Neither the EU AI Act nor the NIST AI Risk Management Framework names a title responsible for AI governance. Both require an accountability framework, and both leave the org chart entirely to the enterprise. That matters because only 38.5% of enterprises have a Chief AI Officer, according to EW Solutions’ 2026 research, so most companies default governance to the CDO or the CTO instead. This piece breaks AI governance into four accountable moments: risk sign-off, policy authorship, regulatory-role mapping, and the audit trail, and shows who typically holds each one.
Both frameworks treat accountability as a structure to build, not a title to assign, the same reckoning enterprises went through when they first asked who would own the context layer itself. Article 3 of the EU AI Act defines “provider” and “deployer” as legal-entity roles, not job titles, and a single enterprise can hold both roles on the same AI system. Four moments end up deciding who is actually on the hook: the risk sign-off, the policy that gets written, the regulatory role a company maps itself to, and the audit trail regulators eventually ask for. None of the three titles in this page’s headline appears in either framework’s text.
| Dimension | CAIO | CDO | CTO |
|---|---|---|---|
| What it is | Executive charged with AI strategy and, where the role exists, governance oversight | Executive who owns the data foundation AI depends on | Executive who owns the technology stack AI runs on |
| Primary governance task | Chairs the AI review board, approves the risk register where the role exists | Owns data quality, lineage, and privacy controls feeding AI systems | Owns infrastructure risk and platform-level access controls |
| Prevalence | 38.5% of enterprises have this role (EW Solutions, 2026) | Near-universal at enterprise scale; ~70% now hold primary AI-strategy responsibility (Gartner, 2025) | Near-universal; governance role varies by company AI maturity |
| EU AI Act “provider” mapping | Most often the internal contact when this role exists | Frequently co-owns via data-lineage evidence | Sometimes owns when AI is built as a shipped product |
| Audit-trail ownership | Named owner where the role exists | Common default owner absent a CAIO | Common default at tech-native or product companies |
| Reporting trend | Newer role; reporting line varies by company | CDAO-to-CEO reporting rose from 21% to 36% (Gartner, 2025) | Typically reports to the CEO already; stable trend |
| Best for | Organizations with a distinct, named AI program and mandate | Organizations where data governance is already mature and centralized | Organizations building AI as a product feature, not a governed program |
| Questions it answers | “Who is accountable for the AI program overall?” | “Is the data behind this AI system trustworthy and traceable?” | “Who controls the infrastructure and access this AI runs on?” |
Sources: EW Solutions (2026); Gartner 2025 CDAO Agenda Survey (figure corroborated via independent secondary reporting, see Sources).
CAIO vs CDO vs CTO: what’s the difference in AI governance?
Permalink to “CAIO vs CDO vs CTO: what’s the difference in AI governance?”The three roles split along different axes: the CAIO owns program-level accountability, the CDO owns whether the data behind an AI system can be trusted, and the CTO owns the infrastructure the system runs on. None of that split is mandated by regulation. It is a practice convention that varies by company, not a rule enforced from outside.
This piece stays narrowly on who is accountable for AI governance: who signs the risk register, who authors the policy, who maps the company to a regulatory role, and who owns the resulting audit trail. It does not cover who builds or delivers the AI platform day to day. That is a genuinely different question about delivery ownership, not accountability, and it deserves its own answer rather than getting folded into this one.
Article 17(1)(m) of the EU AI Act requires providers of high-risk AI systems to maintain an “accountability framework setting out the responsibilities of the management and other staff,” without naming which manager that is. NIST’s AI Risk Management Framework, under its GOVERN function, makes the same move: GOVERN 2 requires “accountability structures” so that teams are “empowered, responsible, and trained” for managing AI risk, again without specifying a title. NIST’s framework is voluntary and cross-sector; the EU AI Act’s is binding on providers of high-risk systems. Both arrive at the identical structural choice.
In practice, enterprises tend to name one executive with final accountability for the AI program, while legal, risk, security, data, and engineering each own a distinct piece of the control stack underneath that person. Where that single point of accountability is missing, the four moments below simply default to whoever is already positioned closest to them, usually with no documented mandate to do so.
The four accountable moments
Permalink to “The four accountable moments”| Governance task | Typically named owner | Regulatory anchor |
|---|---|---|
| Model risk sign-off | CAIO where one exists; otherwise CTO or CDO by explicit mandate | NIST AI RMF GOVERN 2 |
| AI policy authorship | CAIO or a cross-functional AI governance committee | EU AI Act Art. 17(1)(m) |
| EU AI Act “provider” mapping | Varies; a legal-entity role, not a title (Art. 3) | EU AI Act Art. 3 |
| Audit-trail ownership | CDO (data lineage) or CISO (control evidence) most often | EU AI Act Art. 9, NIST GOVERN 2 |
Why the generic three-way split undersells the actual question
Permalink to “Why the generic three-way split undersells the actual question”A quick, three-column comparison is useful as a reference, and most write-ups on this topic stop there: “CAIO does strategy, CDO does data, CTO does infrastructure,” settled. That surface-level split answers a different question than the one an auditor actually asks: who signed off on this specific model? A well-run data governance program can be mature and fully staffed and still leave AI governance unassigned, because data trustworthiness and decision defensibility are not the same claim. Assuming the data-governance org chart transfers automatically, without checking whether it actually covers these four moments, is the gap most AI governance framework work leaves open. The four accountable moments in the table below are what should transfer between governance disciplines, not the title that happens to hold them today.
What does a Chief AI Officer (CAIO) own in AI governance?
Permalink to “What does a Chief AI Officer (CAIO) own in AI governance?”A CAIO’s governance role is fairly consistent where the position exists: chair the AI review board and approve the risk register before a model reaches production, the same discipline enterprises now expect around AI agent risk and guardrails more broadly. According to Godwin Avodagbe of Solaris, “the CAIO is neither a second CTO nor a lighter CDO,” a distinction that matters because the role gets created, in practice, specifically to hold accountability that a CTO or CDO title does not already cover.
That accountability is still rare. Only 38.5% of enterprises have a Chief AI Officer at all, according to EW Solutions’ 2026 analysis, which means roughly six in ten readers of this page work somewhere without one. For those readers, the CAIO’s governance duties do not disappear. They move to whichever of the CDO’s or CTO’s teams happens to sit closest to the AI system in question.
Not every analyst agrees the role should exist as a separate seat at all. Matthew Geyman, Managing Director at Intersys, has argued that most organizations should treat a CAIO as a subset of the chief technology officer’s function rather than as a standalone hire, while still expecting more companies to appoint one anyway to keep guardrails in place as programs scale. Both things can be true at once: the function is contested, and the accountability it covers still has to sit somewhere.
What a CAIO typically signs off on
Permalink to “What a CAIO typically signs off on”Where the role exists, a CAIO is usually the named signer on the AI model risk register, the chair of the AI review board, and the internal point of contact for EU AI Act provider-role questions. That same named-owner requirement shows up in any serious enterprise AI agent guardrails checklist: a control without a name attached to it is not a control. None of that changes the underlying finding of this page, though. A title does not settle accountability. What settles it is whether the sign-off, the policy, and the audit trail actually get assigned to someone on paper, whether or not that someone carries the word “AI” in their title.
Get the playbook CAIOs, CDOs, and CTOs use to govern AI on a live graph
See how enterprise leaders turn a lineage and ownership graph into the audit trail regulators actually ask for, instead of building governance evidence from scratch.
Get the CIO Context GuideWhat does a Chief Data Officer (CDO) own in AI governance?
Permalink to “What does a Chief Data Officer (CDO) own in AI governance?”A CDO’s governance claim rests on a narrower, more concrete foundation than the CAIO’s: they own the data quality, lineage, and privacy controls that any AI governance claim has to stand on. Rohit Prabhakar’s comparison of governance roles puts it directly: “the CDO owns data quality, data lineage,” while broader AI strategy and cross-cutting governance sit with the CAIO where one exists.
That data-first claim increasingly comes with the AI-strategy job attached, whether or not the title changes. According to Gartner’s 2025 CDAO survey, 70% of Chief Data and Analytics Officers now hold primary responsibility for their organization’s AI strategy and operating model, and CDAO-to-CEO reporting rose from 21% to 36% in a single year.
This is a practice default, not a regulatory mandate. No framework requires the CDO to inherit AI governance. It happens because the CDO is usually the only executive already holding data lineage records for CDO-scale governance and quality evidence when an AI question gets asked. Security teams have made an analogous move for infrastructure, building zero-trust data governance models around the same insight: control has to attach to evidence, not to a job description.
What a CDO typically signs off on
Permalink to “What a CDO typically signs off on”Where there is no CAIO, a CDO most often becomes the default audit-trail owner, because the trail gets built from the same lineage and ownership records that data governance teams working inside the context layer already maintain. That default is convenient, not automatically correct. A CDO who owns lineage evidence is not necessarily the right person to own AI risk sign-off, and treating the two as interchangeable is exactly the kind of hand-me-down assumption that leaves gaps a regulator will eventually find.
What does a Chief Technology Officer (CTO) own in AI governance?
Permalink to “What does a Chief Technology Officer (CTO) own in AI governance?”Infrastructure is where a CTO’s governance claim gets concrete fastest: control over what an AI system actually runs on, and who can push a new version to production. Digital Chiefs’ comparison of ownership roles draws a related line: infrastructure ownership and data ownership are separate claims from AI-specific accountability, and neither one changes just because “AI” entered the conversation. At most enterprises building AI as an internal capability, the CTO ends up holding infrastructure and platform-level access controls by default, while the CDO owns the data foundation underneath it.
The CTO becomes the practical governance default at a specific kind of company: one building AI as a shipped product feature rather than an internal capability. At tech-native and product-led organizations, the CTO’s or CPO’s office, not a CAIO or CIO, ends up owning the AI stack, because that is where the engineering judgment about what a model can and cannot be trusted to do already lives. That is a different unit of ownership than what a context layer actually provides architecturally, and infrastructure ownership and context ownership increasingly sit in the same conversation whether or not a company has named a CAIO.
Some of the sharpest recent examples of what happens without that ownership come from vendor concentration itself. The governance risk created when a single AI lab controls too much of the stack is fundamentally an infrastructure-ownership problem wearing a policy costume: nobody assigned the audit trail before the dependency became load-bearing.
What a CTO typically signs off on
Permalink to “What a CTO typically signs off on”Where a CTO owns AI governance by default, they typically sign off on deployment access, model-serving infrastructure risk, and the EU AI Act’s provider-role mapping when AI ships as the company’s own product. The title itself tells a reader almost nothing about which of these three actually has a documented mandate attached to it. Infrastructure ownership without a policy is control without accountability, and it fails an audit exactly as often as a policy without infrastructure does.
CAIO vs CDO vs CTO: head-to-head on the four accountable moments
Permalink to “CAIO vs CDO vs CTO: head-to-head on the four accountable moments”The sharpest divergence between the three roles is not who has the word “AI” in their title. It is who is named on the risk register versus who owns the evidence trail behind it, the same split enterprises face when deciding who owns the context layer itself: centralized ownership sounds cleaner on a slide, but federated ownership split between data and AI teams is closer to what actually happens.
| Dimension | CAIO | CDO | CTO |
|---|---|---|---|
| Primary governance focus | Program-level accountability | Data trustworthiness | Infrastructure control |
| Model risk register ownership | Named owner where the role exists | Common default absent a CAIO | Default at tech-native or product firms |
| AI review board chair (default) | CAIO, where present | Data governance council chair, often | Rare; usually delegates to the CDO or CAIO |
| EU AI Act “provider” mapping | Frequent internal contact | Co-owns via lineage evidence | Owns when AI ships as a product |
| Audit-trail accountability | Named owner where the role exists | Most common default owner | Default at product-led organizations |
| Reporting line / seniority trend | Newer, inconsistent reporting line | CDAO-to-CEO rose 21% to 36% (Gartner) | Stable, typically reports to the CEO |
| Prevalence in practice | 38.5% of enterprises (EW Solutions) | Near-universal; 70% hold AI-strategy responsibility | Near-universal |
| Failure mode when this role governs alone | Program without data-quality teeth | Governance without a program mandate | Infrastructure controls without policy accountability |
| Governance maturity indicator | Dedicated AI governance charter exists | Lineage-backed data catalog exists | Access-control and platform audit logs exist |
| Framework alignment | NIST GOVERN 2 (accountability structures) | EU AI Act Art. 9 (risk management system) | EU AI Act Art. 17 (QMS requirement) |
The 70% and 21%-to-36% Gartner figures in this table are corroborated via independent secondary reporting (Technology Magazine, AI Magazine, Gartner’s own newsroom coverage); see the corrected citation in Sources.
Example: a mid-size insurer with no CAIO
Consider a mid-size insurer building an underwriting model, with no CAIO and no plan to create one. The CDO ends up holding the audit trail by default, because the CDO’s team already tracks data lineage for regulatory reporting. The CTO controls who can push a new model version to production, which means the CTO effectively controls deployment risk without ever being asked to formally sign anything. Private equity and asset management firms building AI-driven diligence tools report the identical default: a data or risk lead absorbing audit-trail ownership nobody formally assigned them.
Neither executive has a documented AI governance mandate. When a regulator asks who approved the model’s use of a protected-class proxy variable, the honest answer is that no one did, because no one was assigned to ask the question before deployment. The audit trail exists, technically, but it belongs to whoever was closest to the data, not to whoever was supposed to be accountable for the decision.
The same pattern shows up across enterprises with genuinely different infrastructure and different regulators: whoever lays the technical foundations, supplies the data, and ships the product ends up closest to the decision, while governance itself gets orchestrated, when it gets orchestrated at all, by whoever the CAIO turns out to be. Article 9 of the EU AI Act requires a continuous, iterative risk management system across an AI system’s lifecycle, and NIST’s GOVERN 2 function requires the same thing in different language. Neither framework cares which title runs that system, only that someone demonstrably does. An org chart borrowed wholesale from data governance, where lineage ownership was the whole job, does not automatically produce a person who owns AI risk decisions. It just produces a plausible-looking name to write in the box when someone asks.
How do CAIO, CDO, and CTO share AI governance responsibility?
Permalink to “How do CAIO, CDO, and CTO share AI governance responsibility?”The practitioner pattern that recurs across enterprises is federated, not singular: one named executive holds final accountability for the AI program, while legal, risk, security, data, and engineering each own a distinct piece of the control stack underneath. In practice, a single AI system typically has at least four simultaneous stakeholders with a claim on accountability: a business owner, an executive accountable for the AI program overall, a Chief Risk Officer, and a DPO or general counsel covering legal exposure.

The federated pattern: one named executive holds final accountability while data, infrastructure, and legal each own a distinct control. Source: Atlan.
Brandon Purcell, Vice President and Principal Analyst at Forrester, has framed the stakes in similarly blunt terms: legal and compliance teams already understand that a problem with an AI-driven brand experience creates culpability, whether or not it ever reaches litigation, because the court of public opinion renders its verdict first. That culpability does not wait for a title to exist. It attaches to whoever is closest to the decision when something goes wrong.
Frances Karamouzis, Distinguished VP Analyst at Gartner, goes further: she has argued that enterprises should not rush to appoint a chief AI officer, and per Gartner’s 2024 AI board poll, has made the case that an AI board is what actually helps organizations work through the multidisciplinary challenges of driving AI value while managing its risk. The board is the more defensible answer than the hire. That is where self-service analytics governance and securing multi-agent systems actually get assigned, moment by moment, rather than role by role.
When there’s no CAIO, who owns AI governance? (the majority case)
Permalink to “When there’s no CAIO, who owns AI governance? (the majority case)”For the roughly 61.5% of enterprises without a Chief AI Officer, the inverse of EW Solutions’ 38.5% adoption figure, accountability shifts to the CTO or CDO with an explicit, documented mandate, and that word “explicit” is what actually differentiates outcomes, not which of the two titles inherits the job. A CTO or CDO who is verbally understood to “own AI stuff” is not the same as one whose name is written on a risk register and a policy document. This distinction touches, but does not answer, a related question: who then actually builds and delivers the AI platform day to day is a separate question about delivery ownership, distinct from the accountability question this page covers.
When to formalize a dedicated AI review board regardless of title
Permalink to “When to formalize a dedicated AI review board regardless of title”A dedicated AI review board is worth formalizing the moment a company ships more than one AI system into production, or the moment a single system touches regulated data, whichever comes first, alongside whatever AI leadership and literacy obligations already apply to the executives being asked to sign. Building that board does not require resolving the CAIO question at all. It requires assigning a chair, a documented meeting cadence, and explicit sign-off authority over the same four moments this page keeps returning to: risk, policy, regulatory mapping, and the audit trail. The habit of building an AI center of excellence usually starts here, and enterprises that skip straight to hiring a CAIO without building this structure first tend to rediscover, a year later, that the hire alone did not fix anything: the four moments still needed names attached to them, on paper, regardless of which org chart got used to get there.
See how Atlan connects AI governance to the context layer already in place
The lineage and ownership graph that already governs your data can carry AI governance too, instead of starting a second, disconnected system from scratch.
Explore the context layerHow Atlan approaches AI governance ownership
Permalink to “How Atlan approaches AI governance ownership”Governance that gets bolted onto an AI program as a separate compliance layer produces exactly the failure mode this page keeps surfacing: a named owner on paper, and no evidence trail underneath them when someone actually checks. That gap is not a tooling problem first. It is an ownership problem that tooling later inherits, and it is the reason live AI risk registers built on top of stale spreadsheets fail the moment a regulator asks a follow-up question.
Atlan is the Context Layer for AI: a living graph of lineage, ownership, and business definitions that already exists underneath any AI system built on governed data. Govern AI Assets attaches asset-level policy and approval workflows to that same graph, so AI governance inherits the ownership and lineage records a data program has already built, rather than starting a second, disconnected ownership chain from zero, the same principle behind what context engineering does for AI agents more broadly. The audit trail this page keeps returning to is not a separate artifact to construct. It is the graph the organization already has, made queryable at the moment a regulator or auditor asks for it. That queryability is what turns AI-ready data from a data-quality claim into a governance claim that actually holds up.
Financial services, insurance, and technology companies working through this problem describe the same pattern in different words: governance sits in a parallel team, separate from traditional data governance, until someone connects the two. CME Group is a public example of what that connection looks like in practice, moving from reactive data management toward proactive AI enablement once lineage and ownership became shared vocabulary rather than separate systems. The pattern holds even without naming every account: whoever already owns the context AI agents actually draw from is closer to owning defensible AI governance than whoever simply has the newest title.
Make AI governance provable, not just assigned
See how Atlan's context layer turns lineage and ownership into an audit trail regulators can actually query, instead of one someone has to reconstruct after the fact.
See AI agent governanceThe four accountable moments still need names, not just a chart
Permalink to “The four accountable moments still need names, not just a chart”Neither regulation nor practice has actually settled who owns AI governance. The frameworks refuse to name a title on purpose, and the practice default, the CDO or CDAO absorbing the job, is emerging without a mandate to back it up. Both hold simultaneously, and pretending otherwise produces exactly the kind of tidy org chart that falls apart the first time a regulator asks a specific question.
A title will end up holding each of the four accountable moments this page has returned to throughout, risk sign-off, policy authorship, EU AI Act role mapping, and the audit trail, because someone always does. What differs is whether that assignment happened on purpose, in writing, or by default because no one else was closer to the evidence. The organization best positioned to hold the audit trail on purpose is whoever already owns the core components of the context layer the AI system actually draws from, not whoever has the most recently created title. That is not a settled answer. It is a live one, and the CDAO-default pattern Gartner’s data shows is still being written, one enterprise at a time.
FAQs about who owns AI governance
Permalink to “FAQs about who owns AI governance”1. What is the difference between AI governance and data governance?
Permalink to “1. What is the difference between AI governance and data governance?”Data governance covers whether the data feeding a system is accurate, lineage-tracked, and access-controlled. AI governance covers whether a specific AI decision is defensible: who signed off on the model, what policy it follows, and who owns the audit trail. A mature data governance program does not automatically produce AI governance; the two answer different questions even though AI governance depends on data governance being solid underneath it.
2. Who is responsible for AI compliance under the EU AI Act?
Permalink to “2. Who is responsible for AI compliance under the EU AI Act?”The EU AI Act assigns compliance to legal-entity roles, “provider” and “deployer,” not to job titles. A single company can be both at once: a provider when it builds its own model, a deployer when it uses a third-party one. Internal accountability mapping, meaning which executive represents that legal role day to day, is left entirely to the organization.
3. Does a company need a Chief AI Officer if it already has a CTO?
Permalink to “3. Does a company need a Chief AI Officer if it already has a CTO?”Not necessarily. Only 38.5% of enterprises have a Chief AI Officer at all, per EW Solutions’ 2026 data, and most run AI governance through the CTO or CDO instead. Some analysts argue the CAIO function works better as a defined mandate inside the CTO role than as a separate seat; the accountability matters more than whether a new title exists to hold it.
4. Who should chair an internal AI review board or ethics committee?
Permalink to “4. Who should chair an internal AI review board or ethics committee?”Where a Chief AI Officer exists, they typically chair the board. Where one does not, the chair usually falls to whichever of the CDO or CTO already holds the closest thing to a documented AI mandate, provided that mandate is explicit and written down rather than assumed. The chair’s job is to hold the four accountable moments, not to personally execute all of them.
5. How do you document an AI audit trail for regulators?
Permalink to “5. How do you document an AI audit trail for regulators?”An AI audit trail needs to show which data and model version produced a given decision, who approved it, and what policy governed the approval. The EU AI Act’s Article 9 risk management requirement and NIST’s GOVERN 2 accountability structures both expect this to be continuous and queryable, not reconstructed after the fact from scattered emails and spreadsheets.
6. What happens to AI governance ownership when there’s no CAIO?
Permalink to “6. What happens to AI governance ownership when there’s no CAIO?”For the roughly 61.5% of enterprises without a Chief AI Officer, per EW Solutions, accountability shifts to the CTO or CDO, and the explicit, documented nature of that mandate is what actually determines whether governance works, not which of the two titles inherits it. A verbal understanding that someone “owns AI stuff” is not the same as a name on a risk register.
7. How does Atlan connect AI governance ownership to the context layer?
Permalink to “7. How does Atlan connect AI governance ownership to the context layer?”Atlan’s Govern AI Assets attaches policy and approval workflows to the same lineage and ownership graph that already governs an organization’s data, so AI governance inherits an existing evidence trail instead of starting a second, disconnected one. Accountability follows whoever already owns that graph, rather than waiting on a new title to be created.
Sources
Permalink to “Sources”- Article 17, Regulation (EU) 2024/1689
- Article 9, Regulation (EU) 2024/1689
- Regulation (EU) 2024/1689, full text, EUR-Lex
- AI Risk Management Framework 1.0, NIST
- Chief AI Officer: CAIO vs. CDO and CDAO, EW Solutions (2026)
- Who Owns AI: CIO, CDO, or CTO Compared, Digital Chiefs
- CTO, CDO, CAIO: Who Really Owns AI Strategy in Your Organization?, Solaris (Godwin Avodagbe)
- Who Owns AI Governance?, Rohit Prabhakar
- Gartner Survey Finds 70% of CDAOs Are Responsible for AI Strategy and Operating Model, Gartner Newsroom (2025)
- Chief AI Officer: Does Your Enterprise Need a Head of AI?, Gartner (Karamouzis)
- Gartner Poll Finds 55% of Organizations Have an AI Board, Gartner Newsroom (2024, Karamouzis)
- Navigating AI Regulation and Legislation, Computer Weekly (2024, Purcell, Forrester)
- Chief AI Officer (CAIO): What Is It? Do You Need One?, Intersys (2024, Geyman)
