AI ownership often looks clear while an organisation is running a handful of experiments. A platform is approved, a use case is tested, a pilot begins and the relevant checks take place. With several people involved at different stages, everyone assumes the work is covered.
Then adoption spreads.
Marketing uses one set of tools, operations builds an automated workflow, HR tests an assistant and client teams begin using AI in live work. Questions arrive faster than the organisation can answer them. Who decides which use cases deserve investment? Who can approve deployment? Who owns an inaccurate output? Who measures value? Who stops a system that is no longer performing as intended?
At that point, AI is no longer a collection of technology projects. It is an operating-model question.
The latest UK evidence makes this urgent. The Department for Science, Innovation and Technology’s AI Adoption Research, updated in February 2026, found that 16% of UK businesses use at least one AI technology. Among adopters, 77% said fewer than half of their staff use AI. Only 54% of organisations already using AI felt ready to scale it.
The pattern is clear: activity is expanding, but embedded capability and readiness remain uneven.
The answer is not to place every AI decision in one team. Nor is it to declare that AI belongs to everyone. Organisations need broad participation with explicit accountability. The people closest to the work should shape and own use cases, while named individuals set direction, coordinate activity, manage risk and make final decisions.
The structure used to achieve this should reflect the organisation’s size, resources and level of AI activity.
Why “everyone owns AI” usually means nobody does
AI touches several areas of responsibility at once:
- Strategy determines where AI could create value.
- Business functions identify problems and change how work gets done.
- Technology supports platforms, integration and security.
- Data responsibilities include access, quality and appropriate use.
- Legal, compliance and risk considerations shape higher-impact uses.
- People and learning responsibilities include training, adoption and changing roles.
- Financial oversight tests business cases and tracks value.
These are responsibilities, not necessarily separate departments. In a smaller organisation, one person may cover several areas, while specialist support may come from an external partner or adviser.
What matters is that each responsibility has been considered and important decisions have a clear owner.
When participation and accountability become confused, predictable problems emerge. Decisions move slowly because no one has final authority. Teams duplicate experiments because existing activity is not visible. Risk is considered too late. Business outcomes are handed to technology teams that do not control the processes being changed. Projects also continue after their value has faded because no one is responsible for monitoring or stopping them.
The useful question is: who owns each decision across the AI lifecycle?
What an AI operating model needs to do
An AI operating model is the practical system for turning strategy into repeatable decisions and delivery. It defines responsibilities, decision rights, ways of working, measures and escalation routes.
It should make six things clear:
- Who sets the organisation’s direction and investment priorities?
- Who owns the outcome of each use case?
- Who coordinates technology, data and implementation?
- Who assesses risk and can require changes or stop deployment?
- Who is responsible for adoption, process change and workforce readiness?
- Who monitors performance and decides whether to improve, expand or retire a solution?
This is broader than an AI policy. A policy states what is permitted. An operating model determines how people make decisions and deliver work within those boundaries.
NIST’s AI Risk Management Framework reinforces this distinction. Its Govern function calls for documented roles, responsibilities and lines of communication, with leadership taking responsibility for decisions about AI risk.
The principle is simple: controls only work when people have the authority, capability and information to apply them.
A practical model that matches the size of your organisation
Large enterprises and SMEs need the same clarity around AI ownership, but they do not need the same structure.
For SMEs and mid-sized organisations
Most smaller and mid-sized organisations do not need a dedicated AI committee, portfolio manager or centre of excellence. They can establish clear ownership through a simpler model:
- A senior sponsor takes overall responsibility for AI priorities, investment and risk.
- A named AI lead maintains visibility across tools and use cases, coordinates implementation and monitors costs, adoption and issues.
- A business owner for each use case remains accountable for the intended outcome, process change and user adoption.
- Specialist input is brought in when a use case involves sensitive data, customers, employees, regulated decisions or significant automation.
These responsibilities can sit within existing leadership, technology, operations or transformation roles. AI decisions can also form part of existing management meetings rather than requiring a separate committee.
The goal is not to create more roles. It is to make sure that every important decision has an owner and that the level of oversight matches the risk.
For large enterprises
Large organisations with AI activity across several functions, business units or markets may need a more formal, federated model:
- An executive sponsor sets the overall direction, investment priorities and risk appetite.
- An AI portfolio owner coordinates projects, monitors dependencies and escalates unresolved decisions.
- A cross-functional group decides which opportunities should progress and how higher-risk uses should be managed.
- A central enablement team provides shared technology, standards, methods, training and specialist support.
- Functional owners remain accountable for business outcomes, process changes and adoption.
- Product and control owners oversee performance, security, data use, compliance, incidents and improvement.
This structure allows different parts of the organisation to develop relevant use cases while maintaining consistent standards and visible accountability.
Assign ownership to decisions, not job titles
The same person may hold several responsibilities, particularly in a mid-sized organisation. What matters is not the title on an organisation chart, but who has the final authority to make each decision.
At a minimum, ownership should be clear for the following decisions:
- Set AI priorities and risk appetite. A senior sponsor should decide where the organisation will focus, what it will invest and what level of risk it will accept.
- Approve a use case. A business owner should define the expected outcome, while the senior sponsor or AI lead confirms that the use case fits the organisation’s priorities.
- Choose the technology and implementation approach. The named AI or technology lead should coordinate the decision and involve specialist support where needed.
- Approve the use of data. Someone with responsibility for the relevant data should confirm that it can be used appropriately and securely.
- Accept or escalate significant risk. A senior decision-maker should make the final decision, supported by appropriate internal or external advice.
- Approve deployment. The business owner should confirm that the solution is ready to use after the necessary technical, data and risk checks.
- Monitor, improve or stop the solution. The business owner should track results and work with the AI lead to address issues, expand successful uses or retire solutions that no longer deliver value.
One accountable owner does not mean one person works alone. It means everyone knows where final responsibility sits.
Use proportional governance to keep work moving
Not every use case needs the same approval process. An internal assistant that summarises low-sensitivity documents should not face the same scrutiny as a system that influences hiring, credit, legal advice or customer eligibility.
Create a simple assessment at the start of the lifecycle. Consider factors such as:
- the sensitivity of the data;
- the potential impact on employees, customers or other people;
- how independently the system can act;
- whether its outputs will be used externally;
- how easily a decision or action can be reversed;
- whether regulatory or contractual requirements apply.
The answers can be used to place work into three broad routes:
- Low-risk route: use approved tools, record the use case, name an owner and complete appropriate local testing.
- Managed route: document the assessment, complete more formal testing and obtain relevant technical, data or legal input before deployment.
- High-impact route: require senior approval, specialist internal or external review, strict human oversight and enhanced monitoring.
This approach protects speed as well as safety. Low-risk work can move quickly because the boundaries are clear. Higher-impact work receives appropriate attention before the organisation invests heavily or exposes users to unnecessary risk.
Measure the operating model, not just the technology
Technical accuracy is only one measure of success. Leaders also need evidence that the organisation can select, adopt and improve AI responsibly.
Not every organisation needs an extensive performance framework. Start with a small set of measures that reflect the scale and purpose of each use case:
- Value: revenue, cost, capacity, cycle time or service improvements.
- Adoption: active use, repeat use, workflow completion and user confidence.
- Quality and risk: errors, human overrides, incidents, complaints and control exceptions.
- Delivery: time from idea to decision, time to deployment and stalled activity.
- Cost: implementation and running costs, supplier spend and duplicated tools.
- Capability: workforce readiness and the ability to operate solutions without constant specialist support.
McKinsey’s 2025 State of AI report found that CEO oversight of AI governance correlated with higher self-reported bottom-line impact. It also identified workflow redesign as the organisational factor with the greatest effect, while only 21% of respondents using generative AI said their organisations had fundamentally redesigned at least some workflows.
The lesson is that ownership must reach beyond approval. It must extend into how work changes and how value is measured.
A 90-day route from scattered activity to accountable scale
Organisations do not need to redesign their entire structure before making progress. A focused 90-day sequence can establish the foundations.
Days 1 to 30: understand the starting point
Review current AI activity, including approved tools, local experiments, supplier capabilities and known unapproved use.
Speak to leaders and teams to understand business priorities, operational problems, data constraints, risk concerns and workforce readiness. Create a single list of use cases and group them by outcome, maturity and risk.
Many organisations discover that they have more AI activity than expected, but less coordination and ownership.
Days 31 to 60: set ownership and priorities
Name a senior sponsor and the person responsible for coordinating AI activity.
In a large enterprise, this may include a portfolio owner and a regular cross-functional forum. In an SME or mid-sized organisation, the responsibility can form part of an existing technology, operations or transformation role, with decisions handled through established management meetings.
Assign a business owner to every priority use case. Agree a small set of principles, risk levels and approval requirements. Prioritise use cases according to value, feasibility, strategic relevance and organisational readiness. Stop or combine duplicated experiments.
Days 61 to 90: test the model through delivery
Run one or two priority use cases through the new process. Test the decision path as carefully as the technology.
Record where ownership remains unclear, where reviews repeat one another and where people lack the information or expertise to decide. Bring in specialist support where necessary.
Establish a simple performance view covering value, adoption, risk, cost and lessons learned. Use the results to improve the operating model.
The first version should be practical, not perfect. Continuous improvement applies to ownership and decision-making as much as it does to AI systems.
The goal is clear accountability without unnecessary complexity
AI should be shaped by the people who understand the organisation’s strategy, customers, operations, technology, data, risks and workforce. But broad participation is not a substitute for ownership.
For an SME or mid-sized organisation, responsible scale may require only a senior sponsor, a named AI lead, a business owner for each significant use case and access to specialist advice when needed.
A large enterprise may divide these responsibilities across a portfolio owner, central team, functional leaders and control functions.
The structure can vary. The principles should not. Important decisions need a clear owner, oversight should match the level of risk and every solution should remain connected to a measurable business outcome.
When these elements are explicit, teams spend less time searching for approval, repeat less work and identify risks earlier. Leaders gain a portfolio they can steer rather than a growing list of disconnected experiments.
The organisations that scale AI well will not necessarily have the largest team or the longest policy. They will make responsibility visible in every important decision.
Move from scattered AI activity to accountable scale
As AI activity grows, unclear ownership can lead to duplicated investment, delayed decisions and solutions that never achieve meaningful adoption.
Calls9’s AI Fast Lane helps organisations understand what is already happening, identify the right priorities and create an operating model that fits their structure and resources.
Through the programme, we help you:
- Audit your existing AI capabilities
- Create your Generative AI strategy
- Identify Generative AI use cases
- Build and deploy Generative AI solutions
- Testing and continuous improvement




