Launching soon

Atlas opens to its first companies this quarter. Leaders can list now.

List yourself

Who owns AI, the CTO, the CIO, the CDO, or a new seat

Four existing seats each own part of an AI programme and none of them owns the register. That gap is where UAE companies are currently exposed, and it is an org chart problem rather than a technology problem.

A building ceiling seen from below, its structure exposed.
rawpixel. Public domain, CC0.

Every company we speak to in Dubai has already had this argument, and most have not finished it.

The argument is usually framed as a turf question. It is not. It is an arithmetic question about what four existing seats already carry, and what happens to a fifth set of duties when you add them to a full desk.

What each seat already owns

The CTO owns the platform: infrastructure, the build, security architecture, the vendor stack, and in a product company the roadmap. AI capability sits naturally here. AI accountability does not, for one reason. The register covers systems the technology function itself bought and deployed. A seat that audits its own purchases is not an audit.

The CIO owns the estate: the applications the business runs on, licensing, integration, service. The CIO is the only person who can tell you every place a copilot has already been switched on, which makes the CIO the best supplier of the register's first draft. Owning the draft is not the same as owning the accountability.

The CDO owns the data: quality, lineage, definitions, access, retention. Every AI failure traces back to data eventually, so the CDO is upstream of everything. The CDO does not own what the business chooses to do with a model once it exists.

The Chief Risk or Compliance Officer owns the regulatory response and, in a licensed institution, the relationship with the regulator. This seat will end up carrying AI risk in the risk register whatever else happens. What it cannot do is run the programme it is meant to challenge.

Four seats, four legitimate claims, and a hole in the middle.

What sits in the hole

Four duties, and they travel together.

A current inventory of every AI system, with data, vendor, owner and oversight mode. The impact assessments for anything that touches a person's money, health, employment or housing. One page to the board, the same page every quarter. And the internal policy plus the training that makes it real.

Split those four across four seats and each becomes the fifth priority on a full desk. The inventory ages, the assessments lapse, the board sees a different deck each time, and the policy stays a memo nobody read.

That is not a hypothetical failure mode. It is the observed one, and it is why the Data Protection Officer became a named seat rather than an extra duty on the general counsel.

Why the UAE forces the question earlier than most markets

Three regulators have now written the bundle down.

DIFC Regulation 10, enacted September 2023 with enforcement running from January 2026, binds the Deployer and the Operator of autonomous and semi-autonomous systems. It requires a record of use cases and processing activities, certification against applicable standards, human intervention where processing may produce unfair or discriminatory impacts, impact assessments for high-risk processing, and an Autonomous Systems Officer where the processing is high risk.

The Central Bank of the UAE, on 11 February 2026, told licensed financial institutions to hold documented AI governance frameworks proportionate to their size, nature and complexity, to maintain a comprehensive inventory of AI models, to stress test for bias, to conduct due diligence on third-party vendors and cloud providers, and to retain full responsibility for AI outcomes regardless of outsourcing. Boards and senior management are named as accountable.

Abu Dhabi's Department of Health went further in its Responsible AI Standard of October 2025, which requires that AI systems have designated owners, that specific individuals or teams are assigned to monitor outputs, review override events and report adverse outcomes to governance bodies, and that every decision and change is logged and traceable to a responsible party.

Read those three together and the common instruction is the same: name someone.

The test that settles the argument in one meeting

Ask the executive team a single question. Who, by name, can produce the current inventory of AI systems in this company by Thursday, and who signs it.

If a name comes back and the person agrees, the argument is over and the seat exists already. If the room looks at each other, the seat does not exist, and the company has been operating on the assumption that it did.

We have watched this question end the turf argument in under ten minutes, because it converts a status conversation into a task with a deadline.

The shape most UAE companies land on

A separate seat, held part-time, reporting to the Chief Executive, with the four duties above and no headcount in year one.

The CTO keeps the platform. The CIO keeps the estate and supplies the register's data. The CDO keeps the data. The risk seat keeps the risk register and receives the assessments. The new seat holds the bundle and the board line, and has a veto on anything that fails an assessment.

IBM's 2026 CEO study found 76% of organisations globally now have a Chief AI Officer, up from 26% a year earlier. It publishes no Gulf cut. What it does say is that the argument above is being had everywhere and is resolving the same way.

When the answer is no new seat

Small company, no regulated entity, no personal data inside any AI system, fewer than six touchpoints in total. Give the register to the CIO, book a review in twelve months, and spend the money on the one use case instead.

Be honest about the count first. Companies that assume they have three touchpoints and then look usually find eleven.

Where to go next

If the seat is agreed and the question is what to write down, read the Chief AI Officer job description. If the question is which rules apply to which entity in your group, read the map of UAE AI regulation.

If you need the person rather than the argument, read the register.

Questions

Can the CTO own AI?
The CTO can own the AI platform and usually should. The difficulty is that the register covers systems the technology function itself procured, and a seat cannot audit its own purchases. That is the same reason the Data Protection Officer was separated from the general counsel.
What is the difference between a Chief AI Officer and a Chief Data Officer?
The Chief Data Officer owns the data, meaning quality, lineage, definitions and access. The Chief AI Officer owns what is done with it, meaning the inventory of systems, the assessments, the board line and the policy. In a company that has both, the CDO supplies the input and the CAIO is accountable for the output.
Do we need a new seat at all?
If the company has fewer than six AI touchpoints, no personal data in any of them, and no regulated entity, then no. Give the register to the CIO and revisit in a year. Most UAE companies that count their touchpoints honestly find more than six.
Who should the AI owner report to?
The Chief Executive or the board. A seat that reports into technology cannot hold technology to account, and the register covers technology's own systems.

Sources

  1. DIFC, Regulation 10 on autonomous and semi-autonomous systems
  2. CBUAE, Guidance Note on the responsible adoption of AI and machine learning by licensed financial institutions, 11 February 2026
  3. Department of Health Abu Dhabi, Responsible Artificial Intelligence Standard, October 2025
  4. IBM newsroom, CEOs are reshaping C-suite roles for the AI era

The Atlas letter

One leader added to the register, by name. One thing that changed in the rules. One number, with its geography on it.

Once a month. Atlas sends one email to confirm the address before adding it. Nothing arrives until that link is clicked.

Back to writing