⚡
Brief IA
›

AI at Work: PwC Highlights Ambiguity on Responsibility

⚖️ Regulation & Ethics·Tom Levy·

AI at Work: PwC Highlights Ambiguity on Responsibility

AI at Work: PwC Highlights Ambiguity on Responsibility
⚡
Key Takeaways
1PwC notes that no single position clearly manages AI governance and security within companies
2The roles of CIO/CTO, CISO, and dedicated AI functions share responsibility depending on the organization
3Experts recommend applying the same identity controls to AI agents as for human users
💡Why it matters — The lack of a single responsible party and the diversity of practices expose companies to increased AI-related risks.
⚡Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

PwC notes a lack of clear ownership for AI governance and security within companies. Cybersecurity experts suggest applying the same identity controls for AI agents as for human users, without replacing managerial oversight.

Proposed Identity Controls to Regulate AI Agents

Jim Taylor, Product and Strategy Director at RSA, recommends using the same identity controls as for human users to manage AI agents. Each AI model or deployed instance has its own identity, associated with identifiers, access rights to resources, and the ability to act on behalf of an employee. Zero-trust principles, the use of multi-factor authentication, and other access control measures are already employed to validate human identities; Taylor proposes extending these practices to any deployment of AI agents. This method does not replace the oversight exercised by management. According to him, strengthening security through governance controls for AI agents can better prepare organizations for the ongoing risks associated with AI.

PwC Observes the Absence of a Single AI Leader

PwC finds that no single role clearly assumes responsibility for the management and security of AI agents. Awareness of the benefits and drawbacks of AI has reached the board level in about half of companies. For PwC, the chain of responsibility surrounding the deployment, monitoring, and security of AI is not yet defined.

Current Role Distribution Remains Fragmented

29% of CEOs and security and risk leaders believe that responsibility lies with the CIO, CTO, or an equivalent technology role. 17% attribute it to the CISO or cybersecurity teams, while 26% think it should belong to a dedicated AI leader or function. For 11% of respondents, responsibility remains vague and shared among several roles. Additionally, nearly one-third of organizations, about 33%, have hired profiles specifically dedicated to AI, such as AI managers or expert administrators. Regarding overall governance, 47% of respondents report that cybersecurity is on the agenda of boards of directors, and nine out of ten leaders claim to have mechanisms such as board oversight, executive accountability, and integration of enterprise risks.

Widespread AI Deployment but Associated Risks

The adoption of AI extends from enterprise applications to delivery chatbots, driven by agentic models and LLMs. For companies, this is a lever to optimize operations, limit manual interventions, support research and analysis, and lighten the workload of employees. This widespread adoption comes with tangible threats: uncontrolled models, attacks deemed friendly by AIs, several thousand security incidents related to AI currently under review, and agents becoming new access vectors to networks. These elements are drawn from PwC's Digital Trust Insights 2027 report, published on a Friday, which is based on responses from approximately 4,000 executives across 71 countries.

⚡

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.