Who Really Decides Whatever AI Wins or Fails?
by Denis Huré

Most companies are asking the wrong question about AI implementation.
They ask: Should the CEO, CTO or Chief AI Officer own AI?
The more urgent question is: who is accountable when AI reshapes customer relationships, changes jobs, commits capital, exposes the company to risk—and determines whether the business wins or falls behind?
The answer is the CEO.
Not because the CEO should choose models, write prompts or approve every vendor. But because AI is no longer an IT upgrade. It is a strategic decision about the company’s future. The CTO should define the tools and architecture. The CAIO should lead organisational change. But the CEO must own the decision, the ambition and the outcome.
The old model is breaking
For years, companies treated new technology as an implementation issue.
A new CRM? Let IT deploy it.
A cloud migration? Let the CTO lead it.
A productivity tool? Let each department choose what it needs.
That model worked reasonably well when technology mainly supported existing processes.
AI is different.
It does not just automate a task at the edge of the organisation. It can influence pricing, customer service, sales, marketing, product design, fraud detection, supply chains, workforce decisions and executive decision-making. It can change the cost of serving a customer, the speed of launching a product, the quality of insight available to managers and the nature of work itself.
So the familiar assumption: “AI is technology, therefore the CTO should decide” is increasingly dangerous.
The CTO can decide whether an AI platform is secure, scalable and technically sound. But the CTO should not be left alone to decide whether the company uses AI to reinvent its customer proposition, cut operating costs, redesign jobs, enter a new market, change its service model or take on a new category of regulatory and reputational risk.
Those are CEO decisions.
The evidence is already pointing in this direction. McKinsey’s 2025 survey found that 88% of respondents said their organisations used AI regularly in at least one business function. Yet nearly two-thirds had still not scaled AI across the enterprise, and only 39% reported any enterprise-level EBIT impact. The gap is not primarily a shortage of tools. It is a shortage of leadership, workflow redesign and accountable execution.
AI adoption is widespread. AI value creation is not.
The new reveal: AI is not a technology decision
Here is the reveal many executive teams still miss:
The biggest AI decision is not which AI tool to buy. It is which parts of the company should become meaningfully different because AI exists.
That reframes the entire leadership question.
A CTO can legitimately recommend whether the business should use a proprietary model, an open-weight model, a cloud AI service, a retrieval-augmented generation architecture, an internal data platform or an external vendor. Those are important choices.
But deciding whether to use AI to transform the business is a different level of decision.
Consider a global rewards or loyalty platform. A narrow technology decision might be:
- Which large language model should power a customer-support assistant?
- Which data source should be connected to the assistant?
- How should identity, permissions, logging and security controls work?
- Should the service be built internally or purchased from a provider?
Those questions belong with the CTO and technology leadership.
But the strategic questions are bigger:
- Should the company use AI to make reward discovery radically more relevant to each member?
- Can AI increase redemption, engagement, retention or partner-funded campaign performance?
- Can intelligent recommendations create a differentiated proposition for clients and members?
- Which customer interactions can be automated without weakening trust or brand value?
- What skills will account managers, campaign teams, customer-service agents and product managers need?
- Where must humans remain accountable for judgement, exceptions and relationship management?
Those questions determine the future economics of the business. They define where the company will compete and how it will create value.
They belong to the CEO.
The contrast: technical success versus business success
This is where many AI programmes fail.
They deliver a technically successful pilot but a commercially irrelevant result.
A company launches an internal AI assistant. Employees are impressed. The technology works. The interface looks good. The CTO reports that security testing passed and the platform is ready to scale.
But six months later:
- Managers have not changed how work is allocated.
- Employees do not know when they can rely on the output.
- Customer-service processes are unchanged.
- Business units have launched duplicate tools.
- No one has agreed on a financial baseline.
- No executive owns the revenue, margin, customer-experience or risk outcome.
- The pilot remains a pilot.
This is not an AI failure. It is a leadership failure.
The difference between a technology initiative and a business transformation is not the sophistication of the model. It is whether the executive team makes clear choices about priorities, operating model, investment and accountability.
|
The old assumption |
The strategic reality |
|
“AI belongs to IT.” |
AI affects every major business function and must be owned as an enterprise priority. |
|
“The first task is selecting a tool.” |
The first task is deciding the business outcome worth transforming. |
|
“A proof of concept demonstrates value.” |
A proof of concept only demonstrates possibility; scale requires workflow redesign, controls and adoption. |
|
“Technology teams deliver AI.” |
Business leaders own outcomes; technology leaders enable safe, scalable delivery. |
|
“Employees will adopt good tools naturally.” |
Adoption depends on leadership, redesigned work, incentives, training and trust. |
McKinsey’s research reinforces this contrast. Organisations that achieve stronger AI outcomes are more likely to pursue transformative change, redesign workflows and have senior leaders visibly take ownership of AI.
The message for CEOs is uncomfortable but simple: if AI has no owner above the functional level, it will usually remain below the strategic level.
Why urgency has arrived
This question has become more urgent because AI is moving from generating content to taking action.
A generative AI assistant can draft an email, summarise a report or propose a marketing campaign. An agentic AI system can potentially retrieve information, plan a sequence of tasks, interact with enterprise applications, trigger workflows and act within defined permissions.
That expands the opportunity. It also expands the consequences of poor governance.
McKinsey reported that 23% of surveyed organisations were already scaling an agentic AI system in at least one part of their business, while 39% were experimenting with such systems. Yet functional-scale deployment remained limited—an indication that many companies are still working through the governance, integration and operating-model requirements needed for safe scale.
This is not a distant concern. Organisations are making architecture, data, vendor and operating-model choices now. Those choices will shape:
- The degree of vendor concentration and lock-in.
- The company’s ability to protect proprietary data and intellectual property.
- Whether employees use approved AI capabilities or ungoverned alternatives.
- Whether the firm can audit, explain and monitor AI-supported decisions.
- Whether the business can deploy agents safely across customer, finance, HR and operational workflows.
- Whether AI becomes a source of growth or merely another layer of cost.
For European companies, the urgency is also regulatory. The EU AI Act establishes a risk-based legal framework for AI. High-risk systems face obligations related to risk management, data governance, technical documentation, record-keeping, transparency, accuracy, robustness, cybersecurity and human oversight.
Human oversight is not satisfied by placing a vague disclaimer next to an AI output. For high-risk systems, the AI Act requires meaningful human capability to understand limitations, monitor operation, recognise automation bias, override outputs and intervene or stop the system where necessary.
That is why AI cannot be treated as a delegated technical project. Decisions about risk tolerance, acceptable autonomy, customer impact and executive accountability must be made at the top of the organisation.
The bullseye proof: who owns what
The most effective model is neither CEO-only nor CTO-only.
It is a deliberate division of authority:
CEO-led strategy. CTO-led architecture. CAIO-led change. Business-led outcomes. Board-level oversight.
This is not a slogan. It is a practical operating model.
|
Decision area |
Accountable leader |
What they must decide or deliver |
|
Strategic AI ambition |
CEO |
Define whether AI is primarily a growth, efficiency, innovation, resilience or differentiation agenda—and where it will change the company’s business model or competitive position. |
|
Capital allocation |
CEO, with board oversight where material |
Prioritise investment, approve strategic trade-offs, establish scale-or-stop criteria and hold executives to outcome commitments. |
|
AI risk appetite |
CEO, supported by legal, risk, privacy and security leaders |
Decide which uses are prohibited, which require enhanced review and which business risks are acceptable. |
|
Enterprise technology strategy |
CTO |
Define the target architecture, approved tools, data patterns, integrations, security controls and technical standards. |
|
Data, cybersecurity and resilience |
CTO |
Ensure AI systems use authorised data, apply appropriate access controls, resist foreseeable threats and can be monitored and recovered. |
|
Vendor and model choices |
CTO, with procurement, legal and business input |
Assess build, buy and partner options, manage commercial terms, reduce unacceptable lock-in and establish audit and exit rights. |
|
Workflow redesign and adoption |
CAIO |
Convert AI capability into changed processes, roles, behaviours and management practices. |
|
Value realisation |
CAIO and relevant business-unit leader |
Establish financial baselines, adoption metrics, quality measures and a credible plan to scale, redesign or stop each initiative. |
|
Business outcomes |
Business-unit leaders |
Own the commercial, customer, operational or risk outcome—not merely the delivery of an AI tool. |
|
Material oversight |
Board and CEO |
Review major AI investment, systemic risk, high-risk deployment, incidents and strategic dependencies. |
The CEO: owner of the “why”
The CEO owns the corporate AI thesis.
That means answering questions such as:
- Where can AI create a defensible competitive advantage?
- Which customer or employee experiences should be materially better within the next 12 to 24 months?
- Is the priority margin improvement, growth, innovation, service quality, resilience—or a specific combination?
- Which AI risks are incompatible with the company’s values, strategy and brand?
- How much should the company invest before it expects demonstrable value?
- Which executives will be accountable for results?
The CEO does not need to run the AI programme day to day. But they must provide the mandate that makes cross-functional decisions possible.
Without CEO ownership, each business unit optimises locally. Finance focuses on cost. Marketing focuses on content. HR focuses on policy. Operations focuses on productivity. IT focuses on platforms and controls.
All of these priorities may be valid. But no one makes the enterprise trade-offs.
The CTO: owner of the “how”
The CTO must be deeply involved in every serious AI programme. In many ways, the CTO’s role becomes more consequential—not less—as AI use expands.
The CTO should lead the technical foundation that makes responsible AI possible:
- A clear architecture for models, applications, APIs, agents and integrations.
- Data-quality, data-lineage and access-control standards.
- Identity and permissions appropriate to the AI system’s level of autonomy.
- Security controls against data leakage, prompt injection, insecure integrations and misuse.
- Evaluation methods that assess accuracy, hallucination, bias, reliability, latency and cost.
- Monitoring, audit logging, incident response and mechanisms for model updates or withdrawal.
- A coherent approach to vendor selection, portability and long-term dependency.
NIST’s AI Risk Management Framework places governance at the centre of effective AI risk management. Its Govern function focuses on the organisational culture, policies, roles and accountability that support AI risk management throughout the AI lifecycle.
The CTO should therefore have real decision rights over tools and architecture. A CEO should not dictate a model choice because it is fashionable, nor force a rollout before data quality, security, testing and operational controls are sufficient.
But technical stewardship is different from strategic accountability. The CTO builds the runway. The CEO decides where the company is flying.
The CAIO: owner of the “so what”
The CAIO should own what is too often neglected: changing how the company works.
The central mistake in AI implementation is to add AI to an existing workflow and expect transformation. That is the equivalent of putting a faster engine into a business process that is still heading in the wrong direction.
A capable CAIO leads the work required to make AI useful at scale:
- Prioritising use cases based on strategic value, feasibility, risk and readiness.
- Establishing a business case and baseline before deployment.
- Redesigning workflows rather than automating inefficient processes.
- Defining human-in-the-loop and exception-handling practices.
- Creating role-based training, leadership toolkits and adoption support.
- Coordinating legal, compliance, HR, security, risk and business teams.
- Measuring actual usage, employee confidence, quality, customer impact and financial value.
- Stopping pilots that cannot demonstrate a credible route to scale.
The CAIO is not there to become a parallel CTO. Nor should the role become a “chief experimentation officer” responsible only for innovation theatre.
The CAIO’s job is to turn AI capability into enterprise behaviour and measurable value.
In a smaller organisation, this mandate may sit with the COO, chief digital officer, transformation director or a senior AI programme leader rather than a dedicated CAIO. The title is secondary. The accountability for organisational change is not.
A practical example
Imagine a company deploying an AI-powered customer-service capability.
The CEO decides the strategic ambition: reduce resolution time, improve customer satisfaction, increase service availability and protect the brand’s reputation for reliable support. The CEO also decides the investment envelope, acceptable service risks and whether the company wants AI merely to assist agents or to handle defined customer requests autonomously.
The CTO designs the technical solution: the approved model, secure access to knowledge sources, data classification, retrieval architecture, authentication, customer-data protections, integration with CRM and ticketing tools, evaluation thresholds, audit trails and incident-response mechanisms.
The CAIO redesigns the operating model: which customer journeys are suitable for AI, which cases must be escalated to humans, how agents review and override recommendations, how managers track quality, how teams are trained and how the organisation measures the impact on customer satisfaction, resolution time and cost-to-serve.
The business leader owns the outcome: the actual improvement in customer experience and service economics.
If any one of these roles is missing, the programme weakens:
- Without the CEO, the initiative may lack strategic priority and cross-functional authority.
- Without the CTO, it may become insecure, fragmented, expensive or technically unsustainable.
- Without the CAIO, it may remain an impressive demonstration with limited adoption.
- Without a business owner, it may have no measurable reason to exist.
The opposing view
There is a credible case for putting the CTO in charge, particularly in the early stage of AI maturity.
A company that lacks secure data foundations, cloud capability, integration standards or AI engineering expertise cannot simply declare an AI strategy and expect results. The CTO is best placed to prevent unsafe shadow AI, stop fragmented procurement, select credible technology partners and establish the platform required for scale.
For a technology company with narrowly defined use cases, a CTO-led programme may be the fastest and most effective starting point.
But that approach becomes insufficient when AI affects customer propositions, pricing, workforce design, investment choices or enterprise risk. At that point, the question is no longer “Can we deploy this safely?” It becomes “Should this change how we compete?” Only the CEO has the mandate to make that decision across the whole organisation.
There is also a case for a CAIO owning AI end to end. A dedicated AI executive can bring speed, focus and a clear centre of gravity, particularly in a large, complex organisation.
The danger is creating an AI silo. If business leaders, the CTO and the CEO quietly assume that “AI belongs to the CAIO,” the company has simply created another function rather than transformed itself.
The better model is partnership with clear boundaries: CEO ownership of strategy, CTO authority over technology and CAIO authority over change.
What CEOs should do now
A CEO does not need an AI lab to begin exercising leadership. The immediate priority is clarity.
- State the business ambition.
Define the two or three enterprise outcomes AI must improve. Avoid vague language about “becoming AI-powered.” - Name accountable leaders.
Confirm decision rights for strategy, architecture, risk, change and business outcomes. Publish a practical RACI, not an aspirational diagram. - Prioritise a small portfolio.
Select a limited number of use cases with material value, realistic data readiness and visible executive ownership. Avoid launching dozens of disconnected pilots. - Require a value baseline.
Every initiative should specify its starting point, intended outcome, adoption target, risk rating, investment need and scale-or-stop decision date. - Fund the foundations.
Support the CTO’s investment in data, security, governance, integration, monitoring and reusable platforms. These may not look as glamorous as a customer-facing AI launch, but they determine whether scale is possible. - Treat adoption as a management responsibility.
Give the CAIO, COO or transformation leader authority to redesign workflows, train managers and challenge business units that are not changing behaviour. - Create board-level visibility.
Review major investments, high-risk use cases, vendor dependencies, incidents, value realisation and emerging regulatory exposure at a cadence proportionate to the company’s AI footprint.
Conclusion
The decision about AI implementation belongs to the CEO because the decision is strategic.
It determines where the organisation will compete, how it will create value, what risks it is prepared to carry, how it will allocate capital and how its people will work. Delegating this decision entirely to the CTO is as limiting as asking the head of facilities to decide the company’s market-entry strategy because a new office will be required.
The CTO should lead the tools, architecture, data foundations, cybersecurity and vendor choices. The CAIO should lead change management, workflow redesign, capability building and value realisation. Business leaders should own results in their domains. The board should oversee material risk and investment.
But the CEO must own the ambition and the final decision.
Because AI will not transform a company simply because it is implemented.
It will transform a company only when leadership decides what must change and makes the organisation change with it.
How TLA&C Can Help
TLA&C helps CEOs and executive teams turn AI interest into a focused, governed and value-led transformation agenda. We work with leadership teams to define an AI ambition linked to growth, efficiency, customer experience, innovation and resilience; identify high-value use cases; assess readiness; and build a prioritised roadmap with clear investment and value-realisation logic.
We also help organisations design practical AI governance: executive decision rights, board reporting, risk appetite, accountable ownership, use-case controls, technology and vendor evaluation, and an operating model that aligns the CEO, CTO, CAIO, business leaders and control functions.
For companies moving beyond experimentation, TLA&C supports the harder work of workflow redesign, organisational adoption, leadership engagement, capability building and performance measurement—so AI becomes an operating capability rather than a collection of disconnected pilots.
Bibliography
- McKinsey & Company, “The state of AI in 2025: Agents, innovation, and transformation.” The survey reports widespread AI use but comparatively limited enterprise scaling and value realisation; it also examines the role of senior leadership, workflow redesign and agentic AI adoption.mckinsey
- National Institute of Standards and Technology, “AI Risk Management Framework.” The framework provides voluntary guidance for incorporating trustworthiness and AI risk management across the AI lifecycle. Its Govern function addresses organisational culture, policies, roles and accountability.orca
- European Commission, “AI Act: Shaping Europe’s digital future.” The EU’s risk-based AI regulatory framework establishes requirements for high-risk systems, including risk management, data governance, documentation, transparency, human oversight, robustness and cybersecurity.regulations
- European Union, “Regulation (EU) 2024/1689, Article 14: Human oversight.” Article 14 describes requirements for meaningful human oversight of high-risk AI systems, including the capacity to monitor, interpret, override and stop systems when appropriate.datenschutzgesetze
About Denis Huré
Denis Huré is the founder & Managing Consultant of TLA&C. His consulting practice is grounded in first-hand entrepreneurial experience, having built, scaled, and operated businesses himself; he brings a founder’s instinct for what actually works alongside the strategic rigor of a seasoned consultant. Denis brings also a rare combination of strategic innovation, platform architecture expertise, and hands-on business building to consulting assignments. He advises organizations on how to modernize their technology base, reduce structural dependency on vendors, and translate emerging capabilities such as AI, compliance tooling, and advanced payment models into scalable commercial outcomes. TLA&C – Denis Huré
Researched and drafted with AI assistance, edited and fact-checked by the author. Illustration: AI-generated.


