Why the Head of AI Role Needs Both Adoption and Stop Authority in One Seat

Should your Head of AI own both AI adoption and AI controls?

Stop authority gets resisted when someone else owns the upside.

The Situation

Most firms hiring a Head of AI write the role one of two ways: (1) as an adoption mandate or (2) as a governance mandate, and almost never both. In a recent LinkedIn discussion about what the role should be, I asked which decision authority draws the most resistance, and a CHRO answered without hesitating that it's Stop Authority, because ideas and deployments are scattered across the business and carry real enthusiasm, which makes restraint hard to impose. However, when one executive owns both the value and the controls, a halt is simply part of managing the portfolio. When those responsibilities are divided, the seat holding stop authority doesn't also own the upside, so every halt becomes one executive overruling another executive's program.Insurance and banking regulators expect named, senior accountability for AI and models. The NAIC's model bulletin on insurers' use of AI, adopted in 24 states and jurisdictions, says insurers should vest responsibility for oversight "and for setting the Insurer's strategy for AI Systems with senior management accountable to the board" so that strategy and oversight sit in the same hands. In April, the Fed, OCC and FDIC replaced SR 11-7 with revised guidance stating that "sound governance practices delineate the individual(s) responsible for key activities throughout the model lifecycle." The updated guidance expressly excluded generative and agentic AI, leaving that governance to each bank's own risk management and governance practices. Deciding who owns them is now explicitly your call. When those responsibilities are split between an adoption lead and a governance lead, halting a live system producing harmful outputs means winning an internal argument first, which delays the halt, and every email in that argument is discoverable.

The Exposure

Insurance and banking regulators expect named, senior accountability for AI and models. The NAIC's model bulletin on insurers' use of AI, adopted in 24 states and jurisdictions, says insurers should vest responsibility for oversight "and for setting the Insurer's strategy for AI Systems with senior management accountable to the board" so that strategy and oversight sit in the same hands. In April, the Fed, OCC and FDIC replaced SR 11-7 with revised guidance stating that "sound governance practices delineate the individual(s) responsible for key activities throughout the model lifecycle." The updated guidance expressly excluded generative and agentic AI, leaving that governance to each bank's own risk management and governance practices. Deciding who owns them is now explicitly your call. When those responsibilities are split between an adoption lead and a governance lead, halting a live system producing harmful outputs means winning an internal argument first, which delays the halt, and every email in that argument is discoverable.

The Judgment Call

The prevailing approach treats the Head of AI as a coordinator. "No one person should own AI," a co-author of IBM's 2025 Chief AI Officer report said this spring. "It has to be shepherded." In that model the role focuses on adoption and embedding, while risk trade-offs implicitly sit with compliance, legal or a governance committee. It's right about the operational work, since business units build and run AI. It's wrong about the decision mandate, since whether a system ships and whether it stays running is a different class of decision. Finance faced and solved this for its own processes long ago: the CFO owns both capital allocation and the controls over it, certifying them under SOX Section 302, while the external auditor provides independent attestation. Owning both halves doesn't compromise the CFO, because the independence sits with the auditor. The IIA's Three Lines Model says the same thing, that first and second line roles "may be blended or separated," with independence reserved for internal audit. So under this well-established model, a single seat should hold the use-case portfolio with the path to production, intake, risk classification, stop authority and evidence custody. Ideally it reports to the CEO, and it should never report to an executive whose deployments it evaluates. With value and control unified in one seat, halting a system becomes a portfolio decision instead of a political one.

  • Risk: A seat measured predominantly on deployments will be tempted to go easy on its own controls, and the CIO or CTO who holds the AI portfolio today will read consolidation as lost scope and budget.

  • Benefit: Halts become portfolio calls by the one person accountable for both value and exposure, and your board and regulators get one name and one evidence trail.

This Week’s Action

  • What to do: Run your Head of AI job description, or the mandate of whoever carries AI today, through the checklist below. Answer based on how the role actually operates.

  • Who to involve: Your CEO or the role's executive sponsor, your CHRO as owner of the job specification, and your CAE to confirm internal audit's attestation role.

  • What outcome to achieve: A one-page map showing whether value and control sit in one seat or two, each authority tied to a named person, and a decision on whether to consolidate before the next hire.

  • Time required: 20 minutes to complete the checklist; 45 minutes with the CEO and CHRO to review the gaps.

Artifact

Answer for how your Head of AI operates today.

The Mandate

1. Does one named person own the AI use-case portfolio and the path to production?

☐ YES     ☐ NO     ☐ UNKNOWN

2. Is that person also accountable for AI controls and evidence?

☐ YES     ☐ NO     ☐ UNKNOWN

The Five Authorities

3. Decision Intake: Can they reject a use case over the sponsoring executive's objection?

☐ YES     ☐ NO     ☐ UNKNOWN

4. Risk classification: Is the risk tier they assign binding on the business?

☐ YES     ☐ NO     ☐ UNKNOWN

5. Stop Authority: Can they halt a live system on pre-set triggers without committee approval?

☐ YES     ☐ NO     ☐ UNKNOWN

6. Evidence Custody: Can they produce any system's full audit trail within 48 hours?

☐ YES     ☐ NO     ☐ UNKNOWN

7. Reporting Line: Do they sit outside the reporting chain of every executive whose deployments they evaluate?

☐ YES     ☐ NO     ☐ UNKNOWN

Attestation

8. Does internal audit, not the Head of AI, independently review how the AI program is run?

☐ YES     ☐ NO     ☐ UNKNOWN

A NO on question 1 or 2 means the role is split across two seats, and every halt gets negotiated.

Any NO on questions 3 through 7 means the seat has the title without authority that holds up to regulators, plaintiffs or the press.

Two or more UNKNOWN answers is a finding to take to your CEO.

If your CHRO hasn't checked whether your Head of AI posting gives one seat both mandates, this checklist shows it in ten minutes.

Full Head of AI role specification template (customizable Word file): blackboxzero.com/resources/head-of-ai-role-specification

Working through a specific AI decision right now? Reply to this email and tell me what it is. I read every response and answer directly.

When the stakes exceed your internal capacity:

  • AI Exposure Diagnostic: A 2-hour strategic evaluation for risk, compliance, and legal leaders to identify your highest-priority governance gaps and deliver a 90-day remediation roadmap.

  • 12-Week Governance Sprint: Translate regulatory requirements into audit-ready policies, control frameworks, and accountability structures.

  • Fractional Chief AI Officer: Embedded ownership of governance, intake, and board reporting before the function is formalized, with the eventual role scoped and the search supported when it's time to hire.

Reply with "Diagnostic," "Sprint," or "Fractional" to schedule a conversation for next month.


Chris Cook writes Judgment Call weekly for compliance and risk officers navigating AI governance.

Former IBM Vice President and Deputy Chief Auditor. Published in the AI Journal, speaker at Yale.

Chris Cook

Managing Partner & Founder

Blackbox Zero

Forwarded this by a colleague? Subscribe to Judgment Call

Next
Next

Why an ISO 42001 Certificate Doesn't Satisfy Your Insurer's Model-Level Audit Obligation