Navigating the AI Accountability Vacuum: Lessons from PwC’s Digital Trust Insights 2027

Nobody is responsible for AI risks

Artificial Intelligence is reshaping the modern enterprise at a breakneck pace. But as companies rush to integrate frontier models and autonomous agents, a glaring question remains: Who is actually driving the bus?

PwC recently released its Global Digital Trust Insights 2027 report, surveying nearly 4,000 business and tech leaders across 71 countries. The findings paint a striking picture of an industry caught between massive ambition and fundamental vulnerability. While security budgets are climbing to fund AI initiatives, organizations are grappling with a chaotic ownership model for AI risk and a deep-seated distrust of autonomous technology.

Let’s dive into the key takeaways from the report and look at actionable recommendations for business leaders looking to close the trust gap.

Key Takeaways: What the PwC Report Reveals

  1. The Great Ownership Vacuum:Who is responsible for managing agentic AI and its security? According to the survey, no single ownership model has emerged.Responsibility is scattered: 29% of leaders point to the CIO/CTO function, 26% look to a dedicated AI leader or function, and 17% attribute it to the CISO.While about a third of organizations (33%) have hired for dedicated AI roles (like a Chief AI Officer), the lack of uniform governance leaves plenty of room for critical risks to fall through the cracks.
  2. AI Security is the Biggest Blind Spot:When asked which cyber threats organizations are least prepared to handle, attacks targeting AI systems take the crown.Security leaders specifically cited fears over compromise by autonomous botnets (53%), adversarial attacks (52%), and data poisoning (52%).
  3. Budgets Are Up, But Trust in “Autonomous Agents” is Low:Spurred by AI integration, 84% of senior leaders expect their cyber budgets to increase. However, while companies are eager to deploy AI agents for defense, they are hesitant to hand over the keys. Only 22% of organizations would authorize fully autonomous AI actions, citing concerns over technological reliability, maturity, and a lack of explainability in decision-making.
  4. Foundational Data Gaps Persist:Even as companies race to feed data into complex AI architectures, foundational data hygiene is lagging. On average, companies have implemented only three out of seven key data risk measures across their enterprises, leaving sensitive information exposed.

Actionable Recommendations for Business & Tech Leaders

If your organization wants to stay ahead of the curve and bridge the AI trust gap, you can’t afford to wait for a crisis to define your strategy. Consider these four steps:

1. Establish Clear, Centralized AI Ownership

Ambiguity breeds vulnerability. If everyone is responsible for AI risk, no one is.

  • The Fix: Form a cross-functional AI governance committee consisting of the CEO, CISO, CIO/CTO, and Legal/Compliance leads. Clearly define who holds ultimate accountability for AI deployment, ethics, and security. Whether you appoint a dedicated Chief AI Officer or anchor it within the risk department, the lines of reporting must be crystal clear.

2. Shift from “Hands-Off” to “Trust, But Verify” Autonomy

You don’t need to give AI agents completely unrestricted power out of the gate, but paralyzing fear shouldn’t stall your defense strategies either.

  • The Fix: Adopt a tiered trust model for autonomous agents. Use AI to accelerate threat detection, phishing triage, and alerting, but maintain human-in-the-loop or human-on-the-loop checkpoints for actions that could disrupt business operations. Invest in explainable AI (XAI) tools so your security teams can understand why an AI agent made a specific decision.

3. Prioritize Data Hygiene Before Scaling Frontier AI

You cannot build a secure intelligent enterprise on top of shaky data foundations.

  • The Fix: Audit your data pipelines. Before deploying advanced models or expanding data-sharing for AI initiatives, ensure you have implemented rigorous data-risk measures—such as strict classification, access controls, and encryption—to minimize your data exposure footprint.

4. Close the Talent and Expertise Gap

With specialized AI and cybersecurity talent at an all-time premium, internal teams are often stretched thin.

  • The Fix: Look outward to scale capabilities. Consider leveraging strategic managed security service providers (MSSPs) to bridge gaps, particularly for complex emerging fields like cloud security and AI-driven defense.Concurrently, invest heavily in upskilling your existing workforce on AI governance and risk oversight.

Final Thoughts

AI is a powerful force multiplier—it expands the attack surface for adversaries, but it is also essential for defending modern enterprises at scale. Closing the gap outlined in PwC’s report requires more than just a larger cyber budget; it demands deliberate governance, clear accountability, and a balanced approach to human-machine trust.