The real test of AI risk ownership is who can say no
PwC's numbers show nobody agrees who owns AI risk, with 17% of organizations handing it to the CISO and a third creating a dedicated AI role. I'd skip the org chart debate and apply Stanislav Kazanov's test instead. If you can't stop an agent from deploying after its security review fails, you don't own that risk. I've sat on governance committees where accountability was assigned in a slide and decision rights were never written down anywhere. Those are the committees that end up holding a post-mortem to find out who was supposed to say no. So ask your CISO a simple question this week. What can you actually block?
Source: Unclear AI risk ownership could leave CISOs in familiar scapegoat role - TechTarget (TechTarget)