Skip to main content
AdvisoryBy Jason LeeSeptember 4, 202613 min read

Five Over the Speed Limit: Who Actually Owns AI and Cyber Risk?

The direct answer: no title owns AI and cyber risk cleanly today, and in most organizations it lands with whoever is closest to business outcomes and most trusted, not with whoever the org chart names. On episode six of The Blind Spot, Chad Lorenc of AWS makes the case that the most durable answer is to elevate the CISO into a true C-level CSO who owns AI security and reports to the CEO and board, because the core of protecting AI, transparency, input and output validation, data hygiene, and access, is security work. What follows is his argument, and the trap the CTO, the CIO, and the new chief AI officer each fall into.

Drawn from The Blind Spot, episode six, recorded September 2026 with Chad Lorenc, Global CSO, board director, and Security Practice Manager at AWS.

Every few years a new title appears at the top of the org chart and a quiet fight breaks out over what it actually owns. Episode six of The Blind Spot is about the current version of that fight: who owns AI and cyber risk when the CTO, the CIO, and the CISO all think they do.

Chad Lorenc has sat in most of those chairs. He founded a startup and was its CTO, built a bank's security program from scratch as an early CISO under Gramm-Leach-Bliley, served as chief architect and then deputy CISO at a Fortune 500 with security deployments across three dozen countries, and now advises Fortune 500 security leaders on cloud and AI security strategy at AWS. That range is the point of the conversation: he has argued this turf war from every side of the table.

The winner is rarely the person who is right

Jason opens with the question the episode is named around: when a CTO, a CIO, or any other C-level leader disagree in the room, who is actually right, and how do you tell? Chad's answer reframes the question. He does not tell you who is right. He tells you who wins.

"The winner in those is always the person that's tied to business outcomes."

Sometimes that is the CISO, if they are well positioned and smart about using security to enable technology. A lot of the time it is the CTO, who already leans into moving fast. It is rarely the CIO, whose role has narrowed to cost controls and process. The common thread is not correctness. It is who can speak the terms the rest of the executive staff and the board understand. The person who translates a technical position into a business one wins the room, even when someone quieter in the corner is more right.

Drive five over, not ten under

Jason pushes on the phrase "well positioned," and Chad's answer is the line the episode is titled after. Reporting structure, he says, is usually the CISO's problem, not their advantage. Unless you are in a bank with a chief risk officer, or you are lucky enough to be a true C-level reporting to the CEO, most CISOs report through the CIO and have to build credibility rather than inherit it. And the way they lose it is predictable: the ones who take too many risks to make friends blow up, and the ones who are all restrictions, speed bumps, and red tape burn out trying to stop a train they cannot stop.

"The most dangerous drivers on the road are actually the ones that go five to ten under the speed limit. I want to be in a car with a CISO that's going about five over the speed limit."

The metaphor carries his whole philosophy of the role. A CISO is not there to avoid risk. They are there to take the best calculated risk. The one who explores whether a bad idea can be made into a workable one, and who protects the business from a real loss when they do say no, earns the standing to be believed the next time. That is the difference between a trusted business advisor and the person who predictably produces the same compliance checkmark that says no. It is the same translation problem Antonio Bovoso described from the boardroom in episode one, seen from the driver's seat.

Cloud did not start the war. Shadow IT did.

Chad calls cloud migration the real inflection point for the confusion over these roles, but the crack showed up earlier. As IT matured it compartmentalized, chased cost savings and outsourcing, and the CIO became the person who ran a cost center. Weighed down by security, compliance, and every other cost pressure, that center hardened into a department of red tape. The first visible symptom was shadow IT.

"Shadow IT was the first sign that the CIO was no longer mapping to the business."

Then the cloud arrived and any shadow IT person with a credit card suddenly had access to nearly everything central IT could do, faster and easier, if less safely. The business leaned in hard. The organizational answer, one that AWS itself helped drive, was to stand up an office of the CTO built to move fast, which was in effect a direct attack on the CIO role. Now one group moved methodically and securely while another moved fast and less securely, and the chasm between them widened as the cloud grew. The DevOps engineer who was also the security team and the compliance team worked fine for one experimental app and broke completely at fifty. That 2006 to 2014 gap, he argues, is where today's competing CIO and CTO roles were born, and it never got fixed.

The chief AI officer owns everything and nothing

So where does the newest title land? Chad is blunt: the chief AI officer is the unfortunate person tasked with somehow blending the CIO and CTO roles, and it inherits an older failure. The CIO connected to the business through applications. Data lakes and then AI revealed that the value was never in the apps, it was in the data inside them. When that value moved out of applications and into the lake, no one truly owned it, so the chief data officer was invented to own data that was still actually owned by the business and the apps themselves.

"What does a chief AI officer really own? They own everything and nothing."

The chief data officer quickly became a governance officer of data, and the first pain point in AI turns out to be exactly the data hygiene problem that was never solved: tagging, classification, identification, and then access through identity and access management. Those problems carried straight into AI, which is now embedded in nearly every application. The chief AI officer, like the chief data officer before them, ends up a governance role, and the honest question becomes whether that is a role at all or just part of a risk officer's remit. It is the same unclassified, ungoverned data that Heather Case-Hall showed AI can already reach in episode five.

Who owns AI in your organization?

Glance's AI Governance module inventories your AI systems, maps who and what can reach your data, and keeps the register current, with an advisor working from the same state.

See AI Governance →

The case for the CISO owning AI

Chad admits his bias, then makes the argument anyway. If AI governance has to span the enterprise, the apps, the cloud, and the data, that starts to sound an awful lot like the chief security officer's job.

"The only part of AI that's not security is the building of the inference."

Transparency, input and output validation, data hygiene, access hygiene: every element of protecting AI is a security function. Before any algorithm runs, someone has to decide what data is allowed into it, which is a security decision. His conclusion is to elevate the CISO out from under the CIO into a true C-level CSO who owns AI security, reporting to the CEO and the board rather than to the CIO or CTO. You still keep AI specialists, but the accountability sits with the person whose discipline is already governance.

Nobody buys least privilege

The most useful few minutes for any security leader writing a budget request is Chad's take on why those requests fail. His favorite example is the one control everyone agrees they need and no one will fund.

"Nobody wants to buy your least privilege."

You can cross out least privilege and write zero trust over the top of it, and that might buy you a few more legs, but they are strategies and principles, not the value a board, a CIO, or a CEO will pay for. The move is to sell the business outcome the control enables. Instead of asking for least privilege, a CISO working with a CTO who wants to move fast and a business chasing a market can offer to build, launch, and secure accounts at scale instantly, with security baked in, visibility for the CISO, and operational controls for the CIO and CTO. That is least privilege in the cloud, described in the language of the compliance checkmarks it clears, the speed it adds to the pipeline, and the market share the board already expects to capture. Same work, fundable framing. It is the mirror image of what Chris Carter said finance actually hears when security says risk.

What really resolves the fight: trust

When two leaders are genuinely at odds and a CEO or board has to decide, two things settle it. The first is business outcomes and the ability to speak to them. The second is trust, and Chad is clear it often matters more.

"Not always the person that's right wins those battles. It's often the person that's earned the most trust."

His proof is a story. As a CISO he faced a project that broke the rules: putting vending and dorm access onto the company's ATM cards, a Visa no-no with real liability attached. Rather than reflexively refuse, he investigated whether the problem was solvable, and it was. Because most cards read in both directions, he got authorization from Visa to run one track with the Visa number and CVV and the other with the data the campus needed, and worked the legal pieces through. The CISO was the only person in the room who could hold that conversation with Visa, with the lawyers, and present both the risk and the mitigations at once. After that, every time he said no, the business knew it really meant no. The credibility to say "that is fifteen over the speed limit and we are not going there" is earned by first proving you will find the way to yes when one exists.

People, process, and the four CISO profiles

Asked where security programs actually fail, Chad separates two things leaders conflate. The talent gap is real on a numbers basis, but he has four CISO profiles he can drop nearly any security leader into, and they predict how far that person gets. The GRC and compliance-checkbox profile, without the builder and solver technical side underneath it, is limiting: those leaders say no more often and enable the business less. The powerful combination is the architect background paired with the willingness to go five over the speed limit but not fifteen. Governance still matters enormously, but on its own it produces roadblocks, and in a world where what you know today can change tomorrow, the job is to enable securely rather than to block.

The first question a board should ask

The Blind Spot ends every episode by asking the guest to pick a side of the table and name the one thing they wish that side understood. Before he gets there, Chad answers a related question about what boards should ask, and the answer is not the one most boards reach for.

"The first question should be, what is our transparency?"

Boards get hung up on governance before they have visibility. Do we have an AI policy is the wrong opener, because a policy with no transparency behind it does not save you, it just becomes the standard you are later measured against and failed by. Know where AI is being used, how, and why, and whether you can explain it. Explainability is the next layer: once you can explain why something was done and why it produced the output it did, you have something far more valuable than a stack of policy documents, and something you can actually build policy around.

Then the one thing he wishes boards understood, which is also why transparency cannot wait:

"You're already using AI. You're using AI all over the place."

There is no holding off until a policy exists. If it is not happening directly through a frontier model, it is happening indirectly through the models embedded in the apps, APIs, and vendors already in the environment, some of them ingesting data nobody realizes. Deciding you are not ready for AI does not slow it down. It only means it is happening without you watching. The shift a board has to make is from approving AI to seeing it, as fast as possible.

Listen to the full episode

The full conversation runs about 33 minutes and is worth the time for any CISO, CTO, or board member trying to work out who owns AI risk before the next incident decides it for them. Watch or listen here:

Chad Lorenc is a Global CSO, board director, and Security Practice Manager at AWS. New episodes of The Blind Spot are released every two weeks. If you cannot yet answer who owns AI and cyber risk in your organization, talk to a Z Cyber advisor.

Frequently Asked Questions

When the CTO, CIO, and CISO disagree about AI, who wins?

According to Chad Lorenc, the winner is almost never the person who is technically right. It is the person tied most closely to business outcomes and able to speak the terms the rest of the executive staff and the board understand. Sometimes that is the CISO, if they are well positioned and use security to enable technology. Often it is the CTO, who already leans toward moving fast. It is rarely the CIO, whose remit has narrowed to cost control and process. The decider is who connects to the business, and just behind it is who has earned the most trust.

What makes a CISO well positioned to influence AI decisions?

Credibility, not the reporting line. Most CISOs report through the CIO and have to build credibility rather than inherit authority. Chad Lorenc's test is a driving metaphor: the most dangerous drivers go five to ten under the speed limit, and a CISO is not there to avoid risk but to take the best calculated risk, about five over. The CISO who occasionally says yes, and whose rare no has been proven right, becomes a trusted business advisor. The one who always says no becomes a speed bump the business routes around.

Is the chief AI officer a real role or just a renamed chief data officer?

Chad Lorenc argues the chief AI officer inherits the same trap as the chief data officer: they own everything and nothing. The chief data officer was created to own data that was still actually owned by the business and the applications, so the role collapsed into governance. AI is now embedded in nearly every application, and its core problems, transparency, input and output validation, data hygiene, and access hygiene, are security functions. In his view the more durable move is to elevate the CISO to a true C-level CSO who owns AI security, reporting to the CEO and board rather than to the CIO or CTO.

Why is it so hard to get budget for least privilege and zero trust?

Because nobody buys the control, they buy the outcome. Least privilege and zero trust are principles, not products, and they do not move a board, a CFO, or a CTO on their own. The same work sells when it is framed as a business outcome: the ability to launch, run, and secure new accounts at scale with security baked in, which lets an application reach market faster and capture the market share the board is already counting on. The control is identical; the framing is what gets funded.

What is the first question a board should ask about AI?

Not whether the organization has an AI policy. Chad Lorenc's answer is transparency: do you know where AI is being used, how, and why, and can you explain it. A policy written without that visibility only becomes the standard the organization is later measured against and failed by. Once transparency exists, explainability follows, and together they are worth more than a stack of policy documents, because they are what you actually build defensible policy around. The uncomfortable premise underneath it: the organization is already using AI, everywhere, whether or not anyone has approved it.

Subscribe for Updates

Get cybersecurity insights delivered to your inbox.