Product1 publisher3 min readPublished
Executives split four ways over who owns AI risk, PwC survey finds
PwC's survey of about 4,000 business and tech leaders found no agreed owner for AI risk, with the CIO or CTO the top answer at just 29%. Until that settles, the usable control is per agent: its own credential and one named owner.
The Product Desk · Product desk

What happened
- A dedicated AI leader or function drew 26% of answers on where AI accountability sits, and the CISO or cybersecurity teams drew 17%.
- Another 11% said accountability for AI is unclear, with responsibility shared across multiple roles or functions.
- Nine in ten leaders said practices such as board oversight and executive accountability are already in place.
- About a third of organisations have hired for dedicated AI roles, including chief AI officers and AI board members.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- contradiction A company's statement that executive accountability is in place tells an auditor little about its AI agents when its own leaders split on who owns them.
- decision Boards that count AI governance as done still have to pick one executive to answer for agents; until they do, each incident gets its owner decided after the fact.
- cost Handing AI security to the CIO, the most common answer, adds it to a role ZDNET says already has enough to handle.
An incident ticket about an AI agent has the same owner field as any other ticket. The engineer filling it in on a Friday needs one name. PwC's Digital Trust Insights 2027, drawn from about 4,000 business and tech leaders in 71 countries, shows the executives above that engineer have not agreed on one [1][2].
No single home for AI accountability drew even a third of respondents [1]. The four answers ZDNET reports add to 83%, which leaves 17% of responses outside them [2]. The governance leaders report and the ownership they agree on are two different measurements. The nine-in-ten figure counts practices that exist. The split counts whether anyone agrees whose name goes in the field [5][1]. Even for cybersecurity, 47% of respondents said it is a standing item on the board agenda [3].
Creating new executive titles takes longer. ZDNET recalls that Citigroup hired Steve Katz as the first formal CISO in 1994, after Russian cyberattacks, and suggests a chief AI security officer could be the next seat [12][13]. PwC's research leaves open whether the AI roles companies have already created include accountability for AI security and governance at all [10].
The control a team can apply sooner is at the level of each agent. Each agent is tied to a set of credentials and can act on behalf of an employee, ZDNET notes [15]. Jim Taylor, chief product and strategy officer at RSA, told ZDNET that each agent build should have the "same identity controls that have been securing human users for decades" [11]. That prescription is a product executive's view. The survey figures in ZDNET's report do not measure how many agents hold credentials of their own. ZDNET's example of applying it is a central platform that registers the agents sanctioned to operate in an organisation [17].
I'd name an owner for each agent now, at the team that deploys it, and give every agent its own credential without waiting for the org chart to settle. The cost is fragmentation. A dozen team leads each owning a few agents looks a lot like the shared arrangement some respondents already call unclear. So the names need to sit in one register that a single executive can read [9][17].
The test fits on one sheet, with a row per agent in production and two yes-or-no columns. The first asks whether the agent signs in with its own credential. The second asks whether one named person answers for it. Yes on both covers Taylor's identity point and the ownership question the survey respondents have not settled. An owner with a borrowed credential produces logs that show a human doing what the agent did. A credential with no owner is an account with access and nobody to call. No on both is the case ZDNET describes as a new entry point into corporate networks [16]. Fix the no-owner column first. An owner can replace a borrowed credential, but an agent without an owner has nobody to do that.
What to watch
- Whether PwC's full Digital Trust Insights 2027 report counts how many organisations give AI agents their own credentials or register them centrally.
- Whether companies that have hired chief AI officers formally assign them AI security incidents, or create separate chief AI security officer seats.