Closing the AI Control Gap: What UK CIOs Must Own in 2026
UK CIOs are now accountable for AI systems they do not fully control — and as enterprise deployment accelerates, the governance gap is widening.
According to a June 2026 study by the IBM Institute for Business Value, conducted with Oxford Economics across 2,000 senior technology executives in 33 countries, two-thirds of CIOs and CTOs are held accountable for AI systems they do not fully control. The same study found that 77% of organisations report AI adoption is already outpacing their current governance capabilities. For UK CIOs, this is not a future risk — it is a present operational and regulatory exposure.
Why Are UK CIOs Being Held Accountable for AI They Don’t Control?
The root cause is decentralised AI deployment. Business units — procurement, finance, HR, and marketing — are deploying AI tools independently, often bypassing IT governance entirely. According to the IBM study, 70% of surveyed executives say teams across the business are deploying technology faster than IT can track. Each deployment creates an accountability obligation with no corresponding control mechanism for the CIO.
The UK’s ICO AI and Data Protection Code of Practice reinforces this concern: organisations must be able to demonstrate accountability for any AI system that processes personal data, regardless of which business unit deployed it. The CIO, as the named accountability officer in most UK enterprise structures, carries that liability directly. At the same time, 80% of respondents in the IBM study report that their CEOs have issued AI transformation mandates — creating top-down pressure to scale faster, even as governance infrastructure lags.
- Establish a formal AI system register capturing every production deployment, the business unit owner, the data processed, and governance status.
- Define escalation criteria: specify which AI deployments require CIO sign-off before go-live and which may proceed under delegated business unit governance.
- Agree accountability boundaries with the CEO and CFO in writing — particularly where AI touches financial reporting, customer outcomes, or regulated data.
Executive Action: implement the three steps above before year-end 2026.
What Does the AI Control Gap Mean for Operational Risk in Regulated Firms?
The IBM study provides a clear operational benchmark: organisations experienced an average of 54 AI agent incidents last year — unintended or harmful outcomes that required human correction. In organisations relying on manual governance, incident risk increases proportionally as AI deployment scales. Organisations that embed control mechanisms directly into their AI infrastructure experience 25% fewer incidents than those that do not.
For UK CIOs in regulated sectors, the implications extend beyond operational disruption. Under the FCA’s Operational Resilience Policy Statement PS21/3, firms must map important business services and set impact tolerances for disruption. AI-induced failures that breach those tolerances must be reported and remediated. A 54-incident annual average is not compatible with FCA operational resilience expectations. CIOs who have not mapped AI deployments against their firm’s important business services are carrying an unquantified regulatory exposure.
- Map AI deployments against FCA important business services to identify which AI failures would trigger operational resilience reporting obligations.
- Commission an AI incident response protocol that distinguishes AI-specific failure modes from standard IT incidents and sets clear escalation thresholds.
- Report AI incident data to the board’s Risk Committee quarterly, distinguishing between automated resolution and human intervention events.
Executive Action: complete the incident mapping exercise before Q3 2026 board reporting.
How Should UK CIOs Build Centralised Oversight Without Slowing AI Innovation?
The governance solution is not to centralise AI deployment — it is to centralise AI oversight. The IBM study found that only 36% of organisations have a centralised approach to AI governance, and just 12% use a centralised platform to maintain visibility across AI deployments at scale. Those that do significantly outperform peers on both governance maturity and incident rates.
A federated governance model — where business units retain deployment authority within pre-agreed guardrails — gives CIOs the oversight they need without creating innovation bottlenecks. The guardrails must be defined in an AI Policy Framework specifying data classification requirements, prohibited use cases, human-in-the-loop obligations, and minimum audit log standards. Use INFORMD’s AI governance self-assessment tools to benchmark your current posture before building the framework.
- Adopt a federated AI governance model with a central AI Office responsible for policy, standards, and audit — not operational deployment decisions.
- Implement an AI observability platform providing real-time visibility into AI agents operating across the enterprise, including third-party tools accessed via API.
- Publish an internal AI governance dashboard for the board, updated quarterly, covering deployment counts, incident rates, and remediation status by business unit.
Executive Action: present the AI governance model to the board by Q3 2026 with a clear ownership structure.
What Is the Financial Exposure of Unmanaged AI Spend for UK Organisations?
Beyond governance risk, the AI control gap has a direct financial dimension. According to the IBM study, AI spend is projected to grow from approximately 15% of IT budgets in 2025 to nearly 25% by 2027 — a 71% increase in two years. Yet 84% of technology leaders have not fully operationalised AI financial management, and 85% lack real-time visibility into AI spend across the organisation.
For UK organisations, shadow AI spend — where business units procure AI capabilities outside IT budgets — creates audit exposure and weakens cost control disciplines. HMRC’s guidance on software cost capitalisation has not kept pace with AI-as-a-service models, adding financial reporting complexity that CIOs and CFOs must address together. INFORMD’s Technology Strategy Review templates provide a structured framework for AI investment governance and board reporting. Access the full executive briefing library for additional tools.
- Implement FinOps for AI — a dedicated cost management discipline that tracks AI spend, maps it to business outcomes, and integrates with the CFO’s budget cycle.
- Require all AI procurement above a defined threshold to route through IT and Finance for approval, regardless of the originating business unit’s budget source.
- Present an AI investment portfolio view to the board at each meeting — cost per initiative, expected ROI, and current governance status.
Executive Action: establish an AI FinOps function before AI spend reaches 20% of IT budget.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library or access our free assessment tools.
The AI control gap is the mismatch between AI systems a CIO is accountable for and those they can actually see and govern. According to a June 2026 IBM Institute for Business Value study, two-thirds of CIOs are held accountable for AI they don’t fully control, largely because business units deploy AI tools independently without IT oversight.
According to the IBM Institute for Business Value 2026 study, organisations experienced an average of 54 AI agent incidents last year — unintended or harmful outcomes requiring human correction. Organisations with embedded AI controls experience 25% fewer incidents than those relying on manual governance processes.
A federated governance model is most effective: business units retain deployment authority within pre-agreed guardrails, while a central AI Office owns policy, standards, and audit. Only 36% of organisations currently have a centralised governance approach, according to the IBM 2026 study.
AI spend is projected to grow from 15% to 25% of IT budgets by 2027 — a 71% increase. Yet 84% of technology leaders have not operationalised AI financial management. Shadow AI procurement outside IT budgets creates audit exposure and financial reporting complexity that CFOs and CIOs must address jointly.
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk.
