Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

There is no clear winner in the reported debate over who should own agentic AI security at work. Secondary coverage of PwC’s Digital Trust Insights 2027 says respondents most often named technology leaders or a dedicated AI function—but the underlying PwC report and its methodology were not available to verify those figures independently. The percentages concern security accountability for agentic AI, not every kind of AI risk.

What the reported survey figures say

Secondary coverage attributes these answers to roughly 4,000 business and technology leaders in 71 countries, in PwC’s Digital Trust Insights 2027. The primary report was not available to confirm the exact question, field dates, respondent breakdown or figures.

Role or response Share reported
CIO, CTO or similar technology role 29%
Dedicated AI leader or AI function 26%
CISO or cybersecurity team 17%
Responsibility unclear 11%

The largest reported group was technology leadership, but it accounted for less than one-third of respondents. The figures suggest dispersed accountability, not consensus that one executive should own all AI risk. They specifically concern accountability when agentic AI security goes wrong; they should not be treated as results about privacy, legal compliance, employment decisions, safety or model performance.

Because the exact figures come from secondary coverage rather than a verified primary report, they are best read as a reported snapshot, not a definitive measurement of how organizations assign AI risk today.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why different teams claim—or need—a role

AI systems cross organizational boundaries. The team deploying a system can see operational context and control changes; security specialists can challenge threats and monitor incidents; a dedicated AI function can coordinate standards across projects. Each has a different kind of leverage, so assigning all responsibility to one group can leave gaps.

  • Technology leadership: often has authority over infrastructure, deployment and technical operations.
  • AI leaders or functions: can coordinate practices across AI projects and connect technical work with business priorities.
  • Security leadership: can assess threats, challenge risky decisions and help manage security incidents.

These are practical distinctions, not a universal organizational chart prescribed by PwC. An owner also needs clear authority to make decisions or escalate them; a job title alone does not establish who can accept risk or stop a deployment.

PwC’s governance model separates execution, oversight and assurance

PwC describes a three-lines approach to Responsible AI governance: the first line builds and operates systems responsibly; the second line reviews and governs; and the third line provides assurance and audit. That model allows several teams to contribute while making their respective duties explicit. PwC says, “Clear roles and tight hand-offs are now essential to scale safely and confidently as AI adoption accelerates.”

  • First line — build and operate: teams developing or using AI follow approved practices and manage risks in day-to-day work.
  • Second line — review and govern: governance functions set or interpret requirements, review decisions and challenge the first line where needed.
  • Third line — assure and audit: assurance functions independently check whether controls and governance are working.

For this division to work, the hand-offs matter: teams need to know who approves a use, who can raise or accept an exception, who monitors it in operation, and who checks the controls independently. PwC’s model describes a distribution of work; it does not identify one role as the universal owner of every AI risk.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What separate PwC surveys add—and what they do not

Other PwC figures provide context, but they come from different surveys and should not be combined with the reported global agentic-security results.

Finding Survey and scope How to interpret it
51% of companies had a formalized approach to AI risk PwC’s 29th Global CEO Survey, reported in 2026 A separate measure of formalization, not evidence that a particular executive owns risk.
56% said first-line IT, engineering, data and AI teams lead Responsible AI efforts PwC’s 2025 US Responsible AI Survey; 310 US business leaders surveyed September 26–October 2, 2025 A US survey about Responsible AI leadership, not the global question about agentic AI security.
58% reported improved ROI and organizational efficiency; 55% reported enhanced customer experience and innovation PwC’s 2025 US Responsible AI Survey Respondents’ reported benefits, not causal estimates showing that governance produced those outcomes.

PwC argues that formal risk processes can give companies confidence to apply AI in more functions and processes. That is the firm’s interpretation, not proof that governance alone causes broader adoption.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to make accountability workable

Rather than assigning a vague label such as “AI owner,” organizations can map responsibility to decisions and operational hand-offs. A practical allocation should identify, for each AI use, who builds and operates it, who reviews it, who can approve or escalate risk, and who independently checks controls.

  • Name a responsible decision-maker for each use case and define what they can approve, reject or escalate.
  • Give builders and operators explicit responsibility for following controls and reporting issues.
  • Assign a review function with enough independence to challenge business and technical decisions.
  • Specify who monitors incidents and who provides independent assurance or audit.
  • Document hand-offs so a change, exception or incident reaches the right decision-maker instead of falling between teams.

This approach reflects PwC’s three-lines framing without assuming that every organization needs the same reporting structure. It also distinguishes shared participation from ambiguous accountability: several teams can have duties, while decision rights and escalation paths remain clear.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.