Taylor Root’s latest global survey* of over 400 senior in-house legal professionals suggests that organisations are still working through that answer. While AI governance is increasingly shared across multiple functions, confidence in how AI is governed drops noticeably when accountability sits outside legal.
The findings point to a growing challenge for legal teams: carrying responsibility for AI-related risk while operating in governance structures that are often fragmented, unclear or led elsewhere.
Legal remains the most common home for AI accountability
When asked where ultimate accountability for AI-related legal risk sits today, legal was the most frequently cited answer.
Among respondents:
- 32% said accountability sits with legal
- 27% said accountability sits with executive leadership
- 26% said accountability sits with IT or technology
- 9% said responsibility sits with risk or compliance
- 7% said accountability is unclear or sits elsewhere
That distribution tells its own story. Despite AI being positioned as a business-wide transformation initiative, many organisations still see legal as the final owner of AI-related risk.
Yet ownership alone is not the most revealing finding. The more important question is whether organisations are confident in their governance arrangements once accountability has been assigned.
Confidence falls when accountability sits outside legal
Across the survey, just 17% of respondents described themselves as either very or extremely confident that AI tools used across their business are appropriately governed. More than a quarter (28%) said they were either not so confident or not at all confident.
However, confidence levels vary significantly depending on where accountability sits.
Where legal holds ultimate accountability:
- 21% report being very or extremely confident in AI governance
- 21% report being not so confident or not at all confident
Where accountability sits with IT:
- Confidence falls to 13%
- 37% report being not so confident or not at all confident
Where accountability is unclear:
- Just 7% report being very or extremely confident
- 41% report being not so confident or not at all confident
The message is difficult to ignore: Legal-led accountability is associated with higher confidence levels than technology-led or unclear governance structures. The lowest confidence scores appear in organisations where ownership is uncertain.
That does not necessarily mean legal should own AI governance alone. It does suggest that legal involvement appears to provide a stronger sense of control, oversight and accountability.
Shared responsibility is becoming the norm
Most organisations are not operating with a purely legal-led model. When asked whether legal is involved in overseeing AI within their organisation, the overwhelming majority described governance as a shared responsibility model. Others said legal was aware of AI activity but not formally responsible, while a smaller group reported legal-led ownership.
This reflects reality. AI governance touches technology, cybersecurity, compliance, privacy, procurement, risk and legal. Very few organisations can manage it effectively through a single function.
The challenge is that shared governance only works when decision-making authority is clearly defined.
Several respondents highlighted uncertainty around accountability, citing issues such as unclear ownership, the absence of formal governance frameworks and responsibility spread across multiple departments.
These comments point to a familiar governance problem. Organisations have created committees, steering groups and cross-functional structures, but many have not yet established clear ownership.
Where accountability is diffuse, confidence tends to suffer.
The real risk is governance ambiguity
The strongest signal from the data is not that legal should own AI governance outright. Instead, it is that governance structures perform best when accountability is clear.
That finding should be a warning for legal leaders and boards alike.
As AI adoption accelerates, governance maturity will increasingly be judged not by who sits on a steering committee, but by whether the organisation can clearly answer three questions:
- Who owns AI-related risk?
- Who has authority to intervene when risks emerge?
- Who ultimately signs off on the decisions?
At many organisations, those questions still appear unresolved.
See the full findings
Taylor Root’s global in-house legal market report and salary guide contains the complete AI governance dataset alongside salary and bonus benchmarks across every market and in-house specialism we cover.
Taylor Root recruits legal, privacy, risk and compliance professionals globally, on both a permanent and an interim basis. Download the guide for the full data, or speak to our team about building AI governance capability into your function.
Who signs off the robot? Accountability, authority and AI in the legal function
The question boards are asking about AI has changed. Two years ago it was whether the business was using the technology. Today it is who answers for it when something goes wrong. For most in-house legal teams, the answer has arrived without a conversation about whether they have the authority to match.
Our global in-house survey found that [XX%] of senior in-house lawyers say legal holds responsibility for AI governance in their organisation. Only [XX%] say legal has the power to prevent the business adopting an AI tool. That gap between accountability and authority is the defining AI issue for legal functions in 2026.
Where AI governance actually sits
We asked respondents where primary ownership of AI governance falls within their organisation:
- Legal – [XX%]
- Risk – [XX%]
- IT or technology – [XX%]
- Compliance – [XX%]
- A shared or cross-functional model – [XX%]
- No clear owner – [XX%]
The [XX%] reporting no clear owner is the figure worth pausing on. In those organisations, ownership tends to default to legal the moment an issue arises, which is the least useful moment to discover you own something.
Shared models are the most common structure at [XX%], and in principle they are the right answer. AI governance genuinely does sit across legal, technology, risk and compliance. But shared ownership only works where decision rights are documented. Where they are not, shared tends to mean that legal is consulted late and asked to approve quickly.
The authority gap
On the question of veto power, [XX%] of respondents said legal has a formal ability to block deployment of an AI tool. [XX%] said legal is consulted but cannot prevent adoption. [XX%] said legal is frequently informed after deployment has already happened.
For a function carrying regulatory exposure under the EU AI Act, data protection law and an expanding set of sector-specific rules, being informed after deployment is not a governance model. It is a reporting line. And it puts legal in the position of defending decisions it had no realistic opportunity to shape.
Signing off on AI-generated work
Institutional accountability eventually becomes personal accountability, which is why we tested comfort levels directly. [XX%] of senior in-house lawyers said they are comfortable signing off on AI-generated legal output. [XX%] said they are not. [XX%] said it depends entirely on the use case and the review process in place.
That final group is the most instructive. Comfort is not really a question of confidence in the technology; it is a question of whether a defensible review process exists. Where one does, sign-off is straightforward. Where it does not, individual lawyers are making judgement calls on their own professional risk.
Privilege recurs throughout the qualitative responses. Where AI tools process legal advice, whether privilege survives remains unsettled in most jurisdictions, and senior lawyers are being asked to form a view without clear guidance to rely on.
Shadow AI: recognised, unmeasured
[XX%] of respondents said shadow AI – employees using unapproved tools for work – is a recognised risk in their organisation. Only [XX%] said their organisation has a reliable way of measuring the extent of it.
Anyone who lived through shadow IT will recognise the pattern. The risk is understood, the exposure is unquantified, and the function that will answer for it is legal. The specific concerns raised were:
- Confidential or client data entering consumer AI tools – [XX%]
- Contractual or regulatory breach through unapproved processing – [XX%]
- Inability to evidence decision-making to a regulator – [XX%]
- Loss of privilege – [XX%]
An unquantified risk cannot be reported to a board honestly, which makes measurement the first practical step rather than policy drafting.
What legal teams are hiring for
The market is responding in three visible ways.
Data protection and privacy has become the fastest-moving in-house specialism. Demand for privacy lawyers with genuine AI governance experience has outstripped supply, and the salary data reflects it: privacy roles showed [XX%] year-on-year movement, the strongest of any in-house specialism in our dataset. Briefs that would have been written at a junior privacy level two years ago are now being written at counsel level.
Risk and compliance functions are absorbing AI scope alongside legal. Where governance is genuinely shared, the risk function is most often the co-owner, and the demand is for candidates who can work credibly alongside both legal and technology teams.
Hybrid profiles command a premium. Lawyers who can hold a technical conversation about model behaviour and a board conversation about regulatory exposure are rare, and priced accordingly at [XX%] above the equivalent generalist band.
What legal leaders should be doing now
- Document decision rights. If legal owns the risk, write down what legal can stop. If legal cannot stop anything, escalate that as a governance finding rather than absorbing it quietly.
- Get a measure of shadow AI before writing a policy about it.
- Set a review standard for AI-assisted output, so that sign-off is a process rather than an individual judgement call.
- Resource for it. AI governance is a workstream, not a task to add to an existing role.
See the full findings
Our global in-house legal market report and salary guide contains the complete AI governance dataset alongside salary and bonus benchmarks across every market and in-house specialism we cover.
Taylor Root recruits legal, privacy, risk and compliance professionals globally, on both a permanent and an interim basis. Download the guide for the full data, or speak to our team about building AI governance capability into your function.