Share with your CHRO
EY’s Peter Fox makes a pointed case that responsible AI is a workforce capability problem, not a policy problem, and the accountability lands on the CHRO. The EY Responsible AI Pulse Survey puts two numbers on the table that should sting: only 9% of CHROs can identify appropriate controls for key AI risks, and only 30% of HR teams have begun building strategies for hybrid AI-human workforces. Meanwhile, two-thirds of organisations already allow employees to build their own AI agents on unapproved platforms.
What this means for your business
The 9% figure is the one worth sitting with. If nearly every CHRO lacks the fluency to identify AI risk controls, then every “human in the loop” governance model, the design principle that keeps a person accountable for AI decisions, is running on a hollow assumption. Your organization may believe it has oversight. What it actually has is a signature on a form. Whether this story is about you depends on a single honest question: could your HR leadership explain, concretely, what makes a citizen-developed AI agent dangerous before it causes damage?
The citizen developer problem is where the argument sharpens. Fox’s framing, coming from an advisory firm that sells AI governance services, predictably tilts toward the “equip and govern” solution rather than the “restrict and audit” alternative. That tilt is worth noting, but it doesn’t make him wrong. Blocking shadow AI has a poor track record; the history of shadow IT is instructive. Employees routed around VPN restrictions, unauthorized cloud storage, and unsanctioned SaaS tools for years before IT gave up containment and moved to management. The same dynamic is playing out faster with AI agents, because the no-code tools are better and the productivity gains are more immediately visible to the person building them.
The real exposure isn’t the agents that get discovered. It’s the Pareto tail Fox describes, the roughly 80% of citizen-built agents that consume budget, introduce unvetted data flows, and carry risk no one formally accepted. A CHRO who can’t name what’s in that tail, or who owns accountability for it, is not running a responsible AI program. They’re running a compliance theater production. The decision this reframes isn’t whether to invest in AI training, it’s whether workforce AI governance sits inside HR’s budget and mandate at all, or whether it defaults by neglect to a CIO who’s already stretched thin.
Based on reporting from My message to the CHRO: You can’t install responsible AI | EY, originally published 2026-08-05 00:43:00.

