The Enterprise Accountability Gap: Who Should Own AI Governance?
Published: Aug 20, 2026
Most enterprises have a sense of who owns AI risk, yet few know what happens when that risk turns into an incident.
That's the pattern unearthed inside Schellman's new research, The 2026 State of AI Governance Report. In most cases, organizations can easily name an owner for AI decisions, but they're struggling with how narrow that ownership actually is and what happens when the person who approved an AI purchase is also the person left holding the liability when something goes wrong.
Who Owns AI Purchasing Decisions in the Enterprise?
When it comes to AI purchasing and adoption decisions, 42% of surveyed organizations place that authority with a single role: the CIO or head of IT. The Chief Data Officer or AI Officer picks up another 16%, and the CEO accounts for 10%.
On paper, that looks like clarity, but in practice, that type of ownership model is overly simplified, and may not demonstrate sufficient governance for owning and managing AI risk. In most of these organizations, the same executive who decides whether to bring in a new AI tool is also the person held accountable if that tool creates a compliance failure, security gap, or bad customer outcome. That's a single point of failure, not a governance structure.
The problem is that risk assessment gets harder to trust when the person doing the assessing has an incentive to see their own decision as low-risk. Escalation is ineffective or doesn’t exist altogether because there's no second function positioned to challenge the call. And when something does go wrong, the organization's response tends to stop at correcting the immediate issue rather than examining why the governance structure allowed it to happen in the first place.
What Is Distributed Accountability in AI Governance?
For most other high-stakes enterprise decisions around financial controls, data privacy, and physical security, accountability doesn't sit with one executive. It's spread across IT, security, compliance, and legal, each owning the piece closest to their function. AI governance remains one of the few categories of enterprise risk where a single leader is still expected to own the governance processes, AI approval decision, and the consequences.
Why Aren't Boards Discussing Third-Party AI Risk?
Accountability concentration at the executive level would be less consequential if boards were providing a meaningful additional check. Only 54% of organizations report AI governance to their board or equivalent leadership body on a regular basis. And even where that reporting happens, it tends to stay at the level of broad trends rather than the specific gaps that actually create exposure.
That gap becomes most visible around third-party AI. Just one in three organizations name vendor or third-party AI risk as a top concern, even though it may be the least visible risk they carry. Only 69% say they're confident in their ability to govern AI embedded in tools they didn't build. And only 36% of boards discuss third-party AI risk regularly, despite the fact that nearly every SaaS tool an enterprise runs (e.g., CRM, analytics, collaboration software, scheduling, ATS, etc.) now deploys with AI embedded somewhere inside. Organizations remain liable for AI functionality within procured tools and systems.
Vendors rarely disclose what AI is embedded in their tools or how it handles data, so boards end up deprioritizing a risk they can't easily see. But invisibility doesn't transfer liability. If AI embedded in a vendor's platform causes a data breach or a discriminatory outcome, the enterprise using that tool is still the one accountable for it, regardless of whether anyone on the board ever asked about it.
What Does a Mature AI Accountability Model Look Like?
The organizations getting this right are the ones making sure executive ownership doesn't operate in isolation. A single leader, whether that's a CIO, Chief AI Officer, or equivalent role, still holds ultimate accountability for AI governance. What changes is who feeds into that decision. IT, product, engineering, security, compliance, legal, procurement, and the business units actually using the tools each contribute the risk expertise closest to their function, so the executive at the top is making an informed call based on governance functions and codified controls, rather than an isolated one.
Accountability stays concentrated where it belongs. What gets fixed is the blind spot that comes from one person evaluating risk without the functions best positioned to catch what they'd miss.
This shift requires enabling a designated governance owner with informed inputs from a cross functional AI governance team, policies specific enough to be enforced rather than just referenced, and regular reassessment as AI use expands. A one-time policy filed away after the initial rollout won't hold up as AI use grows.
According to our research, accountability concentration is one of the clearest structural gaps separating organizations that can prove their governance from those only assuming it works.
The full report breaks down what a distributed accountability model looks like in practice, including five steps to follow to build out that model and the specific questions boards should be asking about third-party AI risk before their next meeting.
Download the full 2026 State of AI Governance Research Report Here
About Joe Sigman
Joe Sigman is a Manager with Schellman based in Denver, Colorado. Prior to joining Schellman in 2021, Joe worked as a Senior Associate at a management consulting firm specializing in IT strategy and compliance, solution architecture, and enterprise digital transformation. Joe has led and supported AI Assessments, Cybersecurity Assessments, Information Security Architecture Solutioning, Information Technology Gap Analysis, and Cloud Migration Roadmaps. Joe has over 6 years of experience comprised of serving clients in various industries, including Information Technology, Professional Services, Healthcare, and Energy. Joe is now focused primarily on ISO Certifications for organizations across various industries.