No one voted to put AI governance on the CISO's desk. It landed there anyway, the same way every ungoverned risk category in a large organization eventually lands on whoever already has an incident response process, a budget line, and the political standing to say no to a business unit. That is not a compliment to the security function. It is a description of what happens by default when nobody else claims the job first.
This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.
The Ownership Gap the Data Actually Shows
The IAPP's AI Governance Profession Report 2025 asked which function holds primary responsibility for AI governance across the organizations it surveyed. Security came in at just 5 percent. Privacy and legal and compliance each held 22 percent, IT held 17 percent, data governance held 10 percent. On paper, AI governance is a privacy and legal problem, not a security problem, and the numbers back that up cleanly.
Then look at what CISOs actually report doing day to day. Okta's Global CISO Insights 2026 report, surveying 306 CISOs and cybersecurity executives across the United States, United Kingdom, Japan, Germany, Canada, and France, found 81 percent worry their AI systems lack proper governance, and 68 percent reported observing some degree of unauthorized AI deployment inside their own organization already. Only 47 percent of surveyed companies claimed visibility into all AI agents operating on their networks, and only 46 percent reported controlling those agents' access to corporate data. Those are not privacy team metrics. Those are security operations metrics, being tracked and worried about by the people whose formal governance ownership share is 5 percent.
That gap between formal ownership and functional accountability is the actual story. The IAPP report also found that privacy, IT, security, and legal functions are all expected to gain additional AI governance responsibility going forward, and separately found that only 1.5 percent of the 671 organizations surveyed believe they will not need additional AI governance staff in the next year. Everyone expects the job to grow. Almost nobody has decided who does it.
Why It Lands on Security Specifically
Four categories of AI risk explain why the CISO's desk absorbs the mandate even without a formal charter.
Shadow AI is the clearest case. IANS Research found more than 90 percent of enterprises no longer allow blanket AI tool access, and 56 percent now block most AI tools by default, running an allowlist for what is approved. That is access control, which has always been a security function, applied to a new category of tool. When a business unit spins up an unsanctioned AI assistant with a personal API key, the discovery, the blocking, and the incident writeup all route through security, whether or not anyone updated the CISO's job description to say so.
Model and vendor supply chain risk is the second driver. IANS also found roughly 80 percent of organizations now run multi vendor AI strategies, and 90 percent block DeepSeek access outright, more than 65 percent citing ties to China specifically as the reason. Evaluating a vendor's model provenance, data handling, and geopolitical exposure is a security assessment discipline, extended to a new asset class. Legal can write the contract clause. Security is the function that actually vets whether the vendor's claims hold up.
Data leakage through AI interfaces is the third. Every prompt typed into an ungoverned AI tool is a potential exfiltration event, and detecting that pattern requires the same DLP tooling, network monitoring, and browser controls security already owns for every other channel. Nobody builds a parallel monitoring stack in the privacy office. It gets bolted onto the security stack that already exists.
AI enabled attacks are the fourth, and the most direct. Attackers using AI to accelerate phishing, reconnaissance, and social engineering are a threat the CISO already owns by definition, the tool changed, the mandate did not. Okta's survey found 57 percent of CISOs globally reported extreme or very high worry about AI driven breaches specifically, rising to 84 percent among US security leaders. That is not a new governance category arriving on the CISO's desk. That is the oldest category the CISO owns, adapting to a new capability.
A Worked Example
A mid sized financial services firm discovered, during a routine access review, that a customer service team had been using a consumer AI chatbot to draft responses to account inquiries for six months, pasting redacted but still identifiable account details into the prompt window to get better answers. No one in privacy or legal had approved the tool, and no one in IT had provisioned it, an employee had simply signed up with a personal account. The CISO's team found it because it showed up as anomalous outbound traffic during a security review, not because a governance committee flagged it. The response, blocking the tool, notifying legal and privacy of a potential data exposure, and standing up an approved alternative, ran entirely through the security function, even though the underlying failure was a gap in acceptable use policy that predates any AI specific governance charter. The CISO did not ask for that incident. The CISO owned it anyway, because the CISO was the only function positioned to find it and stop it the same week.
The Honest Counterargument
The strongest case against the CISO absorbing this mandate is that security leaders are being asked to govern categories of harm that have nothing to do with security expertise. Bias in a hiring algorithm, a model producing discriminatory loan decisions, an AI system violating a sector specific ethics rule, none of that is a confidentiality, integrity, or availability problem, and a CISO evaluating it purely through a security risk lens will miss what actually matters. The IAPP data backs this concern directly. Legal, privacy, and compliance hold 44 percent of primary AI governance ownership combined for good reason, those functions have the training to evaluate fairness, discrimination, and regulatory exposure that security training does not cover.
That critique is correct, and it is also not an argument against the CISO's current role, it is an argument against the CISO being the only owner. The realistic outcome, and the one the data already shows emerging, is a shared model where security owns the access control, monitoring, and technical exposure layer while privacy, legal, and compliance own the fairness, bias, and regulatory layer, with a named executive accountable for making sure the two halves actually talk to each other. The mistake is not that security has a mandate. The mistake is treating it as the whole mandate instead of one third of it, which is how organizations end up with a CISO drowning in a governance scope no security budget was ever sized to cover.
Monday Questions for Leadership and the Board
Ask the CISO what percentage of AI governance work they are doing today that is not reflected in their formal charter or budget. Ask who owns the fairness and bias review for AI systems used in hiring, lending, or customer decisions, and confirm it is not defaulting to security by omission. Ask whether an inventory exists of every AI tool with network access, and who reviews it. Ask leadership and the board directly whether the CISO was resourced for this scope, or simply absorbed it because no one else moved first.
The CISO did not write the AI governance job description. Somebody still has to answer for the fact that no one else did either.