By Nick Stringer, Non-Executive Director & Board Adviser, specialising in global digital public policy, AI governance, and data protection/privacy. Nick’s executive experience includes serving as Director of Regulatory Affairs at the IAB UK and as VP of International Affairs at TAG.
Over the past two years, boards have watched the AI boom with a mixture of commercial optimism and quiet concern. Executives have sat through glossy sales pitches about productivity gains while lawyers and auditors have signed off on initial risk assessments. Today, as major regulatory frameworks shift from proposal to enforcement – most notably the implementation of the EU AI Act, the increasing number of US state laws, and tighter scrutiny from the UK Information Commissioner’s Office (ICO) – boards must keep pace.
Most organisations aren’t at risk because they’re ignoring AI. They’re at risk because nobody’s actually governing it effectively. Relying on general management assurances, vendor promises, or legacy data protection and ePrivacy policies won’t cover this new category of systemic risk. And this isn’t a problem that IT or compliance can handle in a silo. AI governance belongs at the board level because of its significant impact on strategy, liability, and reputation.
Good governance acts as a clear framework that gives leadership the confidence to deploy AI quickly and safely. Yet, with 51% of global boards feeling equipped with enough knowledge to supervise AI effectively, closing this expertise gap is now an urgent priority.
At your next Board or leadership meeting, here are three specific questions to put on the agenda.
- How does management continuously audit our live AI environment?
Boards are often presented with a list of corporate AI initiatives. What rarely appears on those slides are the unapproved automated workflows running in daily operations, or the growing shift toward autonomous AI agents acting across systems without human intervention. For example: a board might review a slide of three ‘approved’ AI tools, while across the business dozens of unsanctioned ones are running. This gap between the board briefing and operational reality is usually much wider than many directors assume.
Boards don’t need to manage software inventories themselves: that operational duty belongs to the CIO. However, directors must demand that executive leadership maintains a practical system for detecting, categorising, and auditing every AI application in use, including ‘shadow AI’ (such as employees uploading proprietary data into public consumer models).
If an autonomous system feeds incorrect financial advice to customers or executes an unauthorised trade, ultimate legal accountability still rests with the board. Without continuous auditing, directors cannot prove they exercised reasonable care. Deloitte’s 2026 State of AI report reveals that while enterprise use of autonomous AI agents is accelerating, only 20% of organisations have a working model to govern them.
- How are we protecting our proprietary data and managing vendor risk?
This responsibility breaks down into two operational realities every board must evaluate separately:
- Protecting Outbound Data & IP: When staff enter sensitive corporate information, strategic plans, or proprietary code into external tools, the board needs confirmation that this data isn’t being scraped to train public models. This requires explicit internal usage policies, regular staff training, and full alignment with GDPR and ePrivacy requirements.
- Conducting Vendor Scrutiny (Inbound): Expecting management to trace the full legal origin of training datasets inside third-party foundation models is unrealistic. Instead, the business must enforce strict procurement standards. Contracts with tech partners need ironclad liability clauses, clear risk allocations, and explicit guarantees on how company data is handled and stored.
3. Where does human judgement sit, and how do we prevent ‘rubber stamp’ oversight?
It is easy for leadership to treat AI outputs as verified facts. But when automated decisions directly hit customers, employees, or financial records, regulators and courts will demand to know who made the call.
Organisations must prove that qualified staff maintain active oversight of high-impact systems. Simply dropping a human into the loop as a formality creates a dangerous trap known as ‘automation bias’, where employees passively sign off on machine decisions while taking the fall when the system hallucinates or fails.
Management must show where human accountability actually lives. Employees need the training, time, and explicit authority to question and override machine outputs whenever necessary.
Active governance builds real trust
Effective AI governance isn’t an administrative overhead: it builds lasting trust with investors, policymakers, regulators, and customers.
Treating oversight as a simple checklist signals to stakeholders that the board isn’t paying attention. Directors don’t need to inspect source code. But every board needs at least one member who can spot the difference between genuine operational control and a polished sales demo, and who is willing to ask tough questions until they get clear answers. That is how organisations bridge the gap between AI innovation and real accountability





