In many IT companies today, it plays a role it should never have been given. It is supposed to ensure security, assess suppliers, block risky ideas, monitor the use of AI, protect data, and even take responsibility for the consequences of decisions made by other departments. In practice, it becomes the last line of defence against the risks created by the entire organisation.
This model is no longer scalable
Technology is no longer the sole domain of the technology department. Marketing buys its own SaaS platforms, HR implements recruitment tools, finance automates processes, and employees use generative AI, often without IT’s involvement. According to the Stanford AI Index 2026, 88 per cent of organisations surveyed were already using AI in 2025, and 70 per cent were using generative AI in at least one business function.
The scale of adoption is growing faster than the ability to control it. IBM reports that 63 per cent of the organisations surveyed lacked adequate governance mechanisms for AI. In companies with high levels of ‘shadow AI’ – that is, the use of unauthorised tools – the average cost of a data breach was $670,000 higher. Of the organisations that experienced an AI-related security incident, 97 per cent lacked proper access control mechanisms.
This highlights a fundamental problem. IT can secure the platform, but it is unable to control every decision regarding what data an employee enters into the model, in which process the algorithm will be used, or whether the supplier chosen by the business department is worth the risk involved.
An IT failure can, above all, be a business failure
This is equally evident in the costs of major incidents.
Following the cyberattack on MGM Resorts in 2023, the company estimated the negative impact of the disruption on the adjusted operating profit of its properties at around $100 million. One-off costs for technology consultants, lawyers and other advisers amounted to less than $10 million.
The proportion is telling. The biggest problem was not fixing the technical cause. The cost lay in the unavailability of services, booking issues and disruption to hotel operations.
An even larger-scale disruption was caused by a faulty CrowdStrike update in July 2024. Delta Air Lines cancelled around 7,000 flights over five days. The problems affected 1.4 million passengers. The company reported around $380 million in lost revenue and a further $170 million in additional operating costs.
Servers and applications form part of the IT infrastructure. Cancelled flights, customer refunds, idle staff and lost revenue do not.
Therefore, attributing full responsibility for technological risk to the CIO is fundamentally flawed. The more digital a company is, the less sense it makes to separate ‘IT risk’ from business risk.
Regulations are now formalising this shift
By 2026, this is no longer merely a discussion about best practice.
DORA explicitly states that, in financial institutions, ultimate responsibility for ICT risk management rests with the management body. It is the management body that approves the digital resilience strategy and the risk tolerance level. Similarly, NIS2 requires management bodies to approve cybersecurity risk management measures and oversee their implementation.
In Poland , the amendment to the Act on the National Cybersecurity System implementing NIS2 came into force on 3 April 2026. According to the Ministry of Digital Affairs, the new regulations may apply to around 38,000 entities.
Added to this is the AI Act. Most of its provisions came into force on 2 August 2026, including some of the requirements concerning the transparency of AI systems.
The common thrust of these regulations is clear: responsibility for technology cannot simply be handed off to the IT department.
The CIO is not the corporate guardian of common sense
The role of IT remains to create the architecture, security standards, access controls, system resilience and mechanisms for identifying risks. However, the NIST Cybersecurity Framework 2.0 places cybersecurity squarely within the organisation’s risk management system and emphasises the role of senior management in setting priorities and defining risk tolerance.
The boundary should therefore be clearly defined. IT is responsible for the quality of the technological mechanisms. The business process owner is responsible for how the technology is used. The board is responsible for the risks the company consciously takes.
If, before implementing AI, purchasing a system or signing a contract with a supplier, the most important question is ‘has IT approved this?’, the organisation has probably defined the problem incorrectly.
The right question is: who owns this decision, its economic rationale and its consequences?
