Business leaders lack consensus on who should be accountable for artificial intelligence security and governance, according to a new report from PwC released Friday. The Digital Trust Insights 2027 survey, which polled roughly 4,000 business and technology executives across 71 countries, reveals that no single role has clear responsibility for managing agentic AI or its security. While awareness of AI's benefits and drawbacks has reached the boardroom in approximately half of organizations, responsibility for AI oversight remains fragmented and poorly defined.
The data shows a splintered approach to AI accountability. Among CEOs, security leaders, and risk executives, 29% said responsibility sits with the CIO, CTO, or a similar technology role, while 26% believe it should rest with a dedicated AI leader or AI function. Just 17% of respondents pointed to the CISO or cybersecurity teams as the accountable party. Another 11% said accountability is unclear, with responsibility shared across multiple roles or functions. About a third of organizations—33%—have hired for dedicated AI roles, including AI chief officers and AI board members, though it's uncertain whether these positions include overall accountability for AI-related security and governance. Meanwhile, only 47% of surveyed leaders said cybersecurity is a standing agenda item for boards. On a more positive note, nine out of 10 business leaders reported that practices such as board oversight, executive accountability, and enterprise risk integration are now in place.
The report finds that while enterprises understand someone needs to take responsibility for agentic AI and the security issues surrounding its deployment, monitoring, and protection, the chain of responsibility hasn't yet been defined. Jim Taylor, Chief Product and Strategy Officer at RSA, told ZDNET that the same identity controls that have secured human users for decades need to be applied to manage agentic AI. According to Taylor, "Companies will keep investing in AI, but they've brought on workers they don't see and can't control." He warned that while AI agents won't be held accountable in compliance violations, the organizations deploying them will be.
PwC's research highlights a fundamental challenge: AI agents now function as new entry points into corporate networks, yet they may lack the identity controls that manage employees today. Each AI model or agentic AI deployment has an identity—it's linked to credentials, has varying levels of access to resources and information, and can perform tasks or act on behalf of a human employee. Taylor suggests that organizations apply the same identity controls to AI agents that have protected human users for decades, including passwords, zero-trust principles, and multi-factor authentication. He recommends that companies use a centralized platform to register AI agents sanctioned to operate in corporate networks, tie each agent to a human owner who must personally authorize high-risk actions, and ensure governance controls mapped to industry frameworks are applied. AI agents should also be evaluated frequently and decommissioned when they're no longer needed. The enterprise may be on the verge of a new hiring wave for AI-expert CISO counterparts—a chief AI security officer, or CAISO—given that CIOs and CISOs already carry substantial responsibilities. The question of who owns AI risk will likely shape governance structures for years to come, much as the rise of cyber threats led Citigroup to hire the first formal CISO back in 1994.

