AI risk: Who Owns It When You Don’t Have a CISO?
CyberKainos. Reading time: 5 mins
Without a CISO, AI risk tends to land in one of three places, none of which really works.
Ask your leadership team a simple question about AI risk: if an AI tool caused a data breach or a compliance failure tomorrow, whose job would it be to have seen it coming? In a lot of organisations, the honest answer is uncomfortable silence, followed by a name nobody actually gave that responsibility to.
This is the accountability gap sitting underneath the AI governance conversation. Everyone agrees AI risk needs managing. Almost nobody without a dedicated security leader can say, with confidence, who is actually managing it, which means boards are increasingly going to be asked that question directly.
The default owner is usually nobody, or everybody
It can land with IT, because AI tools run on IT infrastructure right? But the role of an IT team is to keep systems operational, not for assessing regulatory exposure, data governance, or third-party risk. They are unlikely to be resourced or positioned to be able to do this.
It can also land with AI users, often a genuinely capable operations or marketing lead who has taught themselves about ChatGPT, Claude, Copilot, or an AI-enabled SaaS tool. They may even have spent time creating their own agents and as a result they can ‘speak AI’ fluently. They too however are almost never equipped or able to handle this task.
Or, most commonly, it lands nowhere. Sort of sofa surfing between departments that have started using AI tools to get work done, but with no single person accountable for the aggregate picture. Everyone owns a slice. Nobody owns the whole.
None of these are examples of effective governance. They’re a diffusion of responsibility dressed up as delegation, and it’s precisely the setup regulators and insurers are starting to test for.
Why this gap matters more for AI than it did for general cyber risk
Organisations have muddled through similar gaps in traditional cybersecurity for years, often getting away with it. AI is different for three reasons:
- The speed of adoption is unprecedented and is outpacing governance. Staff are integrating AI tools into daily workflows faster than most organisations can write policies for them, let alone assign clear ownership. By the time a decision-maker notices a tool is in wide use, it’s often already processing sensitive data.
- Regulatory expectations are becoming explicit about board accountability. The UK’s Cyber Governance Code of Practice, published by the NCSC, sets out board-level actions across risk management, strategy, people, incident response, and assurance. It explicitly frames cyber (and by extension AI-driven) risk oversight as a director’s duty of care, not a technical function to be quietly delegated downward. Separately, the ICO’s guidance on AI and automated decision-making puts direct obligations on organisations using AI to process personal data, obligations that assume someone is actually monitoring compliance. Boards are being told, with increasing specificity, that “we didn’t have anyone looking at this” is not an answer a regulator will accept.
- The failure modes are new and harder to spot. A biased hiring algorithm, a hallucinating customer-facing chatbot, or a model quietly trained on data it shouldn’t have touched won’t necessarily trip the alarms your existing IT and compliance processes were built to catch. These require someone who understands both the technology and the governance frameworks well enough to know what to look for, which is exactly the skill set even mid-sized organisations don’t possess in-house.
Cost. Its the reason most organisations operate without a CISO
A full-time CISO in the UK typically commands a salary in a similar range to other C-suite functions, well into six figures once you account for salary, benefits, and the seniority needed to be credible at board level. For a mid-sized organisation without the risk profile of an enterprise, that’s a hard number to justify against other potentially revenue generating priorities or positions. Meanwhile, nearly half of all reported cyber incidents now involve smaller organisations.
So the calculation many boards make, whether consciously or not, is to accept the risk rather than pay for the role. That’s a legitimate business decision if it’s made deliberately, with eyes open. It’s a much riskier one when it’s simply the default, because nobody ever explicitly decided who owns AI risk in the first place.
The false choice, and the pragmatic middle ground
When framed as “hire a full-time CISO or accept the exposure,” most organisations without one will continue to keep choosing exposure, often without recognizing that’s the choice they are making. But that’s a false binary. There’s a pragmatic middle ground between nobody watching anything and a six-figure full-time executive hire that isn’t needed all the time: a virtual CISO or vCISO.
A vCISO gives your organisation a named, accountable, and senior security leader, someone who reports to the board, sets AI governance policy, and answers the “who’s watching this” question without the full-time overhead of an in-house hire. It’s a model that’s growing fast, driven by a combination of expanding regulatory expectations and a persistent shortage of in-house security talent.
A vCISO doesn’t just fill a gap on an org chart. Real ownership of AI risk looks like:
- Being able to point to a named, accountable individual, reporting into the board on a defined cadence, who can be asked “what’s our AI exposure right now” and give a substantive answer.
- Well documented AI governance frameworks covering acceptable use, data handling, vendor assessment, and incident response that’s actually maintained as tools and regulations change, not written once and filed away.
- Independent assessments of AI-driven decisions and tools, particularly where they touch personal data, hiring, credit, or other consequential decisions, so bias and compliance failures get caught before they become incidents or headlines.
The bottom line
Every organisation using AI has AI risk. The only question is whether someone is actually accountable for managing it, or whether that accountability is scattered across departments, informal arrangements, and good intentions. If your organisation can’t currently name the person who owns that answer, that’s not a reason to keep deferring the decision, it’s the reason a vCISO model exists: board-level accountability for AI risk, sized to fit an organization that doesn’t yet need, or want, a full-time executive.
How CyberKainos can help manage AI risk
CyberKainos provides vCISO services for organisations that need real ownership of AI and cyber risk without the cost of a full-time hire. If you can’t currently answer “who owns this,” let’s have that conversation.