ZDNET’s key takeaways
- PwC reveals enterprise leaders can’t agree on who’s liable for AI.
- AI brokers could lack the identification controls that handle workers right this moment.
- Is a devoted AI govt or chief the reply?
Synthetic intelligence (AI) adoption continues to surge, with agentic AI and huge language fashions (LLMs) now built-in into all the things from enterprise purposes to chatbots that show you how to with meals supply.
Additionally: LLMjacking can run up your small business’ AI invoice quick – methods to cease it
The advantages of AI are clear: it will probably streamline enterprise operations, cut back guide workloads, function a analysis and evaluation assistant, and provides workers instruments that make day-to-day work much less strenuous and time-consuming.
However we’re now experiencing the trade-offs. Rogue AI fashions, pleasant AI hacking harmless firms, probably 1000’s of AI-related safety incidents being investigated, and AI brokers performing as new entry factors into company networks.
Who needs to be accountable and take possession of AI when issues go mistaken? In accordance with new analysis from PwC, companies can’t agree.
Cybersecurity and AI within the boardroom
On Friday, PwC launched its Digital Belief Insights 2027 report, which surveyed roughly 4,000 enterprise and tech leaders throughout 71 international locations.
In accordance with the survey, no single position has a transparent accountability for managing agentic AI or its safety, though consciousness of each the advantages and downsides of AI has reached the board stage in round half of companies.
Additionally: Rogue AI incidents hit ‘tens of 1000’s’: Can companies belief these instruments?
In whole, 47% of these surveyed mentioned cybersecurity is a standing agenda merchandise for boards, which is much from sufficient. Nonetheless, the foundations are there: 9 out of 10 enterprise leaders mentioned practices like board oversight, govt accountability, and enterprise threat integration are actually in place.
On AI, a couple of third of organizations (33%) have acknowledged the necessity for accountability and employed for devoted AI roles, together with AI chief officers and AI board members.
CEO, CIO, CISO, or AI chief?
PwC’s analysis reveals an issue within the enterprise sector: whether or not these AI roles additionally embody general accountability or accountability for AI-related safety and governance.
General, 29% of CEOs and safety and threat leaders mentioned accountability sits with the CIO, CTO, or an identical know-how position. 17% of respondents mentioned the accountability lies with the CISO or cybersecurity groups, whereas 26% mentioned it ought to stick with “a devoted AI chief or AI perform.”
As well as, 11% of respondents mentioned accountability is unclear, with accountability shared throughout a number of roles or features.
The analysis exhibits that whereas the enterprise understands somebody must take accountability for agentic AI and the safety points round its deployment, monitoring, and safety, the chain of accountability hasn’t but been outlined.
Additionally: Who’s liable for catching rogue AI brokers? You’re
It was solely again in 1994 that the primary formal CISO, Steve Katz, was employed by Citigroup to deal with the aftermath of Russian cyberattacks. Now, the concept of a medium-to-large enterprise with out one is nearly inconceivable.
CIOs and CISOs typically have sufficient to deal with, so including new AI-related safety administration and management may very well be an excessive amount of of a burden. In that case, we could also be on the verge of a brand new hiring drive for AI-expert CISO counterparts: the CAISO, a chief AI safety officer.
Can know-how shut the hole?
Whereas the enterprise at giant experiments with defining AI accountability and dividing duties throughout completely different roles, know-how can now help companies in sustaining management of their AI brokers.
Jim Taylor, Chief Product and Technique Officer at RSA, informed ZDNET that the identical identification controls which have secured human customers for many years must be used to handle agentic AI.
It’s straightforward to overlook that every AI mannequin, or agentic AI deployment, has an identification. They’re linked to a set of credentials; they’ve various ranges of entry to assets and data, and might carry out duties or act on behalf of a human worker.
Simply as now we have passwords, zero-trust rules, multi-factor authentication (MFA), and different entry controls that confirm our identities, Taylor suggests every agentic AI construct ought to have the “similar identification controls which have been securing human customers for many years.”
That’s to not say this removes the necessity for a leadership-level human overseer, however by boosting safety via agentic AI governance controls, organizations can higher put together for the continuing dangers related to AI.
Additionally: AI agent kill change urged by Okta-led alliance – how companies might make it work
For instance, a centralized platform might register AI brokers sanctioned to function in company networks, and every agent may very well be tied to a human proprietor who should personally authorize high-risk actions. Taylor additionally means that organizations deploying AI ought to guarantee governance controls mapped to business frameworks are utilized, and that AI brokers be evaluated ceaselessly and decommissioned when they’re not wanted.
“Firms will preserve investing in AI, however they’ve introduced on employees they don’t see and might’t management,” Taylor commented. “These brokers gained’t be held in compliance violations — however the group will. In the event that they do deploy brokers, then they’ll want the means to maintain them safe.”

