Position paper — Version 5, September 2026

The Case for a Dedicated Chief AI Officer

Why the CIO/CTO portfolio is overloaded, and when AI becomes strategic enough to require explicit executive ownership.

For boards, CIOs, CTOs, CDOs, CISOs, Legal & Compliance

AI governanceEU AI ActExecutive ownershipCIO vs CAIO

Above the threshold, explicit executive ownership of AI should be the default.

Once AI becomes strategic, cross-functional and consequential, the burden of proof shifts. A CAIO — or a properly mandated CDAIO — becomes the logical default. An extended CIO/CTO mandate or fully federated model remains possible, but should be explicitly justified.

Victor Angelier, MSc – Founder IamVera.ai | Former IT Architect, Dutch Government

Victor Angelier works at the intersection of IT architecture, cyber security, AI governance and executive decision-making. His background includes designing mission-critical, secure IT infrastructure for government, where inspectability, continuity, identity, security-by-design and clear ownership are operational requirements.

That experience shapes the practical lens of this paper: not which executive title is fashionable, but which governance structure demonstrably creates enough expertise, mandate and attention once AI has organisation-wide impact.

"Deploying AI without inspectable governance creates an unacceptable liability risk. I wrote this paper to give boards a framework for scaling AI defensibly and safely."

Three reasons AI stops being ‘more IT’ above a certain threshold

The paper does not argue for a universal new C-suite title. It explains why explicit executive ownership becomes rational once AI is strategic, specialist and organisation-wide at the same time.

01

The Ownership Gap

AI often enters in fragments through business units, data, IT, security, legal, HR and suppliers. Everyone can own part of the problem while nobody owns the full chain from strategy and investment to deployment, governance, transformation, risk and accountability.

02

AI Is a Specialist Domain

AI governance requires current expertise in model behaviour, evaluation, upstream decisions, agentic workflows, AI-specific risks and fast-moving regulation. That expertise depreciates quickly and cannot credibly be maintained as a sideline.

03

Saturated C-Suite Portfolios

CIO and CTO portfolios already cover infrastructure, architecture, applications, suppliers, security dependencies, continuity and digital transformation. Adding AI does not create more executive attention; it splits a scarce resource across yet another specialist domain.

The five thresholds: when does a dedicated CAIO become defensible?

A dedicated CAIO below the threshold is overhead. Above it, the alternative should be justified.

ThresholdBoard questionSignal
1. Strategic materialityWhat share of revenue, cost base or customer-facing decisions will depend on AI within 24 months?AI affects corporate strategy, not only productivity.
2. Cross-functional deploymentIn how many functions beyond IT and data is AI already in production or procurement?Ownership must operate across organisational boundaries.
3. Consequential decisionsWhich decisions affecting customers, employees or finances can be initiated or materially shaped by AI — and who may stop or scale them?Stop/scale authority becomes an executive-governance question.
4. Regulatory exposureDoes at least one current or planned system fall within Annex III or Annex I of the AI Act — and who owns that classification decision today?Regulatory mapping can no longer remain implicit.
5. FragmentationHow many separate AI initiatives lack a common owner with stop/scale authority and budget influence?Distributed responsibility is not accountability.

The Case for a Dedicated Chief AI Officer

Version 5 is reproduced in full below.

# The Case for a Dedicated Chief AI Officer: When AI Outgrows the Technology Executive's Portfolio

A position paper — Version 5, September 2026


Position Statement

This paper defends a specific position:

Once artificial intelligence crosses a defined organisational threshold — becoming strategic, cross-functional and consequential — dedicated executive ownership of AI should be the default organisational response: typically a Chief AI Officer, equivalently a properly mandated Chief Data, Analytics and AI Officer (CDAIO). An extended CIO/CTO portfolio or a purely federated model remains possible, but becomes the choice that must be justified.

Two premises carry this position. First, AI has become a specialist executive domain: governing it requires sustained, specific expertise — in model behaviour, evaluation, AI-specific risk, agentic systems and a fast-moving regulatory landscape — that cannot be maintained as a sideline to another executive agenda. Second, executive attention is a finite resource, and the portfolios of the CIO and CTO are already saturated: assigning AI to an executive whose mandate spans infrastructure, architecture, applications, suppliers, security dependencies, continuity and digital transformation does not create AI leadership; it dilutes it.

The position is deliberately scoped. Below the threshold defined in Section 6, a dedicated CAIO is unnecessary overhead, and this paper says so. This inverts the framing common in the practitioner debate, where the CAIO is treated as the exotic option that must prove itself against the status quo. The evidence reviewed here suggests the opposite: above the threshold, the status quo is what needs defending. One genre marker applies throughout: this is a position grounded in organisational mechanisms and corroborated — not proven — by adoption and regulatory trends; where the evidence supports the position rather than demonstrating it, the text says so (Sections 4, 5 and 9).

1. The Problem: AI Has an Ownership Gap by Default

For many organisations, artificial intelligence did not enter through a central strategy. It arrived incrementally. A business unit experimented with generative AI. A data team developed predictive models. IT negotiated contracts with AI providers. Security evaluated access controls. Legal examined privacy and regulatory implications. HR considered workforce effects. Individual departments purchased their own AI tools.

Each decision can make sense in isolation. Collectively, they produce a governance structure nobody designed: responsibility distributed between the CIO, CTO, CDO, CISO, legal counsel, risk management, HR and individual business executives — with none of those roles owning the entire chain from AI strategy and investment to deployment, governance, organisational transformation, risk and accountability.

The earliest direct academic examination of the question reached a conclusion that has aged well. Schäfer et al. (2022), combining a literature review with interviews among nine AI professionals from small and medium-sized companies, concluded that establishing a CAIO appeared justified because of the complexity of AI and the extensive interaction and coordination required for effective AI governance. The SME context of that sample is telling: it suggests that coordination pressures are not confined to large enterprises with inherently complex organisational structures.

This paper's argument is that the ownership gap is not an accident of immaturity that organisations will outgrow. It is the predictable result of assigning a specialist, cross-functional, high-velocity domain to executives whose roles were designed for something else. The following two sections develop the two premises in turn.

2. First Premise: AI Is a Specialist Executive Domain

The instinct to treat AI as "more IT" — and therefore as naturally belonging to the CIO or CTO — rests on a category error. Traditional information systems primarily store, process and transmit information according to relatively explicit rules. AI systems classify, recommend, rank, generate, predict, interpret and prioritise — and, increasingly, initiate actions through agentic workflows. Schmitt (2026; first circulated as a preprint in 2024) identifies the properties that make this a distinct governance domain rather than an extension of an existing one. Three matter most.

Distributed accountability for judgement. A consequential decision may no longer originate entirely with an identifiable employee; it can emerge from an interaction between data, a model, system instructions, retrieval sources, automated tools and human judgement. Someone must own the organisational conditions under which machine-generated judgement may be used — a question that is neither an infrastructure question nor a conventional risk question, but a new kind of executive question.

Upstream governance. The most important AI risks are determined before a system enters normal IT operations: during data selection, model selection, procurement, evaluation design, threshold setting, workflow integration and the allocation of decision rights between humans and machines. Governing AI competently therefore requires understanding those upstream choices technically — knowing what an evaluation can and cannot demonstrate, what a model update changes, what an agentic workflow can now do that it could not do last quarter. This is specialist knowledge, and it depreciates fast.

Non-stationarity. AI systems do not remain behaviourally stable after deployment. Models change, providers release updates, data distributions shift, retrieval sources change, prompts and connected tools alter what a system can do without the organisation formally replacing it — and, as Section 5 shows, even the regulatory calendar moves. AI governance is a continuing management function that demands continuous, current expertise.

The empirical record confirms that organisations experience this as a distinct domain. Uba and Böhmann (2025), analysing 40 Chief AI Officers at large firms through the first empirically grounded taxonomy of the role (ten dimensions, 37 characteristics), document responsibilities — AI strategy, cross-divisional coordination, governance, capability development, organisation-wide adoption — that span domains traditionally distributed across several existing executive roles. The heterogeneity they find in reporting lines and configurations is sometimes read as evidence that the role is unsettled. The better reading, and the one this paper adopts, is that organisations have recognised a distinct function and are still converging on its design.

A specialist domain, governed continuously, with expertise that depreciates fast: that is the profile of a dedicated executive function, not of a portfolio appendix.

3. Second Premise: Executive Attention Is Finite — and the Technology Portfolio Is Full

The second premise is organisational rather than technological, and it is where the peer-reviewed evidence is strongest.

The attention-based view of the firm holds that organisational outcomes follow the allocation of scarce executive attention. Bendig et al. (2023), analysing a cross-industry panel of U.S. S&P 500 firms with up to 2,852 firm-year observations in MIS Quarterly, show the mechanism at work: the presence of a CIO in the top management team is positively associated with both ideated and commercialised digital innovation. What receives dedicated executive attention is what the organisation notices, resources and pursues. Li et al. (2021), in a study of 1,454 publicly listed firms in China (a context that bounds generalisation, but on a mechanism with no obvious jurisdictional dependence), find the complementary result: executive-level expertise shapes strategic AI orientation, further strengthened by board AI experience.

Note carefully what this evidence implies. It is routinely cited — including by opponents of the CAIO — to argue that technology executives matter, and therefore that the CIO or CTO can absorb AI. But the attention-based logic cuts the other way. If dedicated attention is the mechanism through which executive roles produce outcomes, then attention is the resource being allocated — and attention, unlike headcount, does not scale. The modern CIO portfolio already spans infrastructure, enterprise applications, architecture, service delivery, technology suppliers, cloud platforms, cybersecurity dependencies, continuity, IT investment and digital transformation. This accumulation is not merely anecdotal: Chawla, Goyal and Saxena (2023), in a multiple case study of six organisations undergoing digital transformation, find that traditional CIO responsibilities persist while the transformation context adds new, multidimensional role demands — including legacy systems integration, risk management and IT security — rather than replacing the existing portfolio. The CTO's remit — in product organisations often deeper still — spans platform architecture, engineering organisation, technical strategy and delivery. Adding a specialist, fast-moving, regulatorily exposed domain to either portfolio does not extend the attention mechanism to AI. It fractions it.

There is also a boundary problem that breadth cannot solve. The technology executive's mandate covers the technology used for AI. The AI governance domain described in Section 2 covers the organisational consequences of AI: strategy, organisational design, legal accountability, workforce transformation, risk, ethics, data governance, financial prioritisation and business ownership. Kučević et al. (2026), investigating precisely this question through C-level interviews and a systematic literature review, conclude that the CAIO complements rather than replaces traditional IT executives — particularly where AI drives innovation, operational efficiency and long-term profitability. The complementarity finding is often presented as a moderate middle position. Read against the responsibility matrix itself, it says something sharper: typical CIO mandates, as currently designed, do not cover that matrix. Extending them to cover it would require a redesign of competence, capacity and decision rights so substantial that the result is a CAIO in all but name.

The conclusion from the two premises together: above the threshold, assigning AI to the CIO or CTO is not the prudent default it appears to be. It is a decision to govern a specialist domain with fractional attention from a generalist portfolio — and the organisation should be asked to justify that choice with the same rigour it would demand of a proposal to create a new C-suite role.

4. Practice Is Moving in the Same Direction

If the argument above is right, one would expect organisations under the greatest AI pressure to be creating dedicated roles — and they are, at remarkable speed.

The IBM Institute for Business Value's 2026 CEO Study — conducted with Oxford Economics among approximately 2,000 CEOs across 33 countries and 21 industries — reports that 76% of surveyed organisations had a Chief AI Officer in 2026, up from 26% in 2025 (IBM Institute for Business Value, 2026). Honesty requires the caveats: this is a self-reported executive survey of large organisations; other measurements run far lower (Foundry's 2025 State of the CIO survey, canvassing 906 IT leaders, found 14%; Foundry, 2025); the gap reflects sampling and, above all, definition — a relabelled CDO without decision rights is a CAIO in name only; and adoption of a role is not evidence that the role causes better outcomes. The prevalence of the title says little about the prevalence of the mandate.

For the position defended here, the direction of the signal is what matters: within IBM's surveyed population of large global enterprises, a substantial majority now report having a CAIO. That is consistent with movement away from treating AI solely as an absorbed technology responsibility — and with this paper's position — although the survey does not establish how many of those CAIOs hold standalone rather than combined mandates, and it is not proof of the position. Executive titles also follow fashion, peer signalling and the advice of consultants and search firms, and some share of the new CAIOs will be relabels rather than mandates. What the adoption data cannot be read as is evidence against the position — and the governance record points the same way. EY's Responsible AI Pulse (2025) shows the underlying strain: 72% of surveyed C-suite executives reported AI integrated and scaled across most or all initiatives, while only around one third reported controls covering all elements of EY's responsible AI framework. Deployment scaling faster than governance capability is the exact failure mode predicted when a specialist domain is governed with fractional attention.

Adoption data cannot prove the position. It can, and does, corroborate it.

5. Regulation Has Removed the Do-Nothing Option

Regulation now closes off the one response that used to be free: leaving ownership implicit.

5.1 The United States

The federal requirement that agencies designate Chief AI Officers was established in March 2024 under OMB memorandum M-24-10 (Biden administration, Executive Order 14110) and survived its own rescission: the replacing memorandum M-25-21 (April 2025, Trump administration, Executive Order 14179) shifted the mandate's emphasis from risk management to innovation and adoption — but retained the CAIO designation requirement (Office of Management and Budget, 2025). The designation survived the transition; the content of the mandate did not remain constant. That continuity should not be overread: M-25-21 retained a designation already embedded in agency practice, which is weaker evidence than two independent judgments would be. What the episode does show is that neither a risk-oriented nor an innovation-oriented policy regime found it workable to leave AI without an identifiable executive owner — and that ownership structures can be designed to survive changes in what the owner is asked to prioritise. Notably, the federal model permits designating an existing CIO, CDO or CTO where that official has appropriate AI expertise and sufficient authority — a pragmatic concession to public-sector constraints, and one whose expertise-and-authority proviso concedes this paper's premises: the designation is only valid where specialist competence and real attention capacity exist.

5.2 The European Union

Regulation (EU) 2024/1689 — the AI Act — regulates outcomes, not organisation charts, and prescribes no role. But it converts multiple dimensions of AI accountability into binding legal obligations that organisations must allocate internally. The Article 4 AI literacy duty (in application since February 2025) spans HR, business units and technology functions. The Article 26 deployer obligations for high-risk systems — competent and authorised human oversight, monitoring, logging — presuppose that someone knows which systems are in scope and owns how oversight is arranged. High-risk classification across procurement, internal builds and vendor-embedded AI is a continuing cross-functional assessment, backed by sanctions of up to €35 million or 7% of global annual turnover for the most serious infringements.

The framework itself has already moved once. The Digital Omnibus on AI — Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026 — deferred the high-risk regime for stand-alone Annex III systems to 2 December 2027 and for Annex I product-embedded AI to 2 August 2028, while leaving the Article 50 transparency obligations, the general-purpose AI regime and the prohibitions on their original schedule (European Union, 2026). Article 4 illustrates that even retained obligations do not stand still: the Omnibus rewrote it in full — organisations must now take measures to support the development of AI literacy, without having to guarantee any specific individual level — softening the wording while retaining it as a direct duty on its original timeline. An organisation without identifiable AI ownership lacks even the internal function capable of tracking which obligations apply, in which wording, from when, to which systems — questions whose answers have changed once already and may change again.

The Act requires identifiable internal allocation; it does not require a dedicated officer. What follows is this paper's normative inference, not a statutory reading: given the premises of Sections 2 and 3, allocating obligations this strategic, this cross-functional and this dynamic to a dedicated role — with specialist competence and undivided attention — is the rational default for organisations above the threshold.

6. Scope: Where This Position Applies — and Where It Does Not

The position defended here is conditional, and the condition is doing real work. A dedicated CAIO below the threshold is cost, conflict and title inflation. The threshold is met when several of the following conditions hold; each is paired with a diagnostic question a board can answer concretely.

  1. Strategic materiality (Bajwa, 2024; Wade et al., 2024). What share of revenue, cost base or customer-facing decisions will depend on AI within the next 24 months?
  2. Cross-functional deployment (Schäfer et al., 2022; Schmitt, 2026). In how many distinct functions beyond IT and data is AI in production or in procurement?
  3. Consequential or autonomous decisions (Schmitt, 2026). Which decisions affecting customers, employees or finances can be initiated or materially shaped by an AI system — and who has authority to stop or scale each of them?
  4. Regulatory exposure (European Union, 2024; 2026). Does at least one current or planned system fall within Annex III or Annex I of the AI Act — and who owns that classification judgment today?
  5. Fragmentation. How many separate AI initiatives currently lack a common owner with stop/scale authority and budget influence?

Below the threshold — AI as a bounded productivity layer, few functions, no consequential automation, no high-risk exposure — this paper's position does not apply, and an existing technology or operations mandate is the proportionate home for AI (Bajwa, 2024). The position is also compatible with a time-bounded design: Shaik's (2026) proposal of the CAIO as a transformation catalyst with explicit milestones and a planned dissolution is a legitimate variant, provided the mandate is real while it exists. What the threshold rules out is the fourth model: letting AI spread while assuming responsibility will organise itself. Distributed responsibility is not the same thing as distributed accountability.

7. Counterarguments — and Why They Do Not Defeat the Position

A position paper earns its position by meeting the strongest objections directly. Three deserve full treatment.

"Combine it with data and analytics instead" (the CDAIO objection). Gopal, Davenport and Bean (2025), writing in Harvard Business Review, argue that data readiness, analytics and AI are so interdependent that separating them creates a new boundary instead of removing one; a combined Chief Data, Analytics and AI Officer is their answer. This is the strongest counterargument, and this paper partially concedes it: where a mature data and analytics organisation already exists, a CDAIO is a legitimate implementation of the position defended here — a dedicated, specialist, organisation-wide AI mandate that happens to carry data and analytics with it. What the concession does not extend to is the reverse construction: bolting "and AI" onto an incumbent CDO title without adding the specialist competence of Section 2 or the attention capacity of Section 3. The test is not what the role is called but whether AI governance receives dedicated expertise and undivided attention. Where it does, the CDAIO and the CAIO are variants of the same answer.

"The role fails in practice" (the paradox objection). Shaik (2026) — an SSRN working paper, weighted accordingly — documents how CAIO roles fail: ambiguous mandates, overlapping authority, insufficient institutional legitimacy; the evangelist without operational authority, the technologist without strategic influence, the strategist at war with incumbents. Wade et al. (2024) add the organisational costs: overlap, expense, cross-functional conflict, and the risk of framing every problem as an AI problem. These are real failure modes — but they are arguments about implementation quality, not about the position. Every executive role can be created badly. The correct inference from Shaik and Wade is a set of design requirements — decision rights, budget influence, CEO access, explicit interfaces with CIO, CDO and CISO — which Section 8 adopts as conditions of the position rather than exceptions to it.

"The CIO/CTO can absorb it" (the status quo objection). This objection now carries the burden of proof, and the evidence it must overcome is the evidence of Sections 2 and 3: a specialist domain with fast-depreciating expertise, an attention mechanism that does not scale, a complementarity finding (Kučević et al., 2026) showing that the AI responsibility matrix falls outside typical technology mandates as currently designed, and field evidence (EY, 2025) that governance is losing the race with deployment under exactly this arrangement. An organisation may still conclude that its particular CIO has the competence, the capacity and the mandate. Above the threshold, that conclusion should be demonstrated, documented and revisited — not assumed.

8. What the Position Requires: Mandate Design

Defending the dedicated CAIO obliges this paper to say what the role must have — because a CAIO without these is the ceremonial role Shaik (2026) warns against, and worse than no CAIO at all.

The mandate must include: decision rights over scaling, pausing and stopping AI initiatives; budget influence across the AI portfolio, not merely an advisory voice; a reporting line to the CEO (the configuration most consistent with the organisation-wide scope documented by Uba and Böhmann, 2025); explicit, negotiated interfaces with the CIO (platforms and infrastructure), CDO (data readiness and governance), CISO (AI security posture) and legal/compliance (regulatory obligations under the AI Act and successor instruments); ownership of the regulatory map — which systems are in scope of which obligations, in which current wording, from which dates; and a capability agenda covering AI literacy (a legal duty under Article 4 as amended), workforce transformation and organisational adoption. In concrete terms: the stop/scale right should be written into the enterprise AI policy as a named authority, not a committee outcome; budget influence should mean sign-off on a defined share of AI-related spend across business units, not only control of a central AI budget; and the CEO reporting line should be direct — an indirect line through the CIO reproduces the very attention problem the role exists to solve. In every configuration — standalone CAIO, CDAIO variant, or a time-bounded transformation mandate — one design rule is non-negotiable: exactly one role owns the coherence of the whole.

9. Limitations

Four limitations bound this position. First, the CAIO-specific evidence base is young: most sources directly examining the role are conference papers, preprints or practitioner analyses, and the strongest peer-reviewed evidence (Li et al., 2021; Bendig et al., 2023) concerns the CIO, supporting the attention mechanism rather than the CAIO directly. Second, no study yet demonstrates a causal relationship between CAIO appointment and organisational outcomes; the adoption figures cited are descriptive, self-reported and definition-sensitive, and are used here as corroboration, not proof. Third, generalisability is bounded by context: Chinese listed firms (Li et al., 2021), U.S. S&P 500 firms (Bendig et al., 2023), large-enterprise secondary data (Uba and Böhmann, 2025) and SME interviews (Schäfer et al., 2022). Fourth, the regulatory landscape is demonstrably non-stationary — within this paper's citation window, U.S. federal policy was rescinded and replaced once and the EU high-risk timeline was amended once (Regulation (EU) 2026/1744); readers should verify the applicable regulatory state at the time of use. These limitations are why the position is scoped by a threshold rather than asserted universally — and why the honest formulation of the claim is a shifted burden of proof, not a demonstrated superiority.

10. Conclusion

AI is a specialist executive domain governed under continuous change, and executive attention is among the scarcest resources in the C-suite. Assigning the first to executives already spending much of the second is the organisational design most large organisations drift into — and one that the evidence, organisational practice and regulatory demands increasingly call into question.

This paper has therefore defended a position rather than surveyed a debate: above the threshold at which AI becomes strategic, cross-functional and consequential, dedicated executive ownership of AI — typically a Chief AI Officer, equivalently a properly mandated CDAIO, possibly as a time-bounded transformation mandate with the same authority — should be the default, and the alternatives should carry the burden of justification. Below the threshold, the position does not apply, and this paper resists the title inflation that would discredit it.

What no organisation above the threshold can any longer defend is the model that requires no decision at all: allow AI to spread across the enterprise, distribute its consequences across multiple executives, and assume that responsibility for it will somehow organise itself.

References

Bajwa, F. (2024) 'When you should (and shouldn't) have an AI leader in the C-suite', Harvard Law School Forum on Corporate Governance, 7 November. Available at: https://corpgov.law.harvard.edu/2024/11/07/when-you-should-and-shouldnt-have-an-ai-leader-in-the-c-suite/

Bendig, D., Wagner, R., Piening, E.P. and Foege, J.N. (2023) 'Attention to digital innovation: Exploring the impact of a Chief Information Officer in the top management team', MIS Quarterly, 47(4), pp. 1487–1516. Available at: https://doi.org/10.25300/MISQ/2023/17152

Chawla, R.N., Goyal, P. and Saxena, D.K. (2023) 'The role of CIO in digital transformation: An exploratory study', Information Systems and e-Business Management, 21(4), pp. 797–835. Available at: https://doi.org/10.1007/s10257-023-00651-1

European Union (2024) Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union, L series, 12 July. Available at: https://eur-lex.europa.eu/eli/reg/2024/1689/oj

European Union (2026) Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI). Official Journal of the European Union, 24 July 2026; in force 27 July 2026. Available at: https://eur-lex.europa.eu/eli/reg/2026/1744/oj

EY (2025) 'EY survey: AI adoption outpaces governance as risk awareness among the C-suite remains low', EY, 4 June. Available at: https://www.ey.com/en_gl/newsroom/2025/06/ey-survey-ai-adoption-outpaces-governance-as-risk-awareness-among-the-c-suite-remains-low

Foundry (2025) State of the CIO 2025 (executive summary). Available at: https://b2b-contenthub.com/wp-content/uploads/2025/04/R-ES_State-of-the-CIO_2025.pdf

Gopal, V., Davenport, T.H. and Bean, R. (2025) 'Why your company needs a Chief Data, Analytics, and AI Officer', Harvard Business Review, 1 December. Available at: https://hbr.org/2025/12/why-your-company-needs-a-chief-data-analytics-and-ai-officer

IBM Institute for Business Value (2026) 2026 CEO Study. Armonk, NY: IBM Institute for Business Value. Available at: https://www.ibm.com/thought-leadership/institute-business-value/en-us/c-suite-study/ceo/ (press release: https://newsroom.ibm.com/2026-05-04-ibm-study-ceos-are-reshaping-c-suite-roles-for-the-ai-era)

Kučević, E., Leible, S., Schanz, N. and Grünewald, F. (2026) 'Do CAIOs replace traditional CIOs? An investigation into the responsibilities of IT executives in the age of artificial intelligence', AMCIS 2026 Proceedings, paper 3. Available at: https://aisel.aisnet.org/amcis2026/sig_lead/sig_lead/3/

Li, J., Li, M., Wang, X. and Thatcher, J.B. (2021) 'Strategic directions for AI: The role of CIOs and boards of directors', MIS Quarterly, 45(3), pp. 1603–1644. Available at: https://doi.org/10.25300/MISQ/2021/16523

Office of Management and Budget (2025) M-25-21: Accelerating federal use of AI through innovation, governance, and public trust, 3 April. Washington, DC: Executive Office of the President. Available at: https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-21-Accelerating-Federal-Use-of-AI-through-Innovation-Governance-and-Public-Trust.pdf

Schäfer, M., Schneider, J., Drechsler, K. and vom Brocke, J. (2022) 'AI governance: Are Chief AI Officers and AI Risk Officers needed?', ECIS 2022 Research Papers, paper 163. Available at: https://aisel.aisnet.org/ecis2022_rp/163/

Schmitt, M. (2026) 'Strategic integration of artificial intelligence in the C-suite: The role of the Chief AI Officer', arXiv preprint, arXiv:2407.10247v3 (first version 30 April 2024; version 3 revised 8 June 2026). Available at: https://arxiv.org/abs/2407.10247

Shaik, A.S. (2026) 'The Chief AI Officer paradox: Role ambiguity, organizational power, and strategic misalignment in the C-suite', SSRN working paper, 1 March. https://doi.org/10.2139/ssrn.6627438. Available at: https://ssrn.com/abstract=6627438

Uba, C. and Böhmann, T. (2025) 'Who is driving AI-enabled transformation? Towards a taxonomy of Chief AI Officers', ECIS 2025 Proceedings, paper 19. Available at: https://aisel.aisnet.org/ecis2025/ai_org/ai_org/19/

Wade, M., Lagodny, A., Andersen, A.-C., Avelines, C. and Plueckebaum, A. (2024) 'Do you really need a Chief AI Officer?', MIT Sloan Management Review, 7 August. Available at: https://sloanreview.mit.edu/article/do-you-really-need-a-chief-ai-officer/

From a one-off position paper to continuous governance intelligence

The theory in this paper is point-in-time; the reality of the EU AI Act changes continuously. Let us track compliance and governance developments for you each month with the Vera Monitor.