Insights
Who owns AI risk in a mid-market company?
In most mid-market companies, no one owns it, and that is the risk. AI touches technology, law, data, people, and commercial decisions at once, so its risk falls into the gaps between the functions that own each of those things. IT assumes legal has it, legal assumes the business has it, the business assumes IT has it, and the exposure sits unowned in the middle until something goes wrong and everyone discovers it was theirs.
This is a governance question before it is a technology one, and it has a workable answer that does not require a new C-suite hire.
The default answer is "no one"
AI risk is unusually good at falling between chairs. A marketing manager pasting client data into a consumer tool is a data-protection issue, a contractual issue, a security issue, and a commercial one, so it belongs to four functions and is actively managed by none. Each assumes another is watching. The result is orphaned risk, surfacing only when a breach, a complaint, or a regulator makes it someone's problem after the fact.
Diffuse ownership feels collaborative and behaves like neglect. Someone has to be accountable, or no one is.
Why it cannot just live in IT
The instinct is to hand AI to the technology team, because AI looks like technology. That is the wrong home for the risk. IT can own the tools, meaning provisioning, access, and security controls, but most AI risk is not a tools problem. Whether an AI-assisted hiring process discriminates, whether a chatbot's advice creates liability, whether staff trust and adopt a new way of working: none of that is within IT's remit or expertise, and asking a technology function to own business, legal, and people risk sets it up to fail quietly.
The risk is cross-functional, so its ownership has to be as well, though that can never mean ownerless.
What ownership actually means
Ownership is one accountable person plus a small forum that spans the functions, with a clear list of what is being owned.
| What needs owning | Sits closest to |
|---|---|
| Acceptable-use policy and the approved-tools list | Risk / operations |
| Data rules and data-protection exposure | Legal / data protection |
| High-risk uses and EU AI Act obligations | Risk / compliance |
| Vendor terms, DPAs, and procurement | Legal / IT |
| AI literacy and adoption | People / operations |
| Incident response when something goes wrong | Risk, with IT |
The accountable owner does not personally do all of that. Their job is to make sure each line has a home, that the homes talk to each other, and that the whole picture is reported upward. The forum is where the functions coordinate; the named owner is who the board holds responsible.
You do not need a Chief AI Officer
For a mid-market company, minting a new executive role is usually overkill and can even make things worse. A Chief AI Officer with no authority over the functions that actually carry the risk becomes a single point of blame without a single point of control. The better move is to assign accountability to an existing member of the executive team, often the COO or a senior risk or operations lead, and give them a standing cross-functional group with real representation from legal, IT, data protection, and the business.
The test of whether ownership is real is simple: if a regulator or your board asked "who is accountable for AI risk here," would one name come back without a pause? If the answer is a list of functions, you have diffusion, not ownership.
Start by naming one person
The first move costs nothing and closes most of the gap: name the accountable owner, give them the list above, and convene the forum. You can refine the governance from there, but until one person owns it, every improvement you make sits on a foundation of "someone should really look at that." Name them, and AI risk finally has an owner.
The owner named, the forum standing, and someone finally accountable when a regulator asks: that is the governance Firestarter sets up in its six-week accelerator, so AI risk has a home before it has a headline.