Companies Turning to CISOs to Manage AI Risks

by Zachary Barlow

September 9, 2026

While AI adoption is growing among companies, governance of AI risks is lagging behind. This is particularly true of agentic AI, which has the potential to upend entire industries when things go wrong. Part of the problem is ownership of AI. Unlike other tools and departments, AI is used across different departments in drastically different fashions. It is difficult to establish one controlling role or function for AI.  No one position can adequately meet the needs of an entire company while establishing one-size-fits-all guardrails. A recent Deloitte article attempts to tackle this issue. The article calls for Chief Information Security Officers (CISOs) to take a leading role in risk management. The authors argue that the unique and cross-functional nature of the position allows CISOs to manage AI risks more effectively:

“The growing prevalence of the CISO role suggests that organizations already see security and resilience becoming more important. Forty-nine percent of organizations in our survey report having a CISO role in 2026, up from 31% in 2023. Many CISOs are being measured on outcomes that extend beyond cybersecurity, including integration of security into AI initiatives, organizational security culture and workforce awareness, and business value enabled through risk reduction. AI could push that evolution further… The CISO’s role, then, is less about preventing or owning every risk AI might introduce and more about helping ensure that the enterprise can see the risks across functions, contain them, and intervene when necessary.”

The article suggests that CISOs cannot manage every AI risk, but they can manage how risk management frameworks are incorporated into company practice. In the case of modern technology, it is not a question of if a risk will manifest, it is a question of when and how severely. Leveraging the CISO’s skills, a company can develop AI systems with security in mind. These can include automated code checks for vulnerabilities and auditable systems that allow for problems to be detected, isolated, and solved with a quick turnaround. Using CISOs to manage AI risks may place companies in a better position to govern and respond to risks.