Who Should Own AI Governance in a Growing Company?
IT, legal and security all have a claim. Giving it to any of them produces a predictable failure, and so does giving it to all three.

Erin Moore
Fractional Chief AI Officer
AI governance should be owned by one named person with authority over the AI budget — usually whoever owns the AI portfolio, reporting to the CEO. Not IT, not legal, not a committee. Each of those produces a specific and predictable failure, and understanding which failure helps explain why single ownership wins.
The three defaults and how each fails
Give it to IT and governance becomes a security review. Tools get assessed on data handling and access control, which matters, while nobody asks whether the tool produces good decisions or whether the process it automates was worth automating. You end up with safe, well-administered software that nobody can prove was worth buying.
Give it to legal and governance becomes risk avoidance. The output is a long policy written to survive a hypothetical dispute, which staff route around because it makes ordinary work impossible. Governance that is ignored is worse than none, because it creates a written standard you are visibly failing.
Give it to a committee and governance becomes latency. Decisions wait for the monthly meeting, teams stop asking, and you have manufactured the shadow AI the committee existed to prevent. Do you need an AI governance committee covers the narrow cases where the structure genuinely earns its overhead.
Why budget authority is the deciding factor
Governance without budget authority is advice. The person who can say "we are not buying that" or "we are switching that off" is the only person whose decisions bind, and separating the governance role from the spending role means every real decision gets escalated anyway.
This is why the seat usually sits with whoever owns the AI portfolio. They are already deciding what gets funded; governance is the same decision viewed from the risk side.
What the owner actually does
Four recurring responsibilities, none of which requires a department:
- Maintains the approved list and the route for adding to it, measured in days rather than weeks.
- Keeps the register of AI systems in use, what data each touches and who owns it. NIST's AI Risk Management Framework treats this inventory as foundational, and it is what you reach for when a customer asks how their data is handled.
- Runs the standing agenda item — fifteen minutes in an existing leadership meeting on what was adopted, declined, or went wrong.
- Owns the policy, one page, reviewed quarterly. The free template is a starting point rather than a project.
What about small companies with no obvious owner?
Below roughly fifty people the answer is usually the CEO or COO directly, and the whole apparatus is a page and a spreadsheet. That is not a lesser version of governance — for a company making three AI decisions a quarter, it is the right-sized version.
Where the decision volume outgrows the CEO's attention but does not justify a full-time executive, this ownership is one of the things a fractional Chief AI Officer carries. For the fuller structure, see the AI governance framework.
Frequently asked questions
Who should own AI governance? One named person with authority over AI spend, usually whoever owns the AI portfolio, reporting to the CEO. Governance without budget authority is advice, and advice gets escalated rather than followed.
Why not give AI governance to IT? Because IT will govern it as a security question. Data handling and access control get scrutinised properly while nobody asks whether the tool produces good decisions or whether the process deserved automating.
Should legal own the AI policy? Legal should review it, not own it. Legal-owned policies optimise for surviving disputes, which tends to produce documents so restrictive that staff work around them — leaving you with a written standard you are visibly failing.
What if we are too small to have an owner? Then the CEO or COO owns it directly, with a one-page policy and a register. For a company making a few AI decisions a quarter that is the correctly sized answer, not a compromise.
Further reading
Tagged with:
Ready to Automate Your Business?
Let's discuss how AI automation can deliver measurable ROI for your organization in 90 days or sooner.