Rob Sloan is VP of Cybersecurity Advocacy at Zscaler, where he helps organizations navigate cybersecurity risk and business resilience.
California’s recent decision to require each state agency to designate an AI cybersecurity officer isn’t just about adding another government title. To me, the bigger message is this: AI risk now needs a clear owner.
As companies push AI into revenue, operations and product development, a security failure could mean data exposure, legal trouble or a direct hit to customer trust. Not every company will need a permanent new C-suite title, but a Chief AI Cybersecurity Officer, or a clearly empowered equivalent, could be a smart move at this stage of AI adoption.
Isn’t This Already The CISO’s Job?
Most budget-conscious CEOs will ask the obvious question: why can’t the chief information security officer own this? Maybe the CISO should own it. The problem is that most CISOs are already overloaded. They own cloud security, identity, resilience, ransomware preparedness, third-party risk, incident response and board reporting, frequently all at once.
AI security is different from the cyber problems most companies already know how to manage, and adoption is moving faster than internal controls can keep up.
At many companies, AI is no longer experimental; it’s a central part of the growth plan. It’s showing up in products, support, software development and internal decision-making. Add AI agents to the mix, and the risk picture gets even harder to track. AI security simply cannot be treated as a side job divided between legal, IT, security and engineering.
This person responsible needs to move quickly and work with the business, not slow it down. In my experience in government, consultancy and the private sector, when security is seen as slowing deployments, business teams often bring it in too late or not at all. That is how shadow AI grows and how pilots become production systems before anyone has fully asked what data is being exposed, how models might be manipulated or what new attack paths have been opened. A leader focused on AI security is more likely to be in the room early, when decisions are still being made.
Why This Isn’t Just Another Security Problem
Most companies have a decent handle on traditional cybersecurity. AI security, however, is a different story. Prompt injection, training data poisoning, model manipulation, agent permission abuse and the leakage of sensitive information into unsanctioned tools create new exposures and expand the attack surface. If companies don’t secure these systems properly, the damage will be tangible: exposed data, misused tools and costly mistakes.
Attackers are moving faster as well. Attackers are already using AI to scale up their operations, and better models will only widen that advantage. Companies are deploying AI quickly while the threat environment is shifting just as fast. That alone is a strong argument for putting someone in charge who actually understands the technical risks.
Legal Coverage Isn’t Enough
The EU AI Act and similar rules are making AI governance a real operational problem: documentation, risk classification, oversight and board-level accountability all get harder once AI is embedded across the business. Legal and compliance teams will be essential in interpreting those requirements, documenting obligations and helping boards understand where exposure lies, but they cannot actually secure AI.
The value of an executive leading AI security shows up in technical execution: hardening models against prompt injection, setting guardrails and controlling what AI agents are allowed to do. This person shouldn’t replace legal or compliance; their job is to make sure policy turns into actual controls, testing and guardrails.
Some businesses will get there sooner than others. Regulated companies, multinationals and firms putting AI into customer-facing products will likely be first. This matters even more when the business handles sensitive data, owns valuable IP or depends on customer trust.
What Clear Ownership Actually Signals
This role can’t just be a blocker. It has to help teams innovate and move quickly without creating avoidable risk. If the role is successful, teams know who owns AI risk, while executives and the board get a more honest view of what’s actually exposed.
This may not need to be a permanent standalone role. Over time, as companies get better at governing and securing AI, the work may fold back into a broader security or technology leadership job.
Right now, clear ownership improves accountability and sends a signal inside and outside the company that AI risk is being taken seriously. More importantly, it puts someone clearly on the hook for managing it. If AI is shaping the future of the business, security can’t be an afterthought.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?







