{
  "id": 11157698,
  "title": "Who owns AI risk at work? Business and tech leaders can’t agree, PwC survey finds",
  "url": "https://urgent.news/2026/10/01/who-owns-ai-risk-at-work-business-and-tech-leaders-cant-agree-pwc",
  "topic": "ai",
  "section": "AI",
  "published": "2026-10-01T09:00:00.000Z",
  "source": {
    "name": "ZDNet",
    "slug": "zdnet",
    "url": "https://www.zdnet.com/innovation/pwc-digital-trust-insights-2027-ai-risk-responsibility/"
  },
  "original_language": "en",
  "account": "As AI adoption expands in the business world, integrating agentic AI and large language models (LLMs) into various applications and processes, the responsibility for managing AI-related risks remains a contentious issue. A new PwC survey of 4,000 business and tech leaders across 71 countries reveals that no single role is clearly responsible for overseeing agentic AI and its security. While awareness of AI's benefits and drawbacks has reached the board level in around half of the businesses surveyed, only 47% of those polled consider cybersecurity a standing agenda item for boards, which falls short of being sufficient.\n\nThe study shows that nine out of ten business leaders have implemented practices like board oversight, executive accountability, and enterprise risk integration, but the question remains whether these AI roles also include overall accountability or responsibility for AI-related security and governance. Of the respondents, 29% of CEOs and security and risk leaders believe accountability lies with the CIO, CTO, or a similar technology role, while 17% said it should fall to the CISO or cybersecurity teams. A significant 26% of respondents argue that accountability should rest with a dedicated AI leader or AI function, while 11% think responsibility is currently unclear, with responsibility shared across multiple roles or functions.\n\nTo address this issue, Jim Taylor, Chief Product and Strategy Officer at RSA, suggests that the same identity controls used to secure human users for decades should be implemented for agentic AI. Each AI model or deployment has an identity, linked to a set of credentials and varying levels of access to resources and information. This approach would involve creating a centralized platform that registers AI agents authorized to operate in corporate networks, tying each agent to a human owner who must personally authorize high-risk actions. Additionally, organizations should ensure governance controls mapped to industry frameworks are applied, and AI agents be frequently evaluated and decommissioned when no longer needed. Taylor emphasizes that while AI adoption continues, organizations bring on workers they don't see or control, and if they deploy agents, they'll need the means to keep them secure.",
  "summary": "PwC research highlights a growing need for someone to own AI. Is an AI chief the answer?",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}