Who owns AI risk at work? Business and tech leaders can’t agree, PwC survey finds
ZDNET’s key takeaways
- PwC reveals business leaders can’t agree on who is responsible for AI.
- AI agents may lack the identity controls that manage employees today.
- Is a dedicated AI executive or leader the answer?
Artificial intelligence (AI) adoption continues to surge, with agentic AI and large language models (LLMs) now integrated into everything from enterprise applications to chatbots that help you with food delivery.
Also: LLMjacking can run up your business’ AI bill fast – how to stop it
The benefits of AI are clear: it can streamline business operations, reduce manual workloads, serve as a research and analysis assistant, and give employees tools that make day-to-day work less strenuous and time-consuming.
More from ZDNET
But we’re now experiencing the trade-offs. Rogue AI models, friendly AI hacking innocent companies, potentially thousands of AI-related security incidents being investigated, and AI agents acting as new entry points into corporate networks.
Who should be responsible and take ownership of AI when things go wrong? According to new research from PwC, businesses can’t agree.
Cybersecurity and AI in the boardroom
On Friday, PwC released its Digital Trust Insights 2027 report, which surveyed approximately 4,000 business and tech leaders across 71 countries.
According to the survey, no single role has a clear responsibility for managing agentic AI or its security, although awareness of both the benefits and disadvantages of AI has reached the board level in around half of businesses.
Also: Rogue AI incidents hit ‘tens of thousands’: Can businesses trust these tools?
In total, 47% of those surveyed said cybersecurity is a standing agenda item for boards, which is far from enough. However, the foundations are there: nine out of 10 business leaders said practices like board oversight, executive accountability, and enterprise risk integration are now in place.
On AI, about a third of organizations (33%) have recognized the need for accountability and hired for dedicated AI roles, including AI chief officers and AI board members.
CEO, CIO, CISO, or AI chief?
PwC’s research reveals a problem in the enterprise sector: whether these AI roles also include overall accountability or responsibility for AI-related security and governance.
Overall, 29% of CEOs and security and risk leaders said accountability sits with the CIO, CTO, or a similar technology role. 17% of respondents said the responsibility lies with the CISO or cybersecurity teams, while 26% said it should stay with “a dedicated AI leader or AI function.”
In addition, 11% of respondents said accountability is unclear, with responsibility shared across multiple roles or functions.
The research shows that while the enterprise understands someone needs to take responsibility for agentic AI and the security issues around its deployment, monitoring, and security, the chain of responsibility hasn’t yet been defined.
Also: Who’s responsible for catching rogue AI agents? You are
It was only back in 1994 that the first formal CISO, Steve Katz, was hired by Citigroup to handle the aftermath of Russian cyberattacks. Now, the idea of a medium-to-large business without one is almost inconceivable.
CIOs and CISOs generally have enough to handle, so adding new AI-related security management and control could be too much of a burden. If so, we may be on the verge of a new hiring drive for AI-expert CISO counterparts: the CAISO, a chief AI security officer.
Can technology close the gap?
While the enterprise at large experiments with defining AI accountability and dividing responsibilities across different roles, technology can now assist businesses in maintaining control of their AI agents.
Jim Taylor, Chief Product and Strategy Officer at RSA, told ZDNET that the same identity controls that have secured human users for decades need to be used to manage agentic AI.
It’s easy to forget that each AI model, or agentic AI deployment, has an identity. They are linked to a set of credentials; they have varying levels of access to resources and information, and can perform tasks or act on behalf of a human employee.
Just as we have passwords, zero-trust principles, multi-factor authentication (MFA), and other access controls that verify our identities, Taylor suggests each agentic AI build should have the “same identity controls that have been securing human users for decades.”
That’s not to say this removes the need for a leadership-level human overseer, but by boosting security through agentic AI governance controls, organizations can better prepare for the ongoing risks associated with AI.
Also: AI agent kill switch urged by Okta-led alliance – how businesses could make it work
For example, a centralized platform could register AI agents sanctioned to operate in corporate networks, and each agent could be tied to a human owner who must personally authorize high-risk actions. Taylor also suggests that organizations deploying AI should ensure governance controls mapped to industry frameworks are applied, and that AI agents be evaluated frequently and decommissioned when they are no longer needed.
“Companies will keep investing in AI, but they’ve brought on workers they don’t see and can’t control,” Taylor commented. “Those agents won’t be held in compliance violations — but the organization will. If they do deploy agents, then they’ll need the means to keep them secure.”
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.