PwC: Organizations agree agentic AI needs governance but can't decide who owns it

A PwC survey of roughly 4,000 executives across 71 countries shows that organizations recognize the need to govern agentic AI risk, yet they cannot agree on who sits in the driver's seat. The Digital Trust Insights 2027 report, published Friday, finds that awareness has reached the boardroom, but the chain of accountability remains broken.
Board awareness, no clear owner
47% of respondents said cybersecurity is a standing item on the board agenda — still far from sufficient. The foundation exists: nine out of ten business leaders said mechanisms such as board oversight, executive accountability and enterprise risk integration are already in place. One-third of organizations (33%) have hired dedicated AI roles, including chief AI officers (CAIO) and dedicated board members, but the scope of their responsibilities remains vague.
CEO, CTO or dedicated AI lead?
The split in answers illustrates the confusion. 29% of CEOs and risk and security leaders pointed to the CIO, CTO or an equivalent technology role. 17% assigned responsibility to the CISO and cyber teams, while 26% argued for a dedicated AI leader or a separate AI function. Another 11% acknowledged that ownership is unclear and split across multiple roles. The bottom line: the organization knows it needs an owner, but the keys are still in no one's hands.
History repeating? From CISO to CAISO
In 1994, Citigroup appointed Steve Katz as the first chief information security officer in history, following Russian cyber attacks. Today, a mid-to-large organization without a CISO is almost unimaginable. CIOs and CISOs are already stretched thin, so loading AI security and governance onto them may be too much. The result could be a hiring wave for the AI equivalent of the CISO: the CAISO, or chief AI security officer.
Digital identity for agents, too
While organizations debate the organizational sandbox, technology is already offering an infrastructure-level answer. "The identity controls that have secured human users for decades should also apply to agentic AI," said Jim Taylor, chief product and strategy officer at RSA. Every agentic model or deployment has an identity: a set of permissions, varying access levels to resources and data, and the ability to perform tasks on behalf of a human employee. Without that identity management, every agent is a potential attack vector with no owner to constrain it.