Should AI report to IT?
Not by default. Point AI at your most forward-thinking senior leader, high in the company. If IT is involved, its mandate has to change from control to enablement, or you have pointed the future at the department of no.
Not by default, and the default is the trap.
IT is the reflexive home for anything technical, so AI lands there without anyone deciding it should. The problem is not competence. It is mandate. In a regulated company, IT was built over two decades to control: validated systems, access, data integrity, audit trails. That is real and necessary work, and it trains a function to protect the company by slowing the new thing down. Point your AI ambition at a function whose whole reflex is to say no, and you get exactly that.
So the better instinct is the opposite one. AI is not one more system to lock down; it is the capability the whole company now runs on, which means its owner should be your most forward-thinking, respected senior leader, high in the company, not a compliance silo. Give it a real owner, close to the ambition.
If your AI does end up connected to IT, the reporting line is only half the job. The mandate has to change with it, from “prevent the bad” to “enable the responsible,” and the function has to be rewarded for the new mandate rather than for tickets closed and incidents avoided. Otherwise you have renamed the department of no and changed nothing. Governance done this way is not a brake; it is the shaping cone that turns a blast into directed flight. The worked example is in Don’t Default AI to IT.
Cheers,
-Titus
Get it in your inbox.
New Issues, FAQs, and Case Studies as they go out. Each one names something, explains something, or hands you something you can use on Monday. Subscribe, and I will send each as it goes out.
Prefer the tool you already think in? Here is how to read it in your chatbot.