6 min left
    AIM CIO Vision Summit
    CDO Vision Seattle | The Boardroom Conversation - How CXOs Shape AI Strategy
    Back to Blog
    Inside CDO Vision

    CDO Vision Seattle | The Boardroom Conversation - How CXOs Shape AI Strategy

    May 5, 20266 min read1 views

    Everyone owns the data. Which means nobody does.

    If your board is talking about AI strategy before it has talked about data ownership, dynamic risk management, and accountability structures, it is talking about the wrong things. Not because AI strategy is unimportant. But because without those foundations in place, strategy is just ambition with a slide deck attached.

    Data that nobody has catalogued. Risk frameworks built for a slower threat environment. Accountability structures that look clear on an org chart but dissolve the moment something goes wrong. These are not edge cases. They are the norm inside most large enterprises right now, and they are the reason so many AI initiatives that start with boardroom confidence end somewhere quieter. The gap between what boards want from AI and what their organisations are actually ready to deliver is the defining tension in enterprise technology today, and it was the subject of an unflinching conversation at CDO Vision Seattle, part of the CDO Vision AI World Series.

    CDO Vision Seattle is part of the broader CDO Vision AI World Series, a premier gathering of 30+ senior data, technology, and AI leaders convened to move the conversation on artificial intelligence from aspiration into practice. The panel, titled The Boardroom Conversation: How CXOs Shape AI Strategy, was moderated by Jonathan Barrios, Chief Information Security Officer at Vindicia. He was joined by Aradhna C., Managing Director of Cloud Security and Dev-Sec-Ops at TIAA; Egor Pushkin, Chief Architect of Data and AI at Oracle; Nirmala Sistla, Executive Vice President and Head of Engineering for Data and Analytics Platforms at Mastercard; and Rohit Dudani, Chief Technology Officer at Zelle. Together they brought perspectives from financial services, payments technology, cloud security, and enterprise data architecture, industries where getting AI wrong carries consequences that go well beyond missed targets.

    Data readiness

    The panel was direct about a pattern that has become familiar: boards push for AI adoption before anyone has done the hard work of understanding what data the organisation actually has, who owns it, and whether it is fit for purpose. Nirmala Sistla framed the foundation clearly, data needs to be discoverable, accessible, interoperable, and reusable before AI can reliably produce the outcomes being promised. Without that, the models will hallucinate, the outputs will be unreliable, and the business case will quietly fall apart.

    Rohit Dudani sharpened the ownership problem. "If you go to your organisation and ask who owns the data," he said, "everyone will say we all own the data. If everything is owned by all, then nobody owns it." His point was simple but consequential: ownership has to be assigned to an individual, by segment, by domain, by function, and that individual has to be accountable for quality, pipeline integrity, and access.

    Egor Pushkin introduced a fresh angle. Generative AI, he argued, has introduced a new and largely invisible data risk. Unlike previous technology transitions, GenAI is not just consuming enterprise data, it is generating new data through external vendor channels that most organisations are not tracking, cannot trace, and have not begun to govern. "It became a source and a channel through which new data originates," Pushkin said, "and that data is nearly invisible." That supply chain risk, he argued, is arguably the most important area for enterprises to address right now, and the least attended to.

    Risk management

    Every panelist on stage represented a heavily regulated industry. And the conversation on risk was pointed. The standard approach, identify risks, document them, rate them by probability and impact, escalate to legal, was not built for the speed at which AI is changing the threat environment. Aradhna C. made the case for something fundamentally different: probes embedded directly into systems, continuously monitoring configurations, vulnerabilities, and infrastructure state, with risk indicators updating in real time rather than through periodic reviews. "From static and manual risk management processes," she said, "it has to become dynamic."

    She went further. AI agents, she argued, should be deployed to autonomously remediate certain classes of risk without waiting for human approval. A misconfigured access point that exposes sensitive data does not need a committee, it needs an agent that can close it the moment it is detected. That shift, from human-reviewed to agent-remediated risk response, represents a meaningful change in how security and compliance functions will need to operate.

    Jonathan Barrios added a dimension that reframed the entire conversation. Whether an organisation adopts AI or not, it is going to be targeted by AI-powered attacks. "You're going to be attacked," he said. "So be prepared for that." The implication was clear: the question of AI readiness is not just about what you build. It is about what you can defend against.

    Accountability without ownership is a fiction.

    The final theme ran beneath every other discussion on stage. Governance frameworks, compliance programmes, and data policies all depend on one thing that most organisations have not cleanly solved: someone being genuinely responsible. Egor Pushkin made the product-level argument, accountability has to be top-down and product-driven, because the product is what reaches the customer and carries the liability. Assigning responsibility to a pipeline or a platform means that when something goes wrong, nobody can answer for it.

    Nirmala Sistla offered a pragmatic path forward. The manual work of tagging, labeling, and cataloguing data, work that organisations have been deferring for decades, can now be partially automated using AI itself. LLMs can search for data elements, classify them, and surface what has previously been invisible. The irony, she noted, is that AI can help solve the data governance problem that has blocked responsible AI adoption in the first place.

    Rohit Dudani closed the theme with a cultural observation. Ownership is not just a designation on an org chart. Everyone in an organisation either produces data or consumes it, and until the culture reflects that, until individuals understand their role in the data chain and act accordingly, even the best governance structures will be built on unstable ground.

    The panel at CDO Vision Seattle offered a clear-eyed account of what has to be true before the ambition can safely scale. Data readiness, dynamic risk management, and genuine accountability are not prerequisites that can be deferred. They are the work. And the organisations that treat them as such, rather than as footnotes to a faster AI rollout, are the ones most likely to still be standing when the wave settles.

    Comments (0)

    Sign in to join the conversation