI Officer or a Chief AI Security Officer, will be central to translating technological advancements into trusted, resilient business operations. The organizations that proactively address this accountability gap will be best positioned to harness AI's full potential responsibly, securing both their digital future and their competitive edge.

Frequently asked questions

Why are businesses struggling to assign responsibility for AI security and governance?
Businesses struggle with AI accountability because its rapid adoption outpaces established governance frameworks. A recent survey shows no single role consistently takes responsibility for AI security and deployment, with duties often divided or unclear among CIOs, CISOs, and emerging AI-specific leaders. This fragmentation creates gaps in managing risks associated with increasingly autonomous AI agents and their potential security incidents.
What new leadership roles are emerging to manage AI accountability in organizations?
As AI integration expands, dedicated leadership roles are emerging to address accountability. These include Chief AI Officers (CAIOs) and AI board members, responsible for strategic oversight and governance. There's also speculation about a Chief AI Security Officer (CAISO), a counterpart to the CISO, focusing specifically on managing the security risks and compliance for AI deployments and autonomous AI agents within an organization.
How can companies enhance security and control over their AI agents and deployments?
Companies can enhance AI security by applying established identity controls to AI agents, similar to human users. This includes implementing robust authentication, access controls, and zero-trust principles for each agent. Centralized platforms can register sanctioned agents, tying them to human owners for authorizing high-risk actions. Regular evaluation and decommissioning of unneeded agents also contribute to better governance and reduce potential security vulnerabilities.
Intro and outro generated by Printing Press AI from the source article above. Always consult the original reporting for verbatim quotes and primary sources.