ZDNET’s key takeaways
- PwC reveals business leaders may not agree on who is responsible for AI.
- AI agents may lack the identity control that employees manage today.
- Is a dedicated AI executive or leader the answer?
Artificial intelligence (AI) adoption continues to rise, with agentic AI and large language models (LLMs) now integrated into everything from enterprise applications to chatbots that help you with food delivery.
Also: LLMjacking can quickly open your business’s AI bill – how to stop it
The benefits of AI are clear: it can streamline business operations, reduce manual workloads, serve as a research and analysis assistant, and give employees tools that make everyday work less strenuous and time-consuming.
But we are now experiencing the abortions. Rogue AI models, friendly AI hacking innocent companies, potentially thousands of AI-related security incidents being investigated, and AI agents acting as new entry points into corporate networks.
Who should be responsible and take ownership of AI when things go wrong? According to new research from PwC, companies cannot agree.
Cybersecurity and AI in the boardroom
On Friday, PwC released its Digital Trust Insights 2027 report, which surveyed approximately 4,000 business and tech leaders across 71 countries.
According to the survey, no single role has a clear responsibility for the management of agentic AI or its security, although the awareness of both the advantages and disadvantages of AI has reached the board level in about half of the businesses.
Also: Rogue AI incidents hit ‘tens of thousands’: Can businesses trust these tools?
Overall, 47% of respondents said that cybersecurity is a constant agenda item for boards, which is far from enough. However, the foundations are there: nine out of 10 business leaders said that practices such as board oversight, executive accountability, and enterprise risk integration are now in place.
On AI, about a third of organizations (33%) recognized the need for accountability and hired for dedicated AI roles, including AI chief officers and AI board members.
CEO, CIO, CISO or AI chief?
PwC’s research reveals a problem in the enterprise sector: whether these AI roles also include general accountability or responsibility for AI-related security and governance.
Overall, 29% of CEOs and security and risk leaders said responsibility sits with the CIO, CTO or a similar technology role. 17% of respondents said that responsibility rests with the CISO or cybersecurity teams, while 26% said it should remain with “a dedicated AI leader or AI function.”
In addition, 11% of respondents said that responsibility is unclear, with responsibility shared across multiple roles or functions.
The research shows that while the enterprise understands that someone must take responsibility for agentic AI and the security issues surrounding its deployment, monitoring and security, the chain of responsibility is not yet defined.
So: Who is responsible for catching rogue AI agents? You are
It wasn’t until 1994 that the first formal CISO, Steve Katz, was hired by Citigroup to handle the aftermath of Russian cyberattacks. Now the idea of a medium to large business without one is almost unthinkable.
CIOs and CISOs generally have enough to handle, so adding new AI-related security management and control could be too much of a burden. If so, we may be on the verge of a new hire for AI-expert CISO counterparts: the CAISO, a chief AI security officer.
Can technology close the gap?
While the enterprise is largely experimenting with defining AI accountability and dividing responsibility across multiple roles, technology can now help enterprises maintain control of their AI agents.
Jim Taylor, Chief Product and Strategy Officer at RSA, told ZDNET that the same identity controls that have secured human users for decades must be used to manage agentic AI.
It’s easy to forget that every AI model, or agentic AI deployment, has an identity. They are associated with a number of credentials; they have different levels of access to resources and information, and can perform tasks or act on behalf of a human employee.
Just as we have passwords, zero-trust principles, multi-factor authentication (MFA), and other access controls that verify our identities, Taylor suggests that every agent AI build should have the “same identity controls that have secured human users for decades.”
That’s not to say that this removes the need for a leadership-level human supervisor, but by strengthening security through agentic AI governance controls, organizations can better prepare for the ongoing risks associated with AI.
Also: AI agent kill switch demanded by Okta-led alliance – how businesses can do it
For example, a centralized platform could register AI agents that are sanctioned to operate in corporate networks, and each agent could be tied to a human owner who must personally authorize high-risk actions. Taylor also suggests that organizations deploying AI should ensure that governance controls drawn on industry frameworks are applied, and that AI agents are frequently evaluated and decommissioned when they are no longer needed.
“Companies will continue to invest in AI, but they’re bringing in workers they can’t see and can’t control,” commented Taylor. “Those agents won’t be held in compliance violations — but the organization will. If they deploy agents, they need the means to keep them safe.”
