Thoughtworks Survey Finds IT Expects Blame for AI Tools Other Teams Buy
The survey of 3,200 CIOs shows no dominant budget model. Planned governance changes and new AI leadership roles have yet to settle who gets authority alongside responsibility.
Loading page…
The survey of 3,200 CIOs shows no dominant budget model. Planned governance changes and new AI leadership roles have yet to settle who gets authority alongside responsibility.
Listen to this story
Thoughtworks’ October 7, 2026, survey of 3,200 CIOs across 10 countries found AI budgets and decision-making spread across IT, business units and executives, while governance struggles to keep pace. Though 90% expect central IT to answer for security or compliance failures caused by business-bought tools, the findings reflect executives’ perceptions—not audited controls or a tally of incidents. The operational challenge is defining shared guardrails and decision rights without making IT approve every use case.
Globally, 88% of CIOs said AI adoption was outpacing governance, and 37% felt accountable for security incidents they could not fully influence.
AI budgets were split among central IT (22%), shared IT-business ownership (22%), independent business units (20%), executive or board control (19%), and evolving models (17%).
In North America, 56% said their organization planned to establish a formal AI governance and operating model within 12 months.
Business teams can buy their own AI tools, but technology leaders still expect to answer for failures. Thoughtworks’ Global CIO Survey, published October 7, 2026, found that 90% of CIOs worldwide believe central IT would ultimately be held responsible for security breaches or compliance failures caused by AI tools purchased independently by business units.
Censuswide conducted the research with Thoughtworks from July 1–10, surveying 3,200 chief information officers across 10 countries. The findings measure executives’ views of authority and readiness, rather than an audit of companies’ controls or a count of actual AI-related failures.
Globally, 88% of respondents said AI adoption was moving faster than governance structures could adapt. Influence over decisions was divided: 23% identified the CEO as the strongest voice, compared with 21% for central IT or technology leadership, 11% for the executive leadership team and 10% for dedicated AI roles.
Spending followed no single dominant model. The global budget breakdown was:
The accountability concern was stronger among U.S. respondents: 94% expected central IT to bear responsibility for security or compliance failures involving independently purchased tools. Worldwide, 37% felt personally accountable for AI security incidents they could not fully influence; 35% said the same about data privacy breaches.
Authority over AI is distributed, but accountability hasn’t always moved with it.
Mike Sutcliff, CEO of Thoughtworks
The remit is changing beyond purchasing and security. Globally, 89% of CIOs said they were now more responsible for redesigning workflows and labor models than managing core IT infrastructure. Thirty-five percent felt personally accountable for workforce disruption from AI adoption, despite not being able to fully influence the outcome.
Thoughtworks CTO Rachel Laycock argues that training alone is insufficient. Organizations also need to redesign roles, workflows and decision rights, making clear where human judgment remains essential and where AI can take on more work.
In its North American findings, Thoughtworks said 56% of CIOs reported their organization was establishing a formal AI governance and operating model within the next 12 months. Fifty-two percent were embedding a dedicated technology lead in each business unit, while 48% were expanding the CIO’s role to oversee enterprise-wide AI strategy and implementation.
Those changes sit alongside striking confidence in existing arrangements. Although 91% of North American CIOs said adoption was outpacing governance, 97% considered their organization prepared to govern AI consistently across business functions. Two-thirds described it as very prepared. That strongest confidence rating reached 83% in the U.S., versus 49% in Canada.
Adding an AI executive has not produced a shared leadership structure. Globally, 70% of surveyed organizations had hired a chief AI officer, and another 26% were looking to do so. Thoughtworks found competing descriptions of the role: 36% called it an extension of the CIO’s centralized strategy, while 35% described an independent leader with equal or greater enterprise influence. Another 29% described the relationship as a source of friction or unclear boundaries.
Thoughtworks’ recommendation is not to return every decision to IT. Thomas Squeo, its Americas chief technology officer, told CIO Dive that organizations should give decision-makers authority and information, assign security, privacy and compliance to relevant owners, and let business units act within agreed limits. He recommended a shared technology environment with common architecture and controls, so CIOs would not need to approve every AI use case.
That division of work also gives finance a role beyond approving purchases. Squeo described finance getting visibility into consumption and value, while business units make local decisions within agreed guardrails.
Loading discussion...
Join the conversation
Explain when shared safeguards would be enough—or when approval should be required.
Be the first to share a perspective or an experience.
Reader comments
Newest comments first. Replies stay oldest first.