Businesses lack a clear, consistent framework for who controls artificial intelligence decisions and spending, yet 94% of U.S. chief information officers say their teams will shoulder responsibility for security incidents or regulatory violations caused by AI systems rolled out by other departments, according to a Thoughtworks survey released Wednesday. The tech consultancy polled 3,200 CIOs worldwide in July. The findings reveal a striking disconnect: while authority over AI is fragmented across organizations, accountability lands squarely on technology leaders when things go wrong.

After the chief executive, centralized IT departments, executive teams, and workers in specialized AI positions wield the greatest sway over AI choices and budgets, the report shows. Nearly all technology chiefs claim complete or substantial awareness of the AI systems operating throughout their companies' various divisions. But that visibility doesn't guarantee control over outcomes, the research found. More than half of CIOs plan to place technology leaders directly inside business units, while just under half intend to broaden the CIO role to encompass companywide AI strategy and execution. Despite most CIOs describing their firms as well equipped to govern AI, 88% acknowledged that deployment is outpacing the establishment of oversight frameworks.

The survey findings arrive amid widespread anxiety among technology executives about AI's career implications. Earlier this year, AI platform Writer discovered that 61% of tech leaders worried about job loss if they couldn't successfully guide their organizations through an AI transformation. Organizations should assign security, privacy and compliance responsibilities to appropriate control owners throughout the company, according to the Thoughtworks research. Thomas Squeo, chief technology officer of Thoughtworks Americas, told CIO Dive that companies need to examine their AI ownership structures to confirm that decision-makers possess both the authority and the information required. "Changes to roles and workflows involve people, business and technology leaders together," Squeo said.

But no single ideal ownership model fits every company, Squeo noted. He recommended that CIOs make AI adoption scalable across the enterprise by building a shared technology environment with standardized architecture and controls, eliminating the need to sign off on every individual AI application. "I see the CIO as the person connecting local adoption to enterprise scale," Squeo said. "Making sure what works in one part of the business can grow without losing the architecture and controls that made it reliable." The report suggests finance departments should gain visibility into consumption and value, while business units make localized choices within established boundaries. Organizations that fail to align decision rights with accountability risk creating a persistent gap between who experiments with AI and who answers for its consequences. The distributed nature of AI ownership means companies must rethink traditional governance structures before operational failures force their hand.