The Next Shared Responsibility Model, Who Owns Intelligence in the Age of AI?

Author

Ginniee, Co-Founder & CRO, SpikedAI

The Next Shared Responsibility Model, Who Owns Intelligence in the Age of AI?
7 min read | Vol. 2026 | Signal Verified

From Shared Responsibility to Shared Intelligence

Our teams have lived the shared responsibility model, and I believe deeply in it. It shaped how I work with enterprises because the premise is remarkably simple, security works when responsibility is explicit, not assumed. The cloud provider has responsibilities, the enterprise has responsibilities, and those responsibilities change depending on what is being built and where it runs. I believe we are entering a similar moment with AI, except this time we are not simply distributing responsibility for infrastructure and applications. We are distributing responsibility for intelligence, data, knowledge, memory, reasoning, and increasingly, the ability to act. Something remarkable has happened in a very short period of time. We began this AI cycle talking almost entirely about models, which model is smartest, which benchmark it wins, how large its context window is. Then enterprises moved to copilots. Copilots evolved into agents. Agents began accessing enterprise systems, using tools and taking actions.

At SpikedAI, teams thinking about the next evolution, Digital Teammates working alongside humans. And suddenly the question has changed from Which model should we use? to something much harder. Who is responsible when an AI system accesses enterprise data, retrieves institutional knowledge, reasons across multiple models, invokes a tool, remembers previous interactions and ultimately takes an action on behalf of a human? The industry itself is beginning to formalize this question. On May 28, 2026, the Coalition for Secure AI (CoSAI) published its AI Shared Responsibility Framework, designed specifically to clarify accountability across the AI stack, with responsibility shifting depending on architecture and deployment model. CoSAI's work now extends into agentic identity and access management, incident response, model-context security and secure-by-design agentic systems. That matters to me because it tells us something important, AI security cannot belong to one company or one layer. As AI moves from generating answers toward taking actions, we are moving from simply securing applications toward governing intelligence itself.

One Enterprise, Many Models

The second shift is what I think of as shared intelligence. For a while, we talked as though every enterprise would eventually choose a winning model and build around it. I increasingly doubt that will be the dominant architecture. OpenAI can sit alongside Anthropic, Google, NVIDIA and increasingly capable open models; enterprises may also develop specialized models of their own. A bank could use one model for coding, another for research, another for customer conversations, another for specialized reasoning and perhaps its own models for particularly sensitive workloads. Each will have different strengths, economics, latency characteristics and risk profiles. The model becomes a component of the architecture, not the architecture itself. What NVIDIA is doing right now is particularly interesting because openness and security are moving together. On July 27, NVIDIA and other industry leaders launched the Open Secure AI Alliance around open technologies for AI security.

120+ Organizations
Alliance Growth

Just eight days later, on August 4, NVIDIA reported that the alliance had grown to more than 120 organizations, with NVIDIA, Cisco, CrowdStrike, Hugging Face and Red Hat among those working with the Linux Foundation on proposed Shared AI Findings Exchange, or SAFE, guidelines for turning agentic cybersecurity incidents into shared protection.

NVIDIA pushed the infrastructure argument even further on August 17, when Jensen Huang described AI factories as the “defining infrastructure of the AI era,” where compute transforms energy and data into intelligence.

"AI factories are the defining infrastructure of the AI era — where compute transforms energy and data into intelligence that powers every business, industry and country."

— Jensen Huang

OpenAI is approaching another part of the same tension through Trusted Access for Cyber, where access to increasingly capable cyber models is tied to identity, authorization and safeguards.

Anthropic is moving in parallel, its Responsible Scaling Policy was updated again this summer, and its August 14 Risk Report describes AI risk governance as something that must remain proportional and iterative as capabilities advance. These aren't competing ideas. Together they point toward an architecture that is simultaneously becoming more open and more governed. Choice without governance creates risk; governance without choice creates lock-in. What enterprises need is choice with governance.

The Missing Layer, Institutional Memory

But there is a third shift that I believe may ultimately be more valuable than either of the first two, shared institutional knowledge. Models know an extraordinary amount about the world, but they don't inherently know your enterprise. They don't know why your team made a decision three years ago, the history behind a customer relationship, the objection that changed a deal, the promise made during a meeting, the exception approved by a leader or the judgment accumulated by someone who has spent twenty years understanding a customer. That intelligence is scattered across CRM systems, documents, email, research, data warehouses and product systems, and an enormous amount of it still lives in people and conversations. We spent decades building systems of record. We are now rapidly building systems of intelligence. But I keep coming back to another question, Who is building the system of memory? This becomes particularly interesting in banking, where security, identity, entitlements, governance, auditability and human accountability are already fundamental to the operating model. We can already see leading financial institutions participating in this emerging security ecosystem. OpenAI's Trusted Access for Cyber initiative includes Bank of America, BlackRock, BNY, Citi, Goldman Sachs, JPMorgan Chase, Morgan Stanley and U.S. Bank. BNY CIO and Global Head of Engineering Leigh-Ann Russell put the objective clearly as

"BNY is committed to helping protect the security and resilience of the financial system as AI capabilities accelerate."

Leigh-Ann Russell

Now imagine a wealth advisor who has worked with a family for fifteen years. The portfolio system knows the holdings. The CRM knows the account. Research systems understand the markets. Email contains the correspondence. A frontier model understands finance. But who remembers that the client said three years ago that she wanted to retire early? Who remembers why she rejected a recommendation eighteen months ago? Who connects yesterday's conversation with today's market movement and tomorrow's meeting? That is context. That is memory. And that is where intelligence becomes personal.

Photo Credits: BNY 2026 Analyst class

Photo Credits: BNY 2026 Analyst class

The Next Shared Responsibility Model

This is where my own thinking has evolved and where it is influencing what the teams are building at SpikedAI. At AWS, I learn to think about responsibility across layers; today I advise these teams, and find myself applying the same principle to intelligence. I don't believe the durable value of enterprise AI should depend on whichever model happens to be winning this quarter. Models will change. Infrastructure will change. Interfaces will change. Open-source ecosystems will accelerate. What should persist is the enterprise's knowledge, context, relationships and institutional memory. At SpikedAI, the teams are building toward an intelligence layer around the human- governed Enterprise Libraries for customer, product, policy, conversation and institutional knowledge; context and memory that determine what matters to this person, this customer and this moment; a flexible reasoning layer designed to work across frontier, enterprise and approved open models; and Digital Twins and Digital Teammates that bring that intelligence into the human's flow of work before, during and after an interaction.

This isn't about replacing an enterprise's existing security, identity or governance architecture; it is about respecting those boundaries as intelligence moves across the stack. Underneath it is a principle I believe is fundamental,

"The model should never decide what it is allowed to know. The enterprise should."

— Ginniee

Identity determines who you are. Permissions determine what you can access. Governance determines what knowledge can be used. Models provide reasoning. The intelligence layer provides context and orchestration. And the human retains judgment and accountability. The timing matters. On May 28, shared responsibility for AI was formally articulated through CoSAI's framework. By August, an open AI-security alliance had grown to more than 120 organizations, financial institutions were participating in trusted-access models for frontier cyber capabilities, and leading AI companies were evolving their security frameworks alongside rapidly advancing models. The AI stack is simultaneously opening and hardening. I don't think the winners will necessarily be the enterprises that deploy the most AI. They may be the ones that answer four questions better than everyone else. Who owns responsibility? How do we orchestrate intelligence across models? How do we preserve institutional memory? And where must human judgment remain? Shared responsibility was foundational to the cloud era. I believe shared responsibility for intelligence may become foundational to the AI era.

Photo Credits: SpikedAI and Partner Aureum Leaders Circle Event August 2026

Photo Credits: SpikedAI and Partner Aureum Leaders Circle Event August 2026

Don't wing it,
Win it.