Unclear AI risk ownership could leave CISOs in familiar scapegoat role | TechTarget
Published: 09 Oct 2026
AI could be the latest chapter in a story CISOs know well -- in which they are held accountable for incidents they lack the power to prevent.
"Nothing's changed. A CISO's formal job is to set strategy, advise and -- to the best of his or her ability -- prevent the worst from happening," said Johna Till Johnson, analyst at Nemertes Research. "Their actual job is to be fired if something goes wrong, and AI is now one of the biggest 'somethings.'"
New research from consulting firm PwC reveals a lack of consensus on who should own AI governance and AI risk management. Of the organizations surveyed, 17% formally assign responsibility to CISOs; 29% to CIOs, CTOs or the technology function; and another 11% split accountability across multiple functions. One-third have a dedicated AI role, such as a chief AI officer.
"When accountability is...
Copyright of this story solely belongs to www.techtarget.com. To see the full text click HERE