---
title: "Two-Thirds of CIOs Are Accountable for AI They Can't Control"
author: Mallika Bakshi
url: https://truehorizon.ai/news/two-thirds-of-cios-are-accountable-for-ai-they-can-t-control
description: "This is a guide on how CIO's can take charge on what AI product is being deployed and can confidently be responsible for it."
---

# Two-Thirds of CIOs Are Accountable for AI They Can't Control

> This is a guide on how CIO's can take charge on what AI product is being deployed and can confidently be responsible for it.



IBM's Institute for Business Value surveyed 2,000 technology executives across 33 geographies for a study released June 8, and the headline finding is a quietly alarming one: [two-thirds of them are being held accountable for AI systems they don't fully control](https://newsroom.ibm.com/2026-06-08-new-ibm-study-finds-cios-and-ctos-face-growing-ai-control-gap-as-enterprise-deployment-scales). The same executives are under pressure to do more, not less, with 80% reporting a direct CEO mandate to transform the business with AI. And only 11% feel ready for the scale of agents expected in the next year.



Put those together and you get a widening gap. Deployment is being pushed from the top, accountability sits with the CIO and CTO, and the visibility needed to actually govern what's running has not kept pace.

## The incidents are already here

This isn't a hypothetical about future risk. The same study found that the average organization logged 54 AI-agent incidents in the past year, and roughly one in six was high-severity, meaning it took more than four hours to contain. IBM's breakdown of the serious ones is the part that should get a CISO's attention: 37% involved data exposure, 33% caused cascading system failures, and 17% triggered compliance problems.



The agents are live, in other words, and so are the failures. What's missing in most organizations isn't awareness that AI carries risk. It's a clear enough view of what's actually running to catch a problem before it becomes an incident.

## How the gap forms

The control gap is a predictable result of the order things happened in, not a failure of effort. A CEO mandate lands, teams rush capable tools into production to meet it, and the governance work, the inventory of what's deployed, the ownership, the monitoring, gets treated as something to sort out later. Later tends to arrive as an incident.



The tell is speed without visibility. The organizations that end up exposed are the ones that scaled AI faster than they could account for it, which is exactly what an 80% mandate rate and an 11% readiness rate produce when they collide.

## The real cost of being answerable for the invisible

For a CIO, the uncomfortable part is that the accountability is real even when the control isn't. If an agent exposes data or makes a decision the company can't defend, "we didn't have visibility into it" is not a defense a board or a regulator accepts. The name on the org chart is answerable regardless of whether the tooling existed to see the problem coming.



That's why closing the gap is worth doing before the next mandate rather than after the next incident. The goal is simple to state: don't be accountable for AI you can't see.

## How True Horizon does it

This is the layer we build. We start by inventorying every AI system and agent running in production, with a named owner for each, so "what's actually deployed" stops being a guess. We put monitoring on what's already live before the next thing ships, and we match the pace of new deployment to the pace at which it can actually be governed. The result is that the AI a CIO is answerable for becomes AI they can actually see and control, which is the whole difference between a managed program and a growing liability.

## What to do now

Run an honest audit against the study's own framing. Can you name every AI system and agent in production, and who owns each one? Would your monitoring tell you about an incident before the fallout did? Is your deployment pace matched by your governance pace, or only by the CEO's mandate? If the answers aren't clean, you're in the two-thirds, and the fix isn't to slow the mandate. It's to close the distance between what you run and what you can see.



If you want to know where that gap sits in your own business, take our AI assessment and we'll map what's running, who owns it, and where the visibility breaks.

Source: https://truehorizon.ai/news/two-thirds-of-cios-are-accountable-for-ai-they-can-t-control
