As artificial intelligence moves from copilots to autonomous AI agents, many enterprises are delegating more decisions to systems that can access data and act with increasing independence. But the process for establishing accountability for those decisions has not always moved at the same pace. Deloitte research indicates that 80% of automation leaders plan to accelerate investment in AI agents, while only 21% of organizations report having mature agentic AI governance capabilities.1 The result is a widening gap between the frequency of AI deployment and an organization’s readiness to manage the potential risks and outcomes when AI acts.
For chief information security officers and the rest of the tech C-suite, this creates a pressing governance problem. AI risk increasingly cuts across cyber, operations, data, compliance, vendors, finance, and the business itself. No single function can manage all those exposures end-to-end, but shared responsibility shouldn’t mean ambiguous accountability, either.
For the CISO in particular, that tension could reshape the role. As new adversarial risks empower threat actors, organizations will still need the CISO to implement and evolve security capabilities, but the role also now has to work across decisions and domains that the CISO doesn’t own. Those decisions may span both the tech C-suite and the business. How can the CISO help build the controls, relationships, governance, and integrity needed across a shared responsibility model?
Without redefining risk management and oversight for an AI-saturated enterprise, organizations risk scaling AI faster than they can absorb the consequences it could potentially create. CISOs could help move AI governance from broad principles to clear decision rights, named ownership, measurable controls, and continuous oversight, even when the risks themselves sit outside the security function.
AI leadership is already distributed across the tech C-suite. CISOs, chief technology officers, chief information officers, and chief data and analytics officers all bring distinct priorities to AI strategy, delivery, performance, and accountability (figure 1). Add vendors and autonomous AI agents to the mix, and the lines between who makes a decision and who is responsible for its outcomes become less clear.
Responsibility for AI outcomes can’t be owned neatly by one role or function. Decision rights cross business units, technology leaders, and governance councils today, and many leaders expect them to continue doing so over the next two years.2 As business operations and third-party providers become more interconnected, the traditional assumption that a single function can own technology risk end-to-end is increasingly unrealistic.
That makes collaboration across functions even more important. Yet the functions that could help tech leaders navigate risks that fall outside traditional technology boundaries aren’t necessarily the ones they often consider central to achieving their objectives. For example, just 11% of tech leaders in our survey identify legal, compliance, and risk as critical to achieving their objectives today and in two years (figure 2). But excluding these functions from ownership of AI outcomes could leave organizations less prepared to manage new forms of third-party risk, including managing data rights3 and intellectual property.4
Cross-functional ownership also increasingly extends beyond the boundaries of the enterprise. Sixty-three percent of technology leaders surveyed report that their reliance on vendors increased over the past year, while 62% expect that reliance to increase over the next two years. As organizations depend on more AI platforms, models, application programming interfaces, and engineering partners, responsibility for AI outcomes spans both a growing network of external vendors and more internal teams.
This increasingly distributed network of tech providers and users means that the CISO role could become less about owning those risks and more about orchestrating how they are managed, ensuring the right owners and controls are in place across financial, operational, and brand risks. Many CISOs are uniquely positioned to connect these outcomes and communicate them to the board, working in coordination with the business leaders who define corporate risk thresholds, AI outcomes, and return on investment expectations, and the technology leader who determines the tools and solutions needed to achieve them.
The growing prevalence of the CISO role suggests that organizations already see security and resilience becoming more important. Forty-nine percent of organizations in our survey report having a CISO role in 2026, up from 31% in 2023. Many CISOs are being measured on outcomes that extend beyond cybersecurity, including integration of security into AI initiatives, organizational security culture and workforce awareness, and business value enabled through risk reduction. AI could push that evolution further.
As AI agents become more autonomous and always on, users’ identity and access management could become core elements of the control plane for managing risk.5 The model is shifting from simply “who can access what” to “who (or what) can access what, at what time, and on whose behalf.” CISOs could lead their organizations’ effort to create transparency across the entire system, from managing identification and access processes for both AI agents and humans seeking access to tech platforms and solutions, to developing and owning the orchestration and control planes that manage systems of authority, control, and governance.
Monitoring will likely also need to adapt. Organizations need to be able to detect anomalous tool use, privilege escalation, unusual data access, goal deviation, unexpected interactions between connected systems, and changes in AI agent behavior. Controls should generate auditable logs and support rapid intervention when an AI agent crosses a defined risk threshold. Organizations should also establish in advance which actions require human approval, which can be automated, and which events trigger a pause, escalation, or investigation.
Detection and response also need to happen in near real-time, as AI operations—and the threats targeting them—move faster. As one CISO at a major American biopharmaceutical company says in an interview, “Back in the day, if a vulnerability got introduced, you had at least weeks. These days it’s getting down to hours.”
Given the role security needs to play in AI delivery, more emphasis likely needs to be placed on building in security from the start, as the AI solution is being designed and developed. Secure-by-design principles can work to embed real-time risk monitoring, audit trails, and explainability into the product life cycle—a task that could require more strategic collaboration between the product’s chief architect and the organization’s CISO, according to findings from Deloitte’s Global Future of Cyber Study.6
“Compromises of systems and applications and environments will happen,” the CISO at a healthcare company told us in an interview. “If you try to prevent every compromise, it’s going to be very hard to get business done in the company. The goal is you build your program so that if a system’s compromised, you see it as quickly as possible, you immediately contain it, and you eradicate it from the environment before it has a bigger impact on the company.”
The CISO’s role, then, is less about preventing or owning every risk AI might introduce and more about helping ensure that the enterprise can see the risks across functions, contain them, and intervene when necessary.
Organizations’ tech resilience can now depend on enabling security and managing risk at machine speed. But AI makes technology risk simultaneously a cyber, compliance, vendor, and operational responsibility, potentially leaving accountability gaps where those domains stop and start.
Many organizations will likely need to move from function-by-function ownership of AI risk management—cyber owns cyber, compliance owns compliance—to a single cross-domain risk management process tied to business outcomes. CISOs don’t need to own the governance of every possible risk AI could create, but they’re well positioned to connect security controls, monitoring, escalation, and resilience across functions so organizational leaders can see where risk exposure exists, who owns the outcome of an AI-related risk event, and when intervention is required. In an AI-saturated enterprise, the ability to make that model work at speed might become a defining part of the CISO role.
Deloitte’s 2026 Global Technology Leadership Study surveyed 662 senior technology leaders in the Americas (including Latin America); Europe, the Middle East, and Africa; and Asia-Pacific regions to understand how senior technology leadership roles and responsibilities are evolving, as well as the key challenges and strategic priorities shaping 2026 and beyond. Data was collected through an online survey from Dec. 22, 2025, to Feb. 23, 2026.
A majority of the respondents (87%) were C-suite tech leaders. For thematic and role analysis, respondents were grouped into four C-suite personas based on their title, including chief information officers, chief technology officers, chief data and analytics officers, and chief information security officers. Executives represented organizations with annual revenues of US$1 billion or more, including publicly and privately owned companies, as well as not-for-profit and government entities. Primary industries represented include consumer products and services; financial services; technology, media, and telecommunications; energy, resources, and industrials; life sciences and healthcare; and government and public services.