Every Company Now Needs An AI Risk Officer: Accenture Expert

When it comes to surging AI cyber risk, ‘there needs to be a responsible executive’ in every organization, Accenture’s Ryan Whelan tells CRN.

For most companies, it has now become essential to clearly designate a single executive responsible for ensuring that the drive to deploy AI does not outpace cybersecurity and safety, according to Accenture cyber intelligence leader Ryan Whelan.

Surging cyber risk from unbridled AI adoption makes it clear that “there needs to be a responsible executive” in every organization, who is fully empowered to make sure that usage of AI and agentic does not go unchecked, said Whelan, managing director and global head of cyber intelligence at Accenture, No. 1 on CRN’s Solution Provider 500 for 2026.

[Related: OpenAI Hugging Face Hack Shows Autonomous Threats Are ‘No Longer Theoretical’: Accenture Exec]

“One of the things that any C-suite should be asking themselves right now—and any board should be asking themselves—is, ‘Do we have somebody who’s specifically tasked with looking at the risk of introducing these systems on a daily basis, and regularly talking to us about that?’” he said during an interview with CRN. “So you’re having that risk conversation at the same time you’re having that business acceleration conversation.”

For too many companies right now, those conversations are not happening together, Whelan said.

With current AI discussions, “I’d say the majority of times, that security conversation is trailing” the business acceleration conversation, he said.

The result for such organizations is ultimately that “you’re going to be opening gaps and seams that can be exploited by adversaries,” Whelan said.

Admittedly, organizations may not always actually want to put someone in such a position, however, he noted.

“It’s hard. [It’s possible] if they appoint someone in that position, they’re going to feel like they’re fighting an uphill battle—because their job is to say, ‘Hey, wait, guys, we’ve got to slow down. We’ve got to have a risk conversation here,’” Whelan said.

“So I think it’s got to be done very intelligently, leveraging the other leaders in any organization that are already responsible for risk—your general counsel, your chief risk officer if there is one,” he said.

The situation is analogous to the function of including brakes on a vehicle, according to Whelan.

“If we could all just fly around corners and never have to apply brakes, I’m sure we’d all really love driving,” Whelan said. “But you have to apply brakes intelligently in order to get from point A to point B, and that is the same increasingly for business.”

The reality is that “we do it all the time in other areas—they’re called ethics,” he said. “So it’s not an unknown concept.”

Without a doubt, the accountable executive could be the CISO, but the role is likely to differ by organization, Whelan said.

The most important thing, however, is simply that the responsibility is formally assigned to a single executive—with full buy-in at the board and C-suite levels, he said.

“I really do think organizations need to be thinking about, how do they elevate AI and agentic risk to the C-suite and board commonly? And there needs to be a responsible executive for that,” he said. “I’m not saying it needs to be the CISO, but they need to have a responsible executive. I think that’s really important.”