CIOs Face Growing Challenge in Governing AI Agents

IT leaders are finding themselves accountable for AI systems they don’t fully control as business units increasingly deploy agents without IT oversight. According to a recent IBM Institute for Business Value study, two-thirds of CIOs and CTOs feel responsible for these uncontrolled AI deployments.

The Scale Problem

The pace of AI adoption is outpacing governance capabilities. Organizations are deploying tech systems faster than IT can track, with CIOs expecting a 38% increase in AI agents next year—yet only one in ten IT leaders feels prepared for this scale.

This trend creates tension when IT is held accountable for outcomes they cannot fully manage. As Ben Schein, Chief AI and Analytics Officer at Domo, explains: “The pace problem isn’t that AI is being shipped recklessly; it’s that adoption exceeds governance adaptation rates.”

The Visibility Gap

Many AI deployments occur invisibly to IT leadership. When employees in marketing, finance, or product connect LLMs to workflows or give agents access to data—without IT awareness—the cumulative impact becomes difficult to track.

This lack of visibility creates significant risks regarding:

  • Security vulnerabilities from unauthorized agent access
  • Compliance issues with data usage policies
  • Unexpected costs and inefficiencies
  • Quality control concerns when non-experts build AI solutions

Toward Agent Governance as Standard Plumbing

Experts emphasize that effective AI governance requires more than just policy documents—it needs to be integrated into the core IT infrastructure.

“CIOs who’ll succeed in the next 24 months will embed observability and policy enforcement where data already lives,” says Schein. This approach treats AI agents like employees, tracking their activities, outputs, costs, and issues.

Itai Schwartz, cofounder and CTO at MIND data security vendor, adds: “Every AI tool should have a designated business owner accountable for its performance—and most importantly, we need to ensure these systems operate within defined guardrails.”

By treating AI governance as essential infrastructure rather than an afterthought, IT leaders can help organizations harness the benefits of agentic AI while managing associated risks.