AI security belongs to the CISO. Except in 3 cases.

AI Security belongs to the CISO. Except in 3 cases

There’s a question I hear come up often these days:

“Does every organisation needs a Chief AI Security Officer?”

The answer in most organisational scenarios is that AI security belongs to the CISO.

But there are a few exceptions.

And you want to know which is the standard approach and which is the exception, because getting this question wrong either results in a duplicated function nobody that has no funding, or a seam without anyone watching.

Make sure to read until the end, because there’s an important nuance for non-corporate Commonwealth entities in Australia.

Why the standard approach works

The 9-layer map from Tuesday is a key reason why. Looking at it what do you see…

Compute. Data pipelines. Build environments. Artifacts. Deployment infrastructure. Runtime. Connectors. Credentials. Monitoring.

Every one of those is a discipline the security function already owns from a security standpoint, for every other system in the estate.

Split them and you just introduced a boundary. And as we know all too well, boundaries like this are where incidents live.

Imagine this: if AI security sits outside the CISO’s remit, then somewhere there’s a line where an agent’s credential stops being an identity problem and starts being an “AI problem”… and no incident respects that framing at 3:00am.

The market has largely settled this already: the 2026 Cisco/Splunk CISO Report surveyed 650 CISOs across 9 countries (including Australia), and found nearly all of them now carry responsibility for AI governance and risk management.

(Note though that its fieldwork was done in mid-2025 and a 12-month lag matters in this field)

But the direction of travel it gives us is clear.

The objection I hear from CISOs

Whenever I present this view one-on-one, the same kind of response comes back. And it’s fair. Somthing like…

“We are already underwater and stretched. This would just hand us a ninth layer, a new asset class, and a non-human identity population that’s mushrooming faster than our human one. So you want me to do this with what headcount exactly?”

It’s tongue in cheek and humourous… but truth be told… I don’t have a comfortable answer to that yet.

What I do have, is an honest one.

This scope has arrived whether or not anyone accepted it.

Because guess what?

Agents are already deployed, already holding credentials, already acting in production. The only question on the table is whether someone is accountable for them. Because unowned scope doesn’t stay unowned – it stays unmanaged until it becomes an incident, and then it lands on the CISO anyway. Just at 3:00am, with a regulator on the call.

So the real ask isn’t “absorb this quietly and absorb this now.”

It’s: take the accountability, and use it as the lever. An AI estate you’re accountable for is a budget line you can defend. One you’ve informally inherited is neither.

And if that trade isn’t available to you – if the accountability comes with no funding and no authority to stop a deployment – then that itself is the finding to put in front of the risk committee… in writing.

The 3 exceptions to this

When model risk management (MRM) already exists as a regulated function.

Banks and insurers with mature MRM have a function with quantitative skills the security team simply doesn’t have. And a regulatory home for model performance, validation and bias.

Pull AI oversight wholesale into security and you duplicate that function, but staff it worse.

The split here is clean. Model risk owns whether the model is right. Security owns whether the system can be compromised. They meet at assurance.

When you build AI rather than buy it.

If you ship models to customers, safety questions – harmful output, misuse, unintended capability – become product decisions. With commercial and legal consequences that sit well outside a CISO’s authority.

Security still owns the estate. It just doesn’t own whether a feature should exist.

When statute puts the owner somewhere else.

This is the case most often missed. And Australia has the clearest example going.

What the Commonwealth actually did

The APS AI Plan required every non-corporate Commonwealth entity to appoint a senior leader as Chief AI Officer by 30 June 2026.

And that requirement sits alongside an older one – the Policy for the responsible use of AI in government already mandated an AI Accountable Official.

So: two roles. That’s deliberate.

  1. The Accountable Official carries governance, compliance and risk.
  2. The Chief AI Officer leads adoption, transformation and capability building. Government was explicit that CAIOs complement rather than replace Accountable Officials.

Which means the largest AI governance restructure in the country split the job along the line between making it happen and making it safe

And gave neither half to the security function.

In several agencies the CIO holds the Accountable Official role. In others the split runs through entirely different offices.

So if you’re inside a Commonwealth entity arguing that AI security should be a standalone reporting line, you’re arguing against a structure that’s already mandated and already staffed.

The useful question there isn’t who owns AI. It’s how security gets a formal seat in a governance model that’s been designed without it.

A word on the title

Small caution for anyone building a business case around the words Chief AI Security Officer.

The function is real, and growing. It’s just that title is not yet standard – right now it exists more as a certification program than an established enterprise role, and it isn’t a title an Australian board will recognise from a shortlist yet.

Ask for it and you risk inviting an unflattering response that you’re looking for a promotion rather than a real control.

So ask for the mandate instead. Four things, and the title becomes a detail:

  1. An AI asset inventory that you own, and that is authoritative.
  2. Mandatory security review before any AI system reaches production.
  3. Authority to stop a deployment – exercised at least once, so everyone knows it’s real.
  4. And a standing report to the risk committee that goes up whether or not anyone asked for it.

In this changing landscape, an executive with those four things and no title outranks one with the title and none of them.

The test

Name the person who could be called at 3:00am about an agent that has taken an action nobody authorised.

Not the team

…The person.

If you had to think about it for more than a second or two, that’s your big ticket Monday morning to-do list item for you.

Aaaannd that’s a wrap for week 1. Next week I’m going down to the data layer: what the AI data pipeline actually consists of, where poisoning happens, and why data provenance has quietly stopped being an engineering nicety and become a regulatory artifact.


Sources

About Satheeshan Siva

Continue the conversation.

I write about what emerging technology makes possible and what it takes to make it work inside a real organisation. If you disagree with something here, or want to discuss what it means for yours, get in touch.