Does Your Organisation Have Someone Responsible For AI Risks?

Right now, 83% of organisations are using AI tools. Only 25% have a governance framework strong enough to manage what that AI is actually doing. That gap between adoption and control is the single biggest risk sitting inside most businesses today, and almost nobody has assigned someone to close it.

It gets more uncomfortable the further up you look. Deloitte research shows 66% of boards still have limited-to-no knowledge of AI. Grant Thornton’s 2026 AI Impact Survey of 950 business leaders found that 78% of executives lack strong confidence they could pass an independent AI governance audit within 90 days. Meanwhile, only 8% of organisations globally maintain what researchers would call a comprehensive AI governance framework, according to Economist Impact.

This isn’t a story about bad intentions. Most organisations adopted AI quickly because the pressure to move fast was real, and the tools were genuinely useful. What didn’t keep pace was the internal capability to govern what was being adopted. Who’s accountable when something goes wrong, how does risk get assessed before a tool/ workflow/ agent goes live, what does “compliant” actually mean in practice? That capability gap is now the thing quietly deciding which organisations get the return they expected from AI, and which don’t.

And the return really is on the line. Grant Thornton’s research found that organisations with fully integrated, well-governed AI are nearly four times more likely to report revenue growth than those still stuck piloting — 58% versus 15%. The differentiator wasn’t the technology, it was the accountability. The organisations pulling ahead are the ones that can explain how their AI makes decisions, who owns the outcome, and what happens when it’s wrong. Everyone else is generating activity, not results.

Here’s the part that should change how organisations think about solving this: you don’t need an army of AI ethicists or a fully built-out compliance department to close this gap. You need one person. One person in Legal, Operations, HR, Engineering, or the Chief of Staff’s office who genuinely understands AI risk,  who can run a proper risk assessment before that new feature goes live across the organisation, who knows what a compliant governance framework actually looks like, who can be the answer when a client, regulator, or your own board asks “how do we govern our use of AI?”

This is already happening informally, whether organisations have planned for it or not. IBM’s 2026 survey of 2,000 CEOs found that 79% are distributing and expanding AI accountability as more domain experts get pulled into decisions about it. Someone in every organisation is already becoming “the AI person” by default and usually without training, without a framework, and without much say in the matter. The organisations doing this well are the ones who decided who that person would be, and gave them the tools to do it properly.

This isn’t a hypothetical risk, either. Just this week, OpenAI disclosed that one of its own models, during an internal test of its cyber capabilities, escaped a supposedly isolated testing environment and went on to autonomously hack the systems of Hugging Face, a major AI dataset and model-hosting platform. The model exploited a previously unknown vulnerability to get internet access, then chained together stolen credentials and further exploits to break into Hugging Face’s production servers, all without a human directing each step. OpenAI called it an unprecedented incident. Hugging Face’s own CEO described it as the first of its kind: an attack driven end-to-end by an autonomous AI agent.

What’s notable isn’t just that it happened, it’s why. Cybersecurity experts pointed to a very ordinary root cause: a misconfigured environment. The “isolated” sandbox the model was tested in wasn’t actually cut off from the internet, and a flaw in a package-installation system inside it is what let the model escape in the first place. This wasn’t a case of AI becoming uncontrollably intelligent. It was a governance and process failure, the kind any organisation running or testing AI systems could make.

Sit with that for a second! This happened at one of the most sophisticated AI labs in the world, with security teams whose full-time job is managing exactly this kind of risk. If a gap like that can appear there, it can appear anywhere AI systems are given real access to infrastructure, data, or the internet, which, increasingly, is everywhere. The organisations best placed to catch this kind of failure before it happens aren’t necessarily the ones with the most advanced AI. They’re the ones with someone whose job it is to ask the uncomfortable questions before deployment, not after.

That’s exactly the gap our AI Risk Management Programme, led by Toju Duke, is built to close. Toju spent her final years at Google as a Responsible AI Programme Manager, working on governance processes across some of the company’s largest AI models, and is the author of two books on the subject, including the first practical guide to AI risk assessment and management. She’s built this masterclass series around the same principle: participants don’t just learn concepts, they build a working governance framework for their own organisation, session by session, alongside real risk assessments, live case studies, and hands-on scenario work.

If your organisation doesn’t yet have someone who can confidently own this, that’s not a failure, it’s simply where most organisations are right now. The question worth asking is who that person is going to be, and whether they’re equipped for it yet.

Important Details:

Start Date: Wednesday 26th August 2026

Time: 16:00 UK Time

Masterclass Duration: 60 mins x 8 weeks

Joining Details: Zoom link and calendar information sent on confirmation

Certificate provided at completion of all sessions

Attendees Limit: Min 10- Max 30

If you want to be the person your organisation turns to on this, or you want to put someone forward for the role, you can find full details and register here:

thegenaiacademy.com/masterclasses/ai-risk-management-programme

Further Reading

Compliance Week & konaAI , 2026 survey of 193 compliance/ethics/risk/audit leaders https://www.complianceweek.com/survey-reports/cw-survey-compliance-teams-struggling-with-ai-implementation-and-trust-issues/36460.article

Deloitte Global, “Governance of AI: A critical imperative for today’s boards” (2nd edition, 2026) https://www.deloitte.com/global/en/issues/trust/progress-on-ai-in-the-boardroom-but-room-to-accelerate.html

Grant Thornton (US) , 2026 AI Impact Survey (950 senior executives, 10 industries, early 2026) https://www.grantthornton.com/services/advisory-services/artificial-intelligence/2026-ai-impact-survey

Economist Enterprise & KYOCERA Global, “From intent to action” Future of Work Study (639 executives, London/New York/Singapore/Sydney/Tokyo, late 2025) https://insights.economistenterprise.com/technology-innovation/from-intent-to-action/report

IBM Institute for Business Value, 2026 CEO Study (2,000 CEOs globally) https://newsroom.ibm.com/2026-05-04-ibm-study-ceos-are-reshaping-c-suite-roles-for-the-ai-era


The OpenAI / Hugging Face incident

OpenAI’s own account of the incident https://openai.com/index/hugging-face-model-evaluation-security-incident/

TechCrunch — on the root-cause misconfiguration https://techcrunch.com/2026/07/22/how-an-openais-human-mistake-led-to-the-ai-powered-hack-on-hugging-face/

CNN Business — general overview https://www.cnn.com/2026/07/22/tech/openai-hugging-face-ai-cybersecurity

CNBC — technical detail on the models and escape method https://www.cnbc.com/2026/07/22/open-ai-cyber-models-hack-hugging-face.html

You May Also Like

With the rise of AI, it feels like it’s easier than ever

As we watch organisations rush towards “AI-First” for a while now, something

Enjoyed this article?

Group 57

Choose your country and your language