AI Governance8 min read

Boards Are Now Appointing a Head of AI Governance. Here Is Why Australian Organisations Should Not Wait for a Mandate

Forrester expects 60 percent of Fortune 100 companies to appoint a dedicated head of AI governance in 2026, with Sony, Bank of America and UBS already there. Here is why the same accountability gap exists in Australian organisations of every size, and what a workable version of the role looks like without a Fortune 100 budget.

Shane CoetserBy Shane Coetser
The Risk of the Head of AI Governance

Forrester expects 60 percent of Fortune 100 companies to appoint a dedicated head of AI governance by the end of 2026. Sony, Bank of America and UBS have already done it. The title varies, sometimes it sits under a chief AI officer, sometimes it stands alone, but the pattern is the same: a single named executive whose job is to own AI governance as a function, not as a side project bolted onto someone's existing role.

Most Australian organisations do not have anyone in that position yet. And the gap between those two facts is where the real risk sits.

The scale of the mismatch is worth sitting with. Roughly 88 percent of organisations used AI in at least one business function during 2025, yet only 8 percent maintain what could reasonably be called a comprehensive AI governance framework. That is not a small gap. It is close to the entire market running AI without anyone clearly accountable for governing it.

Agentic AI is about to make that gap considerably more expensive. Around 74 percent of organisations plan to adopt agentic AI within the next two years, but only 21 percent currently have a mature governance model for autonomous agents. Security and risk concerns, not technical limitations and not regulatory uncertainty, are now the primary barrier cited by 62 percent of organisations trying to scale agentic AI. When the barrier to adoption becomes a governance problem rather than a technology problem, the absence of anyone accountable for governance stops being a paperwork gap and starts being a genuine operational risk.

Why "Everyone Owns AI Governance" Usually Means No One Does

Ask most organisations who owns AI governance and the honest answer involves several names: someone in legal, someone in risk, someone in IT security, occasionally a committee that meets quarterly. That arrangement sounds reasonable until an incident happens and it becomes clear that each of those people believed AI governance was primarily someone else's job.

This is a pattern we have seen play out consistently: distributed accountability across multiple functions tends to produce the appearance of governance without the substance of it. Everyone can point to a policy document. Almost no one can explain, in a single sentence, who decided a specific AI system was safe to deploy and who is watching it now that it is live.

What the Head of AI Governance Role Actually Covers

The role that Forrester is describing is not a rebadged chief information security officer or chief data officer, though it works closely with both. Its distinct remit is the AI use case register, the risk classification of each system, the assessment process before deployment and the ongoing monitoring after. It is the single point of accountability the fragmented model above is missing.

What is notable about the organisations that have already appointed someone to this role is that most of them did it before a regulator forced the issue. Sony, Bank of America and UBS are not organisations under active AI enforcement action. They made the appointment because the scale of their AI use had already outgrown informal, distributed governance.

Why Agentic AI Is Forcing the Issue Now

Agentic AI changes the calculation because agents act, they do not just respond. A chatbot that gives a wrong answer is a bad experience. An agent with the permissions to take an action based on a wrong judgement is a different category of risk entirely, and the OECD has been explicit that regulation needs to distinguish between different levels of autonomy in agentic AI deployments rather than treating all AI the same way.

That distinction matters practically, not just academically. An organisation deploying a dozen customer service chatbots and an organisation deploying a handful of autonomous agents that can approve transactions or modify records are facing genuinely different risk profiles, even if both fall under the same generic AI governance policy on paper. Someone needs to own the judgement about which agents get which level of autonomy, and that judgement needs to sit with a named person, not a quarterly committee.

What This Looks Like for a Mid-Market Australian Organisation

Most of the coverage of this trend is written for Fortune 100 companies that can justify a full-time C-suite hire dedicated entirely to AI governance. That framing is not much use to the mid-market Australian organisation that has real AI governance exposure but nowhere near the budget or the volume of AI use cases to justify a full-time executive role.

In practice, the answer for that tier of organisation is rarely hiring a head of AI governance in the literal sense. It is closer to embedding the same accountability, a named owner, a defined mandate, direct reporting to the board or executive team, into a fractional or advisory arrangement until the organisation's AI footprint genuinely justifies a full-time role. The function matters more than the job title, and the function can exist well before the budget for a dedicated executive does.

Building the Role Before a Regulator Forces It

The organisations most likely to regret their timing are the ones waiting for a specific trigger, an APRA letter, an ACCC inquiry, an incident of their own, before assigning clear ownership of AI governance to a named individual. By the time that trigger arrives, the gap between having governance on paper and having a named, accountable owner becomes the first thing an investigator or auditor looks for.

What This Means for Your Organisation

What we see across the organisations we work with is that the ones furthest ahead rarely started with a large governance team. They started by naming one person, giving that person real authority to say no to a deployment and connecting that role directly to the board. Everything else, the register, the risk assessments, the monitoring, gets built around that accountable owner rather than the other way around.

Key Takeaways

  • Forrester expects 60 percent of Fortune 100 companies to have a dedicated head of AI governance by the end of 2026, with Sony, Bank of America and UBS already having made the appointment.
  • Roughly 88 percent of organisations used AI in at least one business function in 2025, yet only 8 percent maintain a comprehensive AI governance framework, a gap that distributed, committee based accountability rarely closes.
  • Agentic AI is accelerating the need for named accountability: 74 percent of organisations plan to adopt agentic AI within two years, but only 21 percent have a mature governance model for it, and security and risk concerns are now the primary barrier to scaling it.
  • Mid-market Australian organisations do not need a literal Fortune 100 style executive hire. A fractional or embedded accountable owner with real authority achieves the same governance outcome at a fraction of the cost.
  • Organisations that name an accountable owner before a regulator forces the issue are consistently better positioned than those that wait for an incident to define the role for them.

How Trusenta Can Help

Fractional AI Officer gives mid-market organisations the named, accountable AI governance owner this post describes, without the cost of a full-time executive hire.

AI Governance gives that accountable owner the use case register, risk classification and monitoring infrastructure the role actually needs to function.

AI Governance Maturity Uplift helps organisations that already have some governance in place move from committee based accountability to the named ownership model this shift requires.

Conclusion

The title on the org chart matters less than the fact of it. What Forrester's prediction actually describes is organisations recognising that AI governance without a named, accountable owner is not really governance, it is aspiration. Australian organisations do not need to wait for a Fortune 100 sized budget to make the same decision. They need to decide, before an incident makes the decision for them, who is actually responsible for AI in their organisation and give that person the authority the role requires.

Shane Coetser

Written by

Shane Coetser

With over 30 years of experience delivering real technology outcomes, he combines strategic insight with deep technical expertise across enterprise, cloud and AI. At Trusenta, he helps organisations move beyond AI hype to accountable, sustainable impact.

Connect on LinkedIn

More from AI Governance

Australia Just Created an Office of AI Inside the Prime Minister's Department. Here Is What It Means for Your Governance Programme

Australia has created an Office of AI inside the Department of the Prime Minister and Cabinet to coordinate AI standards across government. Here is what the move signals for organisations already juggling DTA, APRA and ACCC obligations, and what to build now regardless of what standards the Office eventually publishes.

Read

The Australian Government Now Requires an AI Use-Case Register. If You Supply to Government, That Changes Your Contracts.

On June 15, 2026, Australia's DTA made AI use-case registers mandatory for 94 Commonwealth entities. A second wave of obligations, including mandatory AI Impact Assessments and incident reporting, arrives in December 2026. DTA procurement guidance now requires AI suppliers to disclose AI use in government service delivery and accept accountability for it. Here is what the requirements mean for agencies and the organisations that supply to them.

Read

ACCC Is Now Looking at AI-Powered Consumer Manipulation. With Penalties Doubled, Here Is What Your Customer-Facing AI Deployments Need.

ACCC's 2026-27 enforcement priorities explicitly target AI-enabled dark patterns and consumer manipulation. Penalties doubled to $100 million per contravention in March 2026. The Unfair Trading Practices Bill 2026 proposes further obligations with AI-enabled manipulation explicitly in scope. Here is what customer-facing AI deployments need, why most governance programmes have not mapped this risk and what a proportionate response looks like.

Read

Ready to transform your AI strategy?

Partner with Australia's AI strategy and governance specialists. From adoption roadmaps to ISO 42001 audit readiness.