Even when CIOs don’t have visibility into AI agent actions or don’t choose the vendor, chances are they’ll still take the blame when anything goes sideways.
IT leaders already see this happening inside their organizations, with 52% saying CIOs are blamed for agent mistakes, according to a recent survey commissioned by business communications provider 8×8. Just 6% of respondents say legal or compliance leaders shoulder responsibility when an agent goes rogue.
CIOs are now on the hook for whatever mad dash their organization has undertaken to deploy AI tools in recent years, says Morgan Watts, vice president of IT and business systems at 8×8.
“Going back a year and a half, there was the rush to adopt, and there is now some element of the penalty for that,” he says. “The rush came without the governance frameworks, as well as some of the visibility controls that should be there to help ensure the actual outcome.”
In some cases, AI tools were approved by the board, other executives, or other business units or were adopted as shadow IT by employees, Watts notes. In other cases, vendors shipped agents into platforms running mission-critical applications, resulting in a governance vacuum, according to the 8×8 report.
“The CIO is now the last line of defense for AI, and in a lot of organizations, that’s a job they didn’t apply for,” Samuel Wilson, CEO at 8×8, said in a statement. “The CIO didn’t choose the vendor, and they don’t always have the audit trail. But when an AI agent gets it wrong, their name is the one in the incident report.”
That model — blaming the CIO — isn’t sustainable, and it doesn’t lead to an AI governance model that holds up under scrutiny, Wilson adds.
With CIOs left holding the bag, they need to become AI governance evangelists, Watts says. “That’s not something you can pass off,” he adds.
Watts hasn’t yet seen evidence of IT leaders losing their jobs because of AI mistakes. IT analyst firm IDC has predicted, however, that up to 200 large companies will face either lawsuits, regulatory fines, or CIO firings over the next four years because of inadequate controls and governance of AI agents.
Meanwhile, 71% of IT leaders said in February that they believed they had until midyear to prove AI value or face budget or job fallout, according to a survey published by AI platform provider Dataiku. The impact on budgets or IT leader jobs doesn’t appear to have happened yet, however.
Still, the frenzy for AI, agents in particular, and the pressure of accountability continues to mount for IT leaders.
CIOs are working to fix existing governance gaps but they shouldn’t go it alone.
“There’s a pragmatic approach to how this can be an organizational responsibility,” Watts says, recommending that, while CIOs should lead the charge, organizations must spread the responsibility for better controls and for AI training and adoption.
Boris Kolev, global head of technology at youth-focused nonprofit JA Worldwide, agrees that AI governance should be a top priority for IT leaders, especially given that a malfunctioning agent can quickly become a huge problem when it changes a database record, sends a message, or triggers a transaction.
But Kolev believes CIOs should not be held responsible for agent mistakes if they don’t control the technology.
“It is a serious governance problem whenever responsibility exceeds authority,” he explains. “If a business team chooses an agent or an AI platform, a vendor controls its behavior, and the CIO is expected to answer for every failure, the organization has created an accountability gap before the agent takes its first action.”
CIOs have a responsibility to challenge existing accountability gaps, he adds. “If we cannot inspect an agent’s activity or stop it, we should make that limitation explicit before deployment and require an executive decision about the risk,” he says.
Gil Elbaz, cofounder and chief AI officer at Onyx Security, agrees that CIOs have a responsibility to fix governance problems.
“CIOs shouldn’t be blamed for every agent mistake, but they are accountable for putting effective governance and automated controls in place, alongside CISOs from a security perspective,” he says. “Accountability rests with the people and organizations responsible for governing agents — not with the agents themselves.”
Agents create a governance challenge because they operate at a speed that human oversight cannot keep up with, Elbaz adds. IT leaders need to deploy automated governance tools that allow them to know what agents are operating, what they can access, and whether their actions align with user intent and organizational requirements, he says.
“Unlike human employees, AI agents cannot take responsibility for their mistakes or face meaningful consequences — even when their actions cause serious organizational harm,” he adds. “This creates a new accountability gap that human oversight alone cannot address at machine speed and scale.”