• INSIGHTS – AI GOVERNANCE
Who Actually Owns AI Risk in Your Organisation?
By Suchetana Bauri • 18 min read · 15 September 2026
THE CHALLENGE
The steering committee does not own AI risk. It owns the meeting where people discuss AI risk.
THE OPPORTUNITY
Accountability is not a committee. Map these decision rights before you deploy a system, not after it breaks.
The steering committee does not own AI risk. It owns the meeting where people discuss AI risk. That may sound pedantic, but it explains why so many organisations have governance theatre instead of governance. A cross-functional group meets monthly. It reviews a tidy deck: models deployed, vendors assessed, policies drafted, staff trained. Everyone agrees that “AI risk” matters. Then someone asks the question that turns the room suddenly vague: who is actually accountable if this goes wrong?
The legal team looks to technology. Technology looks to the data team. The data team points to the vendor. Procurement points to the signed contract. The business lead points to the approval. HR says the recruitment team switched on the tool without telling them. Meanwhile, the person whose job, loan application, health care or performance review the system shaped does not care about your organisational chart. They want an answer. And this year, that question has got harder, not easier.
Why accountability got harder
Two things have changed since we published the vendor risk checklist. First, the EU shifted the regulatory baseline that many governance plans relied on: the Digital Omnibus, which took effect in July 2026, moved the AI Act’s toughest requirements for stand-alone high-risk systems — including recruitment and credit-scoring tools — from August 2026 to 2 December 2027. Second, and more consequentially for day-to-day risk, AI stopped being mostly a chat window and started being an agent: something that can log into systems, move money, send emails and take actions without a human clicking “approve” each time. A 2026 survey found 47% of organisations have now adopted agentic AI, up from near-zero two years earlier – and 76% of those leaders admit governance has not kept pace.
That gap is where accountability quietly disappears. This piece maps who should own each part of AI risk, and why “the steering committee” is never a satisfying answer to the question above.
That is not a reason to relax. It is a reason to stop waiting for the law to define your accountability structure for you. Any sensibly run organisation should already assess risks, provide meaningful human oversight, monitor systems and document decisions — whether or not a legal deadline requires it. Regulation was always going to lag the technology; 2026 simply made that lag explicit.
Meanwhile the more urgent shift is operational. Analysts at Info-Tech Research Group, in a report drawing on 2026 industry data, identified “ambiguous ownership” as one of five recurring gaps in how organisations govern AI agents – alongside shadow AI built outside sanctioned tools, unmanaged permissions, and “runtime drift”, where an agent’s scope quietly expands after deployment without anyone re-approving it. Separately, national cyber-security agencies from six countries – including the US, UK, Australia and Canada – jointly warned in May 2026 that “accountability risk” is now one of five core categories of agentic AI risk, because agent decisions are often impossible to trace back to a specific person, system or authorisation.
01 –
What actually changed this year
Get the regulatory picture right. Many governance plans relied on a deadline that no longer applies.
The EU AI Act’s rules for general-purpose AI, along with new enforcement powers, took effect on 2 August 2026. The EU AI Office can now investigate and fine model providers. Transparency rules for chatbots and synthetic media are also live.
But the rules that matter most to many employers have moved. The Digital Omnibus delayed the AI Act’s Annex III requirements for high-risk systems, including recruitment, credit-scoring and education tools, until 2 December 2027. It pushed requirements for high-risk AI embedded in products to August 2028.
That is not a reason to relax. It is a reason to stop waiting for the law to define your accountability structure for you. Regulators deferred these obligations — risk assessment, human oversight, monitoring, documentation — but any sensibly-run organisation should already practise them, deadline or no deadline.
Agents changed the risk
Meanwhile, a more urgent shift is happening operationally. Analysts at Info-Tech Research Group, drawing on 2026 industry data, identified ‘ambiguous ownership’ as one of five recurring gaps in how organisations govern AI agents — alongside shadow AI that employees build outside sanctioned tools, permissions nobody manages, and ‘runtime drift’, where an agent’s scope quietly expands after deployment because nobody re-approves it.
Separately, national cyber-security agencies from six countries — including the US, UK, Australia and Canada — jointly warned in May 2026 that “accountability risk” is now one of five core categories of agentic AI risk, because agent decisions are often impossible to trace back to a specific person, system or authorisation.
In other words: the accountability question this piece started with has become sharper, not softer, in the past twelve months.
The uncomfortable truth is this: a committee, a policy document or a chief AI officer acting as an organisational lightning rod cannot own AI risk. The people who make choices own it in pieces — the people who buy a tool, feed it data, put it into a workflow, trust its output, override it or fail to notice when it changes.
02 –
The ownership illusion
“Who has the authority, information and duty to make each risk-bearing decision — and who is answerable when that decision proves wrong?”
– Suchetana Bauri
People have turned ‘AI risk’ into a catch-all phrase, which is partly why they pass it around so easily. It can mean a cybersecurity breach, personal-data misuse, discrimination, fabricated information, intellectual-property exposure, a bad automated decision, employee surveillance, reputational harm, regulatory non-compliance, an agent taking an irreversible action, or a simple but expensive failure to deliver the promised value. No single function can credibly own all of that. Nor should it.
The more useful question is not, “Who owns AI risk?” It is: Who has the authority, information and duty to make each risk-bearing decision — and who is answerable when that decision proves wrong? That is a different kind of governance. It replaces a foggy collective responsibility with specific decision rights.
Accountability needs authority
The US National Institute of Standards and Technology’s AI Risk Management Framework makes this principle unusually explicit, and it remains the most widely used reference point even as NIST works through a mandated revision in 2026. Its Govern function calls for accountability structures that empower, train and hold appropriate teams and individuals responsible for mapping, measuring and managing AI risk. Linger over one word: empowered.
Equally, authority without accountability creates the familiar AI free-for-all: a product or operations team deploys a tool quickly, treats the risk review as a hurdle to clear, and assumes that legal, security or compliance will catch anything serious. By the time the issue reaches a committee, staff may have already embedded the system in a workflow, making it politically difficult to remove — and, increasingly, the system may already be an agent connected to live systems. The committee has not failed because it lacks expertise. It has failed because it sits too far from the decisions that matter.
03 –
A committee is not an operating model
A useful question for leaders: For every significant AI use case, can you name who owns the decision to deploy it, who owns the data flowing through it, and who has the authority to stop it?
Explore my work on AI governance and accountability mapping →
Most steering committees are useful. They can set direction, establish risk appetite, resolve disputes between functions, approve major exceptions and make sure AI is discussed at senior level. The problem comes when an organisation mistakes oversight for ownership. A committee should not be the place where accountability goes to disappear.
Think of a high-impact AI system as a chain of decisions rather than a piece of software. One person defines the business problem; another selects or builds the tool. A data owner approves the information it can use, while technical teams configure permissions and integrations. The business owner decides how much weight people should give the output — or how much autonomy an agent can exercise without approval. Trainers prepare staff, and operational teams monitor what happens after launch. Every link is a risk decision. Every link needs a named owner.
This is particularly important with generative AI and AI agents. Their apparent fluency and usefulness can obscure their actual role in the business. Gartner analysts have warned that as agents proliferate faster than IT teams can track them, organisations face an “ungoverned sprawl” exposing them to misinformation, oversharing and data loss. Separate research suggests that around 15% of employees are already running unauthorised “shadow agents” that operate entirely outside official governance.
04 –
The accountability map
“Give each role a concrete object of accountability, not a vague obligation to ‘support responsible AI’. AI needs a map of accountability by decision — not a RACI chart with a new label.”
There is no universal AI governance chart. A hospital, a bank, a council and a consumer brand should not pretend to have identical risks. But most organisations need the same core set of roles, even if one person holds more than one role in a smaller business. The crucial rule is this: give each role a concrete object of accountability, not a vague obligation to “support responsible AI”.
“The ‘agent owner’ row is genuinely new territory. Each agent should be treated like an employee, with its own identity, credentials, and job description defining explicit goals and limits.”
This is not a RACI chart with a new label. RACI is often too blunt for AI because it lets organisations assign one “accountable” person to a complex socio-technical system and call the job done. AI needs a map of accountability by decision. The UK Information Commissioner’s Office makes a related point: organisations remain responsible for compliance and for demonstrating it where AI processes personal data. Accountability is not satisfied by having a privacy review somewhere in the project archive. It has to be built into how work is organised.
05 –
Ownership follows the decision
Here is the practical test. For every significant AI use case, take a blank page and write down six decisions: the decision to use AI at all, the decision to use particular data, the decision to trust an output or let an agent act, the decision to release or change the system, the decision to accept residual risk, and the decision to stop. Each belongs to a specific person with authority, not to a committee.
The six ownership decisions
Who owns each part of the AI risk chain
A practical framework for mapping accountability across every significant AI use case.
Use AI at all
Business owner and executive sponsor decide.
Use particular data
Data owner with authority to say no.
Trust output or let agent act
Competence, time and authority required.
Release, change or connect
Technical owner; treat changes as changes.
Accept residual risk
Executive sign-off, traceable and conscious.
06 –
The vendor is not your accountability sink
The vendor risk checklist matters because suppliers can introduce serious risks: opaque training data, weak security, unclear data retention, untested claims, poor incident support, vendor lock-in, unreliable performance and contracts that shift too much liability back to the customer. But vendor due diligence often becomes a way of avoiding the harder internal work. A vendor cannot tell you whether AI should influence a dismissal, a benefit decision or a customer complaint.
A single application can involve a foundation-model provider, a cloud host, an implementation partner, a data provider, third-party tools an agent calls at runtime, and internal teams adding their own prompts, data and integrations. Bain’s 2026 analysis puts it bluntly: “the unit of risk is the whole system, much of which sits outside the organization’s walls.” The supplier is often a supply chain, and increasingly a runtime one.
The answer is not to create a 40-page AI policy that nobody reads. The answer is to make the right decision easy to find, easy to record and hard to bypass. Create a live AI and agent inventory. Set risk tiers that change the route. Use decision records. Make escalation normal. Test the ownership model with a scenario. Every hesitation in that exercise is a governance gap.
AI governance is not the work of finding one owner for a sprawling new category of risk. It is the work of refusing to let important decisions become ownerless. The organisation that gets this right will have named people, clear authority, evidence of what was decided and the institutional confidence to stop when stopping is the responsible choice. If this system causes harm tomorrow, whose phone rings first — and do they have the authority to act? If the answer is “the steering committee”, you do not yet have accountability. You have a calendar invitation.
References
- Digital Applied, “EU AI Act Enforcement Begins: Penalties and Powers” (August 2026). Explains what activated on 2 August 2026 versus what the Digital Omnibus deferred.
- Software Improvement Group, “A comprehensive EU AI Act Summary” (August 2026 update). Confirms Regulation (EU) 2026/1744 entered into force on 27 July 2026.
- itbrief, “Everyone read ‘EU Delays AI Act’ wrong, here’s the actual timeline” (August 2026).
- National Institute of Standards and Technology, “AI Risk Management Framework”. Core four functions remain intact through the current mandated revision.
- Underdefense, “AI Risk Management 2026: Shadow AI, Agentic Risks & NIST Guidance” (May 2026).
- Information Commissioner’s Office, “Governance and accountability in AI”. Recommends designated responsibility, defined roles and documented responsibilities.
- SAP News, “AI Agent Sprawl: Why AI Governance Is Now a Board-Level Issue” (August 2026). Documents Gartner’s warning on ungoverned agent sprawl.
- HCAMag, “AI agents need governance built for workforce that never sleeps” (September 2026). Reports 47% agentic-AI adoption and 76% governance gap.
- Cloud Security Alliance, “Institutionalizing AI Safety: CISA’s Agentic Guide and CAISI Evaluations” (May 2026). Six-nation guidance on agentic AI risk.
- Bain & Company, “Agentic AI Governance, Risk, and Controls for Business Leaders” (July 2026). Frames agent risk as a whole-system supply-chain problem.
- Strata Identity, “Agentic AI Risks: A 2026 Guide” (April 2026). Explains runtime governance, privilege drift and the 15% shadow-agent usage figure.
READY TO MAP AI ACCOUNTABILITY IN YOUR ORGANISATION?
Let’s map it.
I help leadership, communications and learning teams turn AI ambition into practical understanding, useful stories and confident adoption.
