AI news ·
Most CIOs are accountable for AI systems they don't control, IBM survey finds
67% of CIOs and CTOs are accountable for AI systems outside their control, per an IBM survey of 2,000 tech executives. Meanwhile, 77% say AI adoption has already outpaced their governance capabilities.

Two-Thirds of CIOs Held Accountable for AI Systems They Don't Control
A new IBM Institute for Business Value survey of 2,000 technology executives found that 67% of CIOs and CTOs are responsible for AI systems operating outside their direct oversight. The finding exposes a fundamental governance problem as enterprises accelerate AI deployment faster than their leadership structures can manage it.
Seventy percent of respondents said technology is being deployed across the business faster than IT can track it. Seventy-seven percent said AI adoption is already outpacing their governance capabilities. Yet 80% of CIOs reported CEO-driven mandates to accelerate AI transformation efforts.
The accountability gap reflects a structural mismatch. AI capability now sits embedded in SaaS platforms, cloud services, developer tools, and business workflows that operate outside traditional IT governance. Control becomes distributed the moment AI touches multiple platforms, but accountability remains centralized at the top.
The Scale Problem
Organizations expect to deploy an average of 1,661 AI agents by 2027-a 38% increase from today. Only 11% of surveyed executives said they are fully prepared for the scale of AI-agent deployment they anticipate over the next year.
That gap between expectation and readiness is already creating incidents. Surveyed organizations reported an average of 54 AI-agent incidents in the past year that required human intervention or correction. Seventeen percent were classified as high severity.
Among those high-severity incidents, 37% resulted in data exposure or security breaches, 33% caused cascading system failures, and 17% triggered compliance issues.
Shadow AI and Unmanaged Judgment
The problem extends beyond traditional shadow IT. Business teams can now access AI capabilities through embedded SaaS functionality, external tools, APIs, copilots, and agent frameworks with minimal IT involvement.
This creates what analysts call "shadow AI"-unmanaged judgment deployed at the edges of the organization. The risks include unmanaged costs, regulatory exposure, prompt injection attacks, and vulnerabilities at the agent layer.
AI agents that make autonomous decisions and invoke tools introduce dynamic, non-deterministic behavior that breaks traditional governance models. Enterprises lack real-time visibility into how these systems make decisions or what they can access.
Governance Must Become Operational
Fifty-nine percent of respondents identified security and compliance concerns as among the biggest barriers to scaling AI agents. Organizations that embed governance directly into AI systems reported 25% fewer AI-related incidents than those relying primarily on manual oversight.
Governance can no longer function as a periodic review exercise. It must become an operational capability built into how AI systems run.
Enterprises should prioritize centralized observability, policy controls, governed decentralization, and stronger data governance as AI adoption scales. Technology leaders need visibility into what is running, what it can reach, and how to stop it-even when they don't approve every deployment.
CIOs and CTOs navigating this challenge may benefit from structured guidance: AI Learning Path for CIOs and AI Learning Path for CTOs address governance frameworks and operational oversight for enterprise AI deployments.