AI Has a Seat at the Table. Who Holds the Gavel?

AI is no longer just advising the enterprise. It is beginning to act inside it. That changes the question every board should be asking.

For years, technology helped people make decisions.

Now, increasingly, technology can initiate actions, execute workflows and influence outcomes.

That is a fundamentally different proposition.

As a CXO, I see the opportunity clearly. AI agents can remove friction, accelerate operations and give organisations capabilities that were difficult to achieve at scale.

But there is another side to that equation.

When an AI system can act, leadership must decide where its authority ends.


The Boardroom Is Entering a New Phase

The World Economic Forum reports that 94% of cyber leaders identify AI as the defining force in cybersecurity, while 77% of organisations are already using AI in cybersecurity operations.

At the same time, boards are beginning to confront a more fundamental governance question.

Recent World Economic Forum research found that 49% of directors are actively reviewing which board decisions should remain human-led as AI becomes more capable.

That is the conversation I believe deserves more attention.

We have spent considerable time asking:

What can AI do?

The next question should be:

What should AI be allowed to decide or execute?

Autonomy Changes the Risk Equation

A traditional software application waits for instructions.

An AI agent can potentially interpret a goal, determine a sequence of actions and interact with multiple systems.

NIST’s 2026 work on AI-agent identity and authorisation specifically highlights the risks created when agents receive access to diverse data sets, tools and applications.

That means organisations need to think beyond model performance.

They need to think about authority.

An AI system may be highly accurate and still create significant enterprise exposure if it has excessive permissions or unclear decision boundaries.

Before giving an AI system authority, leadership should know:

  • What can it access?
  • What can it change?
  • Which decisions can it make independently?
  • What requires human approval?
  • How is every action recorded?
  • Who can revoke its authority?
  • Who owns the consequence when something goes wrong?

These are not merely technical questions.

They are governance questions.

The Accountability Gap

This is where I believe many organisations could face their next leadership challenge.

Boards traditionally govern people, functions, committees and management structures.

AI introduces another operational actor.

The World Economic Forum describes this as a shift towards organisations in which technology itself becomes an operational actor, requiring boards to define which decisions can be delegated to AI and under what safeguards.

That requires a different governance architecture.

Not more bureaucracy.

Clearer boundaries.

For example:

AI can recommend.
Human approves.

Or:

AI can execute low-risk actions.
Human intervention is mandatory for high-impact decisions.

The exact boundary will differ by organisation and industry.

What cannot differ is the existence of a boundary.

The Five Rules I Would Put on the Board Agenda

1. Define decision rights before deployment

Don’t begin with the question of how autonomous the system can become.

Begin with where autonomy is acceptable.

2. Treat AI agents as governed digital actors

If an agent can access enterprise systems, it needs an identity, defined permissions, ownership and monitoring.

3. Separate capability from authority

An AI system may be technically capable of performing an action without being authorised to perform it.

That distinction is critical.

4. Make high-impact decisions traceable

For consequential decisions, organisations should be able to establish what the AI did, what information influenced it and where human judgement entered the process.

5. Keep accountability human

AI can participate in a decision.

It cannot carry corporate accountability.

That remains a leadership responsibility.

The Board Doesn’t Need to Become Technical

This is another misconception worth challenging.

Boards don’t need to understand how every AI model works.

They need enough AI literacy to challenge assumptions, understand exposure and govern outcomes.

PwC’s 2026 board research found that 71% of directors say AI is the board capability most in need of strengthening. PwC recommends that boards treat AI as an enterprise transformation involving strategy, operations, talent, capital allocation and risk; not simply as a technology programme.

That is the direction I believe executive leadership needs to take.

The boardroom should not become a technical lab.

It should become the place where technology’s authority is consciously governed.

From Human-in-the-Loop to Human-in-Command

The phrase human-in-the-loop has become common in AI discussions.

But I believe the next conversation needs to go further.

The important question isn’t simply whether a human can intervene.

It is whether leadership has deliberately designed:

who has authority,

when intervention is mandatory,

what evidence is required,

and who owns the outcome.

That is closer to human-in-command thinking. It puts accountability where it belongs while allowing automation to operate at scale.

What Future Leaders Need to Understand

The next generation of technology leaders will inherit organisations where humans and AI systems work alongside each other.

Their responsibility will therefore extend beyond cybersecurity, infrastructure or digital transformation.

They will need to understand the intersection of:

  • AI governance
  • Cybersecurity
  • Identity and access management
  • Technology risk
  • Digital trust
  • Data governance
  • Enterprise resilience
  • Board oversight

NIST has already begun work specifically around identity and authorization for AI agents, reflecting how important this issue is becoming as autonomous systems interact with enterprise resources.

The leadership opportunity is significant.

The organisations that establish sensible controls early can pursue AI adoption without allowing autonomy to become unmanaged authority.


My Boardroom Perspective

I don’t believe the answer is to keep AI away from important decisions.

That would ignore the enormous potential of intelligent systems.

The answer is to become much more deliberate about where we give AI authority.

I would rather see an organisation with a highly capable AI system operating within clearly defined boundaries than a less capable system operating without them.

Because the real competitive advantage will not come simply from having AI.

It will come from knowing how much authority to give it;and having the governance to enforce that decision.

The question I would take into the boardroom is simple:

“If AI can act, have we clearly decided where it is allowed to act?”

If the answer isn’t clear, the organisation isn’t facing an AI problem.

It is facing a governance problem.

And that may become one of the defining leadership challenges of the AI era.


Table of Contents

More Related