Scott Gallant โ€บ Insights

AI risk ownership means nothing without the power to say no

PwC found only 17% of organizations formally assign AI risk to the CISO, while a third have created a dedicated AI role. I'd set the org chart aside and ask one question. Who can stop a deployment? Stanislav Kazanov at Innowise puts it well: if the CISO can't block an agent that failed its security review, they don't own that risk, whatever the chart says. I've sat on governance committees where accountability was neatly documented and nobody held a veto. They generated plenty of minutes and very little control. Before arguing about which executive owns AI, find out whether anyone in your company can say no, and whether they ever have.

Source: Unclear AI risk ownership could leave CISOs in familiar scapegoat role - TechTarget (TechTarget)

All insights ยท Talk with Scott