Half Of Finance Chiefs Say They Lack The Authority To Govern AI
- Johan Steyn

- 23 hours ago
- 3 min read
Fifty-one per cent report exactly that, while nearly one in five is told the responsibility for AI governance is theirs.

Sign up for my Substack daily AI newsletter here.
See my AI Training course portfolio for corporate Business Leaders here.
Follow me on LinkedIn: https://www.linkedin.com/in/johanosteyn/
Governance failures are usually described as a lack of care. This one is a lack of power. Deloitte has now put a figure on something South African boards should recognise immediately, and it says nothing about effort or intent. It concerns whether the executive answerable for artificial intelligence is in any position to act.
CONTEXT AND BACKGROUND
Deloitte’s second-quarter 2026 CFO Signals survey polled 200 North American finance chiefs at companies with at least one billion dollars in revenue, conducted between 22 May and 7 June 2026. Ninety-three per cent said their organisations now use AI across key operations, against the 66 per cent who in early 2024 described themselves as still experimenting with generative AI or merely reading and talking about it. Asked to identify the biggest obstacles to developing an effective enterprise-wide AI governance framework, 59 per cent cited the pressure to deploy quickly while managing risk, 51 per cent reported a lack of governance authority, and 43 per cent pointed to insufficient visibility into AI tools or their use. Nineteen per cent said they themselves hold the greatest responsibility for AI governance, placing finance ahead of the chief executive, the board and the chief risk officer, though behind information security and information officers.
INSIGHT AND ANALYSIS
Set those figures beside one another. A fifth of finance chiefs consider themselves the most responsible party for AI governance. Half report they lack the authority to exercise it. Two in five cannot see which tools are operating or how they are used. That is not a governance structure. It is an allocation of blame arranged in advance of the failure it will be needed for. The Oliver Wyman Forum, surveying 494 CFOs whose public companies represent roughly 12 per cent of global listed equity, arrives at the same place by another route, describing midsize-company finance chiefs as operating as de facto chief risk officers without the dedicated teams, tools or frameworks their larger counterparts rely on. Seventy-five per cent of those respondents expect greater involvement in strategic and business model risk, and 44 per cent expect the same in cybersecurity and technology resilience. Responsibility is expanding steadily. Authority is not moving with it.
IMPLICATIONS
The visibility gap carries a measurable price. Among organisations that suffered an AI-related breach, 92 per cent lacked proper AI access controls. An executive who cannot establish which systems are running, what data they reach or who authorised that access is not positioned to prevent any of it. In South Africa the personal exposure runs deeper than the governance debate suggests, since section 99 of POPIA creates a civil remedy allowing affected data subjects to claim compensation, carrying no equivalent to the R10 million administrative ceiling. Local finance leaders carry this while funding transformation in an economy growing near 1.2 per cent, where, as Oliver Wyman’s Sandra Villars observes, businesses do not have the luxury of pursuing transformation without a clear commercial case and every investment competes for scarce capital.
CLOSING TAKEAWAY
The remedy is not another committee. It is a decision the board must take explicitly and minute. Name the executive accountable for AI governance. Give that person authority to approve or refuse deployments, visibility into what is running across the organisation, and budget sufficient to build the controls. Where a board is unwilling to grant all three, it should not assign the accountability at all, because responsibility that cannot be discharged protects nobody and misleads everyone who reads the integrated report. South African governance codes have always held that accountability must rest with someone able to exercise it. Fifty-one per cent is the measure of how far current practice has drifted from that principle, and the drift was nobody’s decision, which is precisely the problem.
Johan Steyn is a prominent AI thought leader, speaker, and author with a deep understanding of artificial intelligence’s impact on business and society. He is passionate about ethical AI development and its role in shaping a better future. Find out more about Johan’s work at https://www.aiforbusiness.net



Comments