That gap is becoming harder to ignore.
A board member sits through another quarterly technology update.
AI adoption is growing. Productivity is improving. Several pilots have moved into production. Management has created an AI policy and established a governance committee.
The presentation looks reassuring. Then she asks a simple question:
"Which AI systems are currently making or influencing consequential decisions in our business?"
The room gets quieter.
Someone mentions the customer-service assistant. Someone else remembers an HR tool. Marketing uses several AI platforms. A business unit recently enabled AI functionality inside an existing vendor product. Employees are using generative AI tools that were never formally procured.
Then come the harder questions. What information do those systems use? Which ones affect customers or employees? Which vendors receive company data? Which systems can take actions rather than simply make recommendations? What happens when one fails?
No one has a complete answer.
The board has been receiving AI updates. But it has not necessarily been seeing the AI risk.
Speed vs. Defensibility
Boards are not supposed to operate AI systems. They should not approve every model, inspect every dataset or become another layer of product management. Their role is oversight. But meaningful oversight becomes difficult when directors cannot see the risk they are supposed to oversee.
That distinction matters because AI can enter an organization through many doors: internally developed systems, third-party vendors, embedded software features, customer-facing products and employee-selected tools.
The National Association of Corporate Directors' 2026 AI discussion guide reflects this reality. It asks boards to examine AI risks across business functions, data-governance ownership, third-party AI risk, unauthorized "shadow AI," AI identity and what happens when an AI system fails. NACD, 2026
It is: "Does the board receive enough reliable information to oversee the AI risks that actually matter?"
AI Oversight Is Moving From Conversation Toward Evidence
There is no standalone SEC rule that requires every public company to create a dedicated AI committee or adopt one prescribed AI-governance structure.
But that does not mean AI is outside existing securities-disclosure obligations. SEC staff has previously noted that existing rules may require disclosure about a company's AI use and related risks — including, where applicable, the board's role in risk oversight — when those matters are material. SEC Division of Corporation Finance, 2024
The governance conversation has continued to develop. In December 2025, the SEC Investor Advisory Committee approved a recommendation that the Commission require issuers to disclose board oversight mechanisms, if any, for AI deployment and, when material, report on AI's effects on internal operations and consumer-facing matters. The recommendation is advisory; it is not an SEC rule. SEC Investor Advisory Committee, 2025
SEC Commissioner Mark Uyeda described the recommendation as fitting within the existing Regulation S-K disclosure framework, while cautioning against rigid or premature disclosure mandates. SEC, Dec. 4, 2025
Then, in February 2026, the SEC published a separate petition for rulemaking seeking mandatory AI-governance and risk-management disclosures in public filings. A petition is a request for agency action — not a regulation and not evidence that the SEC has adopted the requested requirements. SEC Petition 4-882
Five Questions Every Board Should Be Able to Answer
An organization may have internally developed models, third-party AI products, AI features embedded into existing software, customer-facing systems and employee-selected tools operating simultaneously.
A board does not need every configuration detail. Management should, however, be able to identify where AI creates material strategic, operational, legal, privacy, security or reputational exposure.
Board question: Do we know where our consequential AI use actually is?
Not all AI deserves the same level of oversight. A meeting-summary tool has a different risk profile from a system influencing hiring, fraud investigations, lending, healthcare, customer eligibility or access to essential services.
The useful question is not simply "Is this AI?" It is: what happens to a person or to the company if this system is wrong?
AI governance and data governance cannot be cleanly separated. Systems may rely on customer information, employee records, intellectual property, behavioral data, sensitive information or data obtained through third parties.
Third-party AI adds another question: where does the information go after it leaves us? NACD's 2026 board guidance specifically points directors toward data inventory, access controls, data-governance ownership and third-party AI risk.
"We have an AI committee" is not a complete answer. Who can stop a deployment? Who investigates an AI incident? When do Legal, Privacy, Security, Compliance or Risk become involved? What reaches senior leadership — and what reaches the board?
NACD's 2026 AI-incident guidance emphasizes documented escalation thresholds, clear committee ownership and exercises designed to test decision-making and documentation readiness. NACD, March 2026
Management says high-risk AI is assessed. Show the assessment. The company says AI vendors are reviewed. What does the review test? Human oversight is required. Where is it documented? AI incidents are monitored. What qualifies as an incident, and who receives the report?
Policies describe what should happen. Evidence tells the board what is actually happening.
Who Feels the Consequences?
Boards and Executives
The challenge is not becoming an AI engineer. It is learning enough to distinguish meaningful governance information from a reassuring presentation. Boards should understand the organization's most consequential AI uses, material exposures, escalation mechanisms and whether management can substantiate its assurances.
Privacy, Legal and Compliance
These teams increasingly sit between expanding AI adoption and leadership's need for defensible answers. AI inventories, impact assessments, data flows, vendor reviews, policies, incident processes and documentation are not isolated compliance artifacts — together, they form the evidence behind management's governance story.
Product and Technology
More board oversight should not mean directors approving ordinary product decisions. The goal is a governance system that allows innovation to proceed while escalating risk according to consequence — one that tells teams what can move quickly, what requires additional review and what requires leadership attention.
For Organizations
- Identify the AI systems that create the greatest potential impact on customers, employees, operations or the company.
- Map each consequential system to a responsible business owner and risk owner.
- Define which AI incidents, exceptions or control failures must reach senior leadership or the board.
- Review whether board reporting includes unresolved risks, exceptions and control performance — not merely adoption statistics and success stories.
- Test whether leadership can trace a material AI system from business purpose to data, vendor, controls, human oversight and accountable owner.
For Directors and Executives
The next time AI appears on the agenda, ask one question before reviewing another dashboard:
The answer may reveal more about AI-governance maturity than twenty slides about AI strategy.
Unpopular Opinion
A board that receives regular AI updates can still have weak AI oversight. Frequency of reporting is not the same as quality of governance.
One-Line Debate
How much should a board actually understand about the AI systems operating inside its company?
If your board asked tomorrow for the company's three highest-risk AI systems, their data sources, responsible owners and current controls — how quickly could management answer?
Reader Poll
Cast your vote and see how other readers responded.
Informal reader poll, not a scientific survey. One vote per browser.