Products & Tools

PwC survey: AI accountability scattered, 11% say it's unclear

PwC's Digital Trust Insights 2027 report finds no consensus on AI accountability. 29% point to CIOs, 17% to CISOs, 26% to a new AI chief, while 11% admit ownership is unclear.

By James Calloway5 min read

Updated

Why it matters

  • PwC's Digital Trust Insights 2027 report surveyed approximately 4,000 business and technology leaders across 71 countries, released Friday.
  • 47% of boards now treat cybersecurity as a standing agenda item, while 33% of organizations have hired dedicated AI staff such as chief AI officers.
  • 29% of leaders place AI accountability with the CIO or CTO; 17% with the CISO; 26% with a dedicated AI leader; 11% say ownership is unclear or shared.
  • The first formal CISO, Steve Katz, was hired by Citigroup in 1994 to handle the aftermath of Russian cyberattacks.
  • Jim Taylor, RSA's chief product and strategy officer, said companies have 'brought on workers they don't see and can't control.'

PwC surveyed roughly 4,000 business and technology leaders across 71 countries and found no single executive owns AI risk at most companies. The consultancy's Digital Trust Insights 2027 report, released Friday, places accountability for agentic AI in four different camps — and leaves 11% of organizations conceding the answer is simply unclear.

The findings expose a governance gap just as enterprise adoption of AI agents accelerates. Agentic systems have been integrated into enterprise applications and customer-facing chatbots at a pace that has outstripped most governance functions. When those agents malfunction, leak data, or get hijacked, no one function is uniformly accountable for the fallout.

What did PwC actually ask?

PwC polled approximately 4,000 business and tech executives across 71 countries for its Digital Trust Insights 2027 outlook, published Friday. The survey asked respondents to name the role inside their organization that carries primary accountability for managing agentic AI and its associated security.

The answers fragmented almost immediately. Twenty-nine percent of CEOs, security chiefs, and risk leaders pointed to the CIO, CTO, or another technology executive. Seventeen percent named the CISO or a cybersecurity function. Twenty-six percent said a dedicated AI leader or AI team should hold the role. Eleven percent said accountability was unclear or shared across multiple roles and functions.

The remaining respondents named other executives or structures that the survey did not break out in its top-line data. The plurality still sits with the CIO — but a near-equal share backs a category that barely existed three years ago: the chief AI officer.

Is the boardroom paying attention to AI at all?

Roughly half of organizations have elevated AI to the C-suite. PwC found that 47% of boards now treat cybersecurity as a standing agenda item, up from earlier baselines but still short of universal coverage.

The supporting scaffolding is largely in place. Nine in 10 business leaders said practices such as board oversight, executive accountability, and enterprise risk integration already exist inside their organizations. What those leaders have not done, in most cases, is extend that scaffolding to AI specifically.

Only one-third of organizations — 33% — have acted on AI accountability by hiring dedicated staff. Those hires include chief AI officers and AI board members. The remaining two-thirds either delegate AI to existing technology or security leaders, share the responsibility across functions, or have not formalized the question at all.

Does the enterprise need a chief AI security officer?

The CISO role is itself only 31 years old. Citigroup installed Steve Katz, widely credited as the first formal CISO, in 1994 to handle the aftermath of Russian cyberattacks. A medium-to-large business without a CISO is now almost inconceivable in regulated industries.

CIOs and CISOs already manage sprawling technology estates. Layering agentic AI on top of those portfolios risks overloading teams that were not built for autonomous systems. The PwC data hints at an emerging parallel role: a chief AI security officer, or CAISO, sitting alongside the CISO and owning the AI-specific threat surface.

The market has not standardized on that title. Vendors, consultancies, and corporate boards are still arguing over the label. What the survey does suggest is that enterprises want AI-specific expertise — they just have not agreed on where it sits in the org chart, or how much authority the new role should carry.

Can technology close the gap while executives argue?

Vendors are already selling an interim answer. Jim Taylor, chief product and strategy officer at RSA, told ZDNET that the identity controls used for human employees need to extend to AI agents.

"Companies will keep investing in AI, but they've brought on workers they don't see and can't control," Taylor said. "Those agents won't be held in compliance violations — but the organization will. If they do deploy agents, then they'll need the means to keep them secure."

Taylor framed the problem as one of identity. Every agent carries credentials, holds access permissions, and acts under a human principal. The password, zero-trust, and multi-factor authentication toolkit that governs employees should govern AI deployments too, he argued.

He sketched a concrete operating model that enterprises can deploy today:

  • Register every sanctioned AI agent in a central platform.
  • Tie each agent to a named human owner.
  • Require personal authorization for high-risk actions.
  • Map governance controls to existing industry frameworks.
  • Evaluate agents frequently and decommission them when obsolete.

Taylor was careful not to suggest technology replaces leadership. Identity controls reduce risk, but they do not appoint a chief. Organizations still need a human owner, he said, because liability for AI failures flows uphill to the enterprise, not down to the agent.

Why is this question coming up now?

Three forces are pushing AI accountability up the agenda. First, agentic AI has been integrated into enterprise workflows faster than most governance functions have absorbed. Second, security teams are tracking thousands of AI-related incidents, including rogue models and "friendly" AI systems manipulated into attacking their own employers. Third, AI agents now act as new entry points into corporate networks, expanding the attack surface beyond human users.

Each incident surfaces the same unanswered question: who inside the organization owns accountability when an AI agent fails?

What does the PwC report actually change?

The report does not impose rules. It documents a vacuum. Three structural choices now face every enterprise that runs agentic AI:

  • Hand accountability to the CIO or CTO.
  • Extend the CISO's remit to cover AI.
  • Create a dedicated AI executive function.

Each option carries trade-offs. CIOs and CISOs already manage full plates and lack AI-specific training. A new AI chief must compete for budget, headcount, and authority against established executives. Splitting responsibility across multiple functions invites finger-pointing when an agent misbehaves.

So what?

Agentic AI has arrived before governance caught up. PwC's data shows most enterprises know the problem exists and most have not assigned an owner. The companies that move first — whether by promoting a CIO, expanding a CISO, or creating a chief AI officer — will set the template that boards, insurers, and competitors reference for the rest of the decade. Everyone else will be answering the same question PwC just asked: who, exactly, owns the risk?

Original: pwc.com

Share this article:

More from James Calloway

James Calloway

Show full bio

News editor covering industry trends and analytics at AI In Context.

223 articles

Related articles

  1. Okta-Led Blueprint Alliance Wants a Kill Switch for Every AI Agent
  2. Trillium Labs Launches to Do High-Stakes AI Research in the Open
  3. FTC Opens Industry-Wide Probe Into Anthropic, OpenAI Over AI Agent Risks
  4. OpenAI Launches Initiative for Democratic AI Oversight in National Security
  5. RSA Launches Agent ID to Tame Shadow AI Agents

« Previous article