In April 2025, the White House instructed, through a memorandum from the Office of Management and Budget (OMB), that every U.S. federal agency name a formal AI lead within 60 days — with real authority, including the power to grant waivers on high-risk AI use, as long as the decision is publicly documented and reported to OMB itself. It wasn't the first attempt: an earlier version of the same kind of memorandum had already created the role a year before, and analysts at Forrester were already betting the federal requirement would spread to private companies.

That bet paid off faster than expected. A study from the IBM Institute for Business Value, surveying 2,000 CEOs and equivalent leaders across 33 countries and 21 industries, published in May 2026, found that 76% of organizations now have a formal AI lead — up from just 26% a year earlier. It's one of the fastest expansions of any executive role on record.

Behind that growth sits an uncomfortable question that every company that adopted AI over the past two years has already faced informally: if an AI agent makes a wrong call, approves something it shouldn't, or uses information it shouldn't have accessed, who answers for it? Today, at most Latin American companies, the answer changes depending on who you ask.

When AI Belongs to No One

The most common answer is a quiet game of pass-the-buck. The technology team says deciding what AI can or can't do is the business's call — after all, it's sales or finance that knows which data is sensitive and which decisions need approval. The business passes it right back: buying, configuring, and maintaining a tool is technology's job. Legal only steps in once there's already a problem to solve, never before.

Forrester's research on the AI-lead role describes this original tension well. According to analysts Alla Valente and Cody Scott, the role can't be purely reactive, nor focused only on containing risk: it has to coordinate innovation and risk management at the same time, inside the same function. That dual nature — part accelerator, part brake — is exactly why no traditional department can absorb AI on its own without distorting the role itself.

The White House memorandum acknowledges this in practice: beyond naming a lead, it requires every agency to stand up an AI governance board within 90 days, and it requires the role to sit high enough in the hierarchy to engage directly with agency leadership. In other words, a name on a badge isn't enough. Real decision-making power has to come with it.

In private companies, that power is rarely designed in. AI spreads through isolated teams: a project in customer support, an automation in finance, an assistant marketing tested once and never turned off. Every initiative has an informal owner — whoever built it — but none has a formal one, with the authority to decide what scales up, what needs review, and what gets shut down.

Shared Responsibility, No Decision

Shared Responsibility, No Decision

The most common fix so far has been a committee: gather representatives from technology, legal, security, and one or two business units to debate the topic once a month. That works for signing off on general guidelines, but a committee doesn't make day-to-day calls. When someone in sales needs to know, right now, whether they can paste a contract into an AI assistant to summarize its clauses, they won't wait for the next meeting.

The other common fix is publishing an acceptable-use policy and hoping it's followed. A policy with no structure behind it depends entirely on memory and individual goodwill — and it doesn't survive a tight deadline, let alone the pace at which new AI tools keep showing up.

The pattern in both cases is the same: the company produces an institutional answer — a committee, a policy — without producing an operational one, which is who decides, with what authority, and how fast. Forrester itself names this risk: an AI-lead role with no budget and no real authority becomes just a fancy title. In practice, it becomes one more meeting.

What Has to Be in Place

A single owner, with a name and real authority. Before any technical mechanism, there has to be a person — or a defined role, depending on company size — who formally answers for AI, with budget and veto power, not just a committee that meets once a month to rubber-stamp what already happened.

Scope defined in layers. Not everything gets decided at the same level. A company-wide guideline covers everyone; a specific permission covers one department; and a personal tool someone builds for their own work can grow into an official one, with approval, without anyone having to reinvent the rulebook for every new case.

Access based on each person's role. Every person and every agent see only what their function authorizes, even inside the same connected tool. That takes the obligation to approve every single use off the AI lead's plate — the rule is already built into the access itself.

An audit trail for every decision. Creating an agent, approving a policy, changing a permission: all of it gets logged, with an author and a date. That's what turns "who answers for this" from a question that needs an investigation into a lookup any audit can resolve in minutes.

Review before anything becomes official knowledge. Documents that will feed AI answers company-wide go through a two-step review and approval process, with segregation of duties — not because every answer needs sign-off, but because whatever becomes an official source needs an owner too.

That's how Skyller was designed: layered scope across company, department, and individual, access based on each person's role, and an audit trail by default, not as a separate setting. The platform already ships with more than 170 ready-made policy and process templates, so whoever takes on governance doesn't start from zero.

From Gridlock to Decision Speed

From Gridlock to Decision Speed

With a defined owner, the first gain shows up in speed. An idea that today takes weeks bouncing from committee to committee — because no one knows who approves it — gets a path instead: someone authorizes it, someone documents it, and the team gets back to work. The time lost arguing over who decides is usually greater than the time it takes to actually decide.

IBM's study points to a second, less obvious effect: having a formal AI lead doesn't wall the technology off into its own department. Quite the opposite — 77% of the executives surveyed say technology leadership and people leadership are converging, and 85% agree that every functional leader should become a technology expert within their own domain. The formal role doesn't lock AI into a silo; it gives it a point of reference while the capability spreads across the whole company.

At Latin American companies, this rarely means hiring an executive with "AI lead" in the title. It means giving someone who already exists — an operations director, a technology manager, a transformation lead — the formal authority and the structure to decide. The title is secondary. What changes the game is having someone who actually answers for it.

Three Questions for Your Next Meeting

  1. If an AI agent approves something it shouldn't have, who in the org chart answers for it today? If the answer is "it depends who you ask," the problem isn't technical — it's a role-design problem.
  2. Is there anyone with the authority to shut down an AI tool without calling a committee? Without that power, every decision turns into a negotiation, and usage keeps growing while the negotiation drags on.
  3. Do the AI's access permissions track the person's current role, or were they set up once and forgotten? An audit trail is only useful if the permissions it records still reflect who that person is today.
  4. Who reviews the content that becomes an official AI answer before it goes out to the whole company? If the answer is "no one — we review it after someone complains," the problem already happened before anyone noticed.

Discover Skyller