How Should Boards Govern AI Decisions?

Boards govern AI decisions by treating them as a matter of fiduciary oversight, not technical administration. That means three things: building a board-level system to see how AI is used and where it makes consequential decisions, assigning a named human owner accountable for each of those decisions, and monitoring both. The board can delegate the decision to a machine. It cannot delegate the accountability for it.

That distinction is where most board AI governance goes wrong. Directors reach for the familiar instruments — a committee, a policy, a RACI chart — and treat their creation as the discharge of the duty. But a governance structure that produces a record of oversight without the substance of it is not protection. It is exposure with better paperwork.

What does it mean for a board to govern AI decisions?

It means overseeing the system through which AI decisions are made — not making them, and not auditing the model’s code. A board’s job with any material risk is to ensure management has built adequate controls and to monitor whether those controls work. AI is no exception; it is simply a new class of decision-maker inside the organization.

The evidence says most boards are not yet doing this. Grant Thornton’s 2026 AI Impact Survey found that just 11% of boards met a basic threshold for strong AI oversight — having been briefed on AI, having set governance expectations, and having integrated AI risk into ongoing oversight. Protiviti’s 2026 global survey found only 26% of boards discuss AI at every meeting. The governance infrastructure is lagging the deployment it is supposed to govern, and the gap is widening as AI moves from back-office efficiency into decisions that carry legal and strategic weight.

Can a board delegate an AI decision without delegating accountability?

No — and in law, it cannot. This is the crux of what I call accountability anchoring: when authority to decide shifts to an AI system, accountability for the outcome stays anchored to the humans who deployed it. Delegating the decision does not delegate the answerability.

Corporate law has already fixed this anchor. Under the Delaware duty of oversight — the Caremark doctrine and the cases that extend it — directors and officers must make a good-faith effort to implement and monitor an information-and-reporting system adequate to the company’s material risks. That duty is grounded in loyalty, it is personal to each fiduciary, and it is not exculpable by charter provision. When an AI system becomes a material risk, the duty attaches to it directly. “The system decided” is not a defense, and “we left it to IT” is not a governance posture a court or regulator will accept.

Why do AI governance frameworks fail even when boards adopt them?

Because a framework can be adopted without being exercised — and the adoption creates false confidence. The failure mode is ratification hollowing: human oversight that has degraded into a formality. A committee exists, a policy is signed, a human is nominally in the loop — but the reviewer lacks the time, information, or standing to genuinely dissent. Oversight becomes a rubber stamp that manufactures a paper trail of accountability while removing its substance.

The translation problem compounds it. Boards are typically handed operational counts — tools inventoried, incidents blocked, policies violated — when what they need are business-level signals: dollar exposure, trend direction, and a specific decision to make. Fed the wrong inputs, a diligent board ends up informed but not equipped to act, which under the second prong of the oversight duty is its own form of exposure.

What does effective board oversight of AI actually require?

It requires an information-and-reporting system built for AI specifically, and a genuinely empowered human anchor for consequential decisions. Concretely: an inventory of where AI operates and where it makes or shapes decisions; a heightened standard for mission-critical uses, where courts already expect closer attentiveness; metrics that map to board-level decisions rather than operational noise; and enough AI literacy on the board to interrogate management’s answers.

That last requirement is where boards are thinnest. An ISS analysis of over 3,000 companies found only 16% disclosed even one director with specialized AI skills. Directors do not need to understand how a model works — but they do need to understand whether the controls around it exist, function, and are reported. Anchoring also means calibratingautonomy to stakes: wide latitude for low-consequence, reversible decisions; tight human control for high-consequence, hard-to-reverse ones. Over-anchoring throttles the tool; under-anchoring severs accountability exactly where it matters most.

How should boards in different regions approach AI governance?

The anchor is universal; the instruments are regional. In the United States, the pressure is fiduciary and disclosure-driven — the Caremark line makes oversight personal, and emerging SEC expectations push boards toward disclosing material AI risk. In the Gulf, where AI adoption is fast and status-driven and governance codes on the ADX and DFM are maturing in parallel, the opportunity is to build the oversight structure alongside the adoption rather than retrofitting it after an incident. In Central and Eastern Europe, where transformation runs under tight cost discipline, the discipline is proportionality — anchoring accountability without erecting governance overhead that the operating model cannot sustain. In every case the principle holds: the board decides how much agency to grant, and remains answerable for the grant.

Frequently asked questions

Who is ultimately accountable when an AI system makes a bad decision?

The board and responsible officers. Under the Delaware duty of oversight, accountability is personal and cannot be exculpated or delegated to management or to the technology. Assigning a decision to an AI system does not move the answerability for its outcome.

Does a board need technical AI expertise to govern AI?

No. Directors govern the process, not the model — whether control systems exist, function, and are reported. That said, a basic level of AI literacy is now part of the oversight duty, and the current shortage of AI-fluent directors is a live governance risk.

Should AI oversight sit with the full board or a dedicated committee?

Either can work, provided the choice is explicit and the reporting lines are clear. What matters is that oversight is structured rather than left to management’s discretion — and that mission-critical AI uses receive the heightened attentiveness courts already expect.

What is the single biggest board AI governance mistake?

Mistaking the framework for the accountability. Adopting a committee and a policy, then treating that as the end of the duty, produces oversight in form without oversight in substance — which is often worse than none, because it creates false assurance.