CISOs: The New Guardians of AI Governance
Fragmented responsibility for AI risks pushes chief information security officers to assume a role of trusted authority
July 21, 2026 · 5 min read
TL;DR: AI governance is lagging behind adoption. CISOs emerge as the trusted authority for managing risk, according to Forrester. Lack of visibility and shared responsibility demands a new role for security leaders.
What happened?
Artificial intelligence is being integrated at a breakneck pace into business operations, from customer service to supply chain, software development, and decision-making. However, corporate governance models, designed for centralized environments with clear responsibilities, are failing to keep up. As a result, accountability fragments: no one clearly owns AI risk.
According to a Forrester report cited by TechRadar, CISOs (chief information security officers) will become the business's trusted authority and assurance. This marks a significant shift from their traditional role, which focused on protecting systems and managing cyber threats. Now, they are being pushed to address broader issues of trust, resilience, and executive accountability.
Historically, corporate governance was based on functional silos: security teams managed cyber risks, compliance handled regulatory obligations, and operations executed processes. AI breaks down those boundaries. For example, a single AI model can influence credit decisions, customer service, and logistics, crossing departments and generating risks that cannot be attributed to a single area. This phenomenon is unprecedented in scale and speed of adoption: according to McKinsey data from 2023, 55% of companies already use AI in at least one function, and 40% plan to increase their investment. However, only 25% have a specific AI governance framework, according to a 2024 Gartner study. This gap between adoption and governance is the breeding ground for the CISO's new role.
Why is it important?
AI does not operate in silos. It relies on interconnected data pipelines, third-party models, cloud infrastructure, APIs, and continuously evolving business processes. When visibility into these dependencies is limited, organizations cannot trace the origin of AI-driven decisions, how they propagate, or what impacts they cause downstream. This visibility gap quickly becomes an operational resilience problem.
AI governance is no longer just a policy challenge; it is an operational resilience challenge that can have financial and customer consequences. CISOs, with their expertise in risk management and business continuity, are best positioned to close this gap.
A concrete example: in 2023, a European bank's AI model approved loans with racial bias due to unbalanced training data, resulting in a €5 million fine and a 3% drop in brand reputation measured by Net Promoter Score. The lack of visibility into data sources and the model prevented early detection. Situations like this underscore that AI risk is not just technical but affects customer trust and regulatory compliance. Moreover, regulation is tightening: the EU AI Act, in effect since 2024, requires companies to designate an AI governance officer for high-risk systems. The CISO, with their knowledge of auditing and controls, is a natural candidate for this role, as Forrester points out.
What consequences will it have?
The CISO's transition to AI trusted authority entails an expansion of their responsibilities. They will need to collaborate with other leaders (such as compliance, operations, and business heads) to establish governance frameworks that address AI's unique risks, such as algorithmic bias, lack of transparency, and third-party dependency.
This evolution could also create organizational tensions, as CISOs will need budget, resources, and authority to take on this new role. Companies that fail to adapt risk suffering AI incidents that damage their reputation, incur regulatory fines, or lose customer trust.
At the market level, global spending on AI governance is expected to grow from $1.5 billion in 2024 to $4.5 billion in 2028, according to IDC. This includes model monitoring tools, explainability platforms, and audit services. CISOs who lead this transition will have greater strategic influence but also face increased personal exposure: in the event of a serious incident, they could be held accountable. A precedent is the Uber case in 2017, where the CISO was accused of covering up a cyberattack. With AI, responsibility is amplified, as errors can be systemic and affect millions of users. Insurers are already developing specific policies for AI risks, reflecting the growing materiality of this risk.
What should readers know?
For business leaders, it is crucial to recognize that AI governance cannot be the responsibility of a single department. A multidisciplinary approach is needed, with the CISO as the central axis. Organizations must invest in tools that provide end-to-end visibility into AI systems, as well as training so that security teams understand AI nuances.
For cybersecurity professionals, this is a moment of opportunity. Those who develop skills in AI governance, algorithmic ethics, and third-party risk management will be better prepared to lead in this new era. As Forrester notes, the CISO will become the business's trusted authority, a role that goes beyond technical security to encompass the integrity and resilience of the entire organization.
In practical terms, companies should start by taking an inventory of all AI systems in use, assessing their criticality, and mapping data and model dependencies. Then, establish an AI governance committee that includes the CISO, compliance officer, chief data officer, and operations leader. It is also advisable to adopt frameworks such as the NIST AI Risk Management Framework, published in 2023, which provides guidelines for identifying, assessing, and mitigating AI risks. For CISOs, training in concepts like explainability, bias, and differential privacy will be essential. Initiatives like the SANS Institute's AI for CISOs course or ISACA's AI governance certifications are gaining traction. Finally, investors and shareholders should demand transparency in annual reports on AI risks, similar to how cyber risks are reported. The era of responsible AI is not an option; it is a competitive necessity.