According to the latest Airmic Big Question poll, which looked at organizational ownership of AI risk, equal numbers of respondents said the CEO or the CISO is the primary owner. This points to some lack of clarity as to whether AI risk is a business or a technology governance area.
The poll responses to the question ‘Who is the primary owner of AI risk in your organization’ were:
- Chief Executive Officer (CEO): 24%
- Chief Information Security Officer (CISO): 24%
- Chief Risk Officer (CRO): 7%
- Board Chair or equivalent: 3%
- Other: 41%
The large number of other responses also points to lack of clarity in this area. Responses in this category included Chief Technology Officer (CTO), Chief Compliance Officer (CCO), and legal counsel.
Airmic is currently responding on behalf of its members to the UK’s Department for Science, Innovation and Technology (DSIT) consultation on a draft Code of Practice on AI cyber security and is proposing that AI risk needs to be seen as a wider business risk rather than just a technology risk.
Commenting on the consultation Julia Graham, CEO of Airmic, said: “For such a Code of Practice on AI cyber security to be most effectively adopted, we have proposed that it should sit within the globally respected UK Corporate Governance Code published by the Financial Reporting Council. This would crucially frame AI cyber security as a business subject, rather than a purely technological subject.”
Hoe-Yeong Loke, Head of Research, Airmic, said: “The government has rightly framed the code with pro-business, pro-innovation aims in mind, so as to strike a good balance with the need for better regulation for AI risks. This means the business as a whole should be considered as the stakeholder, rather than just the IT team, crucial as their role is. Only then can the code get the buy-in of board directors and the C-suite.”






