Skip to content
iclock 7 Minutes - Read Now
idate

An Open Letter to the New Chief AI Officer

In mid-July, Arnold & Porter named its first Chief AI Officer. New York Life named one around two weeks later. […]

Julia Petre
Julia Petre Head of Marketing, Ethisphere
a woman with binary code projected across her face

In mid-July, Arnold & Porter named its first Chief AI Officer. New York Life named one around two weeks later. Vanguard, CrowdStrike, Opendoor, Manulife, and FactSet have all created the role this year. One industry tracker counted ten new AI leadership appointments in June alone across insurance, cybersecurity, law, real estate, government, and higher education, and more than 50 since the start of 2026.

So congratulations, and welcome to a job that did not exist at most companies eighteen months ago.

“The measure of success won’t be how much AI we deploy. It will be the difference it makes,” says Chandhu Nair, who stepped into the role at Target in early August. We agree, and we want to add the part that determines whether that difference holds up.

We are an ethics and compliance organization, so you can guess where this is going. Stay with us, because this is an argument about your results.

Governance is what makes AI output usable

Enterprise AI works well enough today to change how a large company operates, and it will be better by the time you finish onboarding. Your bottleneck sits downstream of the technology, in whether anyone will act on what it produces in the way you intend.

An output nobody trusts gets a second human review, then a third, then a committee. A deployment nobody documented gets suspended when a regulator asks a question about it. A vendor model nobody assessed becomes the reason a business unit abandons the tool you spent a year rolling out. A marketing campaign that lost sight of its recipient in a sea of targeting data does not result in better sales.  Each of those is a governance failure wearing the costume of a technology problem, and each one lands on your scorecard.

Governance is what converts capability into something the business can rely on and that can achieve the desired results. Companies that build it early move faster in year two, because decisions get made once and each new use case inherits the review that came before it.

Policy is the easy half

Here is the finding that shapes our view. Across the 134 senior ethics and compliance leaders we surveyed in June 2026, nearly 75% have a written AI use policy in place. But only 28% have any monitoring or audit of how AI tools get used.

That distance is the whole subject.

A policy is a statement of intent. Governance, however, lives in artifacts such as a model and use-case inventory, a documented risk review, a contract clause, a human-review trigger with a record behind it, or a usage log someone reads. Boards and regulators evaluate those artifacts. Many companies write the policy and stop there, which leaves them with a strong position on paper and nothing to show when the question gets specific.

When your deployment of AI faces its first challenge—and it will—evidence is what travels. Every hour spent building the artifact now is an hour saved reconstructing a decision trail under pressure later.

Most of your AI will arrive through a vendor

This is the governance gap we would fix first, because it sits where AI enters a large company.

Ethics and compliance owns third-party risk management at most large organizations. Our 2026 World’s Most Ethical Companies benchmark, drawn from the most mature programs we measure, shows how far AI has traveled into that work:

  • 51% include artificial intelligence as a risk type in third-party due diligence
  • 24% include a provision on AI use in their third-party code of conduct
  • 86% reserve a right to audit in that same code
  • 42% have run a stand-alone audit of responsible AI use in the past 24 months

Half of this cohort raises AI when evaluating a vendor. A quarter writes the standard into the document that binds one. Most hold a contractual right to audit against an AI standard they never set.

When we published on this last year, only 15% had an AI provision in their third-party code. It’s easy to see why: a diligence question goes into a questionnaire this quarter, and a code provision moves at the speed of the slowest signature across legal, procurement, and supplier relationship owners.

Our position is that third-party AI governance belongs in your program as a formal gate, such as a questionnaire, a contractual provision, an assurance step, a kill switch, and an annual attestation. Every AI capability entering through procurement passes it. This is the most fixable item on your list, and the work is well understood in every other risk domain.

Blanket human review will reach you first

Among the most AI-advanced organizations in our survey, 71% require a human to check AI-generated work before it is used. Across the full sample, 60% do.

That standard fits AI that drafts and summarizes. It gives way for AI that acts, where systems plan multi-step tasks and execute with intermittent human input. If your roadmap includes agentic AI, you will meet this policy in your first year, and it will read as a brake.

Consider a risk-tiered approach. Low-risk reversible output, a first-pass summary or a draft outline, merits spot-checking. Medium-risk work requires review before external action. Anything touching investigations, legal privilege, or regulatory filings demands review at every step, no exceptions.

Companies that tier this on purpose can take advantage of agentic AI as it matures. Companies that wait for a universal all-clear will hold this conversation again in eighteen months,  perhaps generating significant shadow AI use along the way

Assume the inquiry is coming 

We asked ethics and compliance leaders how prepared their function is to respond to an internal audit, regulator, or board inquiry about AI use.  Only 10% said very prepared. Sixty percent placed themselves as partially prepared or below.

The explanation sits in the artifacts again. Thirteen percent have a documentation requirement for AI-assisted work. Twenty-eight percent have monitoring or audit of AI tool usage. A function asked to account for AI use has thin material to account with.

Our 2026 World’s Most Ethical Companies data shows the same picture from the audit side. Among the most mature programs we measure, responsible use of AI is the least-audited element of the ethics and compliance program. Among the most mature programs we measure, 42% have put it through a stand-alone audit in the past 24 months, against 82% for third-party risk management, 79% for gifts and entertainment, and 61% for data privacy. Programs with deep audit discipline everywhere else have yet to turn it on AI.

Our recommendation is a standing AI report to the board: one page, monthly or quarterly, covering four things. Coverage (inventory completeness, share of use cases through risk review). Controls (human-review rates, exception rates). Third-party assurance (vendors under AI provisions, remediation time). Capability (training reach, AI fluency on the team).

Board visibility is the forcing function for everything above. It also gives you an ally in the room the next time someone asks whether the AI program is under control. 

One last number

We asked ethics and compliance leaders what stands between their organization and responsible AI adoption. Resistance from leadership came in at 1.5%. Accuracy and hallucination risk came in at 46%, confidentiality and data exposure at 42%.

Nobody is fighting you. The open question is confidence in the output, and governance is what builds confidence. The inventory, the review record, the vendor clause, and the tiered human check are all reasons for a business leader to act on what your systems produce.

You will find the people who wrote your company’s AI guardrails understand your risk tolerance and your governance model better than anyone else in the building. Bring them in early. It will make your numbers better.