Sep 17 / Briefings

Who’s Holding the Bag? The High-Stakes Battle Over AI Ownership

Executive Summary

This briefing synthesizes expert analysis on operationalizing the NIST AI Risk Management Framework (RMF) to move beyond theoretical governance into measurable, risk-based outcomes. These findings are derived from the panel webinar session Translating the NIST AI RMF into Measurable Risk Outcomes. The discussion focuses on integrating AI risk into existing GRC workflows, leveraging traditional cybersecurity controls for non-human identities, and shifting toward consequence-based measurement. For senior executive leadership and the board, AI risk management is no longer a peripheral technical concern but a core component of organizational resilience and fiduciary duty. As AI systems become more agentic and deeply embedded in the supply chain, the ability to calibrate trust and define clear ownership is the primary differentiator between secure innovation and catastrophic exposure.

Critical Takeaways:
  • Consequence-Based Scoping: Organizations must define AI systems by what they can affect (customers, financials, or controls) rather than the technology they are built with to ensure proportionate risk treatment.
  • Leveraging Existing Foundations: AI risk does not require a complete overhaul of risk programs; traditional controls like Identity and Access Management (IAM) and least privilege are highly effective when applied to non-human AI identities.
  • The Trust Calibration Imperative: Success in AI deployment is not defined by maximizing trust, but by calibrating it; both over-trust and under-trust represent significant risks to organizational utility and safety.
  • Integrated GRC Architecture: To avoid "shadow" risk registers, AI risk monitoring must be embedded into central GRC platforms to ensure findings land in the queues where risk owners already operate.

1. The Integration Mandate: Holistic Risk Registers

Organizations frequently fall into the trap of "bolting on" AI risk as a separate silo, which leads to fractured visibility and the creation of multiple, ineffective risk registers. Expert analysis suggests that AI should be viewed as one of many dimensions of enterprise risk. A holistic approach ensures that AI-specific findings, such as model drift or prompt injections, are managed within the same central architecture as traditional IT risks, ensuring they receive the same level of executive scrutiny and remediation priority.

To evaluate how organizations are currently navigating these integration challenges, webinar attendees were surveyed on their technical readiness and understanding of AI risk scope:
POLL: When it comes to AI risk, where are you today? Total votes: 326
We understand the risk scope, but our technical capability is not there yet (108 votes) 33%
We understand the risk scope and are technically ready to measure and manage it (97 votes) 30%
We are still developing both (65 votes) 20%
We have technical capability, but the full risk scope is still unclear (56 votes) 17%
The survey data reveals that 33% of respondents understand their risk scope but lack technical capability, while another 20% are still developing both. Trying to manage AI in isolation creates technical and operational disconnects, emphasizing the necessity of an integrated technical architecture.

"An organization with two risk registers, they really have no risk register."Dave Waltermire, Vice President, AI and Platform Engineering at RegScale


2. Identifying the Owner: Security, Legal, and Data Science

Clear ownership remains the primary hurdle for operationalizing AI governance. Because AI impacts security, legal compliance, and data science, organizations struggle to find a central point of accountability—leaving unanswered questions about who is ultimately responsible when a risk materializes. Effective risk management requires that findings arrive where risk owners are actually looking for them, rather than being relegated to specialized tools that lack executive visibility.

When asked to identify the single largest barrier to operationalizing AI risk management within their organizations, attendees highlighted clear structural gaps:
POLL: What’s the biggest blocker to operationalizing AI risk management at your organization right now? Total votes: 328
Lack of clear ownership (who owns AI risk: security, legal, data science?) (153 votes) 47%
No repeatable way to measure or score AI risk (85 votes) 26%
AI risk lives outside our existing GRC/audit tooling (52 votes) 16%
Leadership buy-in or budget (38 votes) 12%
Survey data confirms that nearly half (47%) of organizations see structural ambiguity over ownership as their main source of inertia.

"When we look at this lack of clear ownership, the first thing that comes to mind is: are we asking for a Chief AI Officer just so we can put the risk ownership on one person?"Dirk Schrader, Global VP of Security Research at Netwrix

Schrader noted that centralizing role titles alone misses the operational challenge, a point expanded on by Dave Waltermire:

"Fixing the org chart doesn't necessarily fix the AI problem... You solve it by making findings arrive where risk owners are actually looking for them."Dave Waltermire, Vice President, AI and Platform Engineering at RegScale

Moderator Colin Whitaker further emphasized the need to keep governance documents aligned with active technical environments:

"You've got to keep on track of your AI policy far more so than any other policy within your company to make sure that you're reflecting reality."Colin Whitaker, Founder and Director at Informed Risk Decisions


3. Beyond Model Metrics: Characterizing Real-World Consequences

Leaders must move past internal model metrics—such as accuracy or latency—and focus on characterizing real-world consequences. This involves understanding the blast radius of a misbehaving AI system and its potential for irreversible damage. Measurement science in the AI age requires calibrating human trust appropriately rather than blindly maximizing it, ensuring systems remain reliable while avoiding both over-reliance and under-utilization.

To explore what makes AI risk characterization so complex across embedded and third-party systems, webinar participants were surveyed on their primary measurement challenges:
POLL: For any AI in your organization, including embedded and third-party systems, which of these is hardest to characterize? Total votes: 310
Who and what influences its output (87 votes) 28%
Whether the people relying on it trust it appropriately (79 votes) 25%
What happens when it is wrong (76 votes) 25%
What breaks if it changes silently or disappears (68 votes) 22%
The even distribution across poll choices demonstrates that characterizing AI risk requires context beyond neat numbers, particularly when evaluating supply chain influences and calibrated trust.

"At the end of the day, it's the real-world consequence that matters."Dr. Raymond Sheh, AI Risk Management Researcher, AI Research, Measurement, and Standards Division at NIST

Sheh highlighted that evaluating consequences also means framing user trust appropriately:

"We need to have appropriately calibrated trust, because at the end of the day, if you don't trust the AI system, but it actually did the right thing, you still have a problem."Dr. Raymond Sheh, AI Risk Management Researcher, AI Research, Measurement, and Standards Division at NIST


4. Scaling Through Proportionate Governance

High-performing organizations utilize tiered, risk-based workflows to ensure that lower-risk AI use cases are streamlined while higher-risk applications receive enhanced scrutiny and escalation. This prevents framework fatigue and ensures that the organization can remain adaptable as regulations like the EU AI Act evolve. By defining a persistent operating layer for evidence, businesses can meet rapid innovation needs without interrupting their baseline security and compliance postures.

To measure how widely organizations are applying tiered governance in practice, attendees were polled on their current workflow maturity:
POLL: Has your organization defined risk-based workflows and categories to enable proportionate AI governance? Total votes: 309
Partially—we have some criteria, but workflows and escalation paths are not consistently applied (123 votes) 40%
Yes—use cases are tiered, with streamlined review for lower-risk uses and enhanced review, ownership, and escalation for higher-risk use (67 votes) 22%
We are still determining how to categorize and govern AI use cases (65 votes) 21%
Not yet—all AI use cases generally follow the same review process (54 votes) 17%
Only 22% of organizations have achieved a fully tiered approach to AI governance, with 40% relying on partially applied criteria. Establishing an operating baseline allows businesses to scale process efficiency while keeping pace with rapid technology adoption.

"Defining a baseline around your operating layer... is key to being adaptable from one framework to the next without interrupting your entire baseline."Kaitlyn Archibald, Product Marketing Director at OneTrust


5. The Identity Frontier: AI Agents as First-Class Citizens

As AI systems become more agentic, they must be treated as first-class identities. While AI-specific issues like data lineage and model bias exist, many AI failures are actually traditional control failures relabeled. Risk reduction is evidenced not by the existence of a control document, but by the tangible reduction of unnecessary privileges, the limitation of access to sensitive data, and the ability to revoke access for misbehaving non-human entities.

"An AI agent might be new, no question about it. Least privilege is not."Dirk Schrader, Global VP of Security Research at Netwrix

Schrader emphasized that operationalizing least privilege requires treating non-human entities with the same rigor as human accounts:

"Whatever is non-human is still an identity. Get your permissions, privileges, and data back into shape under control."Dirk Schrader, Global VP of Security Research at Netwrix


Strategic Roadmap

  • Shift to Consequence-Based Scoping: Evaluate every AI use case based on what it can touch—customers, dollars, or controls—and assign owners and measurement plans accordingly.
  • Reinforce Identity and Access Foundations: Treat all AI agents and service accounts as identities. Apply strict least privilege principles to minimize the blast radius of misbehaving systems.
  • Operationalize Continuous Monitoring: Move away from point-in-time assessments toward integrated monitoring that captures real-time evidence of control effectiveness, ensuring AI risks are managed within the central enterprise risk register.

Explore these themes in detail by accessing the full panel discussion: Translating the NIST AI RMF into Measurable Risk Outcomes.