
Author: Connor Whitehouse, Senior Technical Consultant
IT & Digital Transformation Services, Ballards
In most mid-sized businesses, there is no one person responsible for AI. IT owns the infrastructure, finance owns the spend and whoever is responsible for data protection looks after that side of things. AI sits across all three, which makes it difficult to say where responsibility for it actually lies. Proper ownership needs to bring together technology, data, security, risk and commercial strategy, and very few organisations have a role that covers all of those areas.
Part of the problem is the way AI has found its way into businesses. It has not arrived through one route, with one decision or one person responsible for approving it. Instead, it tends to come in three different ways.
The first route is through individual departments. Someone in marketing, HR or operations finds a tool that solves a problem they have now, and the monthly cost is low enough that it never reaches procurement. The second is through existing suppliers, and it is the one I see cause the most trouble. A platform the business has used for years gets an AI feature in a routine update, switched on by default and mentioned in release notes that nobody reads. Nothing was bought and nothing was approved, but what that system can do has changed anyway. The third is through staff using public AI tools directly, on work data, because they are quick, free and require no technical knowledge.
Each of those routes makes sense on its own. Together, they leave a business unable to say with any confidence what AI it is using, what those systems can access or who signed them off.
Why the question has changed
For the last two years, the question in most boardrooms was whether to use AI at all. That question has largely answered itself. Adoption happened, and in plenty of cases it happened without anyone actually deciding it should.
What replaces it is narrower and harder. Which AI tools are in use across the business? What information can each of them reach? Who is accountable for them? And how does anything new get assessed before it is switched on?
If a business does not have a clear view of the AI tools already in use, it is difficult to make sensible decisions about what comes next. Before anything else, someone needs to have oversight of what is being used, why it is being used and who is responsible for it.
“A policy tells people what the rules are. It does not tell you who is allowed to say yes.”
Does a policy fix it?
As an internal ISO 27001 auditor, my instinct is to start with the policy, and I would still say you need one. It gives people a clear set of rules to work from and makes the business’s position on AI clear. But having a policy and having someone responsible for it are two different things.
On its own, though, a policy does very little. It tells people what the rules are. It does not tell you who is allowed to say yes. When I ask a business who approves a new AI tool, the honest answer is usually that it depends on who noticed it. A policy without a named owner describes how a business would like to behave rather than how it actually behaves.
The two need to sit together. The policy sets the standard, and somebody has to own it, keep the register current and be senior enough to turn something down when the commercial case is strong, but the risk is not worth taking.
What happens when nobody owns it
What follows is not usually a crisis. It is a gradual loss of visibility. The business keeps working, decisions keep getting made, and nobody quite notices that more of them are being shaped by tools that were never formally adopted and that nobody is responsible for.
Some of that now has a name. Shadow AI means staff using AI tools without the knowledge of IT or management. It is a big enough subject to deserve a piece of its own, and it will get one. It belongs here because it is one of the things that happens when nobody owns the question.
The five things one person has to hold
This is the real difficulty with handing AI to an existing function. Owning it means understanding what the technology does, what data it touches, where the security exposure sits, what the risk actually is and whether the commercial case makes sense. Five disciplines, and in most businesses they sit across four or five people who each understand their own part well.
IT might seem like the natural place for AI to sit, but they only own part of the picture. They can understand the technology, the security implications and where the data is going, but the decision to use a tool is also a commercial one. Data protection has a similar limitation, looking at AI mainly through a compliance lens, while the board is too far removed from the day-to-day decisions being made about individual tools.
Someone needs to have overall responsibility for it. That means knowing what AI is being used across the business, reviewing anything new and bringing in the right people when there are questions around data, security or risk. It does not necessarily need to be a full-time role, but it does need to be clear who is responsible and who has the final say.
Governance is not the brake
There is a fair objection to all of this: governance can slow a business down at exactly the moment it wants to move quickly. In practice, the opposite is often true. The businesses that move slowest with AI are usually the ones where nobody feels confident enough to approve anything. Nothing gets approved formally, so people find their own way around the problem.
Clear ownership does the reverse. It creates a route to yes. Somebody can assess a tool, make a decision and stand behind it, which means the business adopts AI deliberately rather than by accident. The point of governance is not to restrict what people do. It is to make the boundaries clear enough that people can experiment safely inside them.
The question worth putting to your next board meeting is not what the AI strategy is. It is simpler than that. Who in this business is allowed to approve a new AI tool, and do they know that is their job?
For some businesses the answer is appointing someone internally. For others it is bringing that person in from outside, which is where the IT and digital transformation team can help.
This article has been prepared for information purposes only. Formal professional advice is strongly recommended before making decisions on the topics discussed in this release. No responsibility for any loss to any person acting, or not acting, as a result of this release can be accepted by us, or any person affiliated with us.





