Leadership1 publisher3 min readPublished
Zscaler's Rob Sloan makes California's agency rule the case for a corporate AI security owner
A California requirement for state agencies to name AI cybersecurity officers is now an argument for the same thing inside companies. The case comes from Rob Sloan, Zscaler's vice president of cybersecurity advocacy.
The Board Room · Leadership desk

What happened
- California now requires each of its state agencies to designate an AI cybersecurity officer, according to a Forbes Tech Council column by Rob Sloan of Zscaler.
- Sloan argues companies should name a Chief AI Cybersecurity Officer, or a clearly empowered equivalent, while conceding that not every company needs a permanent new C-suite title.
- He writes that legal and compliance teams are essential for interpreting rules such as the EU AI Act but cannot actually secure AI systems.
- Sloan also writes that the role may not need to be permanent, and that the work may eventually fold back into a broader function as companies get better at governing AI.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- decision Two options sit on the same budget line this quarter: widen the CISO's charter by memo, which can be undone quietly, or fund a post with a reporting line and a headcount.
- constraint Spending in legal and compliance cannot close this gap on Sloan's account, because documentation and risk classification do not harden a model or bound what an agent is permitted to do.
- exposure Where nobody owns the question, the first accurate inventory of what AI touches arrives after the pilot is already in production, and the deploying business unit is holding the risk.
- precedent With only a state-agency designation rule in the record, the companies that name an owner now are the ones defining what the job includes, and later rules would inherit that definition.
The record here is one column, and where it was published matters. Sloan's piece ran on Forbes' Tech Council platform, which carries his employer in the byline note [16][3]. His account of the California requirement is a single sentence, with no bill number, no effective date, and no description of what the designated officers are obliged to do [17]. The rule he cites binds state agencies. The recommendation he draws from it is aimed at companies, and the extension is his own [18].
"Maybe the CISO should own it. The problem is that most CISOs are already overloaded," Sloan wrote [5]. The support he offers is a list of what security chiefs hold at once: cloud security, identity, resilience, ransomware preparedness, third-party risk, incident response and board reporting [6]. Sloan lists seven standing mandates in one job [21]. Sloan's claim is that AI security does not fit as the eighth.
Five exposures carry the technical half of the argument [20]: prompt injection, training data poisoning, model manipulation, agent permission abuse, and sensitive information leaking into unsanctioned tools [7]. "AI security simply cannot be treated as a side job divided between legal, IT, security and engineering," Sloan wrote [8]. He puts the work in execution terms, naming model hardening, guardrails and limits on what AI agents are allowed to do [15]. On the boundary with compliance he is direct: "This person shouldn't replace legal or compliance; their job is to make sure policy turns into actual controls, testing and guardrails" [10].
The trade-off a budget owner actually faces is hidden behind the title question. Extending the CISO's charter is a memo, and the next reorganisation can undo it. Standing up an officer with a reporting line and headcount is a commitment that has to be unwound in public later, and Sloan expects an unwinding: he writes that the role may not need to be permanent, and that over time the work may fold back into something broader [12].
On sequencing he is specific about who goes first, naming regulated companies, multinationals and firms putting AI into customer-facing products [11]. For everyone else his case rests on timing. When security is seen as slowing deployments, Sloan writes, business teams bring it in too late or not at all, which is how shadow AI grows and how pilots reach production before anyone has asked what data is exposed [13]. He also argues that attackers are already using AI to scale their operations and that better models will widen that advantage [14].
Sloan's five exposures can each be assigned to a named person on an existing org chart. That mapping tells a board whether it has an ownership gap or a capacity gap. Hiring only closes the second.
What to watch
- The text of the California requirement: whether designated agency officers get budget and authority, or only the title. The column does not say.
- Whether a large company posts a Chief AI Cybersecurity Officer role reporting to the CEO, rather than folding the work under the existing CISO.
- Whether EU AI Act enforcement practice starts asking firms to name an accountable individual for AI security, not just document the risk classification.