Skip to main content

As artificial intelligence moves from copilots to autonomous AI agents, many enterprises are delegating more decisions to systems that can access data and act with increasing independence. But the process for establishing accountability for those decisions has not always moved at the same pace. Deloitte research indicates that 80% of automation leaders plan to accelerate investment in AI agents, while only 21% of organizations report having mature agentic AI governance capabilities.1 The result is a widening gap between the frequency of AI deployment and an organization’s readiness to manage the potential risks and outcomes when AI acts.

For chief information security officers and the rest of the tech C-suite, this creates a pressing governance problem. AI risk increasingly cuts across cyber, operations, data, compliance, vendors, finance, and the business itself. No single function can manage all those exposures end-to-end, but shared responsibility shouldn’t mean ambiguous accountability, either.

For the CISO in particular, that tension could reshape the role. As new adversarial risks empower threat actors, organizations will still need the CISO to implement and evolve security capabilities, but the role also now has to work across decisions and domains that the CISO doesn’t own. Those decisions may span both the tech C-suite and the business. How can the CISO help build the controls, relationships, governance, and integrity needed across a shared responsibility model?

Without redefining risk management and oversight for an AI-saturated enterprise, organizations risk scaling AI faster than they can absorb the consequences it could potentially create. CISOs could help move AI governance from broad principles to clear decision rights, named ownership, measurable controls, and continuous oversight, even when the risks themselves sit outside the security function.

When everyone owns AI, who owns the risk and the outcome?​

AI leadership is already distributed across the tech C-suite. CISOs, chief technology officers, chief information officers, and chief data and analytics officers all bring distinct priorities to AI strategy, delivery, performance, and accountability (figure 1). Add vendors and autonomous AI agents to the mix, and the lines between who makes a decision and who is responsible for its outcomes become less clear. 

Responsibility for AI outcomes can’t be owned neatly by one role or function. Decision rights cross business units, technology leaders, and governance councils today, and many leaders expect them to continue doing so over the next two years.2 As business operations and third-party providers become more interconnected, the traditional assumption that a single function can own technology risk end-to-end is increasingly unrealistic.

That makes collaboration across functions even more important. Yet the functions that could help tech leaders navigate risks that fall outside traditional technology boundaries aren’t necessarily the ones they often consider central to achieving their objectives. For example, just 11% of tech leaders in our survey identify legal, compliance, and risk as critical to achieving their objectives today and in two years (figure 2). But excluding these functions from ownership of AI outcomes could leave organizations less prepared to manage new forms of third-party risk, including managing data rights3 and intellectual property.4

Cross-functional ownership also increasingly extends beyond the boundaries of the enterprise. Sixty-three percent of technology leaders surveyed report that their reliance on vendors increased over the past year, while 62% expect that reliance to increase over the next two years. As organizations depend on more AI platforms, models, application programming interfaces, and engineering partners, responsibility for AI outcomes spans both a growing network of external vendors and more internal teams.

This increasingly distributed network of tech providers and users means that the CISO role could become less about owning those risks and more about orchestrating how they are managed, ensuring the right owners and controls are in place across financial, operational, and brand risks. Many CISOs are uniquely positioned to connect these outcomes and communicate them to the board, working in coordination with the business leaders who define corporate risk thresholds, AI outcomes, and return on investment expectations, and the technology leader who determines the tools and solutions needed to achieve them. 

From security gatekeeper to enterprise risk orchestrator

The growing prevalence of the CISO role suggests that organizations already see security and resilience becoming more important. Forty-nine percent of organizations in our survey report having a CISO role in 2026, up from 31% in 2023. Many CISOs are being measured on outcomes that extend beyond cybersecurity, including integration of security into AI initiatives, organizational security culture and workforce awareness, and business value enabled through risk reduction. AI could push that evolution further.

As AI agents become more autonomous and always on, users’ identity and access management could become core elements of the control plane for managing risk.5 The model is shifting from simply “who can access what” to “who (or what) can access what, at what time, and on whose behalf.” CISOs could lead their organizations’ effort to create transparency across the entire system, from managing identification and access processes for both AI agents and humans seeking access to tech platforms and solutions, to developing and owning the orchestration and control planes that manage systems of authority, control, and governance.

Monitoring will likely also need to adapt. Organizations need to be able to detect anomalous tool use, privilege escalation, unusual data access, goal deviation, unexpected interactions between connected systems, and changes in AI agent behavior. Controls should generate auditable logs and support rapid intervention when an AI agent crosses a defined risk threshold. Organizations should also establish in advance which actions require human approval, which can be automated, and which events trigger a pause, escalation, or investigation.

Detection and response also need to happen in near real-time, as AI operations—and the threats targeting them—move faster. As one CISO at a major American biopharmaceutical company says in an interview, “Back in the day, if a vulnerability got introduced, you had at least weeks. These days it’s getting down to hours.”

Given the role security needs to play in AI delivery, more emphasis likely needs to be placed on building in security from the start, as the AI solution is being designed and developed. Secure-by-design principles can work to embed real-time risk monitoring, audit trails, and explainability into the product life cycle—a task that could require more strategic collaboration between the product’s chief architect and the organization’s CISO, according to findings from Deloitte’s Global Future of Cyber Study.6

“Compromises of systems and applications and environments will happen,” the CISO at a healthcare company told us in an interview. “If you try to prevent every compromise, it’s going to be very hard to get business done in the company. The goal is you build your program so that if a system’s compromised, you see it as quickly as possible, you immediately contain it, and you eradicate it from the environment before it has a bigger impact on the company.”

The CISO’s role, then, is less about preventing or owning every risk AI might introduce and more about helping ensure that the enterprise can see the risks across functions, contain them, and intervene when necessary.

How CISOs can make shared ownership work

Agentic AI can turn fragmented accountability into real-time enterprise risk. Decision rights, escalation paths, ownership of autonomous-agent outcomes, and vendor risk all need remapping as AI distributes authority faster than accountability can be managed.

But cross-functional responsibility still requires clear accountability for outcomes. As risk leaders, CISOs can help define organizational risk thresholds, clarify ownership, and establish the right controls with shared responsibility across functions. Multiple functions might have a role in managing an AI use case, but one accountable owner can provide clarity about who is ultimately responsible for the outcome.

CISOs have an opportunity to develop and drive an AI-related risk management model across functions. These four moves can help clarify the CISO’s role in making that model work.

1. Assign clear ownership and decision rights. Each significant AI use case should have a clearly identified business owner, technical owner, and risk oversight owner. A decision-rights map should specify who can approve deployment, who can pause or restrict the system, who should be consulted, and who should be informed. Organizations should also establish in advance which actions require human approval, which actions can be automated, and which events should automatically trigger a pause, escalation, or investigation. The CISO can help define the security controls and escalation requirements around those decisions without becoming the default owner of the business outcome.

2. Bring cross-functional partners into AI decisions earlier. Security, architecture, data, privacy, compliance, procurement, finance, and business stakeholders should participate early in AI vendor and use-case decisions. Early collaboration can reduce downstream redesign, approval delays, and unmanaged implementation risk.

This is particularly important for third-party risk. Shifting tech-vendor pricing models and data-access terms are becoming sources of dependency risk. Vendor contracts can introduce risks related to data rights and intellectual property, while changing pricing models (such as imposing API fees, data-access charges, or token-based pricing) and data access terms can create new dependencies. As Hanan Szwarcbord, chief security officer at Micron Technology, a global provider of memory and storage solutions, says, “One approach can be making the tool selection a collaborative process across the organization, so it’s not just IT imposing one.”7

This convening role often falls naturally to the CISO, who already sits at the intersection of security, compliance, and vendor risk, and is likely well positioned to bring the right functions and vendors into the conversation.

3. Translate risk appetite into operating guardrails. According to a group chief information security officer in a major Japanese financial services group, “In many organizations, no one has really clearly defined what the cyber risk appetite should be, and how you’re going to calculate it, how you’re going to track it, and how you’re going to present it across the board.”8

As AI systems take on more autonomous actions, organizations need to translate risk appetite into concrete operating decisions. The CISO may not own those business decisions, but the function can help make them enforceable through controls, monitoring, and escalation mechanisms.

4. Test whether governance works at the speed of AI. Determine whether AI governance can function as an operating capability. Use scenario planning to test governance resilience. Regularly test high-impact scenarios such as vendor outages, compromised models, prompt-injection attacks, or unauthorized AI agent actions, and track governance effectiveness through measures such as ownership coverage, limiting system access to only what’s necessary, auditability, and incident response times. Think through owners, outcomes, controls, and operating models across different scenarios. This kind of scenario testing draws on capabilities many CISOs already run for security operations and incident response, making the security function a natural home for stress-testing AI governance.

According to the CISO at one healthcare company, “An annual strategy and planning exercise isn’t effective anymore. You have to consistently be revisiting priorities and understanding whether changes in the world around us have caused us to go back and pivot in our strategy.”9

AI governance effectiveness can also be measured through operational metrics. Useful measures could include the percentage of AI agents inventoried and assigned an owner, the percentage of AI agents with access limited to only the systems and data they need, the time required to revoke AI agent access, the percentage of high-impact decisions supported by audit trails, the number of unresolved policy exceptions, and the average time to detect and contain AI-related incidents..

Governing risk at machine speed

Organizations’ tech resilience can now depend on enabling security and managing risk at machine speed. But AI makes technology risk simultaneously a cyber, compliance, vendor, and operational responsibility, potentially leaving accountability gaps where those domains stop and start.

Many organizations will likely need to move from function-by-function ownership of AI risk management—cyber owns cyber, compliance owns compliance—to a single cross-domain risk management process tied to business outcomes. CISOs don’t need to own the governance of every possible risk AI could create, but they’re well positioned to connect security controls, monitoring, escalation, and resilience across functions so organizational leaders can see where risk exposure exists, who owns the outcome of an AI-related risk event, and when intervention is required. In an AI-saturated enterprise, the ability to make that model work at speed might become a defining part of the CISO role.

Methodology

Deloitte’s 2026 Global Technology Leadership Study surveyed 662 senior technology leaders in the Americas (including Latin America); Europe, the Middle East, and Africa; and Asia-Pacific regions to understand how senior technology leadership roles and responsibilities are evolving, as well as the key challenges and strategic priorities shaping 2026 and beyond. Data was collected through an online survey from Dec. 22, 2025, to Feb. 23, 2026.

A majority of the respondents (87%) were C-suite tech leaders. For thematic and role analysis, respondents were grouped into four C-suite personas based on their title, including chief information officers, chief technology officers, chief data and analytics officers, and chief information security officers. Executives represented organizations with annual revenues of US$1 billion or more, including publicly and privately owned companies, as well as not-for-profit and government entities. Primary industries represented include consumer products and services; financial services; technology, media, and telecommunications; energy, resources, and industrials; life sciences and healthcare; and government and public services.

Continue the conversation

Meet the industry leaders

Upen Sachdev

Principal | Cyber Risk | Deloitte & Touche LLP

Lynne Challender

Managing director | Cyber strategy and transformation leader

Anjali Shaikh

Global CIO Program & US Tech Executive Programs Leader | Managing Director, Deloitte Consulting LLP

Steve Pratt

Managing principal, Indianapolis Marketplace, Deloitte LLP | US Tech Executive Programs Leader | Principal, Deloitte Consulting LLP

by

Upen Sachdev

United States

Lynne Challender

United States

Ali Ziaee

United States

Anjali Shaikh

United States

Michael Wilson

United States

ENDNOTES

  1. Jim Rowan, Nitin Mittal, Beena Ammanath, and Costi Perricos, “State of AI in the enterprise: The untapped edge,” Deloitte, January 2026.

  2. Anjali Shaikh and Steve Pratt, “2026 Global Technology Leadership Study,” Deloitte, April 30, 2026.

  3. Michael Wilson, Ram Ravi, Diana Kearns-Manolatos, Whitney Metzger, and David Jarvis, “The pricing paradox of agentic SaaS: What to do about tollgating?Deloitte Insights, June 17, 2026.

  4. Tim Murphy, Diana Kearns-Manolatos, and Aditya Narayan, “How brands are managing intellectual property in the age of AI,” Deloitte and The Wall Street Journal, May 23, 2026.

  5. Deloitte US, “The AI impact on cyber risk: Understanding new threats, defenses, and the CISO’s evolving mandate,” accessed Aug. 26, 2026.

  6. Emily Mossburg et al., “The Global Future of Cyber Survey, 4th edition,” Deloitte Global, Oct. 21, 2024.

  7. Katherine Noyes, “Micron leaders: AI has ‘turbocharged’ collaboration,” Deloitte and The Wall Street Journal, April 1, 2026.

  8. Deloitte interview conducted in December 2025.

  9. Ibid.

ACKNOWLEDGMENTS

The authors would like to thank Monika Mahto and Erika Maguire for their significant contributions to the research and development of this article.

We’d like to thank Steve Pratt, Vikram Kunchala, and Natalie Andrus for their thoughtful review and input based on the impactful work they’re driving in the market.

We extend our appreciation to Ayush Kumar for his support in data analysis, as well as to the marketing team—Jennifer Rood, Saurabh Rijhwani, Akshay Poojari, Jennifer Popovich, and Pratyusha Peddasomayajula—for their support in amplifying the impact of these insights. 

Editorial (including production and copyediting): Corrie Commisso, Elisabeth Sullivan, Shyamili M, Anu Augustine, and Pubali Dey

Design: Molly Piersol and Sonya Vasilieff

Cover image by: Sonya Vasilieff

Knowledge services: Rishitha Bichapogu

COPYRIGHT