As artificial intelligence becomes deeply embedded in enterprise operations, a significant governance gap has emerged regarding accountability. According to the Digital Trust Insights 2027 report released by PwC, there is no consensus among business and technology leaders on which role should take ownership of AI risks, particularly concerning agentic AI and large language models.
The survey, which included approximately 4,000 leaders from 71 countries, highlights a contradiction in corporate strategy. While about half of organizations have elevated AI discussions to the board level, only 47% of respondents indicated that cybersecurity remains a standing agenda item for their boards. Despite this, 90% of leaders claimed that foundational practices such as executive accountability and enterprise risk integration are already in place.
When asked to identify who holds responsibility for AI security and governance, respondents were sharply divided. Twenty-nine percent assigned accountability to traditional technology roles like the CIO or CTO, while 17% pointed to the CISO or cybersecurity teams. Meanwhile, 26% argued that a dedicated AI leader or function should bear the burden. Notably, 11% admitted that accountability is unclear and is currently shared across multiple roles.
Although 33% of organizations have hired dedicated AI officers or board members, the research suggests these positions often lack clear authority over overall AI security. This ambiguity comes as the threat landscape evolves; rogue AI models and insecure AI agents are increasingly viewed as entry points for corporate network breaches.
Jim Taylor, Chief Product and Strategy Officer at RSA, argued that the solution lies in applying established identity controls to AI systems. He noted that AI agents possess identities, credentials, and varying levels of access, yet they often operate without the same security protocols applied to human employees, such as multi-factor authentication and zero-trust principles.
Taylor urged companies to treat AI agents as digital workers that require governance. He suggested that organizations implement centralized platforms to register sanctioned agents, tie each agent to a human owner, and mandate personal authorization for high-risk actions. Without such measures, he warned, companies risk deploying uncontrollable workers that could lead to compliance violations for which the organization remains liable.
I’m surprised by the gap between board-level discussions and actual cybersecurity standing agenda items. Strategy outpaces governance again.
Treating AI agents like digital workers with proper credentials seems obvious. Isn’t this just basic identity management?
Why are we waiting for a breach to assign accountability? Ten percent admitting unclear responsibility is a ticking time bomb.
It’s alarming that 90% claim foundational practices exist when the report shows such fundamental confusion over who actually owns the risk.