Corporate leadership divided on responsibility for managing AI risks in enterprise environments
A PwC survey of approximately 4,000 business and tech leaders across 71 countries reveals significant disagreement about who should bear responsibility for AI governance and security within organizations. While roughly half of businesses have brought AI awareness to board level and nine out of 10 report having oversight and accountability practices in place, no clear consensus exists on ownership of agentic AI systems or their security risks. The research suggests that dedicated AI executives or formal governance structures may be necessary to address the growing gap in accountability as AI integration accelerates across enterprises.
The PwC survey identifies a fragmented landscape of governance responsibility across enterprises. While nearly all organizations (90%) have implemented oversight mechanisms and accountability structures, the actual assignment of AI governance duties remains ambiguous. Only one-third of companies have created dedicated AI leadership positions, leaving two-thirds still determining where accountability should reside within existing executive hierarchies.
The research draws a historical parallel to cybersecurity's evolution, noting that formal CISO positions didn't exist until 1994. This timeline suggests organizations may be at a similar inflection point with AI, where rapid technology adoption has outpaced institutional clarity about governance ownership. The absence of consensus on responsibility—with percentages distributed across technology leaders (29%), security teams (17%), and dedicated AI roles (26%)—suggests the enterprise sector lacks established best practices for AI risk management.
This governance gap could have significant consequences for organizational security and public trust in AI deployment. Companies without clear accountability structures may struggle to implement consistent security standards, potentially leaving agentic AI systems vulnerable to misuse or compromise. Conversely, clarifying these roles through new executive positions could increase costs and complexity for businesses. The findings suggest that how enterprises resolve this accountability question in coming years may influence broader AI governance standards, affecting everything from incident response effectiveness to regulatory compliance across industries.