Who Should Be Responsible for AI in Our Company?

Why AI accountability belongs to one named executive, why handing it to IT fails and what a workable ownership arrangement looks like at 50, 250 and 1,000 people.

AI ownership is one of the most common unresolved questions we hear from UK boards. Someone approved an AI assistant licence, someone else drafted a policy and nobody can say who answers if a model exposes client data. This page covers who should hold accountability for AI, why handing it to IT tends to fail and what a workable arrangement looks like at 50, 250 and 1,000 people.

Reviewed by Jason Holloway, AI Security practitioner and founder of QL Security.

This page offers general guidance on organisational design and accountability. It is not legal or regulatory advice, and readers should take advice specific to their own regulatory position before acting.

Who should be responsible for AI in our company?

Accountability belongs to one named executive at board level, usually the CEO, COO or CFO, who owns AI risk the way they already own financial or health and safety risk. Day to day operation can be delegated to IT, legal or a cross-functional group. The accountability itself cannot be delegated.

Organisations usually ask which department AI belongs to. AI is not a department’s problem; it is a decision-rights problem. Somebody must be able to refuse a use case, approve a risk the business wants to accept and answer to a regulator, client or insurer afterwards. Departments cannot do that. Named executives can. Write the name down and minute it.

Why does putting IT in charge of AI fail?

IT owns tooling. AI risk is mostly not a tooling problem. The harm arrives through commercial decisions: a marketing claim generated by a model, a hiring shortlist filtered by one, a client deliverable drafted by one, a supplier contract that quietly licenses your data for training.

IT has no mandate over any of that. It cannot refuse a revenue-generating use case the sales director has already promised a client, and it usually learns about Shadow AI months after the business started using it. Nominal accountability without the power to intervene gives the appearance of ownership and none of the control. IT should own inventory, access, logging and technical controls. Somebody senior to IT should own whether the use case happens at all.

What is the difference between accountability and operating AI?

Accountability is the authority to set risk appetite, approve or refuse higher-risk uses and report to the board. Operation is the work: maintaining the use case register, assessing vendors, running training, evidencing controls, chasing owners for updates.

Splitting the two is the arrangement that survives contact with a real business: one accountable executive, one operating owner with a defined time allocation and a short standing forum where the two meet. ISO 42001 as currently published directs obligations at top management rather than at a technical function, so appointing only a technical operator leaves oversight hard to evidence. Our AI Governance work almost always begins by separating these two roles, because they have usually been collapsed into one overloaded person.

Do we need a Chief AI Officer?

Below roughly 1,000 people, usually not. Most organisations that ask this question need a named owner, a one-page policy and a register of where AI is actually in use. A new C-suite title with no budget, no decision rights and no reporting line changes nothing except the org chart.

A dedicated Chief AI Officer earns their salary when AI is in the product, when you are building or fine-tuning models rather than buying them, or when AI use is material enough that a regulator will ask about governance directly. Short of that, appointing one can slow decisions down. Be honest about which situation you are in before you write a job description.

Does AI belong to the board or to management?

Both, with different jobs. The board sets risk appetite, asks for evidence and holds management to it. Management operates within that appetite and reports upward. If the board has never discussed AI, management has no appetite to work within and will invent one by default.

Where the EU AI Act applies to your operations, and in the expectations UK regulators have set out more generally, demonstrable governance is assumed rather than informal comfort, which means a documented decision trail. Put AI on the board agenda quarterly, with a standing item covering new use cases, incidents, supplier changes and risks accepted since the last meeting. Two minuted pages beat an hour with no record. Our answer on what the board should be asking about AI risk sets out the questions that belong in that item.

What does AI ownership look like at different company sizes?

Ownership scales with exposure rather than headcount, but the following bands hold in most mid-market organisations we work with:

  • Under 50 people: the CEO holds accountability directly, one operations or finance lead maintains the register alongside their existing role and a single policy covers acceptable use.
  • Between 50 and 250: accountability sits with a named executive, operation moves to a defined part-time role, commonly in the region of two to four days a month, and a small forum with IT, legal or compliance and one business representative reviews new use cases monthly.
  • Between 250 and 1,000: the operating role becomes substantial enough to justify a fractional or dedicated appointment, with formal sign-off thresholds and an assurance programme behind it. See our AI Security Programmes for how this is usually staged.
  • Above 1,000, or where AI is in the product: a permanent senior appointment with its own budget.

What is a virtual Chief AI Officer, and when does the fractional route make sense?

A virtual Chief AI Officer is a senior practitioner who carries the operating side of AI accountability on a part-time retainer while your named executive retains the accountability itself. Scope varies by organisation, but as an illustration this commonly sits in the region of two to three days a month: chairing the governance forum, maintaining the use case register, running vendor assessments, preparing the board pack and building internal capability to take it over.

The fractional route suits organisations that need experienced judgement more than volume of hours, which is most firms between 100 and 1,000 people in regulated markets. We aim to design these engagements for handover, often inside 12 to 18 months, because a permanent dependency on an external adviser for governance decisions is itself a governance weakness. Our answer on whether a 50-person company needs an AI risk officer covers the smaller end of that range.

Nobody currently owns AI here. What should we do in the next 30 days?

Four steps, in order:

  • Name the accountable executive in writing and minute it at the next board or leadership meeting.
  • Inventory where AI is already in use, including tools staff adopted without approval, because that list is always longer than expected.
  • Publish a one-page acceptable use policy with a named contact for questions.
  • Decide the threshold above which a use case needs sign-off, and who signs.

That sequence takes weeks, not quarters. It removes the worst of the exposure. An AI Security Gap Analysis is the usual next step, because it tells you which of your existing controls already apply and which do not.

How do we know the arrangement is actually working?

Five tests. Ask three people at random who owns AI and see whether you hear the same name. Check whether the use case register has been updated in the last 90 days. Ask whether anything has ever been refused or modified, since an approval process that has never said no is not a process. Check whether AI appears in board minutes. Confirm that procurement routes AI vendors through the same assessment as any other supplier holding your data.

Failing any of these is common and fixable. Failing all five means you have documentation rather than governance.

Accountability without a permanent hire

Our vCAIO service carries the operating side of AI accountability on a defined retainer while your named executive keeps the accountability itself.