AI could be the latest chapter in a story CISOs know well — in which they are held accountable for incidents they lack the power to prevent.
“Nothing’s changed. A CISO’s formal job is to set strategy, advise and — to the best of his or her ability — prevent the worst from happening,” said Johna Till Johnson, analyst at Nemertes Research. “Their actual job is to be fired if something goes wrong, and AI is now one of the biggest ‘somethings.'”
New research from consulting firm PwC reveals a lack of consensus on who should own AI governance and AI risk management. Of the organizations surveyed, 17% formally assign responsibility to CISOs; 29% to CIOs, CTOs or the technology function; and another 11% split accountability across multiple functions. One-third have a dedicated AI role, such as a chief AI officer.
“When accountability is diffuse, organizations can end up reacting to AI risk rather than proactively managing it,” said Morgan Adamski, PwC’s U.S. cyber, data and tech risk leader.
Without a clear ownership model, AI governance gaps and after-the-fact blame games become more likely, experts said. That means in an incident, the CISO could end up taking the fall. But security leaders argue that if they are to be held accountable for AI security outcomes, they should have authority that matches the responsibility.
CISOs need both accountability and authority
CISOs should own AI security boundaries, said Omer Cohen, CSO at identity management vendor Descope. But organizations must empower them to do so, not just hold them responsible when something goes wrong.
“A CISO cannot be expected to prevent an incident involving an AI system they didn’t know existed, had no control over or couldn’t restrict from accessing sensitive data and systems,” Cohen said.
CISOs should have authority to review AI systems and agents prior to deployment, said Stanislav Kazanov, head of governance, risk and compliance; cybersecurity; and sustainability at software development firm Innowise.
“If the CISO doesn’t have the right to prevent deployment of an agent whose security review failed, he or she doesn’t own the security risk of that system, no matter how it is depicted on the organizational chart,” Kazanov said. Security executives, he added, should also control identity and access management for AI systems and agents, as well as ongoing AI monitoring and incident response.
AI risk and governance extend beyond cybersecurity’s scope
Experts cautioned, however, that CISOs should not accept responsibility for risk that exceeds their purview.
“AI risk cannot sit solely with the CISO because AI itself doesn’t sit solely within the cyber organization. It touches technology, data, operations, risk and the business,” PwC’s Adamski said. “The problem is when those responsibilities aren’t clearly defined or connected.”
AI governance includes decisions outside the relatively narrow security domain, agreed Kazanov, such as whether a hiring algorithm is discriminatory or whether a business use case justifies potential legal liability. “By accepting ownership of all these decisions, the CISO assumes liability for things they have no control over,” he said.
Shashidhar Angadi, co-founder and CTO at software vendor Exterro, argued that accountability for AI failures should follow the business use case.
“Risk is created where the business puts AI into a workflow,” Angadi said, citing a 2024 incident in which engineering firm Arup lost roughly $25 million because of a deepfake video call. “The failure was a payment-approval process, not a firewall. Asking the CISO to own that risk is like asking the fire department to own the building’s wiring.”
CISOs should push for clarity now
But when responsibilities are murky, warned network and security consultant Daniel Di Nardo, cybersecurity often becomes the default target in the wake of an incident. The best approach, he suggested, is to explicitly separate AI ownership from security and oversight: Business leaders own how AI is used and are accountable for decisions about its use; CISOs own the security of AI systems; and legal and compliance executives own oversight.
“If these lines are not drawn, CISOs can find themselves being held accountable for decisions outside their initial scope,” Di Nardo said.
The goal, according to PwC’s Adamski, isn’t to centralize every AI decision under one person but to clarify and connect areas of accountability, “so there aren’t gaps where everyone assumes somebody else is responsible.”
If she were a CISO, Adamski added, she’d want cybersecurity involved in AI initiatives from the beginning, “with clear ownership, escalation paths and decision rights across technology, data, risk and the business.”
If those conversations haven’t happened yet, she added, security leaders should push to have them now.
“The important thing is establishing that accountability before an incident occurs rather than trying to determine who was responsible after the fact,” Adamski said.
