For typical buttoned-up CFOs who crave safety and security within their purview, it can’t be a great feeling to doubt whether they have a full handle on artificial intelligence oversight.
A vast majority (96.5%) of the 200 North American finance chiefs surveyed for Deloitte’s second-quarter CFO Signals research said they’re at least somewhat confident of their AI governance framework.
However, the “somewhat confident” responses outpaced the “very confident” ones, 53.5% to 40%. “Certainly, the speed and volume of adoption can complicate governance,” Deloitte wrote in its research report.
To wit, in a Deloitte survey less than three years ago, two-thirds of CFOs said their companies were still experimenting with generative AI — or simply reading and talking about it. In the latest survey, 93% of respondents said their organizations are using AI across multiple key functions and operations.
But, offering another clue that finance chiefs aren’t necessarily sanguine about AI governance, more than half (51%) of those polled said lack of governance authority is among their biggest challenges in developing and implementing an effective, enterprise-wide governance framework.
It was the second-most common response to the question, after “balancing business pressure to quickly deploy AI while still managing risks.”
“There’s no shortage of risks to manage, either,” Deloitte wrote, noting that “stories about AI systems behaving unexpectedly are becoming increasingly common.”
Aside from flaws in the technology itself, CFOs also worry about processes related to adopting and utilizing AI. Almost half (46%) said their top internal concern was around cost uncertainty, such as when using cloud-based or hosted delivery models. The report pointed out that many AI providers now charge corporate clients by consumption, rather than a flat rate. “Given that usage fluctuates, the bill can be hard to predict,” Deloitte said.
Next came lack of confidence in the use of AI in key operations (35%), employee resistance or insufficient fluency with AI tools (33%), inaccurate results or flawed analysis (33%), “shadow IT” or employees using unapproved AI tools (28%) and rogue AI, where AI or AI agents ignore commands or rewrite code, for example (27%). (Survey participants could select up to two responses.)
As to external concerns related to the use of AI, the leading response, with 43%, was litigation related to the use of protected or private content, such as copyright infringement and intellectual property violations. Next came cybersecurity (41%), regulatory complexity or uncertainty (36%), fraud committed by external actors (35%), reputational damage due to AI mistakes (25%) and impact on the environment (20%). (Here as well, participants could select up to two responses.)
“As organizations adopt AI more broadly, malicious actors may also use the technology to launch increasingly sophisticated attacks,” Deloitte noted.