Short answer. In a company of 10 to 500 people, the person who should own AI is the leader who already owns how work gets done, usually the president, the COO or whoever runs operations. IT controls access and security. A named privacy lead covers personal information. Ownership means being accountable for results and risk, with the budget to act. In a small firm the owner holds it directly. A dedicated AI leader makes sense only when the volume of AI work outgrows a part-time role.
Survey figures verified 23 September 2026.
The person who should own AI in a 60-person Alberta company is almost never the IT person.
That runs against the usual instinct, because AI arrives looking like software, and software goes to IT. But the questions that decide if AI pays off sound nothing like IT questions. Which quoting process do we change? Who stops doing the old version? What do we tell the crew? Those belong to whoever runs the operation.
The large-company research points the same way. McKinsey’s global survey of 1,491 people, run in July 2024, found that CEO oversight of AI governance was one of the factors most correlated with higher self-reported bottom-line impact from generative AI. Only 28% of respondents at organizations using AI said their CEO held that oversight.
At the other end, IBM’s 2026 study of 2,000 CEOs found 76% of their organizations now have a chief AI officer, up from 26% a year before. Those are big companies with big budgets. The instinct to copy them is where many mid-sized firms go wrong.
Mid-sized Canadian companies are at a different stage. Statistics Canada’s analysis of AI use by businesses in the second quarter of 2026 found 19.2% of businesses used AI to produce goods or deliver services over the previous 12 months, and 27.8% of those with 100 or more employees.
Who should own AI in a company with 10 to 500 staff?
The leader who owns operations should own AI, because AI changes how work is done before it changes any system. In an owner-run firm that is the owner. With a leadership team, it is the COO, president or operations lead, backed by IT and a privacy lead.
Ownership here means three things. The owner is accountable when an AI project fails to pay back. The owner is accountable when an AI tool causes a privacy or client problem. And the owner has enough budget authority to start and stop work without a committee.
If one of those is missing, you don’t have an owner. You have a coordinator.
Alberta’s privacy commissioner makes a version of this point for privacy. The first of the OIPC’s ten steps for putting PIPA in place is to “put someone in charge with enough authority and resources to do the job.” The same test works for AI, and in smaller companies the two jobs often land on the same desk.
What does the AI owner actually do?
The AI owner keeps a list of every AI tool in use, owns the acceptable use policy, approves new tools and agents, picks the next use case, and reports results to the leadership team each quarter. Once projects are running, it should fit in a few hours weekly.
- Keeps the inventory. Which tools, which accounts, who has access, what data goes in. Expect to find tools nobody approved the first time you look, which is why finding shadow AI comes first.
- Owns the policy. The one-page AI acceptable use policy names this person, and they answer staff questions within days.
- Approves tools and agents. Including the access each agent gets, using the rules in AI agent permissions.
- Picks what’s next. One use case at a time, ranked on value and effort.
- Reports. A short quarterly update: what’s live, what it saves or earns, what went wrong, what gets cut.
The last item is the one that gets skipped. A quarterly report that includes what was cut is the best sign the owner has real authority.
Who should own AI, by company size and risk
Size decides who can realistically hold the role. Risk decides who else has to sign off. Low-risk uses such as drafting and internal summaries need one owner. Higher-risk uses involving customer data, hiring, pricing, health information or safety need a second person who can say no.
This is my working rule of thumb, drawn from how Alberta companies of these sizes are usually organized. Adjust it to your own structure.
| Company size | Low-risk AI use (drafting, research, internal summaries) | Higher-risk AI use (customer or staff data, hiring, pricing, health, safety) |
|---|---|---|
| Under 20 staff | The owner, with one keen staff member as the hands-on champion | The owner, plus outside advice from a lawyer, accountant or IT provider before launch |
| 20 to 99 staff | The operations lead or COO, with IT or the managed service provider handling accounts and access | The operations lead, with a named privacy lead and the controller or CFO signing off on anything touching money or personal information |
| 100 to 500 staff | A named leadership team member, with a champion in each department | That leader chairs a small group: privacy, IT security, HR and the affected department. The board hears about it at least once a year |
| Regulated work at any size | The owner or leader stays accountable. Add the regulated role, such as a health custodian’s privacy officer or a professional firm’s practice lead, as a required sign-off | |
The higher-risk column always has two names in it. That’s deliberate. The person who wants the project to succeed shouldn’t be the only person judging its risk.
Should you hire a chief AI officer?
For most Alberta companies under 500 staff, no. Give the role to an existing leader who owns operations and back them with outside help. A dedicated AI leader makes sense once AI work is constant across several departments and the existing leader can’t give it proper time.
There is a real argument on the other side. A dedicated hire brings focus and skills your team doesn’t have, and a new title signals to staff that AI is serious. If your AI plans involve building products or selling AI-driven services, that argument gets stronger.
If the dedicated-hire camp is right for you, hire someone who has run operations as well as built models, and make them report to the owner. If the existing-leader camp is right, protect a fixed block of that leader’s week for AI and buy in the technical skills. Either way, the person doing the work must have authority over the processes being changed, or nothing changes.
My view: most mid-sized companies that hire an AI leader too early end up with a smart person producing recommendations nobody with authority acts on.
The chart below shows how fast large companies moved on the title in a single year, which is exactly why copying them is tempting.

Why shouldn’t IT own AI on its own?
IT should control accounts, access, security and vendor setup, and that job matters. But when IT owns AI outright, projects get judged on the software working, and nobody checks that the business changed. The owner of the outcome has to be someone who can change how people work.
If you outsource IT to a managed service provider, the problem gets sharper. An outside provider can set up Copilot licences cleanly and still have no standing to tell the estimating team to change how it builds a quote.
The same goes for the enthusiast. Every company has one person who tried every tool first. Make them the champion. Don’t make them the owner unless they also run something.
How do you hand over AI ownership?
Name the person in writing, give them a one-paragraph mandate with a budget and the power to stop projects, tell the company who it is, and put the first quarterly report in the calendar. The whole handover fits in one leadership meeting and one all-staff email.
Write the mandate in plain terms. Something like: owns AI tools, policy and projects; approves new tools and agents; can spend up to an agreed amount without further sign-off; reports quarterly on results and incidents. Then give that person the steps to build an AI roadmap and the first 90 days of an AI program as their starting brief.
Two more habits make the role stick. The owner should train supervisors before staff, because supervisors decide if a new process survives its first busy week. And the owner should expect the finance questions early, so the questions a CFO will ask about AI are worth answering before the first budget request.
When the owner starts buying, the questions to ask an AI vendor keep the process honest.
Give AI to the person who can change how the work gets done, and give them the authority to do it. Every other arrangement produces activity instead of results.
Questions people ask
In a business with fewer than about 20 staff, the owner should hold responsibility directly, with one interested employee as a hands-on champion. The owner already controls budget, processes and client relationships, which are the things AI changes. Outside advice from a lawyer, accountant or IT provider helps when AI touches customer data.
IT should control accounts, access, security and vendor setup, but should not own AI on its own. AI projects succeed or fail on changing the way work is done, and that authority usually sits with operations. The best arrangement pairs an operations owner with IT as the gatekeeper for access.
Usually not. Most companies with 10 to 500 staff do better giving AI ownership to an existing leader who runs operations and buying technical skills as needed. A dedicated AI leader makes sense when AI work is constant across several departments, or when the company builds AI into its products.
An AI owner keeps an inventory of AI tools and who uses them, owns the AI acceptable use policy, approves new tools and agents, chooses the next use case, and reports quarterly to the leadership team on results, incidents and anything that was stopped. It should fit in a few hours a week once projects are running.
Yes, at least in oversight. McKinsey’s 2024 global survey found CEO oversight of AI governance was among the factors most correlated with higher self-reported bottom-line impact from generative AI. In mid-sized companies the CEO or owner often holds the role directly or appoints the operations leader and reviews results quarterly.
A second person besides the project owner. For uses involving customer or employee personal information, hiring, pricing, health information or safety, add a privacy lead, the controller or CFO, HR or the relevant regulated role as a required sign-off. The person who wants the project should not be the only one judging its risk.




