There is a question to put to your leadership team this week. Not “what is our AI strategy,” which produces a document. Ask instead: if an employee pastes a customer contract into a chatbot tomorrow, whose job is it to have prevented that?

In most mid-market companies the answer is a pause, then a few names, then a discussion about whether it is a policy issue or a tooling issue. The pause is the finding. AI arrived in these organizations through individual employees rather than through a budget line, so it never acquired an owner the way finance, security, or facilities did.

The visibility gap

Okta surveyed 292 executives and 492 knowledge workers across seven countries in March 2026. Ninety percent of executives said they were confident in their organization’s visibility into which AI tools are being used. Fifty-two percent of knowledge workers said they use AI tools without approval.

90%Executives confident52%Staff using unapproved AI
Okta, AI Agents at Work 2026. Fielded March 2026 among 292 executives and 492 knowledge workers in the US, UK, Australia, Canada, Japan, France and Germany.

Both numbers come from the same study, which is what makes the pairing useful. This is not one group being pessimistic and another optimistic about different things. It is a measurement of how far leadership’s picture of the organization has drifted from what is happening inside it.

The same research found that among employees using unapproved tools, 54 percent had shared internal messages or emails, 45 percent had shared HR information, and 39 percent had shared confidential documents. Twenty-four percent said they use unapproved tools regularly rather than occasionally.

Internal messages54%HR information45%Confidential docs39%
Share of employees using unapproved AI tools who reported entering each data type. Okta, AI Agents at Work 2026.

We see the same pattern in our own engagements. In one mid-market insurance company, a governance review turned up fourteen AI tools already in use across the business that leadership had no record of. None of it was malicious. People had work to do and found something that helped.

Why this is an ownership problem rather than a policy problem

The instinct is to write a policy. Most companies that have this conversation produce a document within a month, and the document rarely changes behavior, because a policy without an owner is a statement of intent.

Okta’s research puts a number on that too: 65 percent of executives believed their AI policies were very clear, while 43 percent of employees agreed. A policy that only its authors find clear is not yet doing its job.

The pattern shows up further downstream as well. Gartner predicts that more than 40 percent of agentic AI projects will be canceled by the end of 2027, attributing it to escalating costs, unclear business value, and inadequate risk controls. Those are not model failures. They are what happens when no one is accountable for deciding whether a project is working, scaling it if it is, or ending it if it is not.

What ownership means in practice

Ownership here is narrower than it sounds. It does not require a new C-level hire or a transformation program. It requires that one named person, with budget authority, is accountable for four things:

  1. Which tools are approved. A short list that people can consult, kept current, with a route for requesting additions that takes days rather than quarters.
  2. What data may go where. Specific enough to act on. “Use good judgment” is not a control.
  3. Whether people can use the tools. Licences bought and unused are a cost, not a capability.
  4. Whether any of it is producing results. Someone has to be able to answer what changed, in numbers, and to stop work that is not producing anything.

Committees struggle with this. A committee can advise, review, and set direction, but accountability does not divide well. When four executives share responsibility for whether AI spending produces anything, the answer to “who owns this” is still nobody.

Where the function usually sits

In companies between $50 million and $1 billion in revenue, the AI function tends to sit in one of three places, each with its own tradeoff.

An existing executive, most often the COO or CIO. Fastest to stand up and the person already has budget authority. The constraint is attention: this becomes a second job on top of a first one, and it is usually the part that gets deferred when the quarter gets difficult.

A dedicated hire. Full attention, deep context, and accountable in the way the role requires. A full-time AI leader runs $250,000 to $400,000 a year fully loaded, and the search takes months in a market where the candidates have options.

A retained external function. Immediate capability, and the accountability sits with a team rather than one person’s calendar. The constraint is that it works only if the engagement carries decision rights rather than producing recommendations for someone else to act on.

Which of these fits depends on how much AI work is already underway and how much of the leadership team’s attention is available. What does not work is leaving the question open, which is where most companies are.

A test you can run this week

Send one email to your leadership team asking three questions. Which AI tools does the company currently pay for? Which ones are employees using that we do not pay for? Who decides when those two lists disagree?

If the third question produces a name, the function exists and the work is making it effective. If it produces a discussion, the function does not exist yet, and everything else in your AI plan depends on creating it.

Sources