AI is changing the speed of business. The next leadership test is whether boards can keep pace with the risk.
The boardroom has a new problem
For years, technology risk was largely discussed as an IT issue.
That era is over.
Today, an AI deployment can influence customer decisions, employee workflows, financial processes, intellectual property, regulatory exposure and business continuity; sometimes simultaneously.
From my perspective as a technology and cybersecurity leader, this changes the role of the board.
The question is no longer:
“Are we using AI?”
It is:
“Are we governing what AI is changing?”
The urgency is real. The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 94% of respondents see AI as the biggest driver of change in cybersecurity, while 87% identified AI-related vulnerabilities as the fastest-growing cyber risk during 2025.
That is not a technology trend.
That is a leadership signal.
1. Technology risk has become business risk
A board doesn’t need to understand every technical detail of a new AI model.
It needs to understand its business consequences.
Consider an enterprise deploying an AI agent that can:
- Access internal information
- Communicate with customers
- Trigger workflows
- Interact with third-party applications
- Generate decisions or recommendations
- Potentially act without continuous human intervention

The technology may create enormous productivity gains.
But it also creates new questions:
Who authorised the AI?
What can it access?
What happens when it makes an incorrect decision?
Who is accountable?
How quickly can its authority be withdrawn?
This is why AI governance, identity governance, cybersecurity strategy and technology risk management can no longer operate as isolated disciplines.
They are becoming one leadership conversation.
2. AI adoption is moving faster than governance
This is perhaps the most uncomfortable gap facing today’s enterprises.
IBM’s 2025 Cost of a Data Breach research found that 63% of organisations studied lacked AI governance policies, while 97% of organisations that experienced an AI-related security incident reported lacking proper AI access controls.
That tells us something important.
The challenge isn’t necessarily that organisations are adopting AI too quickly.
The problem is that governance is struggling to move at the same speed.
Shadow AI makes this harder.
Employees can now adopt AI tools in minutes, often without security or technology teams knowing what information is being shared with those platforms.
IBM found that organisations experiencing breaches involving significant levels of shadow AI faced an average $670,000 increase in breach costs.
For a board, the lesson is straightforward:
If employees can deploy technology faster than the organisation can govern it, risk is already scaling.
3. The new technology risk isn’t only the technology
This is where board-level thinking must evolve.
A traditional technology review might examine:
Vendor → Architecture → Compliance → Security → Cost

An AI-era review needs a wider lens:
Technology
What does the system actually do?
Identity
Who or what can access it?
Data
What information does it consume, generate or expose?
Authority
What decisions can it influence or execute?
Dependency
Which external platforms, models and suppliers does it rely upon?
Accountability
Who owns the outcome?
Resilience
What happens when it fails?
This is particularly important as non-human identities and AI agents become part of enterprise operations.
An AI agent may not be an employee, but if it has credentials and access to critical systems, it deserves governance comparable to any other privileged identity.
4. The board needs a different dashboard
More cybersecurity metrics do not necessarily create better governance.
Boards should move away from simply asking:
- How many attacks occurred?
- How many vulnerabilities remain?
- How many alerts did we receive?
Those numbers have value.
But the boardroom needs to connect them to business consequences.
I would focus on five questions:
- Exposure
What could materially affect the organisation? - Impact
What could the financial, operational and reputational consequences be? - Readiness
How prepared are we to respond? - Accountability
Who owns the decision and the outcome? - Resilience
How quickly can we recover?
The objective is not to eliminate risk.
It is to make risk visible enough to govern.
5. AI needs governance before scale
NIST’s AI Risk Management Framework provides a useful principle: organisations should manage AI risks throughout the lifecycle rather than treating governance as a final compliance checkpoint. Its generative-AI profile specifically highlights governance, pre-deployment testing, content provenance and incident disclosure as major considerations.
For future leaders, this creates a valuable discipline:
Before deployment
Know the use case.
What business problem are we solving?
Before access
Know the data.
What information will the system touch?
Before automation
Know the authority.
What can it actually do?
Before scale
Know the failure mode.
What happens when it gets something wrong?
After deployment
Keep measuring.
AI risk changes as models, users, data and business processes change.
Governance therefore cannot be a one-time approval.
It has to become an operating capability.
6. The geopolitical dimension cannot be ignored
Technology risk is also becoming geopolitical risk.
The WEF’s 2026 outlook identifies geopolitics as a defining factor in cybersecurity, with 64% of organisations accounting for geopolitically motivated cyberattacks in their risk mitigation strategies.
For global enterprises, this raises questions around:
- Data sovereignty
- Cloud concentration
- Critical technology dependencies
- Cross-border regulations
- Supply-chain resilience
- AI model providers
- National cybersecurity requirements
A board approving an AI strategy is therefore also making decisions about dependency and resilience.
That requires a broader definition of technology leadership.
7. What future technology leaders must bring to the board
The next generation of CXOs cannot remain specialists who only understand their own function.
They need enterprise judgement.
A future technology leader should be able to translate:
Cyber risk → Business impact
AI capability → Strategic opportunity
Identity → Digital control
Data → Enterprise value
Technology dependency → Resilience
Regulation → Business constraint
Security investment → Business protection

This is the leadership evolution I believe matters most.
The future CIO, CISO, CTO or technology advisor will not create influence by knowing the most technical details in the room.
They will create influence by asking the most consequential questions.
The 10 Questions Every Board Should Ask About AI
Before approving a significant AI or technology initiative, I would put these questions on the table:
- What business outcome are we actually pursuing?
- What information will the technology access?
- What identities will interact with our systems?
- What authority will AI receive?
- Which decisions remain human-owned?
- What happens when the system fails?
- What third parties are we becoming dependent on?
- How will we detect misuse or compromise?
- What regulatory or geopolitical exposure are we creating?
- Can we scale the technology without scaling unmanaged risk?
If leadership cannot answer these questions, the organisation may not be ready to scale the technology.
The New Leadership Advantage: Responsible Speed
There is a false choice in technology leadership:
Move fast versus stay secure.
I don’t believe that is the right choice.
The stronger model is:
Move fast where risk is understood. Move carefully where consequences are irreversible.

AI can dramatically improve productivity, decision-making and competitive advantage.
The WEF reports that 77% of organisations are already using AI in cybersecurity operations, showing that AI isn’t merely creating risk; it is also becoming an important defensive capability.
The leadership challenge is therefore not to resist AI.
It is to build the conditions under which AI can be trusted at scale.
The Boardroom Playbook
For organisations entering the next stage of AI adoption, I would keep the playbook simple:
1. Govern before scaling
Don’t wait for an incident to create accountability.
2. Treat AI identities as enterprise identities
Know what every agent can access and why.
3. Connect cybersecurity to strategy
Security should influence investment decisions; not simply review them afterwards.
4. Measure business resilience
Track whether the organisation can continue operating when technology fails.
5. Build AI literacy at board level
PwC’s 2026 research found that 71% of directors identify AI as the board capability most in need of strengthening.
6. Make accountability explicit
Automation should never mean ownership disappears.
The Real Boardroom Question
The next decade will not be defined simply by how much AI enterprises deploy.
It will be defined by how intelligently they govern it.
Technology leaders therefore have a larger responsibility ahead.
We must help boards move from technology awareness to technology judgement.
From cybersecurity reporting to cyber governance.
From AI experimentation to accountable AI adoption.
And from risk avoidance to resilient growth.
Because the strongest organisations of the AI era will not necessarily be the ones that move first.
They will be the ones that know where to move, how far to move and what must remain under human control.
My boardroom rule is simple:
Don’t ask only what the technology can do.
Ask what the organisation becomes responsible for once it can.
That is the conversation future leaders must be ready to lead.
