The Board’s New AI Governance Playbook

AI adoption is accelerating. Board-level accountability has to accelerate with it.

AI has moved beyond experimentation.

It is entering customer operations, cybersecurity, software development, financial processes, decision support and increasingly autonomous workflows. That changes the responsibility of the board.

As a CXO who has spent years navigating technology transformation and cybersecurity, I see the challenge differently from the traditional “AI adoption versus AI risk” debate.

The question is no longer whether the organisation should use AI.

The board needs to decide how much authority AI should receive, and how that authority will be governed.

The World Economic Forum describes this shift clearly: boards are increasingly reallocating decision rights to autonomous systems while still relying on governance models designed around human judgement.

That gap is where the next generation of technology risk will emerge.


Why AI Governance Has Become a Board Issue

For years, technology governance could often be delegated to management.

AI is different because its impact can cross almost every enterprise function simultaneously.

An AI system can influence:

  • Customer decisions
  • Employee productivity
  • Financial processes
  • Cybersecurity operations
  • Intellectual property
  • Data management
  • Regulatory exposure
  • Third-party relationships
  • Business continuity

This makes AI governance an enterprise governance issue, not simply a technology programme.

McKinsey and the National Association of Corporate Directors identified four priorities for effective board oversight: stronger governance and accountability, balancing innovation with risk, real-time risk management and greater AI fluency in the boardroom.

That is the direction I believe boards need to take.

1. Start With Authority, Not Technology

One of the most important questions a board can ask is:

“What are we allowing this AI system to do?”

This question becomes particularly important with agentic AI.

An AI agent is not simply producing an answer. Depending on its design, it can interact with applications, retrieve information, trigger workflows and perform actions.

NIST’s 2026 AI Agent Standards Initiative specifically recognises that AI agents can autonomously perform tasks and interact with internal data and external systems.

That creates a new governance requirement.

Boards need visibility into:

Capability → Access → Authority → Oversight → Accountability

An AI system may be capable of acting without being authorised to perform it.

That distinction should become fundamental to AI risk management.

2. Put Identity at the Centre of AI Governance

There is another issue that deserves board-level attention: AI identity and authorisation.

If an AI agent can access enterprise applications, data or APIs, the organisation needs to know precisely:

  • What identity does it use?
  • Who owns that identity?
  • What permissions does it have?
  • Which systems can it access?
  • What actions can it perform?
  • How is its activity monitored?
  • How quickly can its access be revoked?
NIST published an initial public draft in February 2026 specifically addressing software and AI-agent identity and authorisation, highlighting the risks created when agents receive access to diverse datasets, tools and applications.

This is where AI governance, identity governance, IAM and cybersecurity begin to converge.

The board doesn’t need to design the identity architecture.

But it should demand clarity on who or what is receiving authority inside the enterprise.

3. Move From Policies to Accountability

A policy document alone does not create governance.

Someone must own the decision.

NIST’s AI Risk Management Framework explicitly calls for documented accountability structures and states that executive leadership should take responsibility for decisions concerning AI risks. It also recommends clarifying roles across the AI lifecycle, from development and deployment to assessment and monitoring.

For boards, that means asking:

Who owns the AI portfolio?

Who defines the acceptable risk?

Who can approve deployment?

Who can stop a system?

Who monitors performance after launch?

Who owns the consequences of an AI failure?

If those answers are unclear, the governance model is incomplete.

4. Replace the AI Dashboard with an AI Risk Conversation

Boards do not need another screen filled with technical metrics.

They need decision-quality information.

A useful board-level AI risk view should connect technology performance to enterprise consequences.

I would structure the conversation around five dimensions:

Business Impact

What value is AI creating, and what could it disrupt?

Risk Exposure

What could materially harm the organisation?

Authority

What decisions or actions have been delegated to AI?

Resilience

How quickly can the organisation detect, contain and recover from failure?

Accountability

Who owns the outcome?

This moves the board conversation from:

“How well is the AI performing?”

to:

“Are we comfortable with what the AI is permitted to influence?”

That is a much more strategic question.

5. Govern the Entire AI Lifecycle

One of the strengths of the NIST AI Risk Management Framework is that it does not treat governance as a one-time approval.

Its four core functions are:

Govern → Map → Measure → Manage

NIST describes AI risk management as a continuous process that should operate throughout the AI lifecycle.

For the board, that translates into a simple principle:

Approval should never be the end of governance.

AI systems change.

Models change.

Data changes.

Users change.

Threats change.

Business processes change.

Therefore, the risk profile can change after deployment.

The governance model needs to change with it.

6. Establish Clear Human-AI Boundaries

The phrase “human in the loop” sounds reassuring, but it can be meaningless unless the organisation defines what human oversight actually means.

A board should establish clear boundaries around:

  • Decisions AI can make independently
  • Decisions requiring human approval
  • Actions requiring additional verification
  • Situations requiring immediate escalation
  • Circumstances in which the AI system must be suspended

NIST recommends explicitly defining human roles and responsibilities around AI systems, including oversight, monitoring, testing and deployment.

The objective is not to prevent autonomy.

It is to make autonomy intentional.

7. Treat AI Risk as Enterprise Risk

AI governance should not sit in a separate organisational silo.

It should connect with existing:

Enterprise Risk Management

Cybersecurity

Data Governance

Privacy

Compliance

Third-Party Risk

Business Continuity

Internal Audit

This is particularly important because AI risk can move across organisational boundaries much faster than traditional technology risk.

A third-party AI model can become a data-risk issue.

An AI agent can become an identity-risk issue.

An automated decision can become a regulatory issue.

A compromised model can become a business-continuity issue.

The board therefore needs one integrated view of the risk landscape.

8. Build an AI Governance Playbook Around Six Questions

If I were helping an organisation establish its board-level AI governance structure today, I would begin with six questions.

  • What AI are we using?

Maintain visibility across approved, experimental and potentially unapproved AI.

  • Why are we using it?

Every deployment should have a defined business purpose.

  • What can it access?

Map data, applications, credentials and third-party dependencies.

  • What can it do?

Separate recommendation, decision and execution authority.

  • Who is accountable?

Assign ownership before deployment.

  • When do we stop it?

Define escalation, suspension and decommissioning criteria.

These questions create a practical bridge between AI strategy and AI governance.

The CXO Perspective: Governance Should Enable Speed

I don’t believe governance should become another layer of bureaucracy that prevents organisations from experimenting.

That approach will fail.

The objective should be responsible speed.

When boundaries are clear, teams can move faster because they understand what is permitted.

When identity is controlled, access becomes easier to manage.

When accountability is assigned, decisions become easier to escalate.

When risk is measurable, leadership can make informed trade-offs.

NIST itself describes its AI RMF Playbook as voluntary guidance rather than a rigid checklist, allowing organisations to adapt the framework to their specific context.

That flexibility matters.

Every organisation will have a different risk appetite.

But every organisation needs defined governance.

The Future Boardroom Will Govern Machines, Not Just Managers

This is the leadership shift I believe deserves serious attention.

Boards have traditionally governed people, capital, strategy and organisational structures.

The next generation of boards will increasingly govern human-machine systems.

That requires a different kind of technology fluency.

Future leaders will need to understand not only:

What technology can do

but also:

What authority technology should have.

They will need to connect AI governance with cybersecurity, identity governance, digital trust, enterprise risk and business strategy.

And they will need to ask questions that technical dashboards cannot answer.

The New Boardroom Checklist

Before approving a major AI deployment, I would want the board to be able to answer:

  • What business problem are we solving?
  • What data will AI access?
  • What authority will it receive?
  • What identities will operate inside the system?
  • What decisions remain human-owned?
  • How will we detect abnormal behaviour?
  • Who can revoke access?
  • What happens when the system fails?
  • Who owns the outcome?
  • How will we know when the risk profile has changed?

If leadership cannot answer these questions, the organisation may not have an AI adoption problem.

It may have an AI governance problem.


Final Thought

AI governance should not be the mechanism that tells an organisation “Don’t move.”

It should provide the confidence to answer:

“We know where we are moving, what authority we are delegating, what could go wrong and who is accountable.”

That is the difference between AI adoption and AI leadership.

As a CXO, my view is simple:

The future will not belong to organisations that merely deploy AI faster.

It will belong to organisations that can scale AI without losing control of identity, risk, accountability and trust.

And that is why the board’s new AI governance playbook cannot be written as an IT document.

It has to become part of enterprise strategy.

Sources & further reading

Table of Contents

More Related
Published on September 27, 2026