Bonfy Blog

Naming an AI Owner Is Not the Same as Governing AI Data

Written by Gidi Cohen | 9/29/26, 8:41 PM

Fifty-three percent of organizations now say someone at the C-suite level or above is accountable for AI-informed decisions, according to KPMG's Global AI Pulse Q3 2026 survey of 2,131 senior leaders across 20 countries. That number sounds like progress, and in one sense it is. It also masks the harder question KPMG's own data raises: naming an executive owner and actually governing what AI systems and agents do with sensitive data are two different achievements, and most organizations have only managed the first one.

Key Takeaways

  • KPMG's Q3 2026 Global AI Pulse survey found 53% of organizations place accountability for AI-informed decisions at the C-suite level or above, including 18% where the CEO or executive committee holds that responsibility directly.
  • 86% of organizations say they are adapting their cybersecurity operating model to address AI-accelerated threats, according to the same survey.
  • KPMG has separately reported that 44% of employees have used AI in ways that do not adhere to corporate policies and guidelines, a gap that named executive accountability alone does not close.
  • Named accountability without content-level enforcement and audit trails leaves organizations able to say who is responsible for AI risk while remaining unable to show what their AI agents accessed, transmitted, or generated.

What the KPMG Global AI Pulse Q3 2026 Survey Found

KPMG's fieldwork ran from July 23 to August 26, 2026, surveying senior leaders at organizations with at least $50 million in annual revenue. The headline finding is a shift in enterprise priorities: as AI adoption matures past its early pilot phase, KPMG found organizations moving their attention toward accountability, resilience, and connecting AI cost to measurable value rather than adoption volume alone. On accountability specifically, 53% of respondents said a C-suite-level executive or higher owns responsibility for AI-informed decisions, with 35% pointing to a named executive and 18% pointing to the CEO or executive committee directly. In the United Kingdom, that figure climbs to 64%, against a 54% global average outside that specific market.

The survey also found that 86% of organizations are adapting their cybersecurity operating model specifically to address AI-accelerated threats, evidence that boards understand AI has changed the threat surface even where the response has not fully caught up. KPMG's broader Q3 dataset points to a parallel gap in financial discipline: 61% of organizations review AI costs during approval and 59% monitor them in operation, but only 12% consistently assess AI value against cost across the whole organization.

Read together, these numbers describe an enterprise population that has recognized AI accountability as a governance problem worth naming at the top of the org chart, while still building the operational muscle to back that accountability with evidence.

The Accountability Gap Between Naming an Owner and Governing the Data

Here is the uncomfortable arithmetic KPMG's survey leaves unresolved: a named executive accountable for AI-informed decisions is only as useful as the evidence that reaches them. An executive who owns AI risk on paper but cannot see what a given AI agent retrieved from a customer record last Tuesday, or which employee pasted a client's financial details into an unsanctioned chatbot last month, is accountable in name only. KPMG's own research on workforce behavior sharpens this point: the firm has reported that 44% of employees have used AI in ways that do not adhere to corporate policies and guidelines, activity that, by definition, does not show up in whatever governance dashboard the newly accountable executive is reviewing.

This gap between named accountability and actual visibility is exactly what shows up in Kiteworks' own research into AI governance maturity. Kiteworks has found that organizations score a mean AI Governance Maturity rating of roughly 35 out of 100, with a full third lacking evidence-quality audit trails entirely, and that those organizations run 20 to 32 points behind on every other maturity metric, including purpose binding and human-in-the-loop controls. A Kiteworks executive guide to AI governance for sensitive data makes the same argument from the opposite direction: exec-level ownership only functions when it is paired with acceptable use policies, defined accountability at the operational level, and audit trails detailed enough to support real decisions, not just quarterly summaries.

Why 86% Adapting Their Operating Model Still Miss Shadow AI

The 86% of organizations adapting their cybersecurity operating model for AI threats are, in most cases, adapting the parts of the model they can see: endpoint policy, network monitoring, and formal AI tool procurement. What that adaptation typically misses is the browser tab. Employees pasting sensitive data into an unsanctioned chatbot, or an unapproved AI plug-in quietly processing company documents, do not register in a security operating model built around managed applications and approved vendors.

Bonfy has tracked this exact blind spot in its own research: Shadow AI has moved to the browser, and security programs built around managing sanctioned enterprise software were never designed to see it. A separate Bonfy analysis found that shadow AI introduces a distinct category of risk beyond traditional shadow IT, because unapproved AI tools do not just store data outside sanctioned systems, they actively process, transform, and sometimes train on it, often in jurisdictions the organization never vetted. Kiteworks has documented the compliance exposure this creates in detail: unapproved tools can move regulated data across borders in ways that breach GDPR, HIPAA, or other privacy frameworks without a single traditional security control ever firing an alert.

An operating model adaptation that adds AI-specific incident response playbooks and threat intelligence feeds, without adding content-level visibility into what employees and agents are doing with sensitive data outside sanctioned channels, is solving the part of the problem that was already visible. The 44% of employees KPMG found operating outside policy are, almost by definition, in the part that is not.

Turning Named Accountability Into Enforceable Content-Level Control

Closing this gap requires shifting the unit of governance from the tool to the content. Rather than trying to enumerate and approve every AI application an organization's employees might touch, an impossible task given how quickly new tools and browser extensions appear, the more durable approach inspects what data is flowing into and out of any AI interaction, sanctioned or not, and applies policy at that layer.

This is the design premise behind Bonfy's Adaptive Content Security platform: real-time inspection of prompts, uploads, and responses across both human and AI-driven workflows, built to catch regulated or sensitive data before it leaves the organization regardless of which specific AI tool an employee happens to be using. Bonfy's approach to what it calls shady AI, meaning sanctioned tools being used in unsanctioned ways, addresses a variant of the same accountability gap: an approved AI vendor does not guarantee approved use, and a named executive cannot manage what content-level controls never surface.

For regulated industries, the stakes are sharper still. Financial services firms face obligations under GLBA, Reg S-P, and FINRA that attach to the customer relationship itself, a distinction an AI agent has no native way to recognize without content-level enforcement built specifically to carry that context forward. Kiteworks' review of AI governance solutions for regulated industries found that healthcare, insurance, and financial services organizations face compounding pressure from the EU AI Act and state-level frameworks like the Colorado AI Act, on top of their existing sector rules, making content-level enforcement less a competitive advantage than a baseline requirement.

One Policy Model for Humans and Agents: Where Bonfy and Kiteworks Meet

KPMG's accountability finding and Kiteworks' governance maturity research point to the same structural fix from different angles: accountability needs one policy model that covers data in motion, at rest, and in use, applied consistently whether a human employee or an AI agent is the one requesting it. Splitting human data governance from AI agent governance, which is how most organizations have built their controls to date, creates the exact seam where named accountability breaks down, because the executive accountable for AI risk is reviewing a different evidence trail than the one covering ordinary employee activity.

Kiteworks Compliant AI is built around closing that seam: a single policy engine and unified audit log governing both human and AI agent interactions with sensitive data, so the accountable executive KPMG's survey describes is reviewing one evidence trail rather than reconciling several. Bonfy's role in that combined model is the inline layer, classifying and enforcing policy on content as it moves through AI-driven and human workflows in real time, while Kiteworks provides the control plane, the access policy, identity model, and audit infrastructure underneath. Together they give the named executive something to manage: not just a title, but a data trail broad enough to justify the accountability KPMG's survey shows organizations are already assigning.

What C-Suite Accountability Should Look Like in Practice

Executives who now own AI-informed decisions on paper should ask three questions before the next board cycle. First, can the organization produce an audit trail showing what any given AI agent retrieved, transmitted, or generated over a defined period, covering both sanctioned tools and the unsanctioned ones KPMG's 44% figure implies are already in use? Second, does that audit trail cover human and AI agent activity under one policy model, or are they tracked separately in ways that would make a genuine incident hard to reconstruct end to end? Third, is content-level policy enforcement applied consistently across regulated data categories, such as the customer relationship data GLBA and Reg S-P govern in financial services, or does enforcement depend on which specific tool an employee or agent happens to be using that day?

Kiteworks' guidance on closing the AI governance gap frames these questions as the difference between assigning accountability and being able to defend it under regulatory scrutiny, a distinction that is likely to matter more, not less, as more boards follow KPMG's respondents in naming an executive owner without yet building the evidence base that role requires.

Named accountability is a real step forward, and KPMG's data shows most large organizations have taken it. The next step is making sure the executive who now owns that title has something better than a policy document to point to when a regulator, or a board member, asks what the organization's AI agents actually did with sensitive data last quarter. See how Bonfy's Adaptive Content Security platform gives that accountability something to stand on.

FAQs

1. What did KPMG's Q3 2026 Global AI Pulse survey find about AI accountability?

KPMG surveyed 2,131 senior leaders across 20 countries and found that 53% of organizations place accountability for AI-informed decisions at the C-suite level or above, with 18% assigning that responsibility to the CEO or executive committee directly, alongside 86% of organizations reporting they are adapting their cybersecurity operating model for AI-accelerated threats.

2. Does naming an executive accountable for AI reduce AI risk?

Only if that accountability is backed by content-level visibility and audit trails. Kiteworks' AI governance research has found that organizations lacking evidence-quality audit trails run well behind on every other maturity metric, meaning a named owner without the underlying data trail has responsibility in name but limited ability to act on it.

3. How would Bonfy and Kiteworks divide the work of supporting a named AI-accountable executive?

Bonfy operates as the inline layer, classifying and enforcing policy on content as it flows through AI-driven and human workflows in real time. Kiteworks provides the control plane underneath, the unified policy engine, identity model, and audit log that give the accountable executive one evidence trail rather than several disconnected ones. See Kiteworks Compliant AI for how the two layers connect.

4. Is Shadow AI still a risk even with 86% of organizations adapting their security operating model?

Yes. Most operating model adaptations focus on sanctioned tools and known vendors, which does not address employees using unapproved AI tools in the browser. Bonfy's research into shadow AI moving to the browser describes exactly this blind spot, and KPMG's own finding that 44% of employees use AI outside corporate policy suggests the gap remains wide.

5. What should a newly accountable AI executive ask their team first?

Whether the organization can produce a single audit trail covering both human and AI agent activity involving sensitive data, whether content-level policy enforcement applies consistently across regulated data categories, and whether that evidence would hold up under regulatory scrutiny rather than only in an internal governance review.

Gidi Cohen is VP Product at Kiteworks and co-founder and former CEO of Bonfy.AI, which Kiteworks acquired in September 2026. He writes about AI governance, data accountability, and the gap between assigning responsibility for AI risk and being able to prove it.